Digital Library
The Cybersecurity Control Playbook From Fundamentals to Advanced Strategies (Jason Edwards) (z-library.sk, 1lib.sk, z-lib.sk)
The Cybersecurity Control Playbook From Fundamentals to Advanced Strategies (Jason Edwards) (z-library.sk, 1lib.sk, z-lib.sk)
网络安全
No Description
12
Views
0
Downloads
0.00
Total Donations
Text Preview (First 20 pages)
Registered users can read the full content for free
Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.
Page
1
(This page has no text content)
Page
2
The Cybersecurity Control Playbook D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
Page
3
The Cybersecurity Control Playbook From Fundamentals to Advanced Strategies Jason Edwards BareMetalCyber New Braunfels, TX, USA D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
Page
4
This edition first published 2025 © 2025 John Wiley & Sons Ltd. All rights reserved, including rights for text and data mining and training of artificial intelligence technologies or similar technologies. No part of this publication may be reproduced, stored in a retrieval system, or transmitted, in any form or by any means, electronic, mechanical, photocopying, recording or otherwise, except as permitted by law. Advice on how to obtain permission to reuse material from this title is available at http://www.wiley.com/go/permissions. The right of Jason Edwards to be identified as the author of this work has been asserted in accordance with law. Registered Offices John Wiley & Sons, Inc., 111 River Street, Hoboken, NJ 07030, USA John Wiley & Sons Ltd, New Era House, 8 Oldlands Way, Bognor Regis, West Sussex, PO22 9NQ, UK For details of our global editorial offices, customer services, and more information about Wiley products visit us at www.wiley.com. The manufacturer’s authorized representative according to the EU General Product Safety Regulation is Wiley-VCH GmbH, Boschstr. 12, 69469 Weinheim, Germany, e-mail: Product_Safety@wiley.com. Wiley also publishes its books in a variety of electronic formats and by print-on-demand. Some content that appears in standard print versions of this book may not be available in other formats. Trademarks: Wiley and the Wiley logo are trademarks or registered trademarks of John Wiley & Sons, Inc. and/or its affiliates in the United States and other countries and may not be used without written permission. All other trademarks are the property of their respective owners. John Wiley & Sons, Inc. is not associated with any product or vendor mentioned in this book. Limit of Liability/Disclaimer of Warranty In view of ongoing research, equipment modifications, changes in governmental regulations, and the constant flow of information relating to the use of experimental reagents, equipment, and devices, the reader is urged to review and evaluate the information provided in the package insert or instructions for each chemical, piece of equipment, reagent, or device for, among other things, any changes in the instructions or indication of usage and for added warnings and precautions. While the publisher and authors have used their best efforts in preparing this work, they make no representations or warranties with respect to the accuracy or completeness of the contents of this work and specifically disclaim all warranties, including without limitation any implied warranties of merchantability or fitness for a particular purpose. No warranty may be created or extended by sales representatives, written sales materials or promotional statements for this work. The fact that an organization, website, or product is referred to in this work as a citation and/or potential source of further information does not mean that the publisher and authors endorse the information or services the organization, website, or product may provide or recommendations it may make. This work is sold with the understanding that the publisher is not engaged in rendering professional services. The advice and strategies contained herein may not be suitable for your situation. You should consult with a specialist where appropriate. Further, readers should be aware that websites listed in this work may have changed or disappeared between when this work was written and when it is read. Neither the publisher nor authors shall be liable for any loss of profit or any other commercial damages, including but not limited to special, incidental, consequential, or other damages. Library of Congress Cataloging-in-Publication Data Applied for: Hardback ISBN: 9781394331857 Cover Design: Wiley Cover Image: © zf L/Getty Images Set in 9.5/12.5pt STIXTwoText by Straive, Chennai, India D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
