Reference Library · Sari Greene, CISSP
SY0-701 Crash Course
Two-day crash course slide notes (337 slides), sourced verbatim from the provided course material.
Welcome to Day 1
CompTIA SY0-701 Security+ Crash Course Sari Greene, CISSP, ISSMP, CRISC, CISM, CISA, SEC+ sari@sarigreenegroup.com
Why Certify?
e: sari@sarigreenegroup.com t: @sari_greene l: https://www.linkedin.com/in/sarigreene/ w: www.sarigreenegroup.com
Where are You in your Certification Journey?
o I’ve just begun studying for the CompTIA Security + exam. o I am in the midst of studying for the CompTIA Security + exam. o I am almost ready to take the CompTIA Security + exam. o I am already CompTIA Security+ certified.
Crash Course Objectives
You have just begun studying You are currently studying You are almost ready to take your exam You are already Security+ certified Reinforce your knowledge and fill in some gaps. Enhance your skillset and receive continuing education credits. Immersion into the five examination domains. Assess your strengths and weaknesses and perhaps modify your study plan.
Certification Exam Outline
This course is based on the SY0-701 Certification Exam Objectives.
- The CompTIA Security+ Certification
Exam Objectives document can be found at https://www.comptia.org/training/reso urces/exam-objectives.
- Course slides are available in the
“Resource List” window. Please respect the copyright.
- This course is being recorded and will
be available to you within 24-48 hours
Comprehensive Study
My CompTIA Security+ SY0-701 27+hr. Video Course covers in detail every exam objective and includes 3 Second Challenges, Security-in-Action case studies, Word Clouds, Deep Dive Quizzes, and Closer Look Labs. Available to you on the O’Reilly Media platform! CompTIA Labs is a remote lab environment that enables hands-on practice and skill development in actual software applications. The virtual lab scenarios are aligned with CompTIA exam objectives and are based on real workplace events.
- https://www.comptia.org/training/certmaster-labs
Exam Objectives (Course Outline)
Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies
Domain 1
Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies
Domain 1.0 General Security Concepts
# Objective 1.1 Compare and contrast various types of security controls. 1.2 Summarize fundamental security concepts. 1.3 Explain the importance of change management processes and the impact to security. 1.4 Explain the importance of using appropriate cryptographic solutions.
1.1 Compare and contrast various types of security controls.
Cyber Basics
Term Description Vulnerability A vulnerability is a weakness. Threat A threat is a potential danger. Threat Actor A threat actor is an adversary with malicious intent Exploit An exploit is when a threat actor successfully takes advantage of a vulnerability. Controls Controls are tactics, mechanisms, or strategies that proactively minimize risk by either:
- Reducing or eliminating a vulnerability.
- Reducing or eliminating the likelihood that a threat actor will be able to exploit a
vulnerability.
- Reducing or eliminating the impact of an exploit.
Countermeasures• Countermeasures are controls implemented to address a specific threat; they are generally reactive.
Control Categories (implementation)
Category Description Technical Technical control mechanisms are implemented using hardware, software, and/or firmware components.
- Can be native or supplemental.
Managerial Managerial controls support risk management, governance, oversight, strategic alignment, and decision making Operational Operational controls are aligned with a process that are primarily implemented and executed by people. Physical Physical controls are designed to address physical interactions. Generally related to buildings and equipment.
Control Classifications (objective)
Control Objective Description Deterrent Deterrent controls discourage a threat agent from acting. Preventative Preventative controls stop a threat agent from being successful. Detective Detective controls identify and report a threat agent or action. Corrective Corrective controls minimize the impact of a threat agent or modify or fix a situation. Directive Directive controls are proactive actions taken to cause or encourage a desirable event or outcome to occur. They are often used to increase the effectiveness of other controls. Compensating Compensating controls are controls implemented in lieu of a recommended control that provides equivalent or comparable protection
Security Control Diversity
- Controls should not be subject to a cascade effect and should maintain
independence.
- Diversity of type of control and associated vendor should be considered.
Defense-in-Depth (also known as layered security) is the design and implementation of multiple overlapping layers of diverse controls.
1.2 Summarize fundamental security concepts.
Information Security CIA Triad + Privacy
Confidentiality Integrity Information Security Availability Privacy
Fundamental Principles
Confidentiality Integrity is the principle that systems are trustworthy, and work as intended, and the data is complete and accurate. Integrity Availability Confidentiality is the assurance that information is not disclosed to unauthorized persons, processes, or devices. Confidentiality covers data in storage, during processing, and in transit. Availability is the principle that Information, systems, and supporting infrastructure are operating and accessible when needed. Privacy Privacy is the right of an individual to control the use of their personal information. Data privacy controls relate to collection, usage, notification, accuracy, and sharing. .
Zero Trust (ZT)
Zero trust (ZT) is a security framework requiring all subjects, assets, and workflows to be authenticated, authorized, and continuously validated before being granted or keeping access to applications and data.
- The goal is to prevent unauthorized access to data and services coupled with
making the access control enforcement as granular as possible.
- Zero trust supports the principle of least privilege.
- Zero trust minimizes the risks associated with standing privilege.
- Standing privilege refers to 24x7x365 privileged access.
Physical Security
Physical security is based upon a layered defense model. The premise of a layered defense model is that if an intruder can bypass one layer of controls, the next layer of controls should provide additional deterrence or detection capabilities.
- Obstacles (deterrent controls) to frustrate trivial attackers and delay
serious ones.
- Detective controls make it likely that attacks will be noticed.
- Response mechanisms to catch or impede attackers.
Physical security is the protection of people, property, and physical assets from actions and events that could cause damage, loss, or unauthorized activity.
Site Security Controls
Control Description Lighting Lighting for personnel safety and intruder deterrence.
- Intruders are less likely to enter well-lit areas.
Signs Signs for personnel safety and intruder deterrence.
- Warning signs indicate surveillance (“someone is paying attention”).
Barriers Barriers such as walls, fences, gates, bollards, and access control vestibules define the perimeter and can be used to control and divert flow of traffic. Surveillance Surveillance sensors* can be used to monitor and detect suspicious, abnormal, or unwanted behavior. [*infrared, motion, photometric, acoustical, contact, pressure, microwave, ultrasonic] Guards Security guards may be stationed at checkpoints, patrol the area, manage surveillance, and respond to breaches and/or suspicious activity.
Environmental Impact
- Computers, electronic equipment, and transmission media are sensitive to
environmental factors such as heat, humidity, air flow, and power quality.
- Environmental systems are often provided by and/or managed by
contractors.
- Environmental system providers should be subject to due diligence
(investigation) and included in vendor management programs.
- Environmental controls/products should be included in vulnerability
management, patch management, disaster recovery, business continuity, and assessment/audit programs. Environmental imbalance and vulnerabilities can impact stability, availability, and integrity.
Environmental Baselines
Control Description Temperature Acceptable temperature for an area containing computing devices is between 18-27 degrees C (64.4-80.6 F).* Humidity High humidity can cause corrosion and low humidity can cause excessive static electricity. Relative humidity between 50-70% is acceptable.* Power Continuous clean (filtered) power - consistent voltage. Fire Fire detection and suppression capabilities. Discharge and Interference Electronic components and cable can be impacted by electrostatic discharge (ESD), Electromagnetic Interference (EMI), and Radio Frequency Interference (RFI). * Source: American Society of Heating, Refrigerating and Air-Conditioning Engineers
1.3 Explain the importance of change management processes
and the impact to security.
Configuration Management
ITIL defines Service Asset and Configuration Management (SACM) as: “The process responsible for ensuring that the assets required to deliver services are properly Configuration Management (CM) is a set of practices designed to ensure that configuration items are deployed in a consistent state and stay that way through their lifetime. The goal of configuration management is to minimize risk.
- A Configuration Item (CI) is an aggregation of information system components
and treated as a single entity throughout the configuration management process.
- A Baseline Configuration (BC) is a set of specifications for a CI, that has been
reviewed and agreed upon and can be changed only through change control procedures.
- The baseline configuration is used as a basis for future builds and releases.
Automated Provisioning
ITIL controlled, and that accurate and reliable information about those assets is available when and where it is needed. This information includes details of how the assets have been configured and the relationships between assets. Automated provisioning is the ability to deploy information technology (IT) or operational technology (OT) systems and services using predefined, automated procedures without requiring human intervention.
- Automation is used to ensure consistency in provisioning in support of
configuration management.
- Automation reduces or eliminates manual dependencies and human error.
Provisioning Processes
Process Description Demand-generated Resource Allocation Demand –generated resource allocation is the automatic provisioning and deprovisioning of resources based upon demand. Idempotence Idempotence is a principle that every time an automated configuration script is run, the same exact result is produced. Immutable System Immutability is the principle that resources should not be changed, only created and destroyed.
- Utilizes automation to replace rather than fix.
Infrastructure- asCode Infrastructure-as-code is using code to manage configurations and automate provisioning of infrastructure.
- Supports the principle of Idempotence.
Change Management
- The change control process establishes standard procedures for
managing change requests in a secure, timely, and efficient manner.
- Process components include prioritization, impact analysis, testing,
rollback strategies, accountability, documentation, automation and implementation. The objective of change management is to drastically minimize the risk and impact a change can have on business operations.
1.4 Explain the importance of using appropriate cryptographic
solutions.
Cryptography
- Modern cryptography has widened the historical definition to include
assurance of integrity and sender identity.
- Strength of a cryptosystem is a combination of the algorithm, the
algorithmic process, the length of the key, and the secrecy of the key. If one element is weak, the cryptosystem can potentially be compromised.
- Deprecated means that the use of the algorithm and key length is
allowed, but the user must accept some risk due to inherent weaknesses.
- Broken means that the algorithm and/or key length is exploitable.
Traditional Cryptography is the conversion of communication into a form that can only be read by the intended recipient.
Cryptographic Solutions (Use case)
Solution Use Case Encryption Encryption is the process of encoding information.
- The use case of encryption is confidentiality.
Hashing Hashing is a one-way function that turns a file or string of text into a unique digest of the message.
- The use case for hashing is integrity.
Digital Signatures A digital signature is a hash value encrypted using the sender's private key.
- The use case is sender authenticity and non-repudiation.
Digital Certificates A digital certificate is a digital object that is tied to a cryptographic key pair.
- The use case for a digital certificate is authentication.
Cryptographic Primer
Element Description Cipher A cipher is a technique that transforms plaintext into (encrypted text) ciphertext and back. Algorithm An algorithm is a mathematically complex modern cipher. Key A key (cryptovariable) is a secret value used with an algorithm. The key dictates what parts of the algorithm will be used, in what order, and with what values. Symmetric Key A symmetric key is a single shared key used for both encryption and decryption. Asymmetric Asymmetric keys are two mathematically related keys used for encryption and decryption.
Encryption
Clear Text Algorithm & Key Ciphertext Ciphertext Algorithm & Key Plaintext Encryption is commonly used to protect the confidentiality of data in transit and data at rest.
Symmetric Encryption
Clear Text Symmetric Algorithm & Key Ciphertext Ciphertext Symmetric Algorithm & Key Plaintext Symmetric encryption uses the same key to encrypt and decrypt. The key may be referred to as a single key, shared key, secret key, or session key.
Asymmetric Encryption
Clear Text Asymmetric Algorithm & Key Ciphertext Ciphertext Asymmetric Algorithm & Key Plaintext Asymmetric encryption uses two mathematically related keys to encrypt and decrypt. The keys are referred to as public and private keys. The public key is freely distributed. The private key must be secured.
Asymmetric Encryption Message Flow
Plaintext Asymmetric Algorithm & Bob’s Public Key Encrypted Message Encrypted Message Asymmetric Algorithm & Bob’s Private Key Plaintext The challenge is that asymmetric is computationally intensive. Alice sends Bob an asymmetrically encrypted message using public and private keys. The public key is freely distributed. The private key must be secured.
Symmetric and Asymmetric Comparison
Feature Symmetric Asymmetric # of Keys Single shared key Key pair Processing Computationally efficient Computationally intensive Block Sizes Large Small Scalability Not scalable Scalable Key Exchange Key exchange is inherently insecure Key exchange distribution system
Hybrid Message Flow
Encrypted Session Key Asymmetric Algorithm & Bob’s Private Key Session Key Encrypted Message Symmetric Algorithm & Session Key Plaintext Message Plaintext Message Symmetric Algorithm + Session Key Encrypted Message Session Key Asymmetric Algorithm & Bob’s Public Key Encrypted Session Key
Hashing
Hashing can be used to:
- Validate that a message has not been changed during
transmission.
- Verify that a file has not been altered.
- Verify that a forensic clone is the exact same as the original
media The objective of hashing is to prove integrity. Hashing produces a visual representation of a data set that can be used for comparative purposes. The output is known as a message digest, fingerprint, or hash value.
The Hashing Process
Variable Length Input Hash Function Unique One-way Fixed Length Output
Hash Generation
Source: http://onlinemd5.com/
Message Digests in Action
Alice puts message through a hash function and generates a message digest (hash value) Alice sends the message and message digest to Bob Bob receives the message and message digest Bob puts message through a hash function and generates a message digest (hash value) Bob compares both message digests If the message digests are the same – the message was not modified in transmission
Digital Signature
The objective of a digital signature is to prove integrity and non-repudiation. Nonrepudiation means that the signer cannot deny sending the message.
- Digital signatures require two algorithms - a hashing algorithm & a digital
signature algorithm (DSA , RSA). A digital signature is a message digest that has been encrypted using the sender’s private key.
Digital Signatures in Action
Alice puts message through a hash function and generates a message digest Alice encrypts the message digest with her private key Alice sends the message and message digest to Bob Bob puts the plaintext message through the same hash function and generates a message digest Bob decrypts the message digest using Alice’s public key proving Authenticity Bob compares both message digests If the message digests are the same – the message was not modified proving Integrity If the message digests are different – the message was modified
Digital Certificates
- The X.509 standard defines the certificate format and fields for public keys.
- The X.509 standard defines the distribution procedures.
- The current version of X.509 for certificates is v3.
- There are a variety of certificate types including personal, machine, domain,
extended validation, code, trusted/intermediate authority. A digital certificate is a digital form of identification. It consists of a cryptographic key pair and information about the entity associated with the keys. A digital certificate can be purchased from a commercial certificate authority or self-generated.
• Browsers and devices trust a CA by accepting the Root Certificate into its
root store – essentially a database of approved CAs that come preinstalled with the browser or device.
- The CA receives certificate requests, validates the applications, issues
the certificates, and publishes the ongoing validity status of issued certificates.
- A Registration Authority (RA) offloads some of the work from the CA.
