Cyber Security Defence Operations Centre
Services
- Security Device Management
- SIEM
- VM
- IPS/Firewalls
- Cloud
- Endpoint
- AV
- EDR
- MDM
- Threat Intelligence and Monitoring
- Service Management
- Incident Response and Digital Forensics
- Risk Assessments and Strategy
Method
- Protect, Detect, Correct
- People, Process, Policy
Overview
- What is Cyber Security
- http://www.umuc.edu/cybersecurity/about/cybersecurity-basics.cfm
- Compliance (List)
- Services
- Protect
- Monitor
- Correct
- Security Controls
- Governance and Compliance
- SMB, Enterprise, Government
[youtube=https://www.youtube.com/watch?v=3S01vLlvubE]
GOAL
Develop a easy to consume Security Service Catalog that adheres to industry best practice with Managed and Consumption based licensing.
Business
- Low C-level awareness and appreciation for today’s threat landscape leading to an underfunded security operations program and to increased risk exposure
- Defending against advanced threats requires a substantial shift in resources from prevention to detection and response, but organizations that make this shift often discover they don’t have the necessary expertise to create and execute the transition
- Investment Security negativity impacts innovation
Technology
- Point security products that are poorly integrated and deployed without first differentiating high and low asset values, resulting in misallocation of scarce security resources
- Inability to discover sophisticated attack techniques, resulting in exposure to targeted attacks
- Lack of centralized security monitoring and alerting, resulting in difficulty in detecting and investigating attacks and in scoping the nature and extent of an initial breach
- Lack of automation for incident-response workflows, resulting in extended breach exposure time
- Lack of threat-intelligence capabilities, resulting in less effective defense countermeasures
Operations
- Poor patch-management processes, resulting in extended exposure to known vulnerabilities
- Poorly defined security roles and responsibilities, resulting in less effective security defenses
- Ad hoc processes and procedures, resulting in operational inefficiency and extended breach exposure time
- Lack of post-incident “lessons learned” discipline, resulting in foregone opportunities to enhance security operations
- Huge operational impact when a potential breach occurs, resulting in increased costs and negative impact on focus on core business
Business Case
- Business Canvas
- Marketing Description
- SANs 20 Control Products Selection Matrix (RSA, Nessus, Trend)
QUALIFYing questions
- Have you had a virus infection that affected your business?
- How much time do you spend on Security?
- What regulatory requirements to you need to be compliant ?
- Are you comfortable with your network security?
- What was the results of your last security audit?
- How much money have you invested in Security? (Virus software, Firwalls, etc.)
- Would you use a managed service for security back by SLAs?
- Do you have a business score card on your security status?
- Do you have a Security Policy?
- What is the impact on data loss on security breach?
- Do you have complete visibility, control and auditing access to your critical data and systems?
- How do you secure SaaS or Public Clouds beyond your permitter defence?
Cloud Security Solutions
SANs 20 Controls product matrix
- Vendor Solutions :- http://www.sans.org/critical-security-controls/vendor-solutions
- Selection Criteria:
- Single Platform for Multiple Controls
- Service Provider Licensing
- Multi-Tenant Capability
- Consumption Based licensing
- SaaS or Appliance Based
- Primary and Secondary Product
- Key Partners – EMC RSA, Symantec, Trend, Intel, FortiGate, TripWire, Nessus, Cisco, CA Identity Management,https://www.elastica.net/cloudsoc/
- http://lockpath.com/products/
- https://www.unifiedcompliance.com/products/
- Selected – TripWire, EMC RSA, Nessus, Foritinet, TrendMicro, Cyberark, Trustwave, IBM BigFix, IBM QRadar, AlertLogic, NimSoft, RiskNetworks,sciencelogic.com, https://www.cylance.com/mssp, Splunk, Symantec Security Managed Services
- Inventory of Authorized and Unauthorized Devices
- Nessus and Tripwire Enterprise
- Inventory of Authorized and Unauthorized Software
- Nessus and Tripwire Enterprise
- Secure Configurations for Hardware and Software on Mobile Devices, Laptops, Workstations, and Servers
- Nessus and Tripwire Enterprise