Page
5
v Contents Preface xxv Acknowledgments xxvii 1 Understanding Cybersecurity Controls 1 Definition and Importance 1 Types of Controls 3 Timing-Based Controls 3 Nature-Based Controls 4 Classifying Controls for Effectiveness 5 Process-Level, Common, and Entity-Level Controls 5 Inherited, Primary, and Compensating Controls 6 Mowing the Lawn: An Allegory for Cybersecurity Controls 6 The Lifecycle of a Control 8 Leadership Insight: Guiding Teams in Understanding and Valuing Controls 10 Chapter Recommendations 11 Chapter Conclusion 13 Questions 14 2 The Risk-Based Approach 17 Identifying Cyber Risks 18 Exploring the Components of Cyber Risks 18 Understanding External, Internal, and Emerging Threats 19 Essential Techniques for Risk Identification 20 Prioritizing Risks 21 Utilizing the Risk Matrix for Effective Prioritization 21 Understanding the Role of Business Impact Analysis (BIA) 22 Balancing Risk Appetite and Tolerance 22 Tailoring Risk Prioritization to Organizational Size 23 Aligning Cybersecurity Efforts with Business Objectives 23 Developing a Risk Taxonomy 24 Steps to Create a Risk Taxonomy 24 Incorporating Threat Intelligence into the Taxonomy 25 Benefits of a Well-Structured Risk Taxonomy 25 D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
Page
6
vi Contents Leadership Insight: Leading Risk Assessment and Prioritization Efforts 26 Fostering a Risk-Aware Culture 26 Communicating Risk to the C-Suite 27 Ensuring Continuous Risk Assessment 28 Chapter Recommendations 28 Chapter Conclusion 30 Questions 31 3 Small Business Implementation 35 Unique Challenges and Solutions 36 Limited Resources 36 Inadequate Cybersecurity Awareness 37 Supply Chain Risks 37 Scalability Challenges 37 Cost-Effective Strategies 37 Prioritizing the Most Critical Controls 38 Leveraging Outsourced Security 38 Partnering for Security 38 Implementing a Risk-Based Approach 39 Leadership Insight: Leading Security Initiatives in Small Businesses 39 Overcoming Budget Constraints 40 Building Partnerships for Success 41 AI Recommendations: Leveraging AI for Cybersecurity in Small Businesses 41 AI-Powered Security Tools 41 AI for Employee Education and Training 43 AI for Risk Assessment 43 AI for Compliance and Reporting 44 Selecting the Right Managed Security Service Provider (MSSP) for Your Small Business 44 Understanding Your Security Needs 45 Identifying Critical Assets and Risks 45 Essential Services Provided by MSSPs 45 Criteria for Selecting an MSSP 46 Evaluating MSSP Options: A Step-by-Step Approach 47 Recommended Security Controls for Small Businesses 47 Making the Right Choice: Key Considerations 48 Final Thoughts 48 Chapter Recommendations 48 Chapter Conclusion 50 Questions 51 4 Medium-Sized Enterprises 55 Balancing Resources and Security 55 Managing Limited IT and Security Budgets 56 Cost-Effective Security Solutions 56 D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
Page
7
Contents vii Maximizing Existing Resources 57 Allocating Human Resources 57 Outsourcing Cybersecurity Functions 57 Collaborating Across Teams 58 Maximizing Impact Through Strategic Planning 58 Sizing Security Teams for Medium-Sized Enterprises 58 Leadership Insight: Managing Security Teams in Medium-Sized Enterprises 59 Managing Growing Security Demands 60 AI Recommendations: Leveraging AI for Education on Cybersecurity and Medium Enterprise Risks and Controls 62 AI for Employee Training and Awareness 62 AI for Risk Assessment and Compliance 64 Integrating AI into Organizational Strategy 64 Challenges and Considerations in AI Adoption 64 Future-Proofing Security Strategies with AI 65 Collaborative Efforts and Industry Best Practices 65 Embracing the Human Element 65 Chapter Recommendations 65 Chapter Conclusion 68 Questions 68 5 Large Enterprises 73 Advanced Control Strategies 74 Finding the Right Balance 74 Evaluating Your Mix 74 Collaborating Across the Organization to Design Controls 75 Mapping Business Processes 75 Collaborating with IT and Security Operations 76 Iterative Design and Feedback Loops 76 Choosing the Right Cybersecurity Framework 76 Regulatory Requirements 77 Organizational Size and Maturity 78 Engaging Stakeholders in the Decision 78 Avoiding the Compliance Checkbox Mentality 79 Prioritizing Controls in a Large Enterprise Setting 79 Mapping Controls to Business Risks 80 Process Excellence for Control Effectiveness 81 Iterative Implementation and Documentation 82 Incremental Rollouts 82 Advanced Strategies for Large Organizations with Complex Environments 83 Process Mapping for Control Identification 83 Security Process Integration 84 Managing Complexity and Scale 84 Unified Security Strategy Across Regions 84 Handling Mergers and Acquisitions (M&A) 85 D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