The RA can accept and process registration requests and distribute certificates. Digital certificates are issued by commercial trusted parties, called Certificate Authorities (CA). Commercial Certificate Authority
Commercial Certificate Request Process
Using a key generation program, applicant generates a publicprivate key pair Applicant submits a certificate signing request (Identifying info + public key) The CA or RA validates the application The CA generates the certificate and signs it with their private key The CA send the certificate to the applicant The applicant installs the certificate The applicant renews or destroys the certificate
Certificate Validity
CA-maintained list of certificates that have been revoked
- Pull model – CRL is downloaded by the user or
organization.
- Push model – CRL is automatically sent out by the CA at
regular intervals. Process designed to query the status of a certificate in realtime.
- OCSP stapling is a time-stamped (cached) OCSP
response. Certificate Revocation List (CRL) Online Certificate Status Protocol (OCSP)
Emerging Cryptography
Solution Description Homomorphic Encryption Homomorphic encryption allows for encrypted data to be processed.
- Partially Homomorphic Encryption (PHE)
- Somewhat Homomorphic Encryption (SHE)
- Fully Homomorphic Encryption (FHE - in development)
Quantum Encryption Quantum cryptography, also called quantum encryption, applies principles of quantum mechanics to encrypt messages. Quantum computers are machines that exploit quantum mechanical phenomena to solve mathematical problems that are difficult or intractable for conventional computers. Post-Quantum Encryption The goal of post-quantum cryptography is to develop cryptographic systems that are secure against both quantum and classical computers and can interoperate with existing communications protocols and networks.
Steganography
- Steganography consists of a message and a cover image.
- Message is the secret data.
- Cover image is the carrier that hides the message. The cover image
can be text, image, audio or video. Steganography is the science of hiding information. The objective of is concealment.
Steganography Illustrated
Copy /b image1.jpg+text1.txt final1.jpg
Steganography v. Cryptography
Feature Steganography Cryptography Purpose Purpose is to conceal (covered writing). Purpose is confidentiality, integrity, and/or non-repudiation. Communication Channel The existence of the secret communication channel is not known. The existence of the communication channel is known Mathematical Transforms Mathematical transforms are not generally used. Mathematical transforms are used.
Assessment Question 1
Which statement about controls and countermeasure is not true? A. Controls are designed to proactively minimize risk. B. Countermeasures are designed to reactively minimize risk. C. Countermeasures are designed to address a specific threat. D. Controls by design are not independent of each other.
Assessment Question 2
Which statement best describes the principle of integrity? A. Assurance that information is not disclosed without authorization. B. Data is complete and accurate, and systems work as intended. C. Individuals have the right to control their information. D. Consent to collect and utilize information data.
Assessment Question 3
Which action is not supported by Zero Trust? A. Reauthentication B. Least privilege C. Continuous validation D. Standing privilege
Assessment Question 4
What is the acceptable relative humidity for Data Center equipment? A. 0% B. Less than 20% C. 50-70% D.Above 80%
Assessment Question 5
Mary wants to use asymmetric encryption for a session key exchange with Bob. Which cryptovariable should she use to encrypt the session key? A. Mary’s public key B. Mary’s private key C. Bob’s public key D. Bob’s private key
Domain 2
Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies
Domain 2.0 Threats, Vulnerabilities & Mitigations
# Objective 2.1 Compare and contrast common threat actors and motivations. 2.2 Explain common threat vectors and attack surfaces. 2.3 Explain various types of vulnerabilities. 2.4 Given a scenario, analyze indicators of malicious activity. 2.5 Explain the purpose of mitigation techniques used in the enterprise.
2.1 Compare and contrast common threat actors and
motivations.
Cyber Threat Actors
Lone Skilled | Unskilled Attacker Hacktivist Organized Crime (cyber-criminals) Nation- State Insiders | Shadow IT Competitors
Threat Modeling
Threat modeling is a structured process by which potential threats and threat actors can be identified, enumerated, and prioritized. Threat modeling approaches:
- Asset-centric identifies valued assets and related motivation
[what/why].
- Architecture-centric identifies system design component strength and
weaknesses [how].
- Attacker-centric identifies known adversaries [who].
Threat Intelligence Sources
Subscription and/or public feeds provided by vendors such as Microsoft, Cisco, or Apple. Government Agencies Technology Vendors Journalists, Researchers & Thought Leaders Cybersecurity Companies Subscription and/or public feeds provided by cybersecurity vendors such as TylerDetect, AlienVault, FireEye, RSA, and Secureworks. Bruce Schneier, Jeremiah Grossman, Brian Krebs, Mark Russinovich, Kim Zetter, Nicole Perlroth, Andy Greenberg, Ellen Nakashima, etc. Data provided by agencies such as NIST, FBI, USCERT, NVD, and the Cybersecurity & Infrastructure Agency (CISA). Threat intelligence is evidence-based knowledge about emerging threats that can be used to inform control decisions OSINT Open-Source Intelligence (OSINT) is a term used to refer to the data collected from publicly available sources to be used in an intelligence context. .
2.2 Explain common threat vectors and attack surfaces.
Threat Vectors
- Common threat vectors include default credential, weak permissions, data
exfiltration, open ports, unsupported systems and software, unsecured networks, shadow IT, and vulnerable software.
- Operational threat vectors manifest in day-to-day activities and are generally
related to weak or non-existent internal controls. A threat is a danger. A threat vector, (also known as attack vector) is a potential pathway, or scenario that can be exploited. An attack surface is the sum of all threat vectors.
Third-party Threat Vectors
- Third-party threat vectors (pathways to exploit) include lack of support,
proprietary configurations, EOL, and supply chain disruption and nonconformance.
- Consequences can include financial loss, reputational damage, inefficient
operations, data breach | exfiltration, service disruption, and regulatory noncompliance. Third-parties include vendors, managed service providers (MSPs), business partners, consultants, and contractors.
Human Threat Vector
- Social engineering is often considered the path of least resistance.
- Social Engineers use psychology to take advantage of basic human instincts
and exploit human cognition functions. Pretexting and impersonation are the two primary social engineering tactics.
- A significant number of security incidents and data breaches have started
with or have included a social engineering component.
- An emerging trend is the use of synthetic content.
- Social engineering is a critical training topic across an entire organization.
Social engineering is the action of exploiting human nature rather than technical hacking techniques to gain access to minds, systems, data or buildings.
2.3 Explain various types of vulnerabilities.
Types of Vulnerabilities
Type Description Network Network vulnerabilities are weaknesses within an organization's hardware or software infrastructure. Operating System Operating system vulnerabilities are code weaknesses (bugs) which can be exploited and/or OS mis-configurations. Process Process vulnerabilities occur when there is a security exposure within the process. People Human vulnerabilities are the result of human error, inattention, unintentional or accidental actions. Zero-day A zero-day vulnerability is a flaw in hardware or software that has been discovered but a fix is not yet available. A zero-day exploit is a method that weaponizes a discovered vulnerability.
Vulnerability Management
- The goal of vulnerability management is to reduce the risk of security
breaches and minimize the potential impact of any vulnerabilities that are identified.
- Vulnerability management is an ongoing process that requires continuous
monitoring and updating as new vulnerabilities are discovered or new threats emerge. Vulnerability management is the process of identifying, assessing, reporting on, prioritizing, and mitigating vulnerabilities.
2.4 Given a scenario, analyze indicators of malicious activity.
Cyber Attack Terms to Know
Term Description Targeted Attacker chooses a target for a specific objective. Opportunistic Attacker takes advantage of a vulnerable target (not previously known to them). Amplification Attacker uses an amplification factor to multiply its power. Artifact Information of interest (clues) such as virus signature, IP addresses, malicious URLs, command and control connections, file changes, and “reports from the field”.
Attack Indicators
There are two primary types of attack indicators – IoA and IoC. Indicators of Compromise (IoC) are artifacts about an event that has already happened and are used to identify potential security breaches. Typical artifacts left behind by an attacker include new user accounts, file hashes, virus signature, malicious files, command and control connections, modification of system and registry settings, evidence of data exfiltration, and patterns of suspicious behavior Indicators of Attack (IoA) are a set of behaviors or actions (sometimes referred to as tradecraft) that are typically observed during the early stage of an attack although they may be identified throughout the cyber kill chain. These behaviors include network traffic patterns, system events, and user activity.
Categories of Attack
Category Description Malware Malware is used by hackers, cybercriminals, hacktivists, and cyber terrorists to either steal information, harm or disrupt operations, extort, and/or weaponize devices. Brute Force A brute force approach to a problem leverages those qualities of a brute (strength and power) while being bound by its limitations of resources and discovery. Digital Infrastructure The objective of a digital infrastructure attack is the disruption, manipulation, or compromise of information technology (IT) or operational technology (OT) systems. Application The objective of an application attack is either to manipulate the input, what is sent to the processor, or the output. Cryptographic A cryptographic attack is the circumvention of a cryptographic system by exploiting a weakness in a code, cipher, cryptographic protocol, key management scheme, or implementation.
Digital Infrastructure Attack Techniques
Spoofing Poisoning is manipulating a trusted source of data (e.g., DNS)
- Enables an
attacker to control the trusted source of data and redirect / manipulate actions. Poisoning Hijacking Denial of Service Spoofing is impersonating an address, system, or person
- Enables an
attacker to act as the trusted source and redirect or manipulate actions. Hijacking is intercepting communication between two or more systems
- Enables an
attacker to eavesdrop, capture, manipulate, and/or reuse data packets. Web hijacking is misdirection to a fraudulent website for malicious purposes.
- Examples
include domain hijacking, URL squatting, and typo squatting Denial of Service is overwhelming system resources
- Enables an
attacker to make services unavailable for their intended use. Web Hijacking
2.5 Explain the purpose of mitigation techniques used to
secure the enterprise.
Secure Design Engineering
Category Principle Planning Threat modeling, Keep it simple, Default deny posture, Fail-secure, Open design Configuration Secure the weakest link, Defense-in-depth, Least functionality, Appropriate disclosure, Sanitization Relationship Zero trust, Trust but verify, Separation of duties, Least privilege, Psychological acceptance The goal of secure design engineering is to develop trustworthy and survivable systems.
Secure Design Planning Principles
Principle Description Threat Modeling Use threat modeling to anticipate threats. Focus on undesirable consequences. Keep it Simple Security mechanisms should be as simple as possible. Simplicity means fewer possibilities exist for error, and the assessment process is less complex. Default Deny Posture Base access decisions on permission rather than exclusion. This means that, by default, access is denied, and the protection scheme identifies conditions under which access is permitted. Fail-Secure In the event of failure, access is denied. Open Design The security mechanism should not depend upon the secrecy of the design or implementation. Argument against “security through obscurity”.
Secure Design Configuration Principles
Principle Description Secure the Weakest Link Identify and strengthen weak links until an acceptable level of risk is achieved. Defense-in-Depth Utilize multiple layers of diverse controls including endpoint protection such as host-based firewall. Least Functionality Systems and devices should be configured to provide only essential capabilities, and specifically prohibit or restrict the use of unnecessary functions, ports, protocols, and services. Appropriate Disclosure Error and system messages should not include unnecessary information that may lead to a compromise of security. Sanitize Data Sent to Other Systems Sanitize all data passed to complex subsystems such as command shells, relational databases, and commercial off-the-shelf (COTS) components.
Secure Design Relationship Principles
Principle Description Zero Trust No default trust or privilege. Verification (authentication) is required for access. Trust but Verify Dependencies are not trusted until proven trustworthy. Separation of Duties Breaking a task into segments so that no one subject is in complete control or has complete decision-making power. Least Privilege Giving a subject or process only the rights and permissions needed to complete assigned tasks. Psychological Acceptance Human interface should be designed for ease of use, so that users routinely and automatically apply the protection mechanisms correctly.
Segmentation
- Security zones are divisions of the network based on functional, performance,
and/or security requirements.
- Security zones are enforced by firewall ingress and egress access control lists
(ACL) - rules. Segmenting an enterprise into security zones is useful for creating and enforcing security policies, controlling information flow, and securing network access.
Security Zones
An untrusted network is one which the organization has no control over. Screened Untrusted Subnet Trusted Enclave A screened subnet has connections to both trusted and untrusted networks. A trusted network is one which the organization has complete control over. An enclave is a restricted network within a trusted network. Micro-segment Protect Surface Air Gapped Physically Isolated An air gapped network does not connect to any untrusted network. A physically isolated network does not connect to any other network. Micro-segment is a zone within a data centers to isolate workloads and secure them individually. The protect surface is made up of the network’s most critical and valuable data, assets, applications, and services (DAAS).
Isolation
Virtualization technology creates multiple environments from a single physical hardware system
- Virtual machines (VMs) provide fault and security isolation at the
hardware level including memory and CPU access. A virtual local area network (VLAN) divides a single existing network into multiple logical network segments which can be restricted.
- Broadcast domains are portioned and isolated at the data link
layer. Virtualization Logical Isolation is when zones, devices, sessions, or even components need to be segregated, so as not to cause harm or to be harmed.
Assessment Question 1
This adversary’s primary motivation is to make a political or social statement. A. Insider B. Hacktivist C. Competitor D. Nation-State
Assessment Question 2
Which statement best describes an attack surface. A. An attack surface is a danger. B. An attack surface is a scenario that can be exploited. C. An attack surface is the sum of all threat vectors. D. An attack surface is the path of least resistance.
Assessment Question 3
This technique now being used in social engineering campaigns involves generating, manipulating and/or altering data. A. Impersonation B. Gaslighting C. Pretexting D. Synthetic content
Assessment Question 4
The objective of this type of digital infrastructure attack is to manipulate a trusted source of data such as a routing table. A. Spoofing B. Pretexting C. Hijacking D. Poisoning
Assessment Question 5
Basing access decision on permissions rather than exclusion exemplifies this approach. A. Fail-secure B. Default deny C. Least functionality D. Trust but verify
Domain 3
Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies
Domain 3.0 Security Architecture
# Objective 3.1 Compare and contrast security implications of different architecture models. 3.2 Given a scenario, apply security principles to secure enterprise architecture. 3.3 Compare and contrast concepts and strategies to protect data. 3.4 Explain the importance of resilience and recovery in security architecture.
3.1 Compare and contrast security implications of different
architecture models.
Computing Architecture
- Examples of computing architecture include centralized, decentralized
client/server, industrial control systems, cloud, virtualization, embedded systems, and Internet of Things (IoT). A computing architecture model is a conceptual framework used to describe the design and organization of a network. It provides a high-level view of the components, interfaces, and relationships between different parts of the system.
Architecture Primer
Design Description Centralized A processing and data storage are managed and controlled by the central server or mainframe rather than on individual devices. Client-Serer Decentralized computing model in which a client device communicates with a server to request services or data. Industrial Control System Networked devices and software used to monitor and control industrial processes, such as manufacturing, power generation, and water treatment. Cloud Delivery of computing services over the Internet (“the cloud”) that scale to business needs. Virtualized Environment Technology that creates multiple environments from a single, physical hardware system. Embedded Systems A device that contains a microprocessor and software designed to perform a specific task. IoT / IIot A network of physical objects or "things“.