- Continuous Vulnerability Assessment and Remediation
- Nessus and Tripwire Enterprise
- Malware Defenses
- SPAM
- Endpoints
- Internet Access
- TrendMicro and FortiGate
- Application Software Security
- NetScaler Application Firewall
- Wireless Access Control
- Nessus, TripWire
- Data Recovery Capability
- Data Protection
- Varonis
- Security Skills Assessment and Appropriate Training to Fill Gaps
- Secure Configurations for Network Devices such as Firewalls, Routers, and Switches
- Nessus, TripWire
- Limitation and Control of Network Ports, Protocols, and Services
- Nessus, TripWire
- Controlled Use of Administrative Privileges
- TripWire
- CyberArk
- Boundary Defense
- Firewall
- IDS
- IPS
- Cisco, Foritinte
- Maintenance, Monitoring, and Analysis of Audit Logs
- Nessu, TripWire (SIEM)
- Controlled Access Based on the Need to Know
- TripWire
- Account Monitoring and Control
- TripWire
- Data Protection
- Incident Response and Management
- EMC Archer
- Secure Network Engineering
- TripWire
- Penetration Tests and Red Team Exercises
- Nessus
Additional Controls
- Multi-factor Authentication/BioMetrics
- Single Sign On
- Rights Managment
- Data Loss Prevention
- eDiscovery
- Legal Hold
- ITIL
- DDOS Mitigation (DNS)
- MDM
- DR (Snapshots, Imagine, Restore)
- Critical Response Team
- Governance/Compliance
- Education
IT GRC TOols
- http://www.neupart.com/products/iso-27001-policy-and-compliance
- http://www.neupart.com/products/iso-27001-policy-and-compliance
- https://resources.sei.cmu.edu/asset_files/TechnicalReport/2007_005_001_14885.pdf
- http://csrc.nist.gov/publications/nistpubs/800-30/sp800-30.pdf
Service catalog
- UTM
- MDM
- Secure WiFI
- Identify Management and Automation SEIM
- SSO, Multi-factor, Bio metric, vicinity login solutions
- Shadow IT Dashboards
- 24/7 Security Incident Monitoring
- 24/7 Security Breach Critical Incident Response
- Internet Access Security Monitoring and Managed
- SPAM Filtering Monitoring and Managed
- EndPoint Monitoring and Managed
- Patch Management
- Continuous Monitoring and PenTesting
- Web Site Threat Monitoring
- Firewall Monitoring and Managed
- IPS Monitoring and Managed
- IDS Monitoring and Managed
- Compliance and Governance Reporting
- Compliance and Governance Remediation
- Security Governance Policy Development
- Certificate Management
- Configuration Management (Insure any baseline configuration changes are tracked for OS and Networking Devices Only.)
- Privileged Access Management
Managed security service providers and SOCs
- Macquarie Telecom SOC – http://www.macquarietelecom.com/government/security-operations-centre/
- Trustwave MSSP – https://www.trustwave.com/Services/Managed-Security/
- AlienVault – https://www.alienvault.com/solutions/mssp-managed-security-service-providers
- DELL SOC – http://www.dellsecureworks.com.au/it-security-services/
- NNT – http://www.business.att.com/enterprise/Service/network-security/firewall-endpoint/premises-based-firewall/#fbid=ctdQF4Elk79?hashlink=tab2
- IBM – http://www-935.ibm.com/services/us/en/it-services/security-services/managed-firewall-service/index.html
- Verizon – http://www.verizonenterprise.com/solutions/security/network/
- Symantec SOC and MSSP – https://www.symantec.com/managed-security-services/
- DXC
- BT
- NCCGroup
- MissingLink
- Kenetic
SOC Design
- SOC Design Books
- https://www.smart-energy.com/wp-content/uploads/2014/02/EPRI-Planning-ISOC-report.pdf
- https://www.mitre.org/sites/default/files/publications/pr-13-1028-mitre-10-strategies-cyber-ops-center.pdf
- https://cdn.ttgtmedia.com/rms/security/Designing-and-Building-Security-Operations-Center-Chapter3.pdf
- https://securityintelligence.com/best-practices-for-designing-a-security-operations-center/
- https://digitalguardian.com/blog/how-build-security-operations-center-soc-peoples-processes-and-technologies
- the-fundamental-guide-to-building-a-better-security-operation-center-socelements-of-soc
- summit_archive_1493840439
- David Nathans-Designing and Building Security Operations Center-Syngress (2014)
- conference-proceeding
- PaperHICSSSchinaglSchoonPaansSOCv106
- elements-of-soc
SOC Design
- ServiceNow
- 24/7 Tier 1, Tier 2, Tier 3
- Tier 4 Retainer
- Threat Researchers and PenTesting Team
- Security Management
- FortiNet
- Huawei cyber security
- Splunk Enterprise, UBA, Phantom, Security Essentials. Threat Intelligence
- CrownStrike
- Consulting Services
- NIST
- PCI
- PenTesting
- ISO, etc.