Page
8
viii Contents Mitigating Post-Acquisition Risks 85 Governance, Risk, and Compliance (GRC) at Scale 86 Automating Compliance Reporting 86 Leadership Insight: Leading Large-Scale Security Operations 86 Fostering Collaboration Across Teams 87 Managing Vendor Relationships and Third-Party Risk 87 Supply Chain Security 87 Maintaining Executive and Board-Level Engagement 88 Building a Cybersecurity-First Culture 88 AI Recommendations: GRC AI Uses for Large Enterprises 88 AI-Powered Predictive Analytics 89 AI for Compliance Automation 89 Natural Language Processing (NLP) for Policy Management 90 AI for Incident Response and Threat Intelligence 91 AI for Threat Intelligence Correlation 91 Chapter Recommendations 91 Chapter Conclusion 93 Questions 94 6 Introduction to MITRE ATT&CK & DEFEND 97 What Is MITRE ATT&CK? 98 Key Components of MITRE ATT&CK 98 ATT&CK Matrices 100 How ATT&CK Is Used 100 What Is MITRE DEFEND? 100 Key Components of MITRE DEFEND 101 DEFEND Matrices 102 How MITRE DEFEND Is Used 103 Benefits of Using ATT&CK and DEFEND Together 104 Enhancing Threat Detection and Proactive Defense 105 Proactive Threat Hunting and Mitigation 105 Red Team and Blue Team Alignment Using ATT&CK and DEFEND 105 Leadership Insight: Encouraging Adoption of MITRE ATT&CK and DEFEND Within Teams 106 Building Organizational Buy-In 106 Using ATT&CK and DEFEND for Metrics and Reporting 106 Possible KRIs for ATT&CK and DEFEND 107 AI Recommendations: Learning MITRE ATT&CK and DEFEND 108 AI-Powered Threat Detection with ATT&CK and DEFEND 108 Enhancing Red and Blue Team Exercises with AI 109 Chapter Recommendations 110 Chapter Conclusion 112 Questions 112 D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
Page
9
Contents ix 7 Mapping Threats to Controls Using MITRE ATT&CK 117 Practical Guide to Threat Mapping 117 Why MITRE ATT&CK? 118 Challenges in Threat Mapping 118 The Human Element 118 Continual Evolution 119 Steps for Threat Mapping 119 Step 1: Identify Critical Assets and Systems 119 Step 2: Analyze Known Adversary Behaviors 120 Step 3: Map ATT&CK Techniques to Existing Controls 120 Step 4: Prioritize High-Risk Techniques 120 Step 5: Strengthen and Implement New Controls 121 Tools for Effective Threat Mapping 122 MITRE ATT&CK Navigator 122 Threat Intelligence Feeds 123 MITRE Engage 123 Security Information and Event Management (SIEM) Systems 124 Endpoint Detection and Response (EDR) Tools 124 Vulnerability Management Tools 124 Mapping Specific Techniques to Controls 124 The Concept of Technique-to-Control Mapping 125 Why Technique-to-Control Mapping Matters 125 How the Mapping Process Works 125 What Happens Next 126 Leadership Insight: Leading Threat-Mapping Exercises 126 Fostering a Collaborative Security Culture 126 Engaging Cross-Functional Teams 127 Training for Threat Mapping 127 Creating a Sustainable Threat-Mapping Process 127 Aligning Threat Mapping with Business Objectives 128 Risk-Based Prioritization 128 Communicating with Executives 128 Building the Business Case for Threat Mapping 129 Driving Continuous Improvement 129 Ongoing Threat-Mapping Exercises 130 Metrics for Success 130 Building a Culture of Continuous Improvement 131 AI Recommendations: Leveraging AI for Threat Mapping and Analysis 131 AI-Powered Threat-Mapping Automation 132 Automating Threat Intelligence Correlation 132 Dynamic Threat Mapping with AI 132 AI for Prioritizing Threats and Techniques 132 Predictive Analysis for Future Threats 133 D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
Page
10
