National Critical Infrastructure, Cyberthreats, Attack Strategies, Mitigations

profiletestnik2
EmergingThreatsandCountermeasuresWeek7Lecture-Awareness.pptx

ITS 834 Emerging Threats & Countermeasures

Week 7 – Awareness

Dr. Brian Toevs ([email protected])

1

Reference

Amoroso, E. (2012). Cyber attacks: Protecting national infrastructure, 1st Ed. Butterworth-Heinemann.

Introduction

Welcome to our seventh week together covering the protection of our national infrastructure. This week we’ll be

examining awareness of cyberthreat intelligence.

IMPORTANT: Next week is a short week ending on Wednesday night at midnight!

Assigned Reading

Textbook Chapter 10 covering discretion as a mechanism of protecting

the digital infrastructure of our national cybersecurity infrastructure.

Discussion

Pick a cyberthreat intelligence provider.

Identify its audience and the type of information shared.

Provide a history of independent reviews of the provider.

Explain why you would use and / or recommend this provider to your peers.

I ran out of room for all the logos

that I could find

ITS 834 Emerging Threats & Countermeasures

Week 7 – Awareness

Dr. Brian Toevs ([email protected])

2

Learning Outcomes

This week we will be learning about how to utilize awareness in support of the

national critical infrastructure. We will also look at how we can use passive protections to decrease the likelihood

of vulnerability discovery. The less that you look like a target and the less attention you draw to yourself

decreases the likelihood of an intentional attack.

Awareness

What is awareness and how does it apply to the national critical infrastructure?

Describe the Cybersecurity Awareness Lifecycle.

Explain the difference between perception of awareness at the national level versus the local level on your own network and how they interact.

Describe effective use of employee training to increase awareness.

Keep current in best practices through personal training.

Explain the impact of the mobile workforce on awareness

Identify your exposure.

Reference

Amoroso, E. (2012). Cyber attacks: Protecting national infrastructure, 1st Ed. Butterworth-Heinemann.

ITS 834 Emerging Threats & Countermeasures

Week 7 – Awareness

Dr. Brian Toevs ([email protected])

3

Research Paper – Case Study

This week you have a requirement to create a research paper as a final term project. You are required to

select one case study from the textbook, research the topic, and report on the case.

Content

The structure of your paper should be about seven to eight pages, not including

the title, abstract, and reference pages. That’s seven to eight pages of content.

Your submission must be in full APA 7th Edition format.

Title page (no Running Head):

Abstract

Body (7-8 pages)

Introduction

Case Study with appropriate citation

Discussion

Conclusion

Proper Section Headers

References (at least four)

Correct grammar, spelling, form, and format.

ITS 834 Emerging Threats & Countermeasures

Week 7 – Awareness

Dr. Brian Toevs ([email protected])

4

Awareness

The principle of awareness involves an organization understanding the differences, in real time and at all times,

between observed and normal status in national infrastructure. This status can include risks, vulnerabilities, and

behavior in the target infrastructure.

Behavior refers here to the mix of user activity, system processing, network traffic, and computing volumes in the

software, computers, and systems that comprise infrastructure.

Situational awareness refers to the collective real-time understanding

within an organization of its security risk posture. Security risk measures

the likelihood that an attack might produce significant consequences to

some set of locally valued assets.

Amoroso, E. (2012). Cyber attacks: Protecting national infrastructure,

1st Ed. Butterworth-Heinemann.

www.samatters.com/

ITS 834 Emerging Threats & Countermeasures

Week 7 – Awareness

Dr. Brian Toevs ([email protected])

5

Cybersecurity Awareness Lifecycle

Cybersecurity awareness is an ongoing effort by the cybersecurity professional. The threat landscape is constantly

changing and we must also continuously adapt to the cyberthreats as they adapt and exploit our systems.

Closing the Loop

Identify Threats – We now know where to go look for cyberthreat intelligence information, how to correlate it, and how to apply it to our cyber defense.

Identify Vulnerabilities – Knowing the threats that apply to our systems allows us to prepare a proper and relevant defense.

Access Risk Exposure – Prioritize the threat – vulnerability combinations to address the most critical first.

Develop Protection and Detection Measures – You will have intrusion detection / intrusion protection systems.

Establish Contingency Plans – Systems will go end-of-life. What are you going to do then?

Respond to Cyber Security Incidents – Develop an Incident Response Plan. Participate in sector-wide tabletop incident tabletop exercises

https://s3-eu-west-2.amazonaws.com/north-live/

ITS 834 Emerging Threats & Countermeasures

Week 7 – Awareness

Dr. Brian Toevs ([email protected])

6

The Complete Cyberspace Awareness Picture

Cybersecurity is about more than just your local network. There

is an entire national critical infrastructure sector relying upon

you to participate and contribute.

Network Awareness – Asset management, control over configurations, vulnerability auditing, patch management, and compliance reporting.