Industrial Control Systems
- Components include hardware devices such as sensors, actuators, and controllers
and customized software applications.
- ICS (Industrial Control System) architecture can be either centralized or
decentralized depending on the specific design and implementation.
- Supervisory Control and Data Acquisition (SCADA) is a specialized ICS system that is
designed specifically for monitoring and controlling large-scale industrial processes. Industrial Control Systems (ICS) are networked devices and software used to monitor and control industrial processes, such as manufacturing, power generation, and water treatment.
Cloud Computing
- Cloud characteristics
- Service models (SaaS, PaaS, and IaaS)
- Deployment models (private cloud, community cloud,
and public cloud, hybrid cloud)
- Shared Responsibility Model
Cloud computing is the delivery of computing services—including servers, storage, databases, networking, software, analytics, and intelligence—over the Internet (“the cloud”) that scale to business needs.
Defining Cloud Characteristics
Characteristics Description Resource Pooling The provider’s computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources.
- Location independence
- Location abstraction (country, state, data center)
Demand-generated Resource Allocation Ability to a adapt to changing workload demand by auto provisioning and deprovisioning pooled resources to match current demand. Measured Service Metering capability.
Cloud Infrastructure
- The physical layer (e.g., processors, memory, connectivity, and storage) is used
to build the cloud’s resource pools.
- The virtual/abstracted infrastructure.
- All clouds utilize some form of virtual networking to abstract the physical
network and create a network resource pool.
- Typically, the cloud user provisions desired networking resources from this
pool, which can then be configured within the limits of the virtualization technique used. Cloud infrastructure is comprised of two layers – physical and virtual (abstracted).
Demand-generated Resource Allocation
Scalability is the ability of the system to automatically accommodate larger loads by adding resources – either making hardware stronger (scale up) or adding additional nodes (scale out). Elasticity is the ability to fit the resources needed to cope with loads dynamically. When the load increases, more resources are added and when demand decreases, resources are removed. Demand-generated resource allocation is the automatic provisioning and deprovisioning of resources. Scalability Elasticity
Cloud Service Models
Model Provision Software-as-aServices (SaaS)Computing Resources + Operating System + Application
- The customer uses the provider’s applications running on the
provider infrastructure. Platform-as-a-Service (PaaS) Computing Resources + Operating System + (optionally, database)
- The customer deploys onto the provider infrastructure created or
acquired applications. Infrastructure-as-aService (IaaS)Computing Resources (“bare metal”)
- The customer provisions processing, storage, networks, and
other fundamental computing resources from the provider. Anything-as-aService (XaaS)Anything-as-a-service (XaaS) represents the growing type of services available over the Internet via cloud computing opposed to being provided locally, or on premises.
Cloud Deployment Models
Model Description Considerations Public cloud Provisioned for public use. Location Multitenancy Community cloud Provisioned for the exclusive use by a welldefined group. Multitenancy Private cloud Provisioned for the exclusive use of a single organization. Scalability Hybrid cloud Hybrid cloud describes a mixed use of onpremise, private cloud and public cloud platforms with orchestration among the providers.
- Cloud bursting is the on-demand and
temporary use of the public cloud when demand exceeds resources available in the private cloud or on-premise infrastructure. Security of the connection
Cloud Security Options
Option Description CASB Cloud Access Security Brokers (CASBs) are security policy points (software or appliance) placed between “the cloud” and enterprise users.
- CASBs proxy traffic and use auto discovery to identify cloud applications.
Security policies are interjected as cloud-based resources are accessed. For example, authentication, encryption, visibility, and DLP.
- Provides control over shadow IT applications. Shadow IT is used to describe the
use of IT solutions that are managed outside of and without the knowledge of the IT department. Secaas Security-as-a-Service (SecaaS) is the delivery of managed security services for public, private, and hybrid cloud environments.
- SecaaS relieves the burden of relying on the SaaS, PaaS, or IaaS vendor for
security protection and enforcement.
Shared Responsibility Matrix
Component SaaS PaaS IaaS Infrastructure Security CSP CSP CSP Platform Security CSP CSP User Application Security inc. APIs CSP User User Data Security User User User User Security User User User Legend:
- CSP refers to the cloud service provider.
- User refers to the provisioner of the service.
Embedded Systems
- An embedded system can either be fixed or programmable.
- Embedded system applications range from digital watches and microwaves
to hybrid vehicles and avionics.
- It is estimated that 98% of all microprocessors manufactured are used
in embedded systems.
- Commercial uses of embedded systems include medical devices,
biomedical monitoring, vehicle systems (e.g. adaptive cruise control, emission control systems, collision sensors, ABS), aircraft controls systems and sensors, and smart meters An embedded system is an electronic product that contains a microprocessor and software designed to perform a specific task.
Closed Loop
1. System on a chip (SoC) which is microprocessor or microcontroller with advanced peripherals such as Wi-Fi. 2. Real-time Operating System (RTOS) that defines the way the system works. 3. Application software specific to the device. An embedded system generally has three closed loop components.
The Internet of Things (IoT)
The Internet of Things (IoT) refers to a network of physical objects or "things" embedded with sensors, software, and connectivity that enable them to exchange data with other connected devices and interact with users over the Internet (smart devices). Industrial Internet of Things (IIoT) refers to the application of IoT technology and principles in industrial settings to improve efficiency, productivity, and safety. It refers to the use of connected sensors, devices, and machines in manufacturing, logistics, and other industrial settings to collect, analyze, and share data in real-time.
Edge Computing
Edge computing is the deployment of data-handling activities and operations at or close to the source without having to go through centralized network segments.
- Depending on the device or equipment being considered, the network edge
can refer to the area where the device communicates with the Internet.
- For IIoT devices, such as a smart camera, the network edge will be the
processor within the camera.
- Smart edge devices are devices equipped with features for capturing data
and processing.
Virtualization
Virtualization is technology that creates multiple environments from a single, physical hardware system.
Virtualization Benefits
Virtualization enables the efficient use of hardware resources by allowing multiple virtual systems to run on a single physical system, which can improve resource utilization and reduce costs. Virtualization provides flexibility and scalability by allowing virtual systems to be easily created, deployed, and managed, without needing to invest in additional physical hardware. Each virtual instance (server, desktop, storage, network) behaves as if it were a physically separate system but is running on a shared physical host. Resource Utilization Flexibility
3.2 Given a scenario, apply security principles to secure
enterprise architecture.
Network Devices
- An appliance is a self-contained resource that provides a specific function.
- A sensor is a device that collects information about the network or host. A
sensor can report and/or act.
- A collector is a device that performs targeted collection which feeds into an
aggregation or correlation engine. A network device is a piece of hardware or software that is used to enable and manage data communication and report on and/or enforce rules.
Decision States
State Description True Positive Positive activity is correctly identified. False Positive Positive activity is incorrectly identified as negative. True Negative Negative activity is correctly identified. False Negative Negative activity is incorrectly identified as positive.
- Positive state refers to normal or expected (what you’re looking for) activity.
- Negative state refers to abnormal or unexpected activity.
Device Failure Modes
Fail-Open Fail-closed mode means that the network device blocks network traffic even if the device fails. This setting is intended to ensure network security by preventing unauthorized access to network resources in the event of a hardware or software failure. Also referred to as Fail-Secure. Fail-Closed Fail-open mode means that the network device allows network traffic to continue to flow even if the device fails. This setting is intended to prevent disruptions to network connectivity and to minimize the impact of hardware or software failures on network operations. Also referred to as Fail-Safe.
Common Network Devices
Device Description Firewall Isolates network segments and controls ingress and egress traffic. IDS/IPS Intrusion Detection System (IDS) can analyze and monitor network traffic. Intrusion Prevention System (IPS) can analyze, monitor, and proactively deny network traffic. Jump Server A jump server, is a hardened computer system or server that provides secure access to other computers or systems within a network. Proxy Server A proxy server is an intermediary machine, between a client and a server, which is used to filter or fetch and cache requests made by the client. NAC Evaluate endpoints for network access using pre- and post admission policies. DLP Detects data movement and prevents data exfiltration.
Firewall
The primary objective of a traditional firewall is to isolate network segments and traffic by controlling ingress and egress access.
- Firewalls are a deterrent control because a hardened appearance can discourage
opportunistic attackers.
- Firewalls are a preventive control because they can be configured to restrict
ingress and egress network traffic, repel known attacks, manage nonroutable IP addresses, and anonymize internal addresses.
- Firewalls can be a detective control because they can be configured to log events
and to send alerts.
Firewall Devices
Type Description Packet-Filtering (OSI Layer 3) Packet-filtering (stateless) firewalls inspect each packet individually and decides whether a packet is allowed or denied based on the header information. Stateful (OSI Layer 4) Stateful firewalls inspect headers and packet payload and keeps track of the state of the entire connection from start to end. Stateful firewalls filter packets based on the full context of a given network connection. Web-Application (OSI Layer 7) A WAF inspects, protect web applications from malicious attacks such as XSS and SQL injection, It works by analyzing incoming HTTP traffic to a web app and filtering out any malicious traffic before it reaches the application. NextGeneration (OSI Layer 7) Next-gen firewalls inspect the entire transaction; does surface-level and deep packet inspection; and incorporates additional security features and application controls. Virtual FW (OSI Layer 7) Virtual firewalls are designed to protect virtualized environments such as cloud infrastructure and virtual machines.
IDS/IPS
Both IDS & IPS monitor for & analyze suspicious traffic action IPS is a control system and can deny access IPS/IDS can be network-based (NIDS/NIPS) or host-based (HIDS/HIPS). IDS is a monitoring tool and cannot take selfdirected action
IDS Detection Engines
Engines Description Signature-based Pattern-matching decisions are based on established known signatures.
- Signatures must be updated frequently.
Rule-based Analyzes behavior for violation of preconfigured rules. Behavior-based Behavior-based anomaly decisions rely on predicted norms and deviations.
- Can be learned over time and/or start with a set of assumptions and
adapt to local conditions.
- Requires fine tuning.
Heuristic Continually trains on network behavior and can continually alter detection capabilities based on learned knowledge.
Secure Communications
- The objective of secure communications is confidentiality, integrity,
authentication, non-repudiation, or any combination thereof.
- Transport Layer Security (TLS), and Internet Protocol Security (IPsec) are widely
used to secure online transactions, email communication, and other sensitive data transmissions. A secure protocol is a set of rules and procedures designed to ensure secure communication between two or more parties over a network or the internet.
Secure Socket Layer (443)
Developed in 1995 by Netscape, Secure Sockets Layer (SSL) is used to establish a secure communication channel by negotiation using a stream cipher.
- In 2015, SSL 3.0 was deprecated by the Internet Engineering Task Force (IETF) due to
numerous security vulnerabilities discovered over the years. New vulnerabilities continue to be discovered. Most browsers no longer support SSL.
- SSL2.0 and 3.0 should be disabled. When enabled they make a system vulnerable to a
downgrade attack. Connection Request Secure Connection Needed Security Capabilities Encrypted Session Established
Transport Layer Security (443)
Transport Layer Security (TLS) is used to establish a secure communication channel between two TCP sessions using a cryptographic key exchange.
- TLS is the successor and recommended replacement for SSL. TLS uses a block
encryption cipher and includes advanced security features and improved algorithms.
- The current version is TLS 1.3 should be used (or higher, as released). IETF has
officially declared both TLS 1.0 and TLS 1.1 deprecated (weak and vulnerable) and should not be used. Connection Request Session Establishment Confirmation Cryptographic Key Exchange & Encrypted Session Established
IP Security (IPsec)
- Introduced in the mid-1990’s, IPsec was initially designed to secure host-to-host
communication.
- IPsec operates at the Network layer (L3) and can be used to encrypt data being
sent between any systems that can be identified by an IP address.
- IPsec can be implemented in two modes – tunnel (default) and transport.
- IPsec is now the de facto standard for IP-based VPNs.
IPsec (Internet Protocol Security) is a protocol suite used to secure Internet Protocol (IP) communications by providing authentication, integrity, and confidentiality services.
IPsec Modes
- The entire original IP packet is encapsulated to become the
payload of a new IP packet.
- A new IP header is added on top of the original IP packet.
- The payload is encrypted but not the IP header.
- Transport mode has less overhead.
Tunnel Mode (Default) Transport Mode
Virtual Private Network
- VPNs are a cost-effective alternative to dedicated point-to-point connections.
- VPNs isolate the network frames from the surrounding networking using a
process known as encapsulation or tunneling.
- Full tunneling requires all traffic to be routed over the VPN.
- Split tunneling allows the routing of some traffic over the VPN while letting
other traffic directly access the Internet. A virtual private network (VPN) is designed to facilitate secure remote access communication over a public network.
VPN Protocols
- IPsec VPNs are widely used for site-to-site VPNs and remote access
VPNs.
- Because IPsec operates at OSI layer 3, IPsec VPNs can support all IP
based applications.
- TLS VPNs are commonly used for remote access VPN
configurations.
- Because TLS operates at OSI layer 7, TLS VPNs generally only
support browser-based applications. The two most used protocols for virtual private networks (VPN) are IPsec and TLS. IPsec TLS
3.3 Compare and contrast concepts and strategies to protect
data
Categories of Data
Category Description Regulated Regulated data is protected by law, or industry standards. Personally Identifiable Personally Identifiable refers to data that can be used to identify a specific individual (PI. PII). Intellectual Property Intellectual property refers to intangible creations. Contractually Protected Contractually protected data refers to data that is specified in a contract or agreement. Organizationally Classified Organizationally classified data refers to data meets classification criteria.
Regulated Data
- Jurisdiction is the power or right of a legal or political agency to exercise its
authority over a person, subject matter, or territory.
- In relation to information security, jurisdiction pertains to the location of data
and systems (processing, transmission, storage), the type of data, the residence of data owners, and the residence of data subjects.
- GLBA (financial), HIPAA (medical), and FERPA (educational) regulations
related to data types.
- GDPR and CCPA relates to data type (PII) and residence of data subjects.
Regulated data refers to data that is subject to specific laws, regulations, or industry standards that govern its collection, use, storage, and disclosure.
Intellectual Property (IP) Law
- The goal of IP law is to encourage innovation and creativity by granting exclusive
rights to creators and owners of IP, while at the same time balancing the interests of the public.
- While there are international agreements and treaties that provide some
standardization in IP protection there are significant differences in how IP is protected and enforced across different jurisdictions. Intellectual property (IP) law is a branch of law that deals with the protection of intangible creations.
Intellectual Property (IP) Protections
Patent A trademark is intended to protect recognizable names, icons, shape, color, and sounds, used to represent a brand, product, service, or company. ® TM SM Trademark © Copyright Trade Secret A patent gives its owner the legal right to exclude others from making, using, or selling an invention for a period of time, in exchange for publishing a public disclosure of the invention. Copyright protections are intended to allow the creator of certain types of original works to benefit from being credited and compensated for their work. Trade secrets refer to proprietary business and technical information, processes, designs, or practices that are confidential and critical to a business.
Software End-user Licensing Agreements (EULA)
Freeware Shareware is copyrighted software that is available at no cost for unlimited usage. Users are encouraged to share the software to promote larger distribution and sales. Shareware Open Source Commercial of the Shelf (COTS) Freeware is copyrighted software that is available at no cost for unlimited usage. The developer retains all rights to the program and controls distribution. Open source is when the copyright holder grants users the rights to use, study, change, and distribute the software to anyone and for any purpose. COTS is copyrighted software that a company designs and develops to sell or license. The company retains all rights to the program and controls distribution.
Classification
- Sensitivity is based on the impact of asset exposure.
- Criticality is based on the impact of asset loss. This criteria is often used for
disaster recovery and business continuity planning.
- Asset classifications inform risk management decisions, protection strategies,
control decisions, audit scope, and regulatory compliance activities. Classification is the process of organizing assets by criticality and sensitivity.
Security Clearance
- Clearance levels mirror data classifications.
- Clearance is valid for a specific amount of time and then must be renewed.
- Clearance officers are responsible for the clearance process.
A security clearance is a determination made by the government that an individual is eligible to access classified information up to a certain level of classification.
Labeling
- Labels can take many forms: electronic, print, audio, or
visual.
- Labels should be appropriate for the intended audience.
- Labels transcend institutional knowledge and provide
stability and continuity. Labeling is the vehicle for communicating the assigned classification to custodians, users, and applications.
Handling Standards
- Handling standards dictate by classification level how information must be
stored, transmitted, communicated, accessed, retained, and destroyed.
- Handling standards extend to automated tools such as DLP (data loss
prevention) solutions.
- Handling standards may extend to incident management and breach
notification. Handling standards inform custodians and users how to protect the information they use and systems they interact with.
Data Management
- Data protection decisions are generally related to:
- Data classification
- Data state (point in time)
- Data at rest (persistent storage — e.g., disk,
tape)
- Data in use (CPU processing or in RAM)
- Data in transit (transmission)
Data management is the planning and execution of policies and practices that protect data confidentiality, integrity, and availability throughout its lifecycle.
Roles & Responsibilities
Directors & Executive Management Owners are responsible for oversight and decisions related to classification, access control, and protection. Data Owners Data Custodians Data Users Responsible for governance and oversight. From a legal and regulatory perspective, they are ultimately responsible for the actions (or inaction) of the organization. Custodians are responsible for advising, implementing, managing, and monitoring data protection controls. Users are responsible for treating data and interacting with information systems in accordance with organizational policy and handling standards.
3.4 Explain the importance of resilience and recovery in
security architecture.
Backup and Recovery
Traditional Online Replication Automation Backup and recovery processes ensure that accurate and reliable copies of data and system configurations are created, maintained, and tested. Traditional backup and recovery generally uses removable media or local disk library. Online backup and recovery preserve data by creating copies of it and storing them in an online or cloud-based environment. Replication is the process of creating and maintaining multiple copies of data across different locations. Automation an approach to automated provisioning and replacement.
Traditional Backup Strategies
Type Backup Process Restore Process Full Backup Backs up all files Full backup media Differential Backs up all files created or modified since last full backup
- Does not reset archive bit
Full backup + most recent differential Incremental Backs up all changed files
- Does reset archive bit
Full backup + all subsequent incremental Media Options: Disk-Tape, Disk-Disk, Disk-Disk-Tape, Disk-Disk-Cloud
Online Backup Strategies
Strategy Description Cloud Backup Services Scheduled backup to an Internet location. Disk Shadowing Data is written to (and read from) two or more independent disks Process is transparent to the user. Electronic Vaulting Files copied as they change and periodically transmitted to a backup location. Remote Journaling Transaction logs copied and periodically transmitted to a backup location.
Replication Strategies
Type Process Replication is an automated process that streams copies of data to one or more locations in real time or near-time. Point-in-Time • Periodic snapshots replicated
- If replicated, snapshots are pointer-based, just changes
transmitted Asynchronous Replication
- Write is considered complete as soon as local storage commits
- Remote storage updated with a slight time lag
Synchronous Replication
- Data written in two locations (local and remote)
- Both write operations must successfully complete before the
system can proceed
- Guaranteed zero data loss
Cost vs. Complexity vs. Availability
Traditional Recovery
- Tape backup
- Low complexity
- Low cost
- Recovery
measured in hours to days Enhanced Recovery
- Automated
solutions
- Medium
complexity
- Low cost
- Recovery
measured in hours to days
- More recoverable
data Rapid Recovery
- Asynchronous
replication
- High complexity
- Moderate cost
- Recovery measured
in minutes to hours Continuous Availability
- Synchronous
replication or automation
- High complexity
- High cost
- Recovery measured
in seconds
Resiliency
- Availability is a measure of a system's uptime — the percentage of time that a system
is operational.
- For example, “Five-Nines” means the device/environment/process should be
available 99.999% of the time and experience no more than 5.26 minutes of downtime per year.
- Availability measures are used to inform architecture and investment
requirements. Resiliency is the capability to continue operating even when there has been a disruption or abnormal operating conditions.
Resiliency Concepts
Device Description System Resiliency
- Fault Tolerance
- High Availability
- Fault tolerance is the capability of a system to continue to
operate in the event of failure of one or more system components (redundancy)
- High availability is automatic failover for continued
operation Power Resiliency Alternate sources of power Site Resiliency Alternate processing locations and facilities Supplier Resiliency Multiple diverse supply chain options
System Resiliency
State Description Failover Transition to a standby device. High availability Automatic failover. Active / Passive Pair The passive device does not come online unless the primary device fails. Active / Active Pair Two or more components are operational and work as a team In case of a failure, remaining components continue to operate. RAID Disk technology that combines multiple disk drive components into a logical unit for the purposes of data redundancy, performance improvement or both. Fail-secure Principle that a failure will result in a secure or trustworthy state.
Power Resiliency
Option Description Redundant Power Supply A redundant power supply is when a single piece of computer equipment operates using two or more physical power supplies. UPS An uninterruptible power supply (UPS) provides backup power when a regular power source fails, or voltage drops to an unacceptable level; a UPS provides filtering and surge protection. Generator A generator is a standby, secondary, limited source of electrical power when the power grid is down or inaccessible Supplier Diversity More than one supplier and/or access to multiple power grids.
Site Resiliency
Site Description Cold Site A cold site has basic HVAC infrastructure.
- No server-related or communications equipment
Warm Site A warm site has HVAC, servers, and communications infrastructure and equipment.
- Systems might need to be configured
- Data needs to be restored
Hot Site A hot site has HVAC, servers, and communications infrastructure and equipment
- Systems are preconfigured
- Data is generally near-time
Mobile Site A mobile site is a transportable modular unit with pre-ordered hardware and software.
- The delivery site must provide access roads, water, waste disposal, power, and
connectivity Reciprocal Site A reciprocal site is based on an agreement to have access to/use of another organization’s facilities
Continuity of Operations
- In a business context, disasters are disruptive events that significantly impact
an organizations capability to operate.
- Adverse conditions can be geological, meteorological, environmental,
public health, loss of service, technical, and/or human-related.
- The impact could be to people, technology, facilities or any combination
thereof. In its simplest form, continuity of operations is the capability of a business to continue to operate in adverse (disaster) conditions.
Continuity of Operations Planning
DRPs focus on the recovery and restoration of technology, physical plant, and personnel. BCPs focuses on the overall strategy for sustaining business activities during a disaster (or smaller interruption) and subsequent recovery period. The objective of continuity of operations planning is to prepare for continued operation. Disaster Recovery Plans (DRP) Business Continuity Plans (BCP)
Continuity of Operations Planning Workflow
Project Initiation Business Impact Analysis Strategy / Plan Development & Approval Procedure Development Training Testing Auditing Maintenance & Review
Assessment Question 1
In a SaaS model, this security component is the responsibility of the cloud service provider. A. Infrastructure security B. Platform security C. Application security D. All the above
Assessment Question 2
The most dangerous of the decision states. A. True positive B. False positive C. True negative D. False negative
Assessment Question 3
Type of firewall that operates at OSI Layer 4 and filters packets based on the full context of a given network connection. A. Stateful B. Stateless C. Next-Generation D. Virtual
Assessment Question 3
Category of data often referred to as intangible creations. A. Regulated B. Intellectual property C. Classified D. Personally identifiable
Assessment Question 3
Term used to describe a disk-disk backup that does not reset the archive bit. A. Full backup B. Differential backup C. Incremental backup D. Synchronous backup
Study Strategies
Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies
Study Strategies
Commit Create a study plan that works for you. Put it in your calendar and tape it on your refrigerator! Take breaks whenever you feel overwhelmed. Plan Learn Talk to Yourself, Out Loud Schedule your exam! Let everyone know – your boss, your colleagues, your family. Give them the opportunity to support you. Watch my video – The Complete CompTIA Security + SY0- 701 Certification Video on O’Reilly Media! . Make your own flash cards using 3x5” or 4x6” index cards Use this technique to validate that you know a subject. Stand up and out loud teach it. Create Flash Cards
Relax. Breath Deeply. Enjoy.
Adopt the Zen of Studying
- Approach the material with a positive, can-do attitude.
- Don’t think of preparing for the exam as chore – envision it is an
opportunity to learn and enhance your career.
- Be proud of yourself.
- Be kind to yourself. Strive for progress, not perfection.
Remind yourself you can do this.
Tomorrow – Day 2 SY0-701 Crash Course
Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies Day 1 feedback - I encourage you to send me an email sari@sarigreenegroup.com. Until tomorrow ….. Have a great day/evening.
Welcome to Day 2
CompTIA SY0-701 Security+ Crash Course Sari Greene, CISSP, ISSMP, CRISC, CISM, CISA, SEC+ sari@sarigreenegroup.com
Welcome to Day 2 – How are You feeling?
o Yikes, I’m overwhelmed! o I’m tentative but okay. Just need a bit more confidence. o I’m feeling pretty good & I have a study plan. o I’m ready to ace this exam.
Exam Commitment
o Yes, I scheduled my exam. o No, I didn’t but I plan too soon (I promise).
Certification Exam Outline
This course is based on the SY0-701 Certification Exam Objectives.
- The CompTIA Security+ Certification
Exam Objectives document can be found at https://www.comptia.org/training/reso urces/exam-objectives.
- Course slides are available in the
“Resource List” window. Please respect the copyright.
- This course is being recorded and will
be available to you within 24-48 hours
Comprehensive Study
My CompTIA Security+ SY0-701 27+hr. Video Course covers in detail every exam objective and includes 3 Second Challenges, Security-in-Action case studies, Word Clouds, Deep Dive Quizzes, and Closer Look Labs. Available to you on the O’Reilly Media platform! CompTIA Labs is a remote lab environment that enables hands-on practice and skill development in actual software applications. The virtual lab scenarios are aligned with CompTIA exam objectives and are based on real workplace events.
- https://www.comptia.org/training/certmaster-labs
Exam Objectives (Course Outline)
Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies
Domain 4 Security Operations
Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies
Domain 4.0 Security Operations
# Objective 4.1 Given a scenario, apply common security techniques to computing resources. 4.2 Explain the security implications of proper hardware, software, and data asset management. 4.3 Explain various activities associated with vulnerability management. 4.4 Explain security alerting and monitoring concepts and tools. 4.5 Given a scenario, modify enterprise capabilities to enhance security. 4.6 Given a scenario, implement and maintain identity access management. 4.7 Explain the importance of automation and orchestration related to secure operations. 4.8 Explain appropriate incident response activities. 4.9 Given a scenario, use data sources to support an investigation
Security Operations
- In larger organizations, this function operates independently and may have
its own physical presence known as a Security Operations Center (SOC).
- In smaller organizations, this function may be integrated within the
Information Technology or Risk Management departments.
- Alternately, SOC’s can be an outsourced function.
Security operations refer to the ongoing activities that an organization undertakes to ensure the security and protection of its information systems, assets, and data.
4.1 Given a scenario, apply common security techniques to
computing resources.
- Hardening Targets
- Wireless Design and Security
- Mobile Connectivity and Device Management
- Application Security
- Secure Coding
Secure Baseline
- The purpose of a secure baseline is to ensure that fundamental security
measures are in place to protect against common threats and vulnerabilities.
- It serves as a starting point for establishing a secure environment and can be
used as a foundation to build upon. A secure baseline is a predefined set of security configurations and practices that are considered the minimum level of protection for a system or network.
Hardening
- The principle of least functionality is that systems and devices should be
configured to provide only essential capabilities and specifically prohibit or restrict the use of unnecessary functions, ports, protocols, and services. Hardening is the ongoing process of configuring security settings, applying security patches, and implementing least functionality in order to reduce the system footprint, minimize vulnerabilities and exposure to threats, and enhance resilience.
Hardening Targets (examples)
Servers & Workstations Applying patches, limiting admin privileges, encrypting data Embedded Systems Restricting physical access, updating firmware, configuring security settings Switches and Routers Changing default settings, disabling unused interfaces, using secure protocols Cloud Infrastructure Configuring security groups, segmentation, encrypting data ICS and SCADA Systems Isolation, securing remote access, limiting EOL/EOS Resources include manufacturer documentation and guidelines, government publications (e.g. NIST SP 800 series), industry (e.g. Cloud Security Alliance (CSA), IoT Security Foundation (IoTSF), forums and community groups. *Wireless, mobile and application security and hardening covered separately in this lesson.
Wi-Fi Network Configurations
Type Description IEEE Standard WPAN Wireless Personal Area Network A.K.A. Bluetooth 802.15 standard Interconnects devices within a limited range (e.g., keyboards) WLAN Wireless Local Area Network 802.11 standard WMAN Wireless Metropolitan Area Network 802.16 standard MBWA Mobile Broadband Wireless Access 802.20 standard Wi-Fi is a radio frequency contained network.
802.11 IEEE Standards
Specification Data Rate Frequency Distance 802.11 2 Mbps 2.4 GHz 100 m 802.11b 11 Mbps 2.4 GHz 140 m 802.11a 54 Mbps 5 GHz 120 m 802.11g 54 Mbps 2.4 GHz 140 m 802.11n 150 Mbps 2.4 / 5 GHz 250 m 802.11i Security for 802.11 technologies
- Legacy (WEP, WPA)
- Current (WPA2, WPA3)
802.11e Quality of Service (QoS) for priority and time sensitive data
Current 802.11i Security
Control WPA2 WPA3 Authentication Enterprise RADIUS, Certificate or Personal PSK (PPSK) Enterprise or Personal Simultaneous Authentication of Equals (SAE) Key Separate 128-bit keys Separate 256 / 384-bit keys Encryption AES Block Cipher AES Block Cipher GCMP-256 mode HMAC-SHA384 Status Current standard Vulnerable if using Wi-Fi Protected Setup (WPS) Optional certification Backward compatible (WPA2)
Simultaneous Authentication of Equals
- WPA3 uses the Simultaneous Authentication of Equals (SAE) to replace WPA2’s
Personal Pre-Shared Key (PPSK) exchange protocol.