x Contents AI for Automated Reporting 133 Real-Time Updates to Security Teams 133 The Future of AI in Threat Mapping 134 Chapter Recommendations 134 Chapter Conclusion 136 Questions 136 8 Enhancing Defenses with MITRE DEFEND 141 Integrating MITRE DEFEND into Organizational Defense Strategies 142 Alignment with NIST 800-53 142 Mapping DEFEND to Control Families 142 Proactive Defense: Shifting from Reactive to Predictive 143 Integration Challenges and Opportunities 143 Creating a Continuous Improvement Loop 143 Alignment with NIST Cybersecurity Framework (CSF) 145 Govern: Setting Strategy and Policies for Effective Defense 145 Identify: Understanding and Prioritizing Risks 145 Protect: Strengthening Defenses Before an Attack 146 Detect: Catching Threats in Real-Time 146 Respond: Disrupting the Attack in Motion 147 Recover: Building Resilience Post-Attack 147 Alignment with ISO 27001: Establishing a Strong Information Security Management System (ISMS) 147 Proactive Security Management: Bridging ISO 27001 and MITRE DEFEND 149 Enhancing ISO 27002 Controls with MITRE DEFEND 149 Creating a Synergistic Approach: ISO 27001 and MITRE DEFEND 150 Alignment with CIS Controls: Prioritizing Actions to Mitigate Common Threats 150 Proactive Defense Measures: Mapping MITRE DEFEND to CIS Controls 151 Active Threat Disruption: Leveraging MITRE DEFEND for Real-Time Defense 151 Shifting from Passive Defense to Active Engagement 151 Integrating MITRE DEFEND to Improve CIS Control Effectiveness 152 Embedding MITRE DEFEND into Risk Management 152 Enhancing Threat Models with Active Defense 154 Operationalizing MITRE DEFEND for Security Teams 155 Continuous Improvement Through Active Defense 155 Tools and Techniques for Defensive Implementation 155 Mapping and Planning with MITRE Shield 156 Integrating MITRE DEFEND with SIEM and EDR Systems 156 Configuring EDR Solutions for Active Engagement 156 Threat Hunting Using MITRE DEFEND 157 Leveraging Open-Source Tools for Active Defense 157 Leadership Strategies for MITRE DEFEND Integration 157 Building Cross-Functional Implementation Teams 158 Incorporating MITRE DEFEND into Metrics and KPIs 158 D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
Page
11
Contents xi Enhancing Response Strategies 159 Fostering a Culture of Proactive Defense 159 Implementing Lessons Learned 160 Enhancing Defense with AI and MITRE DEFEND 160 Predictive Disruption Modeling 161 Automating Active Incident Response with AI 161 Enhancing Incident Response Through AI Automation 162 AI-Driven Threat Engagement 162 Continuous Improvement Through AI Insights 162 Chapter Recommendations 163 Chapter Conclusion 165 Questions 165 9 Cybersecurity Frameworks Overview 169 Why Cybersecurity Frameworks Are Critical 170 Structured Methodologies: Ensuring Scalability and Consistency 170 Consistency in Security Processes 171 Compliance with Regulations: Stay Ahead of the Curve 171 Frameworks as Communication Tools 172 Bridging Technical and Business Leadership: A Unified Strategy 172 Standardized Security Language: Building a Common Understanding 172 Frameworks as Tools for Strategic Decision-Making 173 Fostering Executive Buy-In Through Clear Communication 173 Aligning Cybersecurity Frameworks with Business Goals 174 Operational Efficiency: Streamlining Security Operations 174 Risk Management: Balancing Protection and Business Needs 175 Trust and Assurance: Demonstrating Commitment to Best Practices 175 Frameworks for Different Types of Organizations 176 Small Businesses: Simplicity and Cost-Effectiveness 176 Medium Businesses: Balancing Compliance and Agility 177 Large Enterprises: Managing Complexity and Compliance 177 Tailoring Frameworks to Fit Organizational Needs 178 Leadership Insight: Choosing and Championing the Right Frameworks for Your Organization 178 Selecting the Right Framework for Your Business 178 Leading Framework Implementation 179 Overcoming Resistance to Frameworks 179 Monitoring Framework Effectiveness 180 Integrating AI with Cybersecurity Frameworks 180 How AI Enhances Framework Implementation 181 Benefits of AI-Driven Cybersecurity Frameworks 181 Aligning AI with Business Goals and Frameworks 182 Challenges and Considerations 182 Chapter Recommendations 183 D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
Page
12
xii Contents Comparison of Popular Cybersecurity Control Frameworks 184 Overview of Control Frameworks 185 Detailed Comparison 185 NIST SP 800-53 185 CIS Controls 185 ISO/IEC 27001 186 COBIT 186 HITRUST CSF 186 NIST Cybersecurity Framework (CSF) 186 Choosing the Right Framework 186 Chapter Conclusion 187 Questions 188 10 NIST 800-53 191 Overview of NIST SP 800-53 192 Origins of NIST SP 800-53 192 The Purpose of NIST SP 800-53 192 Adapting the Framework to Fit Your Needs 193 Practical Application and Integration 193 Control Families 193 Access and Identity Management 194 Access Control (AC) 194 Identification and Authentication (IA) 195 Audit and Accountability (AU) 195 Risk Management and Assessment 195 Risk Assessment (RA) 196 Security Assessment and Authorization (CA) 196 Planning (PL) 197 System and Services Acquisition (SA) 197 Operational Security 197 Incident Response (IR) 197 System and Communications Protection (SC) 198 System and Information Integrity (SI) 198 Maintenance (MA) 198 Configuration Management (CM) 198 Physical and Environmental Security 199 Physical and Environmental Protection (PE) 199 Privacy and Data Protection 199 Media Protection (MP) 199 Personnel Security (PS) 200 Privacy Controls 200 Governance and Compliance 200 Program Management (PM) 200 Awareness and Training (AT) 201 Contingency Planning (CP) 201 Supply Chain Risk Management (SCRM) 201 D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
Page
13
Contents xiii Categorization of Information Systems (FIPS 199) 202 System Categorization 202 Tailoring Controls 204 Control Baselines 205 Baseline Overview 205 Tailoring the Baselines 206 Supplemental Guidance 206 Implementation Strategies 207 Planning and Preparing for Implementation 207 Establishing a Governance Structure 207 Conducting a Gap Analysis 207 Prioritizing Controls Based on Risk 208 Risk-Based Approach 208 Low-Hanging Fruit (Immediate Burn Down of Risk) 209 Tailoring Controls to the Organization 209 Customization Based on Business Needs 209 Control Overlays 210 Overcoming Challenges in Implementation 210 Dealing with Resistance to Change 211 Managing Complexity in Large Organizations 211 NIST 800-171—Controls for Non-federal Entities 212 Relationship to NIST 800-53 Controls and Families 212 Similarities and Differences Between NIST 800-171 and NIST 800-53 213 Who Needs to Comply with NIST 800-171? 213 Measuring Compliance with NIST 800-171 213 Chapter Recommendations 215 Chapter Conclusion 217 Questions 217 11 Center for Internet Security (CIS) 18 Controls 221 Overview of CIS Controls 222 Purpose of the CIS Controls 222 Implementation Groups 222 IG1: Basic Cyber Hygiene 222 IG2: Foundational Security 223 IG3: Comprehensive Security 223 Choosing the Right Implementation Group 223 In-Depth Exploration of the 18 CIS Controls 224 Control 1: Inventory and Control of Enterprise Assets 224 Methods for Asset Inventory Management 224 Tools for Automated Asset Discovery 224 Control 2: Inventory and Control of Software Assets 225 Detecting Unauthorized Software 225 Software Licensing and Compliance 225 D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
Page
14
xiv Contents Control 3: Data Protection 226 Encryption Techniques for Data at Rest and in Transit 226 Implementing Data Loss Prevention (DLP) Solutions 226 Control 4: Secure Configuration of Enterprise Assets and Software 227 Configuration Management and Change Control 227 Hardening Guides and Benchmarks 227 Control 5: Account Management 227 Managing Privileged Accounts 228 Monitoring Account Activities 228 Control 6: Access Control Management 228 Implementing Role-Based Access Control (RBAC) 229 Access Control Technologies and Solutions 229 Control 7: Continuous Vulnerability Management 229 Patch Management Best Practices 230 Remediation and Exception Handling 230 Control 8: Audit Log Management 230 Configuring Log Sources and Destinations 230 Analyzing and Responding to Log Data 231 Control 9: Email and Web Browser Protections 231 Web Browser Configuration and Extensions 231 Defending Against Phishing and Malicious Links 232 Control 10: Malware Defenses 232 Endpoint Detection and Response (EDR) 232 Strategies for Malware Incident Response 233 Control 11: Data Recovery 233 Testing Data Restoration Processes 233 Business Continuity and Disaster Recovery Planning 234 Control 12: Network Infrastructure Management 234 Network Segmentation and Isolation 234 Managing Wireless Networks 234 Control 13: Network Monitoring and Defense 235 Centralize Security Event Alerting 235 Deploy a Host-Based Intrusion Detection Solution 235 Deploy a Network Intrusion Detection Solution 235 Perform Traffic Filtering Between Network Segments 235 Manage Access Control for Remote Assets 236 Collect Network Traffic Flow Logs 236 Deploy a Host-Based Intrusion Prevention Solution 236 Deploy a Network Intrusion Prevention Solution 236 Deploy Port-Level Access Control 236 Perform Application Layer Filtering 236 Tune Security Event Alerting Thresholds 236 Control 14: Security Awareness and Skills Training 237 Establish and Maintain a Security Awareness Program 237 Train Workforce Members to Recognize Social Engineering Attacks 237 D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
Page
15
Contents xv Train Workforce Members on Authentication Best Practices 237 Train Workforce on Data Handling Best Practices 237 Train Workforce Members on Causes of Unintentional Data Exposure 237 Train Workforce Members on Recognizing and Reporting Security Incidents 238 Train Workforce on Identifying and Reporting Missing Security Updates 238 Train Workforce on Dangers of Using Insecure Networks 238 Conduct Role-Specific Security Awareness and Skills Training 238 Control 15: Service Provider Management 238 Contractual Security Requirements 239 Monitoring Service Provider Compliance 239 Control 16: Application Software Security 239 Code Review and Testing Practices 239 Application Security Tools (SAST, DAST) 240 Control 17: Incident Response Management 240 Roles and Responsibilities in Incident Handling 240 Post-Incident Analysis and Reporting 241 Control 18: Penetration Testing 241 Internal vs. External Testing Approaches 241 Interpreting Results and Mitigating Findings 242 Leadership Insight: Driving the Application of CIS Controls 242 Embedding Security into Business Strategy 242 Tailoring Controls to the Organization’s Needs 244 Scaling Controls Based on Organizational Growth 245 Leading Change in Organizational Culture 245 Overcoming Resistance to Change 245 Chapter Recommendations 246 Chapter Conclusion 247 Questions 248 12 Agile Implementation of Controls and Control Frameworks 253 Agile Implementation of Controls and Control Frameworks 254 Agile Principles and Practices 254 Key Agile Practices for Control Frameworks 254 Iterative Delivery and Continuous Improvement 255 Adapting Agile for Cybersecurity Controls 255 Benefits of Agile for Large Enterprises 255 Adapting Controls to Agile Environments 256 Challenges of Applying Traditional Controls in Agile 256 Implementing Controls in an Agile Way 256 Breaking Down Security Controls into Sprints 257 Integrating Security into DevSecOps 258 Leadership Insight: Leading Agile Cybersecurity Teams 258 Embracing an Agile Security Mindset 260 Aligning Security Goals with Business Objectives 260 D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
Page
16
xvi Contents Managing Security Debt 260 Risk Management in an Agile Environment 261 Chapter Recommendations 261 Chapter Conclusion 263 Questions 264 13 Adaptive Control Testing & Continuous Improvement 267 What Is Control Testing? 268 Types of Control Testing 268 Why Control Testing Is Critical 268 Control Testing Outcomes 269 The Importance of a Regular Testing Schedule 269 Time-Consuming Nature of Control Testing 269 Resource Allocation for Control Testing 270 Balancing Resources and Time for Effective Testing 270 Using Metrics to Monitor and Evaluate Controls 271 Importance of Metrics in Control Evaluation 271 Choosing the Right Metrics 271 Implementing a Metrics-Driven Approach 272 The Role of Automation in Metrics Collection 272 Key Metrics for Control Evaluation 273 Effectiveness Metrics 273 Efficiency Metrics 273 Balancing Effectiveness and Efficiency 274 Compliance Metrics 274 Coverage Metrics 274 Cost–Benefit Metrics 275 Integrating Metrics into Cybersecurity Strategy 275 Framework for Using Metrics to Evaluate Controls 275 Setting Baseline Metrics 276 Ongoing Monitoring 276 Periodic Review and Analysis 276 Adjusting Based on Metrics 276 Reporting to Stakeholders 277 Common Tools for Control Metrics 277 Security Information and Event Management (SIEM) Systems 277 Dashboard Tools 277 Audit Logs and Reports 278 Continuous Improvement and Adaptation 278 Tuning and Optimization 278 Reducing False Positives and Negatives 279 Importance of Regular Control Tuning 279 Feedback Loop and Continuous Improvement 280 Enhancing Preventive Controls 280 Expanding Coverage 280 D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
Page
17
Contents xvii Adapting to New Attack Vectors 281 Integration with System Updates and Changes 281 Adapting Controls During System Upgrades 281 Software Version Compatibility 282 Reconfiguration of Controls 282 Impact of Organizational Changes on Controls 282 Scaling Controls 282 Post-merger Integration 283 Regular Assessments and Updates 283 Ongoing Evaluation of Controls 283 Adapting to Technological Changes 284 Compliance with Evolving Standards 284 Updating Controls in Response to Threat Intelligence 285 Leveraging Threat Intelligence 285 Proactive Patching and Vulnerability Management 285 Incorporating Feedback and Lessons Learned 286 Post-incident Reviews 286 Feedback from Internal and External Sources 286 Incorporating Results from Control Testing 286 Emphasizing the Importance of Rigorous Testing 287 Testing as a Core Element of Security Strategy 287 Maintaining Organizational Confidence 287 Balancing Costs and Benefits 287 Investment in Security Assurance 288 Communicating the Value of Testing 288 Leveraging AI in Control Testing: Enhancing Efficiency and Accuracy 288 AI as a Complementary Tool for Control Testing 288 AI-Driven Control Testing: Automation and Beyond 289 AI’s Role in Identifying and Reducing False Positives and Negatives 289 Enhancing Preventive and Detective Controls with AI 290 Increased Testing Frequency Without Resource Drain 290 Improved Risk Management and Decision-Making 290 Supporting Compliance and Regulatory Requirements 290 The Future of Control Testing with AI 291 Chapter Recommendations 291 Chapter Conclusion 292 Questions 293 14 Testing Controls in Small and Medium Enterprises 297 Streamlined Control Testing for Small Businesses 297 Basic Automated Testing Tools 298 Prioritizing Critical Controls 299 Routine Spot-Checks 299 Security Checklists 299 D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
Page
18
xviii Contents Simplified Testing Methods for Medium-Sized Enterprises 300 Regular Control Audits 300 Automation of Routine Tasks 300 Log and Monitoring Reviews 301 Continuous Improvement Through Testing 301 Managed Security Service Providers (MSSPs) for Small Businesses 302 Services Provided by MSSPs 303 Benefits for Small Businesses 303 MSSPs for Medium-Sized Enterprises 304 In-House vs. Outsourced SMEs 304 Cross-Functional Collaboration 304 Third-Party Testing for Small Businesses 305 External Audits and Assessments 305 Cost-Effective Options 306 Advanced Testing for Medium-Sized Enterprises 306 Red and Blue Team Exercises 306 Leadership Insight: Managing Control Testing in Small Businesses 307 Simplifying Processes for Small Teams 307 Leadership Insight: Managing Control Testing in Medium Enterprises 308 Resource Optimization for Testing 308 Integration of AI into Small and Medium Enterprise Control Testing 308 AI-Powered Control Testing for Small Businesses 309 AI for Medium-Sized Enterprises: Enhancing Precision and Efficiency 310 AI-Driven Decision Making and Remediation 310 Future Trends: AI and Predictive Analytics in Control Testing 311 Chapter Recommendations 311 Chapter Conclusion 313 Questions 313 15 Control Testing in Larger and Complex Enterprises 317 Dealing with Organizational Complexity 317 Testing Across Multiple Departments and Systems 319 Layered Testing Approaches 319 Cross-Functional Collaboration 320 Tailoring Tests to Specific Environments 320 Cloud Environments vs. On-Premises Infrastructure 321 Operational Technology (OT) Environments 321 Balancing Different Testing Requirements 322 Quantitative Testing Methods 322 Control Maturity Assessments 323 Turning Data into Action 323 Qualitative Testing Methods 324 Gap Analyses and Compliance Audits 325 The Role of Human Judgment 326 Beyond Metrics: Understanding the Bigger Picture 326 D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
Page
19
Contents xix Sampling Best Practices 327 Risk-Based Sampling 327 Maximizing Insights with Strategic Sampling 328 Balancing Risk and Resource Constraints 329 The Role of Automation in Risk-Based Sampling 329 Leveraging Risk-Based Sampling for Continuous Improvement 330 Representative Sampling Techniques 330 Sampling Across Business Units 330 Geographical Sampling 331 Extrapolating Results to the Broader Organization 331 Balancing Depth and Breadth in Sampling 331 Continuous Review and Adjustment of Sampling Strategy 332 Rotational Sampling 332 Building a Rotational Testing Plan 333 Balancing Risk and Resource Allocation 333 Ensuring Periodic Coverage Across All Control Sets 334 