The CISO Evolution: Business Knowledge for Cybersecurity Executives by Matthew K. Sharp & Kyriakos P. Lambros

The CISO Evolution: Business Knowledge for Cybersecurity Executives by Matthew K. Sharp & Kyriakos P. Lambros

Author:Matthew K. Sharp & Kyriakos P. Lambros [Sharp, Matthew K. & Lambros, Kyriakos P.]
Language: eng
Format: epub
ISBN: 9781119782490
Publisher: Wiley
Published: 2022-01-10T00:00:00+00:00


An example STRIDE threat model can be found at https://www.logicworks.com/blog/2020/02/security-risks-in-public-cloud/. However, no matter which method you use, it is vital to consider them in the context of the threat actors (e.g., script kiddies versus nation-states) and their impact as the result of their actions.

IDENTIFYING POTENTIAL ATTACK SCENARIOS

Now that we understand how to identify threats, we need to determine how they can exploit our environment's weaknesses. Again, a threat cannot become a risk unless there is a weakness that the threat can exploit. That is where our traditional understanding of vulnerabilities come in. As we mentioned earlier, vulnerabilities may exist in areas such as business continuity, training, utilities, supply chain, and physical access, so it is essential to understand vulnerabilities across more than just the traditional Common Vulnerabilities and Exposures (CVEs) that an automated scanner can identify. On the flipside, a vulnerability is not a risk unless a threat is willing to exploit it.

Here is another example of why understanding business context is essential. Attack scenarios will differ for your type and size of organization. A Fintech startup will have vastly differing attack scenarios than a nuclear power plant. Take the time to identify the attack scenarios that attackers are most likely to use in your environment.

You can use many methods to identify attack scenarios for your organization, but our preferred method is to directly look at the organization. No data is more relevant than looking at yourself in the mirror. The three primary approaches to do so are penetration testing, red teaming, and threat hunting. No matter which method you use, the Mitre ATT&CK™ framework (https://attack.mitre.org) is a great resource for identifying attack scenarios for many environments, including on-premise enterprise, cloud, and industrial control systems. Figure 7.1 highlights the similarities and differences between each.

A penetration test (pentest) “is an authorized simulated cyberattack on a computer system, performed to evaluate the security of the system.”7 A penetration test aims to find and exploit as many vulnerabilities as possible that can lead to a compromise. Of the three approaches we describe, this is more of a “spray and pray” approach vs. a more targeted approach. Pentests typically only focus on compromising a vulnerable application or service to gain access to the network. A goal is usually defined, but the pentest team is generally not concerned with remaining hidden. This approach is akin to a burglar testing all of the windows and doors to a home in broad daylight. The organization's security operations team may or may not know the pentest is occurring, so security defenses and controls can be tested, to an extent.



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.
Popular ebooks
Eco-friendly approach of bio-indigo synthesis and developing purification methods towards isolation of indigo from indirubin and bacterial fragments by Ramalingam Manivannan & Kaliyan Prabakaran & Young-A Son(211338)
Personalized inhaled bacteriophage therapy for treatment of multidrug-resistant Pseudomonas aeruginosa in cystic fibrosis by unknow(179726)
CONSORT 2025 statement: updated guideline for reporting randomized trials by unknow(88290)
Critical evaluation of the ProfiLER-02 study design and outcomes by Vivek Subbiah & Razelle Kurzrock(87835)
Cardiac gene therapy makes a comeback by Oliver J. Müller & Susanne Hille & Anca Kliesow Remes(87622)
Whisky: Malt Whiskies of Scotland (Collins Little Books) by dominic roskrow(74449)
Unveiling the design rules for tunable emission in graphene quantum dots: A high-throughput TDDFT and machine learning perspective by Şener Özönder & Mustafa Coşkun Özdemir & Caner Ünlü(50900)
A yeast-based oral therapeutic delivers immune checkpoint inhibitors to reduce intestinal tumor burden by unknow(40267)
Covalent hitchhikers guide proteins to the nucleus by Alexander F. Russell & Madeline F. Currie & Champak Chatterjee(40219)
Meet the Authors: Christopher R. Mansfield and Emily R. Derbyshire by Christopher R. Mansfield & Emily R. Derbyshire(40101)
Alkaline-earth metals promote propane dehydrogenation with carbon dioxide through geometric effects: Altering the reaction pathway by unknow(32738)
Induced iron vacancies boosting FeOOH loaded on sustainable Fenton-like collagen fiber membrane for efficient removal of emerging contaminants by unknow(32515)
Efficient electric-field-assisted photochemical conversion of methane to n-propanol exclusively over penetrated TiO2Ti hollow fibers by Guanghui Feng(32458)
Bi2SiO5 nanosheets as piezo-photocatalyst for efficient degradation of 2,4-Dichlorophenol by Hangyu Shi & Yifu Li & Lishan Zhang & Guoguan Liu & Qian Zhang & Xuan Ru & Shan Zhong(32396)
A novel NDIPTA organic heterojunction photocatalyst with built-in electric field for efficient hydrogen production by Jiahui Yang & Baojun Ma & Yongfa Zhu(32369)
Enhanced conversion of methane to liquid-phase oxygenates via hollow ferrite nanotube@horseradish peroxidase based photoenzymatic catalysis by Jun Duan & Shiying Fan & Xinyong Li & Shaomin Liu(32335)
Ordered macroporous superstructure of defective carbon adorned with tiny cobalt sulfide for selective electrocatalytic hydrogenation of cinnamaldehyde by Xiao-Shi Yuan & Sheng-Hua Zhou & San-Mei Wang & Wenbo Wei & Xiaofang Li & Xin-Tao Wu & Qi-Long Zhu(32261)
What's Done in Darkness by Kayla Perrin(27155)
Topological analysis of non-conjugated ethylene oxide cored dendrimers decorated with tetraphenylethylene: Insights from degree-based descriptors using the polynomial approach by A Theertha Nair & D Antony Xavier & Annmaria Baby & S Akhila(26536)
Investigation of mechanical and self-healing properties of hydroxyl-terminated polybutadiene functionalized with 2-ureido-4-pyrimidinone by Mohsen Kazazi & Mehran Hayaty & Ali Mousaviazar(26463)