National Critical Infrastructure, Cyberthreats, Attack Strategies, Mitigations
ITS 834 Emerging Threats & Countermeasures
Week 7 – Awareness
Dr. Brian Toevs ([email protected])
1
Reference
Amoroso, E. (2012). Cyber attacks: Protecting national infrastructure, 1st Ed. Butterworth-Heinemann.
Introduction
Welcome to our seventh week together covering the protection of our national infrastructure. This week we’ll be
examining awareness of cyberthreat intelligence.
IMPORTANT: Next week is a short week ending on Wednesday night at midnight!
Assigned Reading
Textbook Chapter 10 covering discretion as a mechanism of protecting
the digital infrastructure of our national cybersecurity infrastructure.
Discussion
Pick a cyberthreat intelligence provider.
Identify its audience and the type of information shared.
Provide a history of independent reviews of the provider.
Explain why you would use and / or recommend this provider to your peers.
I ran out of room for all the logos
that I could find
ITS 834 Emerging Threats & Countermeasures
Week 7 – Awareness
Dr. Brian Toevs ([email protected])
2
Learning Outcomes
This week we will be learning about how to utilize awareness in support of the
national critical infrastructure. We will also look at how we can use passive protections to decrease the likelihood
of vulnerability discovery. The less that you look like a target and the less attention you draw to yourself
decreases the likelihood of an intentional attack.
Awareness
What is awareness and how does it apply to the national critical infrastructure?
Describe the Cybersecurity Awareness Lifecycle.
Explain the difference between perception of awareness at the national level versus the local level on your own network and how they interact.
Describe effective use of employee training to increase awareness.
Keep current in best practices through personal training.
Explain the impact of the mobile workforce on awareness
Identify your exposure.
Reference
Amoroso, E. (2012). Cyber attacks: Protecting national infrastructure, 1st Ed. Butterworth-Heinemann.
ITS 834 Emerging Threats & Countermeasures
Week 7 – Awareness
Dr. Brian Toevs ([email protected])
3
Research Paper – Case Study
This week you have a requirement to create a research paper as a final term project. You are required to
select one case study from the textbook, research the topic, and report on the case.
Content
The structure of your paper should be about seven to eight pages, not including
the title, abstract, and reference pages. That’s seven to eight pages of content.
Your submission must be in full APA 7th Edition format.
Title page (no Running Head):
Abstract
Body (7-8 pages)
Introduction
Case Study with appropriate citation
Discussion
Conclusion
Proper Section Headers
References (at least four)
Correct grammar, spelling, form, and format.
ITS 834 Emerging Threats & Countermeasures
Week 7 – Awareness
Dr. Brian Toevs ([email protected])
4
Awareness
The principle of awareness involves an organization understanding the differences, in real time and at all times,
between observed and normal status in national infrastructure. This status can include risks, vulnerabilities, and
behavior in the target infrastructure.
Behavior refers here to the mix of user activity, system processing, network traffic, and computing volumes in the
software, computers, and systems that comprise infrastructure.
Situational awareness refers to the collective real-time understanding
within an organization of its security risk posture. Security risk measures
the likelihood that an attack might produce significant consequences to
some set of locally valued assets.
Amoroso, E. (2012). Cyber attacks: Protecting national infrastructure,
1st Ed. Butterworth-Heinemann.
www.samatters.com/
ITS 834 Emerging Threats & Countermeasures
Week 7 – Awareness
Dr. Brian Toevs ([email protected])
5
Cybersecurity Awareness Lifecycle
Cybersecurity awareness is an ongoing effort by the cybersecurity professional. The threat landscape is constantly
changing and we must also continuously adapt to the cyberthreats as they adapt and exploit our systems.
Closing the Loop
Identify Threats – We now know where to go look for cyberthreat intelligence information, how to correlate it, and how to apply it to our cyber defense.
Identify Vulnerabilities – Knowing the threats that apply to our systems allows us to prepare a proper and relevant defense.
Access Risk Exposure – Prioritize the threat – vulnerability combinations to address the most critical first.
Develop Protection and Detection Measures – You will have intrusion detection / intrusion protection systems.
Establish Contingency Plans – Systems will go end-of-life. What are you going to do then?
Respond to Cyber Security Incidents – Develop an Incident Response Plan. Participate in sector-wide tabletop incident tabletop exercises
https://s3-eu-west-2.amazonaws.com/north-live/
ITS 834 Emerging Threats & Countermeasures
Week 7 – Awareness
Dr. Brian Toevs ([email protected])
6
The Complete Cyberspace Awareness Picture
Cybersecurity is about more than just your local network. There
is an entire national critical infrastructure sector relying upon
you to participate and contribute.
Network Awareness – Asset management, control over configurations, vulnerability auditing, patch management, and compliance reporting.
