Risk: What could go wrong?
How Industry Security Requirements Drive Cyberthreat Resilience

- Reputation is a new target for cyber-attacks – all industries
- Criminals value our information – financial, health, critical infrastructure, all industries
- Cyber risk is challenging to understand and address and involves regulations imposed by all industries
- The changing pace of technology increases unknown dependency on third parties and shadow IT
- We cannot trace or control our data
- The role of government and information custody is often misunderstood
Here's a summary of points from this training.
Cybersecurity Mission: Resilience
- What are our critical assets?
- Who is responsible for them?
- Is everyone involved in cyber-resilience?
- Do they have the knowledge and autonomy to make good decisions?
- Are we prepared for when there is a successful attack?
- Will there be a tried and tested process to follow, or will a cyber-attack throw our organization into complete chaos?
We’ve been having a continuous compliance conversation
Compliance is a fabric that breaks down over time
There are many threads in compliance fabric
- Industry – health, finance, consumer, education, government – have different objectives and regulating bodies who impose laws in response to the risks surrounding those objectives
- Audits, Examinations, Assessments – SOC 2, ISO27001+Cloud, Privacy, and Processing..., FFIEC Examination, SOX ITGCC, HIPAA/HITECH compliance, PCI DSS - (people show up, the board gets reports, involves public disclosure, can result in criminal charges)
- Guidance or Guideline - Documents that HELP, explain how to do it – in some cases, guidance supports a policy, so it determines “how” we comply.
- Frameworks – COSO, Cobit, ITIL, NIST 800-53, Cyber Security Framework, CIS CSC, gives us longitude, latitude (frames how and what we govern)
- Standards – criteria based best practice, DISA STIGs, CIS Benchmark, SCAP
- Standard are accepted as best practices whereas frameworks are practices that are generally employed
- Standards are specific while frameworks are general
- Mandates, Orders, Laws – You must comply (CFR)
- Families or Domains – people, technologies, and processes that we generally consider related
- Universe – a collection of processes associated with tests and controls, grouped by families or domains – used to organize ASSESSMENTS
- Controls – are processes, what we do to enforce and govern, for example, “manage change”
- Tests – how we measure it happened. A test can have many sub-items, but in aggregation, the set of measures tell us if the control process is effective. We tie Policy items to Tests. Tests are in Universe.
- Policies – what we tell people they must do – usually, they are within ISO27002 ISMS and the soon-to-release ISO/IEC FDIS 27002, measured by the ISO27001 assessment.
- Policy Items – (system policy) discrete configuration items
(You can open this presentation full screen and it's available for local download. All of our MP4 videos are scanned twice daily.)
What do we want from a fabric?
- When it's hot – let us breathe
- When it's cold – add layers
- Last a long time – holding shape
- Tell the world our story and style – reporting, informing, aligning
- Shrink and Expands – agility, adaptability
- Provide protection – protect our assets, and us (our business, our reputation, our family)
Before we acquire a fabric, let’s examine what we need
- Need begins with (industry) risk
- What are the industries where we see groups of specific types of risk?
- How do industries describe their risks & controls?
Predominantly, industries use NIST SP800-37 Risk Management Framework – RMF
Risk: What could go wrong?
- Reputation is a new target for cyber-attacks – all industries
- Criminals value our information – financial, health, critical infrastructure, all industries
- Cyber risk is challenging to understand and address, the regulation imposed by all industries
- The changing pace of technology increases unknown dependency on third parties and shadow IT
- We cannot trace or control our data
- The role of government and information custody is often misunderstood
Exercise: Identify a risk that is not in your industry.
What behaviors provide most protection?
- Control Administrative Privileges
- Limiting Workstation-to-Workstation Communication
- Antivirus File Reputation Services
- Anti-Exploitation
- Host Intrusion Prevention (HIPS) Systems
- Secure Baseline Configuration
- Web Domain Name System (DNS) Reputation
- Take Advantage of Software Improvements
- Segregated Networks and Functions
- Application Whitelisting

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics