CYB210_Week 8 DiscussionUnderstanding the Work of the IT Governance Board_post4

Is there anything else you׳d like to ask?
Our top-rated tutors can help you.

Click here to post a question
Related Documents
1 / 3100%
IT Governance Board members,
Cybersecurity have become one of the most important components for
governments, businesses, and institutions in the 21st century. What
used to be just simple spam emails are now part of a much more
complex part of cyber-attacks. Online adversaries of our time conduct
sophisticated scouting of the potential target through social
engineering, network scanning, and some daredevils will even go as far
as physically scouting their target’s infrastructure. With the nature of
complexity and many attack vectors in 21st century cyber criminals, it is
no wonder that there are many government and industry standards of
cyber defense frameworks. Though it maybe voluntary to employ these
cyber security frameworks, it is in Padgett-Beale’s best interest to
follow one of the available guidance. It will shed light on the
infrastructures vulnerabilities, and the business will be able to properly
divest funds to safeguard the information systems that are vital to
doing business. By practicing due diligence, existing standards and
guidelines, Padgett-Beale can become one of the industry standards of
cybersecurity.
One of the most recognized frameworks is from National Institute of
Standards and Technology, which was released in 2014 (NIST, 2022).
Babix (2022) describe the NIST Framework as the framework that
provides uniform set of rules, guideline, and standards for an
organization, and is the gold standard for building a cybersecurity
program. NIST Cybersecurity framework allows organizations to be
better prepared for cyber-attacks, from preventative measures to
response and recovery from incidents (Babix, 2022). NIST
cybersecurity framework is broken down into five core functions;
Identify, Protect, Detect, Respond, and Recover. Each core functions
serves critical steps in hardening and responding to cyber incidents.
Identify, involves assessing risks to the information system of an
organization. Everything from systems, people, assets, data, and
capabilities are assessed for cyber security risks. Outlining the physical
hardware used and software that are used in the organization establish
the basis of asset management. Identifying the business environment
and its role in supple chain. Assessing the legal and regulatory
requirements for the organization relating to cyber security.
Organization must identify the vulnerabilities that exits within their
assets and assess the risk to the organization’s resources.
Establishment of risk management strategy; acceptance of
vulnerabilities, mitigation, risk tolerance, and supply chain risk
management strategies (Babix, 2022). Padgett-Beale needs to practice
due diligence and understanding of its information system and its risks
before it can protect the resources and customer data.
Protect function outlines safeguards of critical infrastructure services,
and mitigation and containment of cybersecurity breach. This function
implements identity management and access control for on-premises
and remote access to Padgett-Beale assets. To better protect IT
systems, employees, must be trained in their roles. Establishing
standard user training, and privileged access training should be given to
appropriate roles. Protection includes the proactive patching of
systems. Vulnerabilities that have fixes, needs to be actively patched
with software and operating system updates. As part of the managing
the technology assets, organization needs to ensure the security of the
systems are in complaint with the policies and procedures set by the
organization.
c c c Detection of cyber security threats defines the process of
detecting and identifying the cyber security threats. These include
spam filters, network, and host-based detection of malwares, as well as
monitoring of traffic for anomalies. Padgett-Beale needs policies and
quick response once an event is detected (Babix, 2022). Assets and
resources affected needs to be recognized quickly and quarantined
from the corporate network.
Respond function is the reaction to the detection of cybersecurity
incidents. Padgett-Beale will need to develop a plan of action that are
appropriate in response to an incident. Communication between
response team, management, and outside will be critical in maintaining
good relations with stakeholders. Managing the impact of the events,
and digital forensic evidence gathering to understand the scale of the
incidents will be helpful in the recovery activities. Mitigating the spread
and worsening of the incidents are critical in keeping the business
operational. This function should include lessons learned, and response
improvements for better handling the next event (Babix, 2022).
Recover, identifies the appropriate measures and actions in maintaining
timeframe to restore the capabilities and services that were brought
down by a cybersecurity event. Many functions of recovery overlap
with the respond functions. Improvements in handling incidents should
also be part of the recovery phase.
Padgett-Beale will need Cybersecurity Framework as a guidance of
proper cybersecurity response to the ever-growing threat that are
presented by malicious actors looking for vulnerable IT systems. The
framework will allow for proper policy writing, training, and incident
response necessary to mitigate and deal with cybersecurity incidents.
The framework will also help greatly in recognizing the vulnerabilities
that exists in Padgett-Beale’s corporate networks, and the proper
divestment that is necessary in protecting the Information Systems
assets.
References
Babix. (2022, April 20).
What is the NIST Cybersecurity Framework?
Balbix. https://www.balbix.com/insights/nist-cybersecurity-
framework/
NIST. (2022, April 18).
Cybersecurity Framework
.
https://www.nist.gov/industry-impacts/cybersecurity-framework
Students also viewed