- SAE incorporates secure mutual authentication.
- SAE employs perfect forward secrecy and is resistant to offline decryption
attacks.
- Perfect Forward Secrecy (PFS) is a protocol property that effectively protects
past sessions against future compromises. Simultaneous Authentication of Equals (SAE) also known as Dragonfly Authentication and Encryption (DAE) is a secure password-based authentication and password-authenticated key agreement method.
Wi-Fi Network Security Hardening
Regular Firmware Updates: Keep wireless network devices, including routers and APs, up to date with the latest firmware updates.
- Is
MAC Address Filtering: Use MAC address filtering to allow only authorized devices to connect to the wireless network. Disable SSID Broadcast: Disable the broadcasting of the network's (SSID) to make the network less visible to unauthorized users. Enable Segmentation: Segment the wireless network into virtual LANs (VLANs). Disable Remote Management: Disable remote management capabilities on the wireless router or APs, unless necessary. Strong Authentication & Encryption: Implement the latest Wi-Fi protocols - WPA3. Default Credentials: Change the default login credentials (username and password) for wireless access points (APs), routers, and other network devices.
Mobile Connectivity
- A mobile device is a generic term for any legacy or emerging device that is
portable and has interactive and connectivity capability – for example, a laptop, a tablet, a smartphone, gaming console, e-reader, wearables.
- Connectivity can be via Wi-Fi, Bluetooth, cellular, RFID, NFC, or WUSB bus.
Mobile connectivity facilitates portable (mobile) device communication.
Mobile Connectivity
Method Description Wi-Fi Radio frequency contained network. Bluetooth Shortwave radio low power technology based on the 802.15 standard.
- Bluetooth is subject to Bluejacking and Bluesnarfing
- Bluejacking is injecting an unsolicited message.
- Bluesnarfing is unauthorized device access through a Bluetooth discovery
connection. Cellular Radio frequency distributed network. 4G uses packet switching technology. 5G uses aggregated frequency bands. RFID Radio frequency identification using low power radio waves. Data is sent and received with a system consisting of RFID tags, an antenna, an RFID reader, and a transceiver NFC Short-range wireless technology that requires proximity and/or device contact.
Mobile Device Management
- Mobile Device Management (MDM) software is used to control deployment,
manage settings (policies), and report on activity and usage.
- Unified Endpoint Management (UEM) extends the functionality of MDM to IoT
devices and wearables.
- Mobile Application Management (MAM) focuses on the management of mobile
applications. Mobile Device Management encompasses deploying, securing, monitoring, integrating, and managing mobile devices in the workplace.
Mobile Device Security Concerns
Removing software restrictions imposed by the manufacturer. Jailbreaking Rooting Sideloading Camera Access Gaining administrative or root access on an Android device. Installing applications from sources other than authorized distribution channels. Unauthorized video by malicious or unauthorized apps. Microphone Access Hotspots GPS Tagging Device Loss Reveal location, movements, and activities. Exposure of vulnerable or sensitive locations. Unauthorized access to personal data, financial accounts, and sensitive information. Unauthorized recording by malicious or unauthorized apps. Unauthorized access. Data usage and charges.
Application Security
- Application security categories include:
- Secure development and coding
- Code security testing
- Security and privacy controls
- Logging
Application security is the process of developing, adding, and testing security features within applications to minimize the risk of unauthorized access (confidentiality), modification (integrity), and downtime (unavailability).
SecDevOps
- SecDevOps emphasizes the shared responsibility of integrating security
practices throughout the development process, ensuring that security considerations are incorporated early and continuously.
- The SecDevOps approach enables developers to learn more about what they are
developing and how it can be exploited.
- SecDevOps proactively focuses on survivability by providing reliable software
with a reduced attack surface. SecDevOps (short for Security, Development, and Operations) promotes collaboration between development, operations, and security teams.
Static Application Security Testing (SAST)
- SAST can take place very early in the software development lifecycle as it does
not require a working application and can take place without code being executed.
- SAST scans an application before the code is compiled.
- SAST tools give developers real-time feedback as they code, helping them fix
issues before they pass the code to the next phase of development. Static application security testing (SAST), is a testing methodology that analyzes source code to find security vulnerabilities.
Dynamic Application Security Testing (DAST)
- DAST works by simulating automated attacks on an application, mimicking
a malicious attacker.
- The goal is to find outcomes or results that were not expected and could
therefore be used by attackers to compromise an application.
- DAST tools include web and API scanning, pen testing, fuzzing and
interactive application security testing.
- Fuzz testing, or fuzzing, is an automated testing technique used to
discover coding errors and security loopholes by inputting invalid, unexpected, or semi-random data, called fuzz, and monitoring the application response. Dynamic application security testing (DAST) is a method of application security testing that examines an application while it’s running.
Secure Coding Best Practices
Validate input before passing or processing. Keep it Simple Input Validation Output Validation Heed Security Policy Validate output before retuning. Simplicity means fewer errors and a less complex assessment process. Architect and design for security requirements. Use Effective QA Processes Sanitize Data Sent to Other Code Signing Systems Secure Cookies Trust but verify. When in doubt, sanitize. Use effective (and easy to use) quality assurance testing and evaluation processes. Require cookies to be encrypted in transit (flag with “secure” attribute). Digitally sign executables and scripts to confirm authenticity and integrity.
4.2 Explain the security implications of proper hardware,
software, and data asset management.
- Asset Management
- Asset Lifecycle
- Asset Disposal and Destruction
Asset
- Every asset should have an assigned owner and a custodian.
- Owners are responsible for decisions related to classification, and access
control, as well as oversight of protection mechanisms.
- Custodians are responsible for implementing, managing, and monitoring
controls. An asset is any data, device, or other component of value to an organization.
- A lifecycle management plan covers all aspects of product lifecycle from
acquisition to end-date.
- Preparation for end-date mitigates the risk of serious vulnerabilities and
downtime.
End-date Milestones
Notification End-of-Sale is the date when the product, service, or subscription is no longer for sale. End-of-Sale End-of-Life (EOL) End-ofSupport (EOS) The notification date is when the end-of-sale, endof-life, and end of support milestones for a product, service, or subscription is communicated to the general public. End-of-Life (EOL) is the date when a product, or subscription is determined to be obsolete. Once obsolete, the product, or subscription is not sold, improved, or maintained. End-of-Support (EOS) is the last date to receive applicable service and support. After this date, updates are no longer available.
EOL/EOS Risks
- Adversaries will continue to identify and exploit vulnerabilities.
- Almost every regulation requires that an organization take “reasonable steps
to protect the data and systems under its control”. Not doing so can be considered a compliance violation.
- Exposure to litigation for not upholding the standard of “due care”.
- Risk of downtime due to lack of support / service resolution.
- Incompatibility with newer operating systems, applications, and hardware.
Whenever possible, software/hardware should be refreshed prior to EOL/EOS.
Secure Data Disposal & Destruction
Technique Description Result Wiping Overwrites all addressable storage and indexing locations multiple times Clearing Degaussing Using a electromagnetic field to destroy all magnetically recorded data Purging Shredding Physically breaking media into pieces Destruction Pulverizing Reducing media to dust Destruction Pulping Chemical altering media Destruction Burning Incinerating media Destruction
Certificate of Destruction
A Certificate of Destruction should at a minimum include:
- Date of destruction.
- Description of media (including serial number, if appropriate).
- Method of destruction (burning, shredding, pulping, pulverizing).
- Witnesses.
- Company name, address, and contact information.
A Certificate of Destruction is issued by commercial services upon destruction of media.
4.3 Explain various activities associated with vulnerability
management.
- Vulnerability Identification
- Vulnerability Management
Vulnerabilities and Exposures
A vulnerability is a weakness in a system (hardware or software), process, or person that can be exploited. An exposure is a system or software configuration issue, or lack of a control that could contribute to a successful exploit or compromise.
- A zero-day vulnerability refers to a vulnerability that is actively being
exploited by attackers before the vendor has had an opportunity to develop and release a patch or fix for it.
CVE® Program
- CVE® is a standardized identifier for a given vulnerability or exposure.
- The CVE records are maintained in the CVE® Program catalogue.
- The use of CVEs ensures that two or more parties can confidently refer to a CVE
identifier (ID) when discussing or sharing information about a unique vulnerability.
- https://www.cve.org
The CVE® Program is an international, community-driven effort to catalog hardware and software vulnerabilities for public access.
Common Vulnerability Scoring System
- There are five ratings – none, low, medium, high, and critical.
- Two common uses of CVSS are calculating the severity of vulnerabilities
discovered on one's systems and as a factor in prioritization of vulnerability remediation activities.
- The National Vulnerability Database (NVD) provides CVSS scores for almost all
known vulnerabilities.
- https://nvd.nist.gov/
The Common Vulnerability Scoring System (CVSS) is an open framework for communicating the characteristics and severity of hardware and software vulnerabilities.
Vulnerability Scanning
- Web application scanners look for common types of web flaws such as crosssite scripting (XSS), SQL injection, command injection, and path traversal.
- This category of tools is frequently referred to as Dynamic Application Security
Testing (DAST) Tools.
- FMI: https://owasp.org/www-community/Vulnerability_Scanning_Tools
Vulnerability scanning is an automated activity that relies on a database of known vulnerabilities such as CVE®/NVD -- designed to identify vulnerabilities in the target environment.
Patch Management
- Patch deployment can be manual, automated, or a hybrid combination.
- Timely deployment of security patches reduces the likelihood of exploitation.
- The time from when an exploit first becomes active to when the number of
vulnerable systems shrink to an insignificant number is known as the Window of Vulnerability (WoV). Patch management is the process of identifying, acquiring, installing, and verifying patches (updates) to remediate vulnerabilities.
Patch Management Challenges
- Confirmation
- Prioritization, timing, and testing
- Patch management approach (automated, manual, hybrid)
- Access to unmanaged, mobile, or remote devices
- Unintentional consequences
- Roll-back issues
There are several challenges inherent in the patch management process. Patch management delays should be evaluated considering organizational risk tolerance and brought to management’s attention.
4.4 Explain security alerting and monitoring concepts and
tools.
- Logging and Analysis
- Monitoring and Management Tools
Audit and Event Logs
Audit and event logs are a chronological record of events and actions.
- Critical log sources include firewalls, IDS/IPS devices, proxy servers,
authentication servers and devices, operating systems, and key applications.
- Audit logs are both a near-time and historical detective control.
- Routine log analysis is beneficial for monitoring access, identifying security
incidents, policy violations, fraudulent activity, and operational issues.
Log Analysis Processes
Process Purpose Synchronization The process of synchronizing with an external time source with a time stamp protocol (e.g. NTP). Normalization The process of standardizing the log details into a consistent structure. Aggregation The process of consolidating events from disparate devices and systems. Deduplication The process of filtering out duplicate entries or excessive noise. Correlation The process of tying individual log entries together based on related information. Identification The process of identifying normal and abnormal activity.
Log Analysis and Response Tools
SIEM Threat Intelligence Platform (TIP) is an automation tool that combines multiple threat intelligence feeds and integrates with existing SIEM solutions. TIP UEBA SOAR Security Information and Event Management (SIEM) is an automation tool for real-time data capture event correlation analysis, and reporting. User and Entity Behavior Analytics (UEBA) is an automation tool that models the behavior of humans and machines to identify normal and abnormal behavior.
Security Orchestration, Automation, and Response (SOAR) is an automation tool that responds to the alerts, triaging the data, and taking remediation steps.
SOAR
Automation is the ability to execute a sequence of tasks without human intervention. Orchestration is the integration of disparate tools and platforms for an automated response. Automation Orchestration Security Orchestration, Automation and Response (SOAR) tools allow an organization to define incident analysis and response procedures in a digital workflow.
Monitoring and Management Tools
SNMP NetFlow is a network protocol developed by Cisco Systems that allows the collection and analysis of network traffic data. NetFlow SCAP SNMP provides a standardized framework for collecting information about network devices and their performance. Components include SNMP agents and managers. SCAP is a collection of open standards developed by NIST that provides a standardized approach for expressing and sharing securityrelated information Learn more about the NIST SCAP Project: https://csrc.nist. gov/projects/Se curity-ContentAutomationProtocol
SCAP Components
Common identifiers for publicly known security vulnerabilities. Common Configuration Enumeration (CCE) Common Vulnerabilities & Exposures (CVE) Common Platform Enumeration (CPE) Common identifiers for system configurations. A naming convention for identifying software applications, operating systems, and hardware devices. Common Vulnerability Scoring System (CVSS) Open Vulnerability and Assessment Language (OVAL) A framework for assessing the severity of software vulnerabilities. A standardized language for expressing vulnerability assessments and configuration checks.
SCAP Vulnerability Management (example)
- Is
SCAP content, such as security benchmarks and checklists, is used to assess the compliance of system configurations with industry standards and best practices. The scan results are presented in a unified format, allowing administrators to prioritize and remediate vulnerabilities based on their severity. The tools leverage SCAP's standardized vulnerability definitions (CVE) and scoring system (CVSS) to identify vulnerabilities and assign severity levels. An organization uses SCAP-compliant vulnerability scanning tools to periodically scan their network devices and systems.
4.5 Given a scenario, modify enterprise capabilities to
enhance security.
- Network Device Security
- Internet Protocol (IP)
- Secure Protocols
- Email Security
- Group Policy and SELinux
- Endpoint Detection and Response (EDR) & Extended Detection and
Response (XDR)
Network Device Security Enhancements
Enforce security policy by controlling ingress and egress traffic using rules and ACLs. Firewall IDS/IPS DLP NAC Analyze and monitor for suspicious traffic. IPS can deny traffic access. Enforce restrictions to websites based on pre-defined criteria. Detect and report on changes made to system, application, and configuration files. UEBA Web Filters File Integrity Monitoring EDR/XDR Advanced integrated platforms that monitor, report on, and respond to security threats. Automation tool that models the behavior of humans and machines to identify normal and abnormal behavior. Detect and prevent unauthorized transfer and exfiltration of data. Enforce endpoint access privileges based on preadmission and post-admission policies.
Internet Protocol (IP)
Originally designed for basic data connectivity.
- IP convergence is the use of the Internet Protocol as the standard transport
for transmitting all information (voice, data, music, video, TV, teleconferencing, and so on).
- Extensibility is additional functionality or the modification of existing
functionality without significantly altering the original structure or data flow.
- Open standard is a standard that is publicly available and can be freely
adopted and extended. Internet Protocol (IP) is a set of rules for routing and addressing packets of data – it is the language of the Internet.
IP Versions
IPv4 IPv6 deployed in 1999 (adoption phase).
- 128-bit address in hexadecimal format.
- 2001:0db8:85a3:0000:0000:8a2e:0370:7334
- 2128 addresses (340 trillion trillion trillion).
- Integrated IPsec.
- Stateful and stateless auto configuration
capabilities.
- Scans less effective because of larger
address space.
- Sniffing is more difficult because of
mandated IPsec. IPv6 Deployed in 1981, IPv4 was the first publicly used version (1-3 were experimental).
- 32-bit address in
dotted decimal format
- IP address scarcity
- Limited security
options
Traditional TCP/IP Model
Secure Protocols
The function of a secure protocol is to ensure confidentiality, integrity, authentication, nonrepudiation, or any combination thereof.
- Secure protocols are commonly used in network management and
communications; often replacing older insecure protocols.
Secure Communications and Management Protocols
HTTP+TLS HTTPS (80) FTPS (989,990) Secure Shell (22) SFTP (22) FTP+TLS Secure channel between a local and remote device. Telnet replacement. Secure file transport packaged with SSH. SRTP (5601) S/MIME DNSSec (53) DNSSec is an extension to the DNS protocol that enables origin authentication, authenticated denial of existence, and data integrity. Used for securely delivering audio and video messages over IP networks. Used to send digitally signed and encrypted email messages.
Secure Email Communications
- Secure email communications require both server-side (SPF, DKIM, and DMARC)
and client-side configuration (TLS, S/MIME). Secure email communication refers to the use of various measures and protocols to protect the confidentiality, integrity, and authenticity of email messages exchanged between parties.
Server-side Email Configuration
SPF DKIM (DomainKeys Identified Mail) is an email authentication method designed to verify the authenticity and integrity of email messages. DKIM DMARC SPF (Sender Policy Framework) is an email authentication method designed to prevent email spoofing and protect against forged or unauthorized use of domain names in email messages. DMARC (Domainbased Message Authentication, Reporting, and Conformance) is an email authentication protocol that helps protect against email spoofing and phishing attacks.
Email Encryption
- Server-to-server encryption establishes an encrypted connection to protect the
email data in transit between the sender's and recipient's servers.
- End-to-end encryption ensures that the email message is encrypted on the
sender's device and can only be decrypted by the intended recipient. This means that not even the email service provider has access to the decrypted content.
- Transport Layer Security (TLS) is a cryptographic protocol used to encrypt
communication between email servers during transmission.
- Secure/Multipurpose Internet Mail Extensions (S/MIME) is a standard for secure
email messaging that provides encryption and digital signatures. The goal of email encryption is that only the intended recipient can read the email message.
Windows Group Policy
- A Group Policy Object (GPO) is a group of settings.
- GPOs can be associated with single or numerous Active Directory containers,
including sites, domains, or organizational units (OUs).
- Group Policy Management Console (GPMC) snap-in provides a single
administrative tool for managing Group Policy across the enterprise. Windows Group Policy provides centralized management and configuration of operating systems, applications, and users' settings in a Microsoft Window’s Active Directory environment.
Security-Enhanced Linux (SELinux)
- Created by the United States National Security Agency (NSA) and Red Hat. This
security module is available for most Linux distributions but is mainly used on RHEL and Fedora.
- SELinux operates on the principle of least-privilege. By default, everything is
denied and then a policy is written that gives each element of the system (a process, a user, and so on) only the permissions it needs to function.
- SELinux security policies are a set of rules that instruct SELinux who has access
to which system resource. There are two types of policies.
- Targeted - The most common type of policy is targeted policy where only
selected processes are protected.
- Strict - The more stringent policy where all processes are protected.
SELinux (Security-Enhanced Linux) is Linux kernel access control security module.
EDR/XDR
EDR (Endpoint Detection and Response) and XDR (Extended Detection and Response) are solutions designed to detect and respond to security incidents.
- EDR focuses on monitoring and responding to security threats on individual
endpoints, such as computers, servers, laptops, and other devices.
- XDR builds upon the concept of EDR but extends its scope beyond endpoints.
- The goal of XDR is to provide a more holistic and integrated approach to
threat detection and response by analyzing and correlating data from various security tools and platforms. This broader perspective allows security teams to detect and respond to threats that might span multiple vectors and stages of an attack.
4.6 Given a scenario, implement and maintain identity and
access management.
- Identity and Access Management
- Federated Identity
- Authentication
- Access Control and Authorization
- Privileged Access Management
Identity Primer
Concept Description Identification Who you are (unique record) Identification Schema An identification schema is used to identify unique records in a set. Authentication Method An authentication method is how identification is proven to be genuine. Authorization Model An authorization model defines how access rights and permissions are granted. Identity Management The technical management of user identity including authentication and authorization.
Identity and Access Management
- IAM functions including provisioning, educating, auditing, and deprovisioning.
- Provisioning is the process of creating and managing digital identities.
- Deprovisioning is the process of removing and deleting digital identities.
- IAM functions take place throughout the employee lifecycle.
- IAM functions are a shared responsibility – managers, owners, HR, IT, physical
security, information security, and audit. Identity and Access Management (IAM) is a business process of enabling the right individuals to access the right resources at the right times and for the right reasons.
Identity Management (IdM)
Technology Description Directory Services Centralized collection of subjects and objects Enterprise Single Sign-on (SSO) Authentication system that allows a subject to authenticate to multiple related, yet independent, software systems Federated Identity Management (FIM) Authentication systems that support “portable identity” among multiple enterprises Just-in-Time (JIT) Privileged Access Management Methodology to grant real-time privileged access in order to minimize standing privilege.
- Standing privilege refers to administrator accounts with “always
on” 24x7x365 privileged access. Identity Management (IdM) describes the technical management of user identity, including authentication and authorization.
Federated Identity Management
- FIM includes identity provisioning, authentication, authorization, and attribute
sharing between participating systems.
- Technologies used to implement FIM include Security Assertion Markup
Language (SAML) and OAuth 2.0. Federated Identity Management (FIM) refers to the processes and technologies involved in managing user identities, access rights, and permissions across independent federated systems (trust domains).
SAML
SAML is an XML-based open standard for exchanging authentication and authorization data between a SP and an IdP.
- User
- The subject who needs to access multiple systems or services with a
single set of credentials (portable identity).
- Identity Provider (IdP)
- The system responsible for authenticating the user's identity.
- Service Provider (SP)
- The system or application that the user wants to access. It relies on the
identity provider's assertion to trust the user's identity and grant access to its resources.
SAML Illustrated
Identity Provider (IdP) SAML-compliant authentication service Service Provider (SP) SAML-compliant web application End-user (Principal) Commonly used by businesses that offer subscription/pay services – e.g., Salesforce, Box.
OAuth 2.0
OAuth 2.0 is an open standard protocol and framework designed to provide secure, delegated access to resources without sharing credentials.
- Authorization Server API / Resource
- The server that authenticated the user and issues an access token to
the resource server.
- Client Application
- The application or website that wants access to the protected resource.
- Resource Owner
- The user who owns the protected resource.
OAuth 2.0 Illustrated
Requesting Client Application Resource Owner Resource/ Authorization Server API Commonly used by consumer apps and services.
Authentication Controls
Factor Description Example Knowledge Something a user knows Password/Passphrase/PIN/Cognitive Challenge Question/Out-of-Wallet Challenge Question Possession Something a user has Token, Smartcard Biometric Something a user is Something a user does Physiological Behavioral Location Somewhere a user is GeoIP, Lat/Long Authentication is the process of proving an identity to an authentication system.
- The proof is referred to as a factor.
- The combination of a username and factor is referred to as credentials.
Factor Requirements
Only one factor is required for authentication. Single-factor Multi-layer Multi-factor (2FA) 2-Step Verification Two or more of the same type of factor required for authentication. Two or more different types of factors are required for authentication. Two-step verification confirms a user's identity by requiring a response. An example of a second step is the user repeating back a code sent to a mobile number or email address. Passwordless refers to a method of authentication that eliminates the need for traditional passwords as the primary means of verifying user identity. Instead of relying on passwords, passwordless authentication relies on alternative methods or factors to authenticate users.
Password Vaults (Password Managers)
- Password vaults store passwords in a secure location accessible only to
authorized individuals or systems.
- Passwords stored in the vault are encrypted using robust encryption
algorithms.
- Access to the password vault is typically protected by strong authentication
such as biometric verification or two-factor authentication (2FA).
- Password vaults often provide the capability to generate strong, complex
passwords automatically. The vault securely stores these generated passwords, eliminating the need for users to remember them. Password vaulting is a technology used to securely store and manage passwords and other sensitive credentials.
Possession OPT & Smartcards
Smart Card
- A smart card is a card / badge that is in the user’s possession. A smartcard has an
embedded chip and one or more certificates. One-time Password (OTP) An OTP is either generated by something you have or sent to something you have.
- Time OPT (TOPT)
- A hardware or software token that generates an OTP using a secret shared with the
authentication server and the current time.
- Hash OPT (HOPT)
- A hardware or software token that generates an OTP using a secret key and a
cryptographic hash function.
- SMS | Voice OPT
- A numeric or alphanumeric code is sent to a phone number either via voice or text.
Biometrics
- Biometric options are physiological markers (what you are) or behavioral traits
(what you do). Biometrics are physical or behavioral human characteristics that can be used to digitally identify a person.
Biometric Advantages
- Biometric markers and traits are unique to each individual and difficult to forge,
it provides a higher level of security and helps prevent identity theft or unauthorized access.
- Biometric authentication is convenient for users as they don't need to
remember or carry additional credentials. Biometric authentication offers several advantages over traditional authentication methods.
Authentication Decisioning
Decisions regarding the type and number of factors should always be commensurate with the business value of what is being protected, regulatory requirements, and contractual obligations!
Authorization
Authorization is the process of granting subjects access to objects.
- Subjects are active entities, generally in the form of a person, process, or
device that causes information to flow among objects, or changes the system state.
- Objects are passive entities (resource) that contain or receive
information or instructions.
- Authorization can be static (hard-coded) or dynamic (influenced by
situational factors).
Access Control Models
Model Description Mandatory (MAC) Access is based on the relationship between subject clearance and need-to-know, and the object classification level. Discretionary (DAC) Data owners decide subject access. Role-based (RBAC) Access is based on the subject’s assigned roles. Rule-based Access is based on compliance with established rules. Attribute-based Access is determined by a combination of subject, object, environmental and operational attributes. Risk-based Access is determined by a combination of risk-focused behavioral and contextual data analytics.
Attribute-based Access Control
Attribute-based access control (ABAC) is a logical access control model that controls access to objects by evaluating rules against the attributes of entities (both subject and object), operations, and the environment relevant to a request.
- ABAC supports a complex Boolean ruleset that can evaluate many different
attributes.
- The policies that can be implemented in an ABAC model are limited only to
the degree imposed by the computational language and the richness of the available attributes.
- An example of an access control framework that is consistent with ABAC is
the Extensible Access Control Markup Language (XACML).
ABAC Illustrated
Source: http://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.sp.800-162.pdf
Risk-based Access Control
Activity Description Anonymous IP Address Risk trigger indicates sign-ins from an anonymous IP address. Unfamiliar Sign-in Properties Risk trigger considers past sign-in history to identify nonfamiliar system properties. Atypical Travel Risk trigger identifies two sign-ins originating from geographically distant locations, where at least one of the locations is atypical, given past behavior. Impossible Travel Risk trigger identifies two user activities originating from geographically distant locations within a time period shorter than it would take to travel between the locations.
Privileged Accounts
- Standing privilege is defined as accounts that have persistent privileged access
24x7x365.
- Privileged accounts are rich targets for cyber attacks.
- Zero-standing privilege (ZSP) aims to minimize the standing privileges granted to
users or accounts within a system.
- In practice, ZSP means continuous reauthentication (explicit validation), and
granting to authorized users the privileged access they need for the minimum time and only the minimum rights that they need (least privilege). A privileged account is any account that provides rights and permissions above and beyond those of non-privileged (standard) accounts.
Privileged Access Management (PAM)
- The primary goal of PAM is to minimize the risks associated with privileged
accounts.
- PAM can be applied on-premises and in the cloud.
- PAM solutions assist in meeting regulatory and compliance requirements by
providing detailed audit logs, reports, and visibility into privileged account activities. Privileged Access Management (PAM) is a set of practices, technologies, and policies designed to manage and secure privileged accounts and access to critical systems and sensitive data within an organization.
4.6 Explain the importance of automation and orchestration
related to secure operations.
- Scripting
- Automation
- Orchestration
Scripting
- Scripts are usually written in a scripting language, a type of programming
language designed for integrating and communicating with other programming languages.
- Scripting languages are typically easier to learn and write than lower-level
programming languages.
- Scripts are often interpreted opposed to compiled. This means that scripts are
read and executed line-by-line by the processor at runtime.
- Scripting can be interactive or non-interactive.
- Scripting tools include Python, PowerShell, Bash, and VBA
- Scripts are often used by adversaries in attack scenarios.
A script is a set of instructions used to automate a sequence of repetitive tasks.
Scripting Attack
Attacker hides a PowerShell script in an MS-Office macro written in VBA Victim receives a phishing email with an attached document The victim opens the document Macro executes and launches a PowerShell script The victim's system is potentially compromised.
Automation
- The goal of automation is to improve quality of service, increase agility, and
reduce risk.
- Automation reduces or eliminates manual dependencies and human error.
- Automation can be a workforce multiplier.
- Automation techniques include scripting, robotics, specialized software, and
artificial intelligence (AI).
- Automation often requires a significant investment. Organizations should
consider cost, complexity, and maintenance. Automation is the ability to execute a sequence of tasks without human intervention.
Orchestration
- Network orchestration is the automation and coordination of networking tasks
like configuration, management, and optimization of network services and devices. It is often used in SDN (Software Defined Networking).
- Security Orchestration, Automation, and Response (SOAR) is an automation tool
that reduces response times, improves consistency, and amplifies the productivity of incident response teams.
- SOAR response playbooks allow an organization to define incident analysis
and response procedures in an automated digital workflow. Orchestration is the integration of disparate tools and platforms (often using bi-directional APIs) for an automated response.
SOAR Response Playbook Example
** Single click automated response: 1. Pulls in all emails received by a user at the time of their infection (e.g., from an email server). 2. Parses the emails to extract URLs and attachments. 3. Detonates the attachments in a sandbox (e.g., Cisco Threatgrid). 4. Obtains the URL reputations with a reputation service (e.g., Cisco Umbrella). 5. Geo-locates any network connections being made by the attachments in the Sandbox with a geolocation service (e.g., Maxmind). 6. Uses machine learning to determine if any of the emails are phishing emails based on the info from steps 1 to 5 above. 7. Searches a SIEM for other users that have received the same emails. Source: https://www.exabeam.com/siem/uba-ueba-siem-security-management-terms-defined-exabeam/
4.8 Explain appropriate incident response activities.
- Incident Management
- Incident Response
- Evidence Handling
- Forensic Examination
- Disclosure and Notification
An incident playbook is a set of instructions for responding to a specific type of event,
attack or scenario. Generally, playbooks are developed for high-risk events (measured in terms of likelihood and impact). For example, malware, DDOS attacks, ransomware extortion and payment card compromise. Incident Management Plan and Playbook An incident management plan includes roles and responsibilities, strategies and procedures for preparing for, responding to, and managing incidents.
Incident Management Plan Components
Component Description Threat Modeling Anticipated threats and associated controls Incident Types & Categorization Based on severity and used to determine response times, resource assignments, and preparation requirements Roles Organization role assignments inclusive of internal team and external resources Reporting & Escalation Requirements How incidents are internally reported, documented, and reviewed as well as when escalation thresholds are triggered Training & Study Requirements Training each participant of their role as well as maintaining ongoing attack-related situation awareness (attack frameworks) Exercise Requirements Exercising the plan to evaluate readiness and effectiveness.
Incident Response Exercises
Incident response exercises should be conducted on a periodic basis to assure readiness. Participants should include the IRT team, external resources, and as applicable, executive management. Exercise Description Walkthrough Personnel or departments review (walkthrough) their plans and procedures for completeness
- Objective: accuracy
Tabletop Scenario-based group workshop focuses on the application of plans and procedures as well as participant readiness
- Objective: familiarity, coordination, accuracy
Simulation Localized scenario that simulates an actual event
- Preplanned – scheduled and attendees invited
- Surprise – attendees are notified “in the moment”
- Objective: readiness
Incident Response Flow Chart
Incident Detected Incident Reported Incident Assigned Validation and Prioritization Containment Eradication & RCA Recovery Lessons Learned
Cyber Investigations
- There are three types of investigations: criminal, civil, and internal (also referred
to as administrative).
- In practice, it is difficult for organizations to identify the type of, and the
impact of, a cyber incident until they have carried out an investigation.
- Evidence collection is the first step in an investigation.
- Digital evidence is any information or data of value to an investigation that is
stored on, received by, or transmitted by an electronic device.
- It is critical that first responders are knowledgeable about forensicallysound evidence collection and handling so that they don’t compromise the
investigation. Cyber-related investigations can be triggered by a variety of incidents (e.g., intrusion, insider activity, extortion).
Evidence Collection
- Evidence collection is governed by two main rules.
- Admissibility of evidence – whether the evidence can be used in court.
- Weight of evidence – the quality and completeness of the evidence.
- There are two type of evidence.
- Direct evidence supports the truth of an assertion directly.
- Circumstantial evidence relies on an inference to connect it to a
conclusion of fact.
- Invariably there is tension between response (find and fix) teams and
evidence collectors. Collection of digital evidence is the first step of a forensic investigation.
Evidence Collection Rules
- Preservation is key.
- Do not allow the evidence to become contaminated.
- Act in order of volatility.
- Maintain an evidentiary chain (chain of custody) for all evidence collected
during the investigation.
- Be aware evidence may become public record, and company confidential
information should not be included unless necessary. Assume evidence will be used in a court of law and act accordingly.
Volatility
Order of Volatility refers to the acquisition of evidence before it disappears, is overwritten, or is no longer useful. There are two types of data - persistent data and volatile data.
- Persistent data is data that does not change and is preserved when the device
is turned off.
- Volatile data is data which is easily degradable and can be lost when the device
is turned off.
- Example order of collection:
1. Dynamic data (RAM) 2. Dump files 3. Temp files 4. Log files 5. Static data (media)
Evidentiary Chain
- Evidentiary chain documentation demonstrates trust to the courts that the
evidence has not been subject to mishandling, or evidence spoliation. An evidentiary chain (chain of custody) is chronological documentation that records the collection, control, storage, transfer, analysis, and disposition of evidence.
Digital Forensics
- Forensics work is complex and should be conducted only by trained investigators
and digital forensic professionals.
- Security operations personnel are not expected to be forensics specialists, but they
should be familiar with terminology and the basic operation as they may be expected to manage and/or participate in an investigation. Digital forensics is the application of science to the identification, collection, examination, and analysis of data (evidence) while preserving the integrity of the information.
Digital Forensics Process
Evidence Collection Data Acquisition Examination Analysis and Reporting Testifying (if necessary) Archiving
Retention and Archiving
- Evidence retention parameters are required to ensure that the evidence is
available when it is needed, but they should also consider the costs involved so evidence is not retained indefinitely. Consult legal counsel.
- At end-of-life, all evidence and findings must be securely disposed of.
Throughout the investigation and during the post-investigation retention period original data, acquired data, and all related media, documents, and ancillary items should be stored securely strict access controls.
Jurisdiction, Disclosure and Notification
- Disclosure is the requirement to reveal a situation.
- Notification is the act of informing affected parties
- The purpose of disclosure and notification is to inform others of potential risks
so they can make informed decisions and take appropriate action.
- Jurisdictional requirements may necessitate disclosure and notification
Jurisdiction is an area of legal authority. In relation to cyber, jurisdiction pertains to the location of data and systems (processing, transmission, storage), the residence of data owners, the type of data, and the residence of data subjects.
Data Breach Regulatory Compliance
- In the U.S., all states and territories have enacted data breach notification
legislation (many conflict with each other).
- U.S. federal, sector-specific, security legislation (e.g., GLBA and HIPAA) have risk
assessment and breach notification requirements.
- The EU/EEA General Data Protection Regulation (GDPR) has very stringent breach
disclosure and notification requirements.
- The Payment Card Industry Data Security Standard (PCI-DSS) has breach
notification requirements.
- Contractual obligations may have notification requirements.
Organizations have an obligation to comply with regulatory and contractual requirements.
Information Sharing
- An Information Sharing and Analysis Center (ISAC) is a trusted, sector-specific entity
that facilitates sector-specific and/or geographic-specific information sharing about vulnerabilities, threats, and incidents.
- The 20+ ISACs range from the Aviation ISAC to the Water ISAC.
https://www.nationalisacs.org/
- ISACS, government agencies, and industry use STIX™ and TAXII ™ to facilitate
the exchange and sharing of threat intelligence information.
- STIX ™ is a standardized language for describing threat Information.
- TAXII ™ defines how STIX ™ threat information can be shared.
Information sharing describes a means of conveying information or experience from one trusted party to another.
4.9 Given a scenario, use data sources to support an
investigation
- Data sources
Data Sources
- Vulnerability scan output to identify weakness and potential attack vectors.
- Log files for device, application, and user specific activity and/or anomalies.
- SIEM dashboards for broad overview, trend analysis, alerts, and correlation.
- Metadata for supporting details.
- Packet capture for network traffic.
Incident investigation often requires analysis of several data sources in order to draw a defensible conclusion.
Metadata
Metadata is data about data; it is machine-readable and searchable.
- Example: The content of the photo is the data. Where the picture was taken, date,
time, direction, camera setting, editing, and copyright are metadata extracts.
Packet Capture
- A protocol analyzer (sniffer) is a tool used to capture and analyze network
packets (data can also be imported for analysis).
- Packet capture modes:
- Normal – the NIC only captures frames intended for the interface
(filtering by MAC address).
- Promiscuous – the NIC is instructed to accept any frames it captures.
- Filtered – packet capture limited to specific data elements.
Packet capture is the process of intercepting and logging traffic for analysis.
Packet Capture Illustration
Source: Wireshark screen capture
Assessment Question 4.1
This protocol is a cryptographic replacement for Telnet, includes SFTP, and uses port 22. A. Transport Layer Security B. Secure Real-time Transport Protocol C. Secure Shell D. Lightweight Directory Access Protocol
Assessment Question 4.2
This wireless security configuration relies on Enterprise or Personal/ SAE (Simultaneous Authentication of Equals) for authentication. A. WEP B. WPA C. WPA-2 D. WPA-3
Assessment Question 4.3
Scenario-based group workshop that focuses on the application of incident response plans as well as participant readiness A. Tabletop B. Walkthrough C. Surprise Simulation D. Planned Simulation
Assessment Question 4.4
A FIM authentication system supports this feature among multiple enterprises . A. Portable identity B. File sharing C. Cryptographic exchange D. Complex rule-sets
Assessment Question 4.5
The date when a product, or subscription is determined to be obsolete. A. Notification B. End-of-Sale C. End-of-Life D. End-of Support
Assessment Question 4.6
This automation tool responds to the alerts and initiates a digital workflow. A. UEBA B. TIP C. SIEM D. SOAR
Assessment Question 4.7
A standardized language for describing threat Information. A. STIX™ B. TAXII ™ C. SCAP D. SNMP
Assessment Question 4.8
Logical access control model that controls access to objects by evaluating rules against the attributes of entities (both subject and object), operations, and the environment relevant to a request. A. MAC B. DAC C. RBAC D. ABAC
Domain 5 Security Program Management & Oversight
Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies
5.1 Summarize elements of effective security governance.
Security Leadership & Governance
- Subsequently, they are also responsible for:
- Providing the strategic direction, resources, funding, and support to
ensure that the desired state of security can be achieved and sustained.
- Codify the organizations commitment in policy.
- Risk management.
- Oversight.
- Governance structures and principles identify roles and responsibilities.
As applied to information/cybersecurity, governance is the responsibility of leadership to determine and articulate the organization's desired (future) state of security.
Governance Ecosystem
BOD: Strategy, Due Care, Fiduciary, Oversight EXEC MGT: Strategic alignment, risk management, value delivery, assurance, compliance, prioritization (Steering Committee) ORG Roles: CISO/ISO, Privacy Officer, Compliance Officer, Physical Security Officer, Internal Audit Functional Roles: Owners, Custodians, Users
Governance Strategy
- Governance documents are derived from the information security strategy
and are used to communicate direction, expectations, and rules The governance strategy is derived from the desired (future) state. Desired or future state refers to a vision or goal that an organization aspires to achieve in the future.
Governance Communication
Policy Standard Procedure Simple Step Hierarchical Graphic Flow Chart Guideline Agreement
Standards, Baselines & Guidelines
Standards Baselines are the aggregate of standards for a specific category or grouping such as a platform, device type, ownership, or location. Baselines Guidelines Standards serve as precise specifications for the implementation of policy and dictate mandatory requirements.
- Standards
must be unambiguous. Guidelines help people understand and conform to a standard. Guidelines are customized to the intended audience and are not mandatory.
- Information
security policies codify the highlevel requirements for protecting information and information assets, and ensuring confidentiality, integrity, and availability Policies & Agreements Policies codify and communicate the high-level requirements. Agreements are used to legally enforce policies and related governance documents.
Procedures
Simple Step Hierarchical Graphic Flowchart Procedures are instructions for how to carry out an action. Procedures focus on discrete actions or steps, with a specific starting and ending point. Simple step lists sequential actions. There is no decision making. Hierarchical organizes the instructions in a hierarchical structure, where each level is nested within the one above it. Graphic presents in pictorial or symbol form. Flowchart is used to communicate a process and/or when decision making is required.
User Agreements
Agreement Objective Confidentiality / Non-disclosure (NDA) An NDA is a precursor to sharing information. It includes clauses designed to:
- Protect data from unauthorized disclosure
- Establish data ownership
- Define handling standards including disposal
- Post-relationship requirements
Acceptable Use Policy (AUP) and Agreement Sets forth proper use of information systems, handling standards, monitoring and privacy expectations, as well as violation consequences.
- An AUP should be written in language that can be easily and
unequivocally understood.
- By signing the associated agreement, the user acknowledges that they
understand and agree to the stated rules and obligations. An agreement is a legally enforceable mutual understanding between two or more parties regarding their rights and obligations.
5.2 Explain elements of the risk management process.
Risk
- The outcome could be positive or negative.
- Generally, risk is studied from the perspective of a negative outcome or
consequences.
- Negative risk is a function of likelihood and impact.
- Likelihood is the probability or chance of a particular risk event occurring.
- Impact is a measure of the magnitude of harm.
- Cascading risk is the principle that, often, risks are linked, and failing to address
one risk could cause a chain reaction. Risk is broadly defined as uncertainty of outcome.
Risk Volatility and Velocity
- Low-risk volatility means that the level of risk is relatively stable and predictable
over time. High-risk volatility means that the level of risk is likely to fluctuate significantly over time.
- Risk velocity is the time that passes between the occurrence of an event and
the point at which the organization first feels its effects.
- When the velocity is low, there is time to detect and respond.
- If the velocity is very high, detection and response are much more
challenging. Risk volatility describes the extent to which the level of risk is likely to change over time. Risk velocity measures how fast an exposure can impact an organization.
Risk Appetite
- There are multiple categories of business risk including strategic, reputational,
operational, financial, compliance, legal, ESG, capital, and resilience.
- The Board of Directors (or equivalent) determines their risk appetite on a per
category basis and publishes a risk appetite statement for use by the organization. Risk appetite is the level of risk that an organization is comfortable engaging in. For example, expansive, neutral, conservative.
Risk Management
- Every organization needs to take action to manage risk in alignment with their
strategic objectives, compliance and legal requirements, and risk appetite.
- Risk tolerance is acceptable variation in outcomes related to specific
performance measures. Risk management implies that actions are being taken to either mitigate the impact of an unfavorable outcome and/or enhance the likelihood of a positive outcome.
Risk Assessment Process
Identification Process by which the likelihood, impact and level of risk are determined. Analysis Evaluation Response Process of determining and documenting the risk scenarios the organization faces considering exposure, threats, vulnerabilities, controls, and consequences. Process of comparing the results of the risk analysis with the organizations risk appetite and risk tolerance. Process of determining a recommended course of action. Also referred to as risk treatment. A risk assessment is a structured method of understanding risk. There are four distinct processes within a risk assessment.
Risk Analysis Approaches
Type Description Qualitative Qualitative risk assessments use descriptive terminology such as high, medium, and low or normal, elevated, and severe. Quantitative Quantitative risk assessments assign numeric and monetary values to all elements of the assessment. Key elements of both are likelihood of occurrence and impact.
Qualitative Risk Analysis
- The qualitative risk analysis approach is appropriate in situations where nontangible elements of risk (e.g., reputation) need to be considered and/or when
there is a lack of meaningful numeric data.
- Results are generally presented in a risk range map.
Qualitative risk analysis uses well-defined descriptive terminology to indicate likelihood, impact, and residual risk.
Quantitative Risk Analysis
Quantitative risk analysis assign either numeric and monetary values to all elements.
- Quantitative risk analysis elements include:
- Asset Value (AV) expressed in $.
- Exposure Factor (EF) expressed as a %.
- Single Loss Expectancy (SLE) expressed in $.
- Annualized Rate of Occurrence (ARO) expressed as a #.
- Annualized Loss Expectancy (ALE) expressed in $.
Quantitative Formulas Illustrated
SLE ($) = AV ($) x EF (%) Single Loss Expectancy = Asset Value x Exposure Factor Revenue from one hour of e-commerce is $20,000 (AV) A DDoS attack could disrupt 85% (EF) of online activity $20,000 (AV) x .85 (EF) = $17,000 (SLE) ALE ($) = SLE ($) x ARO (#) Annualized Loss Expectancy = Single Loss Expectancy x Annualized Rate of Occurrence Single Loss Expectancy (for an hour of DDoS disruption) is $17,000 Based on the current threat and controls environment, it is expected that there will be 5 hours of DDoS disruption per year $17,000 (SLE) x 5 (ARO) = $85,000 (ALE) Alternate scenario: it is expected that there will be 30 minutes of DDoS disruption per year. $17,000 (SLE) x .5 (ARO) = $8,500 (ALE)
Risk Treatment Options
Risk response is the responsibility to determine how to respond to the outcome of a risk analysis. Risk treatment is to select one or more options for addressing an identified risk. Option Description Ignore Act as if the risk doesn’t exist Avoid Eliminate the cause or terminate the associated activity Mitigate Reduce the impact or likelihood by implementing controls or safeguards Transfer Assign the risk to another party via insurance or contractual agreement (subject to legal and regulatory constraints) Accept Acknowledge and accept the level of risk, monitor, and report to stakeholders.
- Tools include risk register, heat maps, dashboards and metrics.
Risk Exception and Exemption
- A risk exception is a formal acknowledgment that a risk has been identified, but it
is not feasible or practical to implement standard risk treatment or control measures. Workarounds may be implemented.
- Exception handling is the process of approving an exception on either a
temporary or permanent basis.
- A risk exemption is a formal decision not to address a risk at all. Generally
implemented when the potential impact of a risk is low, and the cost and effort required to mitigate the risk are disproportionate to the potential impact. It is not always possible to avoid, transfer or mitigate a risk to an acceptable level.
Business Continuity
In its simplest form, business continuity is the capability of a business to operate in adverse conditions.
- The objective of business continuity planning is to prepare for the continued
operation of essential functions and services during disruption of normal operating conditions.
- To support this objective:
- Essential services and processes are identified.
- Threat scenarios are evaluated.
- Response, recovery, and contingency plans are developed.
- Strategies, plans, and procedures are tested.
Business Impact Analysis
The objective of a Business Impact Analysis (BIA) is to identify essential services, systems, and infrastructure.
- Essential means that the absence of or disruption of services would result in
significant, irrecoverable, or irreparable harm to the organization, employees, business partners, constituents, community, or country.
- The outcome of BIA is a prioritized matrix of services, systems, and
infrastructure.
- A Business Impact Analysis (BIA) is used by management to:
- make investment decisions.
- prioritize resources.
- guide the development of incident response, disaster recovery, and
business contingency (continuity) plans
Business Impact Metrics
Abbr. Metric Definition MTD MTO Maximum Tolerable Downtime Maximum Tolerable Outage Maximum time a process/service can be unavailable without causing significant harm to the business. RTO Recovery Time Objective Amount of time allocated for system recovery. RPO Recovery Point Objective Acceptable data loss ⁻ The point in time, prior to a disruption or system outage that data can be recovered. MTTR Mean Time to Repair Average time to repair a failed component or device. MTBF Mean Time Between Failures Measure of reliability (usage stated in hours).
RPO | RTO Timeline
Recovery Point Objective Failure Recovery Time Objective Weeks Days Hours Minutes Minutes Hours Days Weeks
5.3 Explain the processes associated with third-party risk
assessment and management
Third-Party Risk Management
- Third-party oversight activities include:
- Conducting a due diligence investigation related to service provider
selection and subsequent business activities.
- Codifying relationships.
- Coordinating incident response protocols and contractual notification.
- Monitoring the service provider through appropriate audits and
testing. Third-party Risk Management is a composite of activities used to research and source third parties, negotiate contracts, manage relationships, and evaluate performance.
Information Security Due Diligence Criteria
Criteria Description Controls Ability to implement required security and privacy controls. Compliance Ability to comply with regulatory requirements. Vulnerability Mgmt. Disclosure of vulnerabilities and frequency of patch releases. EOL/EOS EOL/EOS cycle, notification, and support. Assessment Proof of independent security testing. Right to Audit Agreement to allow independent audits or provide equivalent Incident Mgmt. Detection and response capabilities as well as security breach protocols Business Continuity Ability to continue to provide services and operate in adverse conditions
Third-Party Strategic Agreements
Agreement Type Objective Confidentiality / Non-disclosure (NDA) Protects data from unauthorized disclosure during and post-relationship Memorandum of Understanding (MOU) Non-binding document that outlines the intentions and areas of cooperation between parties Memorandum of Agreement (MOA) Legally enforceable document that establishes a contractual relationship between parties Business Partner Agreement (BPA) Comprehensive legal document that outlines the terms and conditions of a relationship between two or more businesses or entities
Third-Party Tactical Agreements
Agreement Type Objective Service Level Agreement (SLA) Codifies service and support requirements – may include incentives and/or penalties Interconnection Security Agreement (ISA) Documents technical requirements, ownership and management of equipment and supporting infrastructure Master Services Agreement (MSA) Outlines general terms and conditions. It serves as a framework for future agreements or projects between the parties. Statement of Work (SOW) Defines tasks, deliverables, timelines, and performance expectations for a particular project or engagement between a client and a service provider. Work Order (WO) Transactional documentation used for individual service requests, often within the context of ongoing business relationships.
5.4 Summarize elements of effective security compliance
Compliance Monitoring
- Compliance monitoring is used to identify areas for improvement and enables
early detection of non-compliance.
- Monitoring activities include manual inspections, audits, data analysis,
automated systems, or specialized tools. Compliance means acting in accordance with applicable rules, laws, policies, and/or obligations. Compliance monitoring is the active process of evaluating activities, practices, and behaviors to verify compliance and identify any deviations or non-compliant actions.
Automated Compliance Monitoring
- Automated systems can analyze large volumes of data in real-time to identify
patterns, anomalies, or potential compliance breaches.
- Automated systems can be programmed to generate alerts or notifications
when specific conditions or thresholds are met.
- Automation can help maintain comprehensive audit trails and documentation
for compliance purposes.
- Automated tools can monitor regulatory changes and updates in real-time.
Automated compliance monitoring utilizes automated tools to monitor and assess compliance.
Defining Privacy
- Individuals expect their privacy to be respected and their personal
information to be protected by the organizations with which they do business.
- Data minimization approach limits data collection to only what is required to
fulfill a specific purpose.
- Consequences of non-compliance with privacy regulations and/or privacy
breaches include reputational damage, loss of stakeholder trust, fines, and litigation. Privacy is the right of an individual to control the use of their personal information.
Privacy Specific Regulations
GDPR The California Consumer Privacy Act (CCPA) objective is to protect California residents The CCPA draws the scope of “personal information” broadly to mean any information that “identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.” CCPA General Data Protection Regulation (GDPR) objective is to protect people in the European Union (EU) and European Economic Area (EEA) from unlawful data collection or processing and works to increase consent requirements and to provide enhanced user rights. *Canada, Mexico, Brazil, Japan, among others all have privacy regulations modeled on the OECD privacy principles
Privacy Statement
- Best practices (and in some cases, legal and regulatory requirements) dictate
that whenever personal information is being collected there should be a corresponding privacy statement.
- The statement should indicate a mechanism for opting out as well as reporting
real or perceived breach of privacy. A privacy statement describes how an organization collects, uses, shares, and protects personal information collected from individuals.
5.5 Explain types and purposes of audits and assessments
Information Security Assessment
- Two approaches:
- Examination is the process of interviewing, reviewing, inspecting, studying,
and observing to facilitate understanding, comparing to standards or baselines, or to obtain evidence (e.g., Audit).
- The objective of an audit is to provide independent assurance based on
evidence.
- Testing is the process of exercising objects under specified conditions to
compare actual and expected behaviors (e.g., Penetration Testing). An information security assessment is the process of determining how effectively the entity being evaluated meets specific security and/or regulatory criteria.
Audit Framework
ISACA COBIT® 5 https://www.isaca.org/resources/cobit AICPA Statement on Standards for Attestation Engagements No. 18 (SSAE18) **Defacto technology company audit** ISACA AICPA An audit framework is a structured and systematic approach used by auditors to plan, execute, and report on an audit engagement. Audit frameworks are typically developed by auditing standards-setting bodies.
SSAE18 SOC Versions & Types
SOC 1 Report of controls relevant to user entities financial statements
- Agreed upon scope
SOC 2 Based upon Trust Services Principles (TSP) SOC 2, reports on controls intended to mitigate risk related to security, availability, processing integrity, confidentiality, and privacy
- Organization chooses categories; not controls
- Controls criteria provided by the AICPA
SOC 3 Same as SOC2 but does not detail testing performed and is designed for public distribution Type 1 Reports on controls place in operation as of a point in time
- Evaluation of design and implementation; not operating effectiveness
- Cover of report will show as “As of” date (e.g., June 30, 2020)
Type 2 Reports on the design, implementation and operating effectiveness over a period of time Includes tests of operating effectiveness and results
- Cover of report will show a time period (e.g., Jan 1, 2020-Dec 31,2020)
Penetration Testing
- Penetration testing generally involves exploiting combinations of vulnerabilities
on one or more systems. Pivoting is the act of using weakness on one system to access a better protected system.
- Testing can originate from within a target environment or external to the target
environment.
- Penetration testing can be useful for determining incident detection and
response capabilities. The objective of penetration testing is to evaluate the security of a target by identifying and attempting to exploit vulnerabilities, improper configurations, and hidden points of entry (ethical hacking).
Penetration Testing Approaches
Approach Description Unknown Environment
- No information is provided to the testers.
- The testers need to discover vulnerabilities, conduct reconnaissance,
identify potential entry points, and perform exploitation attempts. Partially Known Environment
- The organization provides restricted or selective information to the
testers.
- This approach can simulate scenarios where an attacker gains partial
information through reconnaissance or social engineering Known Environment
- The testers have comprehensive knowledge about the target system
or network.
- With this level of knowledge, the testing team can conduct in-depth
analysis, targeted assessments, and explore potential attack vectors.
Penetration Test Phases
Passive Reconnaissance Active Reconnaissance Exploitation Additional Research* Continued Exploitation Reporting * Research and exploitation are iterative processes.
Offensive / Defensive Penetration Testing
Offensive / Defensive penetration testing is designed to simulate an attack and evaluate preventative and deterrent controls, detection, and response capability.
Physical Penetration Testing
- Physical penetration testing aims to assess the physical security measures in
place, such as access control systems, locks, alarms, surveillance systems, perimeter security, and employee awareness.
- Physical penetration testers simulate the techniques and tactics that malicious
actors might use to gain unauthorized access (e.g., social engineering, tailgating (following authorized personnel into secured areas), lock picking, badge cloning). Physical penetration testing focuses on evaluating the effectiveness of an organization's physical security controls and measures.
5.6 Given a scenario, implement security awareness practices.
Shared Responsibility
- A critical component of a successful information security program is
knowledge and awareness.
- On-going education, training, and awareness programs are essential.
- Programs should always be customized for the target audience.
- Programs should be adaptable to changing circumstances (e.g., remote work
from home). Information security is a shared responsibility throughout an enterprise.
NIST SETA Model [SP800-50]
Security Education Training Awareness Attribute Why How What Level Insight Knowledge Information Objective Understanding Skill Behavior Method Discussion, seminar, reading Lecture, case study, hands-on Interactive, video, posters, games Measure Essay Problem solving True or false, multiple choice Impact Long-term Intermediate Short-term
SETA Maturity Model
Nonexistent Ad Hoc Compliance Driven Integrated Measurable and Reportable (Metrics Driven)
Security Awareness Programs
- Onboarding and post-boarding programs should focus on policies (e.g.,
Acceptable Use Policy), best practices, social engineering, duress, and reporting suspicious activity.
- Annual compliance, hot topic, and refresher program (instructor-led, recorded,
online).
- On-going awareness program which includes posters, games, contests, prizes,
and surveys.
- As needed, situational awareness communications.
Security awareness programs should be inclusive of all levels of the organization and extend to third-parties. The objective is to influence behavior.
Secrets of Impactful Training
Get everyone to believe in a shared outcome.
- Is
Be concise; don’t wander. Engage your audience – interactive activities, games, songs. Begin with an unexpected opening line. Start on time. Create a comfortable and welcoming environment. Invite everyone.
Assessment Question 5.1
Policies are high level governance documents. What is the relationship between policies and standards? A. Standards restate the policy in technical terms. B. Standards are mandatory implementation requirements. C. Standards create awareness. D. Standards influence procurement decisions.
Assessment Question 5.2
The Customer Service Team has informed management that if the Online Banking application is unavailable for more than 10 minutes, their phones start ringing off the hook with calls from unhappy customers. How would this be expressed in a BIA metric? A. RTO=10 B. MTD=10 C. MTBF=10 D. RPO=10
Assessment Question 5.3
Choose the correct formula for calculating an annualized loss expectancy. A. ALE=AV*EF B. ALE=SLE*ARO C. ALE=ARO*EF D. ALE=EF*SLE
Assessment Question 5.4
Type of penetration test that is designed to simulate an attack and evaluate preventative and deterrent controls, detection, and response capability. A. Offensive/defensive B. Open source C. Physical D. Unknown environment
Assessment Question 5.5
This privacy regulation is based on the OECD privacy principles and is designed to protect European Union (EU) and European Economic Area (EEA) residents from unlawful data collection or processing. A. GLBA B. COPPA C. CCPA D. GDPR
Preparing for the Exam
Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies
Test Taking Tips
- Be prepared for a variety of question formats include multiple choice,
multiple response, fill-in-the-blank, drag and drop, scenarios, exhibits (graphic or video), and performance-based.
- Pace yourself. Don’t rush, you will have enough time.
- Read the questions carefully.
- Choose your answer deliberately.
- Don't argue with the answers.
- Don’t panic if you are unsure about a question or the answer. Remind
yourself you can do this.
- If necessary, use the process of elimination.
- Post-exam, treat yourself to an indulgence.
Let’s study together
Stay in touch: e: Sari@sarigreenegroup.com t: @sari_greene l: https://www.linkedin.com/in/sarigreene/ Please complete the online evaluation and thank you for your participation. -All the best, Sari