- Privacy and GDPR
- Data Risk
- Security Design
Research
- 3B-CyberRM-5-WCIA-PrioritizedSANS20Controls
- https://www.giac.org/paper/gsec/1755/closing-gaps-security-how-to-guide/103146
- https://www.giac.org/paper/gsec/3287/overview-practical-risk-assessment-methodologies/105426
- https://www.giac.org/paper/gsec/2022/vulnerability-assessments-methodologies-perform-self-assessment/103498
- http://www.hut3.net/governance-risk-compliance/standards/sans-top-20-gap-analysis
- https://www.sans.org/reading-room/whitepapers/auditing
- 3B-CyberRM-5-WCIA-PrioritizedSANS20Controls
- http://information.rapid7.com/rs/rapid7/images/CG-SANS-Top20-CSC-Compliance-Guide.pdf
- https://www.giac.org/paper/gcia/1131/small-business-budget-implementation-20-security-controls/107303
- http://australia.emc.com/collateral/white-papers/rsa-advanced-soc-solution-sans-soc-roadmap-white-paper.pdf
- http://www.asd.gov.au/infosec/acsc.htm
- http://www.mcafee.com/au/resources/white-papers/foundstone/wp-creating-maintaining-soc.pdf
- http://www8.hp.com/au/en/software-solutions/security-operations-center/
- http://www.macquarietelecom.com/government/security-operations-centre/
- http://www.crn.com/news/security/300073105/idc-security-market-data-reflects-economic-impact-of-cybercrime-study-finds.htm/pgno/0/1
- Top Priority of CEOs
- https://www.idc.com/getdoc.jsp?containerId=prUS25484415
- http://www.marketsandmarkets.com/Market-Reports/cyber-security-market-505.html?gclid=CKWbxtK5i8YCFQOWvQods0wA7A
- https://www.symantec.com/en/au/security_response/publications/threatreport.jsp?cid=70150000000diU3AAI&om_sem_cid=biz_sem_s210258078864899|pcrid|82668137848|pmt|b|plc||pdv|c
- http://www.marketsandmarkets.com/PressReleases/cyber-security.asp
- http://cybersecurityventures.com/cybersecurity-market-report/
- http://www.telstra.com.au/business-enterprise/download/document/telstra-cyber-security-report-2014.pdf
- https://www.gartner.com/newsroom/id/2828722
- https://www.nicta.com.au/category/industry-engagement/security/media-releases/cybersecurity-australias-multi-billion-dollar-market-opportunity/
- http://www-935.ibm.com/services/us/en/it-services/security-services/managed-firewall-service/index.html
- http://www.business.att.com/enterprise/Service/network-security/firewall-endpoint/premises-based-firewall/#fbid=vJowdhAgF4H?hashlink=tab2
- http://www.nttcomsecurity.com/us/services/managed-security-services/
- http://www.verizonenterprise.com/solutions/security/network/
- http://www.symantec.com/managed-security-services/
- CIO Executive Council Cyber Security Handbook_Web (1)
- http://www.asd.gov.au/publications/protect/senior_management_questions.htm
- http://www.asd.gov.au/infosec/mitigationstrategies.htm
- http://www.asd.gov.au/infosec/top-mitigations/mitigations-2014-table.htm
- http://webstore.ansi.org/RecordDetail.aspx?sku=ISO/IEC+-+27001/27002/27005/27006+IT+Security+Techniques+Package&source=package_landing_page
- http://www.prnewswire.com/news-releases/rsa-research-finds-size-doesnt-matter-in-cybersecurity-300096142.html?linkId=14809670&M=8326D9B7-544C-4A48-8E0E-C3633A1520AC
- http://www.blackfinsecurity.com/#section-threatforge
- http://www.dellsecureworks.com.au/it-security-services
- https://www.sophos.com/en-us/medialibrary/PDFs/partners/sophos_complete_security_msps_dsna.pdf?la=en.pdf
SANs Missing Items
- Reporting
- Governance
- MDM
- Single Sign On/Identify Mangement
- http://www.secureconsulting.net/2011/10/the-20-controls-that-arent.html
- https://www.linkedin.com/pulse/20140831040435-12861716-comparing-iso-iec-27001-2013-isms-to-sans-csc-top-20-nerc-cip-pci-dss
- The Definition of SOC-cess? SANS 2018 Security Operations Center Survey – https://www.sans.org/reading-room/whitepapers/soc
Security Mapping and Maturity Models
- NIST IT Security Maturity – http://csrc.nist.gov/groups/SMA/prisma/security_maturity_levels.html
- NERC CIP Standard Mapping to the Critical Security Controls – Draft – https://www.sans.org/media/critical-security-controls/nerc-cip-mapping-sans20-csc.pdf
- Framework for Improving Critical Infrastructure Cybersecurity – http://www.nist.gov/cyberframework/upload/cybersecurity-framework-021214.pdf
- Mapping SANs 20 to ISO and NIST
- SABA – http://www.sabsa.org/
- Security Beachmarks – https://benchmarks.cisecurity.org/downloads/audit-tools/
- ASD Strategies to Mitigate Targeted Cyber Intrusions – http://www.asd.gov.au/infosec/top-mitigations/mitigations-2014-table.htm
- COBIT, ITIL ISO – http://www.isaca.org/Knowledge-Center/Research/ResearchDeliverables/Pages/Aligning-COBIT-4-1-ITIL-V3-and-ISO-IEC-27002-for-BusinessBenefit.aspx
Maturity Model Levels
- Initial (chaotic, ad hoc, individual heroics) – the starting point for use of a new or undocumented repeat process.