Threat Awareness – Monitor and respond to internal incidents and suspicious behavior and integrate external threat intelligence.

Mission Awareness – Establish a comprehensive image of your critical dependencies through the cybersecurity awareness lifecycle.

Infrastructure Sector Awareness – Support your sector critical infrastructure cyberthreat intelligence providers by sharing your own threat information taken from your internal monitoring systems.

https://www.valuewalk.com/

ITS 834 Emerging Threats & Countermeasures

Week 7 – Awareness

Dr. Brian Toevs ([email protected])

7

Training, training, and more training

What do you think could be a better way to increase cybersecurity awareness within your organization or across

the national critical infrastructure sector than training?

Focused Training – Inside the Organization

Establish a culture of cybersecurity protection Business email compromise continues to be the most vulnerable aspect of security your local networks

Online training providers take the trouble out of your responsibility

Repeat the training at least every year

Test the effectiveness of your training

Focused Training – Sector-wide

Infrastructure support training from your sector cyberthreat intelligence resources

https://threatshieldsecurity.com/

ITS 834 Emerging Threats & Countermeasures

Week 7 – Awareness

Dr. Brian Toevs ([email protected])

8

Continuous Ongoing Professional Training Requirement

Continuous training for assessing risks, threats, and evaluating

trends in best practices for cybersecurity is a mandatory requirement

for the cybersecurity professional.

DoD 8570.01M Information Assurance Workforce Improvement

Program (WIP)

The program that you see here is only one of many annual training

events tailored specifically to the national critical infrastructure.

Most have sector-specific programs that are tailored to the

industry that represents your organization. A mix of sector-specific

programs and global infrastructure programs will provide an

excellent exposure to the best practices and threat mitigation

strategies that are going to be critical for you to master in support

of your own organization and the national critical infrastructure as

a whole.

https://public.cyber.mil/training/cyber-awareness-challenge/

ITS 834 Emerging Threats & Countermeasures

Week 7 – Awareness

Dr. Brian Toevs ([email protected])

9

Awareness Extends Beyond the Physical Boundaries of your Organization

Remote workforce, mobile devices, third party providers, Cloud services are the new realities of the modern

workforce. This is also true for critical infrastructure systems and organizations. Maintaining communications

and oversight of this mobile workforce is going to be the new challenge for organization leadership.

Maintaining Communications

Awareness includes knowing what your employees are doing. It’s

facilitating interactions between them while working away from the

centralized office environment. It’s protecting a

wider range of systems and devices that may not

be ‘owned’ by the organization. It’s providing 24-

hour support for teams that used to work set office

hours. It’s increasing efficiency of the workplace

while maintaining security controls and overall

cybersecurity compliance within your sector

rules and regulations.

https://cyware.com/cyber-threat-situational-awareness

ITS 834 Emerging Threats & Countermeasures

Week 7 – Awareness

Dr. Brian Toevs ([email protected])

10

Know Your Exposure

A crucial component of heightening your cyber-defensive awareness is knowing where the threats are originating.

Two simple ways to prioritize your focus are through geographic location and industry sector. Where you are and

what you do plays an important role in your exposure to cyber-attackers.

What are the most Vulnerable Sectors and Regions?

California, New York, Texas, and Florida suffer from the greatest

number of breaches across the country.

Source: Comparitech retrieved from https://docs.google.com/spreadsheets/d/1n2Ck49UtCQf_jtlk2edKj9gM_MLCNd4fqVimhsu6AUs/

edit#gid=856445414

Industry breakdown of incident response reports are:

Healthcare (including Biotech and Pharma) – 25%

Financial Services (including Insurance) – 17%

Professional Services (Engineering and Transportation) – 17%

Retail (including media and entertainment) – 12%

Education – 11%

Source: BakerHostetler retrieved from https://www.bakerlaw.com/

https://norse-corp.com/

ITS 834 Emerging Threats & Countermeasures

Week 7 – Awareness

Dr. Brian Toevs ([email protected])

11

Conclusion

This week you were asked to read Chapters 10 of our textbook. In addition to the lecture you have just followed,

you should have met the learning objectives expected of you this week. You will now be evaluated on the

retention of this material through your Discussion posts and weekly Quiz.

Next Week

Read Chapter 11 of your textbook about Response. You will have a Discussion thread to post and a quiz on the material presented in the textbook. Remember that next week ends on Wednesday night at midnight.

Lessons Learned

What is awareness and how does it apply to the national critical infrastructure?

Describe the Cybersecurity Awareness Lifecycle.

Explain the difference between perception of awareness at the national level versus the local level on your own network and how they interact.

Describe effective use of employee training to increase awareness.

Keep current in best practices through personal training.

Explain the impact of the mobile workforce on awareness

Identify your exposure.

Don’t forget that the course closes

next Wednesday night at midnight.

All Discussion posts and your quiz

must be completed prior to this

deadline.