Threat Awareness – Monitor and respond to internal incidents and suspicious behavior and integrate external threat intelligence.
Mission Awareness – Establish a comprehensive image of your critical dependencies through the cybersecurity awareness lifecycle.
Infrastructure Sector Awareness – Support your sector critical infrastructure cyberthreat intelligence providers by sharing your own threat information taken from your internal monitoring systems.
https://www.valuewalk.com/
ITS 834 Emerging Threats & Countermeasures
Week 7 – Awareness
Dr. Brian Toevs ([email protected])
7
Training, training, and more training
What do you think could be a better way to increase cybersecurity awareness within your organization or across
the national critical infrastructure sector than training?
Focused Training – Inside the Organization
Establish a culture of cybersecurity protection Business email compromise continues to be the most vulnerable aspect of security your local networks
Online training providers take the trouble out of your responsibility
Repeat the training at least every year
Test the effectiveness of your training
Focused Training – Sector-wide
Infrastructure support training from your sector cyberthreat intelligence resources
https://threatshieldsecurity.com/
ITS 834 Emerging Threats & Countermeasures
Week 7 – Awareness
Dr. Brian Toevs ([email protected])
8
Continuous Ongoing Professional Training Requirement
Continuous training for assessing risks, threats, and evaluating
trends in best practices for cybersecurity is a mandatory requirement
for the cybersecurity professional.
DoD 8570.01M Information Assurance Workforce Improvement
Program (WIP)
The program that you see here is only one of many annual training
events tailored specifically to the national critical infrastructure.
Most have sector-specific programs that are tailored to the
industry that represents your organization. A mix of sector-specific
programs and global infrastructure programs will provide an
excellent exposure to the best practices and threat mitigation
strategies that are going to be critical for you to master in support
of your own organization and the national critical infrastructure as
a whole.
https://public.cyber.mil/training/cyber-awareness-challenge/
ITS 834 Emerging Threats & Countermeasures
Week 7 – Awareness
Dr. Brian Toevs ([email protected])
9
Awareness Extends Beyond the Physical Boundaries of your Organization
Remote workforce, mobile devices, third party providers, Cloud services are the new realities of the modern
workforce. This is also true for critical infrastructure systems and organizations. Maintaining communications
and oversight of this mobile workforce is going to be the new challenge for organization leadership.
Maintaining Communications
Awareness includes knowing what your employees are doing. It’s
facilitating interactions between them while working away from the
centralized office environment. It’s protecting a
wider range of systems and devices that may not
be ‘owned’ by the organization. It’s providing 24-
hour support for teams that used to work set office
hours. It’s increasing efficiency of the workplace
while maintaining security controls and overall
cybersecurity compliance within your sector
rules and regulations.
https://cyware.com/cyber-threat-situational-awareness
ITS 834 Emerging Threats & Countermeasures
Week 7 – Awareness
Dr. Brian Toevs ([email protected])
10
Know Your Exposure
A crucial component of heightening your cyber-defensive awareness is knowing where the threats are originating.
Two simple ways to prioritize your focus are through geographic location and industry sector. Where you are and
what you do plays an important role in your exposure to cyber-attackers.
What are the most Vulnerable Sectors and Regions?
California, New York, Texas, and Florida suffer from the greatest
number of breaches across the country.
Source: Comparitech retrieved from https://docs.google.com/spreadsheets/d/1n2Ck49UtCQf_jtlk2edKj9gM_MLCNd4fqVimhsu6AUs/
edit#gid=856445414
Industry breakdown of incident response reports are:
Healthcare (including Biotech and Pharma) – 25%
Financial Services (including Insurance) – 17%
Professional Services (Engineering and Transportation) – 17%
Retail (including media and entertainment) – 12%
Education – 11%
Source: BakerHostetler retrieved from https://www.bakerlaw.com/
https://norse-corp.com/
ITS 834 Emerging Threats & Countermeasures
Week 7 – Awareness
Dr. Brian Toevs ([email protected])
11
Conclusion
This week you were asked to read Chapters 10 of our textbook. In addition to the lecture you have just followed,
you should have met the learning objectives expected of you this week. You will now be evaluated on the
retention of this material through your Discussion posts and weekly Quiz.
Next Week
Read Chapter 11 of your textbook about Response. You will have a Discussion thread to post and a quiz on the material presented in the textbook. Remember that next week ends on Wednesday night at midnight.
Lessons Learned
What is awareness and how does it apply to the national critical infrastructure?
Describe the Cybersecurity Awareness Lifecycle.
Explain the difference between perception of awareness at the national level versus the local level on your own network and how they interact.
Describe effective use of employee training to increase awareness.
Keep current in best practices through personal training.
Explain the impact of the mobile workforce on awareness
Identify your exposure.
Don’t forget that the course closes
next Wednesday night at midnight.
All Discussion posts and your quiz
must be completed prior to this
deadline.