Tracking and Documenting Rotational Sampling Results 334 Combining Sampling with Automated Monitoring 334 How Automated Monitoring Enhances Sampling Efforts 335 Real-Time Detection and Remediation 335 Improving Accuracy and Coverage 336 Challenges and Considerations 336 Combining Automated Monitoring with Sampling for Continuous Improvement 337 Control Testing Frequency 337 Balancing Frequency with Resource Availability 337 High-Frequency Testing for Critical Controls 338 Aligning Testing Frequency with Risk and Impact 338 Resource Allocation and Automation 339 Scaling Testing Frequency Across Large Organizations 339 Lower-Frequency Testing for Less Critical Controls 339 Defining Less Critical Controls 340 Testing Less Critical Controls on an Annual or Biennial Basis 340 Managing the Risks of Lower-Frequency Testing 340 Strategically Scheduling Lower-Frequency Testing 341 Leveraging Low-Frequency Testing for Continuous Improvement 341 Continuous Monitoring vs. Scheduled Testing 342 Continuous Monitoring for Real-Time Control Validation 342 Scheduled Testing for Deeper, More Complex Assessments 342 The Hybrid Approach: Complementary Strengths 343 Maximizing Resource Efficiency 343 Reducing Blind Spots with Continuous Monitoring 343 Strategic Use of Continuous Monitoring and Scheduled Testing 344 Adaptation Based on Business Changes 344 Responding to New Regulatory Requirements 345 D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
Page
20
xx Contents Introducing New Technologies: An Immediate Need for Testing 345 Scaling Testing for Organizational Growth and Expansion 346 Agile Testing in the Face of Organizational Change 346 Involvement of GRC Systems and Risk/Compliance Teams 346 Role of GRC Systems in Control Testing 347 Governance, Risk, and Compliance (GRC) Integration 347 Centralized Reporting and Dashboards 347 Automated Compliance Tracking 348 Collaboration with Risk and Compliance Teams 348 Ensuring Compliance Across Frameworks 349 Bridging the Gap Between Security and Compliance 350 Outside Testing Options, Including Penetration Testing 350 Advanced Penetration Testing 351 Engaging External Experts 351 Specialized Penetration Tests 351 Red Team/Blue Team Exercises 352 Building a Stronger Security Posture Through External Testing 352 Periodic Security Audits and Assessments 353 Regular External Audits 353 Cost Considerations for External Testing 353 Maximizing the Value of External Audits 354 Leadership Insight: Managing Large-Scale Control Testing Efforts 354 Coordinating Large-Scale Testing 355 Establishing a Testing Program 355 Delegation and Oversight 356 Building Accountability Through Leadership Oversight 356 Securing Budget and Resources for Testing 357 Budgeting for Continuous Testing 357 Managing Interdepartmental Collaboration 358 Balancing Resources Across Departments 358 Fostering a Culture of Security and Collaboration 359 Chapter Recommendations 359 Chapter Conclusion 361 Questions 362 16 Control Failures: Identification, Management, and Reporting 365 Defining Control Failures 366 Common Causes of Control Failures 366 Impact of Control Failures on Organizational Security and Operations 367 Handling Control Failures 367 Root Cause Analysis: Identifying the Underlying Issues 367 Remediation Strategies 368 Testing and Validating Remediation Efforts 369 Preventative Measures to Avoid Recurrence 370 Reporting Control Failures 370 D ow nloaded from https://onlinelibrary.w iley.com /doi/ by ibrahim ragab - O regon H ealth & Science U niversity , W iley O nline L ibrary on [07/05/2025]. See the T erm s and C onditions (https://onlinelibrary.w iley.com /term s-and-conditions) on W iley O nline L ibrary for rules of use; O A articles are governed by the applicable C reative C om m ons L icense
The above is a preview of the first 20 pages. Register to read the complete e-book.
Support Author
0.00
Total Amount (¥)
0
Donation Count
Please enter an amount
Minimum ¥1
You will be redirected to Alipay to complete payment, then return here.
Order created — please complete Alipay payment
{{#payUrl}} Pay with Alipay {{/payUrl}} {{^payUrl}}{{message}}
{{/payUrl}}
Donation failed:{{message}}
Log in to link the donation to your account (anonymous payment also works)
Recommended for You
{{#thumbnailUrl}}
{{/thumbnailUrl}}
{{^thumbnailUrl}}
{{/thumbnailUrl}}
Loading recommended books...
Failed to load, please try again later