Padgett-Beale enforces strict policies and standards regarding cyber
security. Cyber security is a broad term that means to secure digital assets
and information. As well as to identify and protect information that is at
risk. Risk meaning it will cost the company if data is lost or productive
environment becomes interrupted from a cyber-attack. This is important,
confidential, and reliable information about company employees, future
goals, innovations, ideas, and financial information. Personally identifiable
information and sensitive personal information regarding the company and
company employees is at risk as well. This information can include payment
information and transactions, social security numbers, email credentials,
personal information (home address, family names). These vectors of data
and online identity is important to individuals and the confidentiality of a
running business such as Padgett-Beale. That is why we enforce strict
policies and procedures and the IT governance board to follow strict
standards to assist the objective of securing and protecting data and
infrastructures.
c c c c To start off Padgett-Beale follows a strict framework from the like
of NIST and COBIT. These frameworks help provide an overview of what
standard procedure should be when dealing with cyber security risks. Each
company is reliable in the function of critical infrastructure. Today, more
technology is being implemented into the business environment for
production purposes. As more tech is implemented so does the impact of a
cyber-attack (NIST, 2018).
c c c c Its is important to also communicate well with management systems.
Creating awareness and knowledge base can help common goals of an
organization. Through recent studies, it has been shown that leaders and
CEO’S who are not “techies” are not prepared or believe it is not in their
responsibility for safeguarding and organizations data (Nasdaq, 2016). This
continues to keep a company at risk no matter how secured an IT team may
be. In the end, all have a common goal to keep the company running safely
and reliably while generating income and finances. It’s important to realize
that security is a team effort and must work collaboratively with
governments, non-government organizations, and peers (NASDAQ, 2016).
Research shows keeping open communication and helping peers
understand the latest security threats through employee training,
information sharing, and knowledge base. Not necessarily saying non tech
people must become cyber security experts.
c c c c Standards and Frameworks from National Institute of Standards and
Technology (NIST) and The Control Objectives for Information and Related
Technology (COBIT) “provides managers, auditors, and IT users with a set of
generally accepted measures, indicators, processes, and best practices to
assist in maximizing benefits derived through the use of IT and develop
appropriate IT governance and control in a company (Sheikhpour, Modiri,
2012).” These frameworks are back by standards and United states law for
(NIST).
COBIT backed by UK department of trade standard ISO/IEC 27001
(Sheikhpour, Modiri, 2012) and NIST backed by United States law CEA act
of 2014 and executive order 13636 “Improving Critical Infrastructure Cyber
Security.” (NIST 2018). All in all, they all have the same goal in mind and
have similar processes.
NIST framework in order
• Framework Core
Consisting of five concurrent and continuous functions
Identify
Protect
Detect
Respond
Recover
• Framework Implementation (Tiers)
Separating duties for reactive responses starting from Tier 1- Tier 4
elevating the situation.
• Framework Profile
The output of business needs and objectives.
(NIST,2018)
COBIT has similar processes the provide a deeper insight for each domain.
• Plan
• Acquire and Implement
• Deliver and Support
• Monitor and Evaluate
(COBIT, 2012).
Another huge procedure is risk management. This is an ongoing process of
identifying, assessing, and responding to risk. Companies are to understand
that some type of cvber attack will happen at some point and that
companies need to prioritize risk. Risks can be handled in different ways by
companies which include
• Mitigating risk
• Transferring risk
• Avoiding risk
• Acceptance of risk
All factors depend on potential impact of critical services (NIST, 2018).
c c c c In conclusion, as I mentioned securing data and infrastructure is a
management team collaboration. According to NASDAQ, most companies
cannot keep up with the pace of cyber hackers and that most company
technology has no been updated, and these are the devices that hold the
most sensitive data (NASDAQ, 2016). It is important to start at a tier 1 level
meaning from the hardware employees use. To access control rights, to
network security.
Use common due diligence to care for the company and respect company
data on the network.
Resources
National Institute of Standards and Technology, 2018. Framework for
Improving Critical Infrastructure Cyber Security. Version 1.1 (NIST). 1.0
Framework Introduction.
https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf
NASDAQ, 2016. Bridging the Accountability Gap: Why We Need to Adopt
a Culture of Responsibility. https://www.nasdaq.com/articles/bridging-
accountability-gap-why-we-need-adopt-culture-responsibility-2016-04-01
Sheikhpour, Razieh. Modiri, Naaser. 2012. An Approach to Map COBIT
Processes to ISO/IEC 27001 Management Controls. International Journal of
Security and Its Applications. 1. Introduction.
https://www.researchgate.net/publication/292833500
National Institute of Standards and Technology, 2018. Framework for
Improving Critical Infrastructure Cyber Security. Version 1.1 (NIST). 1.0
Framework Introduction
https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf
National Institute of Standards and Technology, 2018. Framework for
Improving Critical Infrastructure Cyber Security. Version 1.1 (NIST). 2.1
Framework Core.
https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf
Sheikhpour, Razieh. Modiri, Naaser. 2012. An Approach to Map COBIT
Processes to ISO/IEC 27001 Management Controls. International Journal of
Security and Its Applications. 2.3 COBIT Framework Model
https://www.researchgate.net/publication/292833500
National Institute of Standards and Technology, 2018. Framework for
Improving Critical Infrastructure Cyber Security. Version 1.1 (NIST). 1.2 Risk
Management and the Cyber Security Framework.
https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf
NASDAQ, 2016. Bridging the Accountability Gap: Why We Need to Adopt
a Culture of Responsibility. https://www.nasdaq.com/articles/bridging-
accountability-gap-why-we-need-adopt-culture-responsibility-2016-04-01.