- Repeatable – the process is at least documented sufficiently such that repeating the same steps may be attempted.
- Defined – the process is defined/confirmed as a standard business processes.
- Managed – the process is quantitatively managed in accordance with agreed-upon metrics.
- Optimizing – process management includes deliberate process optimization/improvement
GAP ANALYSIS
Initial – the starting point for use of a new or undocumented repeat process.
- (chaotic, ad hoc, individual heroics)
- Formal, up-to-date documented policies stated as “shall” or “will” statements exist and are readily available to employees.
- Policies establish a continuing cycle of assessing risk and implementation and use monitoring for program effectiveness.
- Policies written to cover all major facilities and operations agency-wide or for a specific asset.
- Policies are approved by key affected parties.
- Policies delineate the IT security management structure, clearly assign IT security responsibilities, and lay the foundation necessary to reliably measure progress and compliance.
- Policies identify specific penalties and disciplinary actions to be used if the policy is not followed
Repeatable – the process is at least documented sufficiently such that repeating the same steps may be attempted.
- Formal, up-to-date, documented procedures are provided to implement the security controls identified by the defined policies.
- Procedures clarify where the procedure is to be performed, how the procedure is to be performed, when the procedure is to be performed, who is to perform the procedure, and on what the procedure is to be performed.
- Procedures clearly define IT security responsibilities and expected behaviors for
asset owners and users information resources management and data processing personnel, management, andIT security administrators.
Procedures contain appropriate individuals to be contacted for further information, guidance, and compliance. - Procedures document the implementation of and the rigor in which the control is applied. .
- Defined – the process is defined/confirmed as a standard business processes.
- Procedures are communicated to individuals who are required to follow them.
- IT security procedures and controls are implemented in a consistent manner everywhere that the procedure applies and are reinforced through training.
- Ad hoc approaches that tend to be applied on an individual or case-by-case basis are discouraged.
- Policies are approved by key affected parties.
- Initial testing is performed to ensure controls are operating as intended.
Managed – the process is quantitatively managed in accordance with agreed-upon metrics.
- Tests are routinely conducted to evaluate the adequacy and effectiveness of all implementations.
- Tests ensure that all policies, procedures, and controls are acting as intended and that they ensure the appropriate IT security level.
- Effective corrective actions are taken to address identified weaknesses, including those identified as a result of potential or actual IT security incidents or through IT security alerts issued by FedCIRC, vendors, and other trusted sources.
- Self-assessments, a type of test that can be performed by agency staff, by contractors, or others engaged by agency management, are routinely conducted to evaluate the adequacy and effectiveness of all implementations
- Independent audits such as those arranged by the General Accounting Office (GAO) or an agency Inspector General (IG), are an important check on agency performance, but are not viewed as a substitute for evaluations initiated by agency management.
- Information gleaned from records of potential and actual IT security incidents and from security alerts, such as those issued by software vendors are considered as test results. Such information can identify specific vulnerabilities and provide insights into the latest threats and resulting risk.
vulnerabilities and provide insights into the latest threats and resulting risk. Evaluation requirements, including requirements regarding the type and frequency of testing, are documented, approved, and effectively implemented. - The frequency and rigor with which individual controls are tested depend on the risks that will be posed if the controls are not operating effectively.
Optimizing – process management includes deliberate process optimization/improvement
- Effective implementation of IT security controls is second nature.
- Policies, procedures, implementations, and tests are continually reviewed and improvements are made.
- A comprehensive IT security program is an integral part of the culture.
- Decision-making is based on cost, risk, and mission impact.
- The consideration of IT security is pervasive in the culture.
- There is an active enterprise-wide IT security program that achieves cost-effective IT security.
- IT security is an integrated practice.
- Security vulnerabilities are understood and managed.
- Threats are continually reevaluated, and controls adapted to changing IT security environment.
- Additional or more cost-effective IT security alternatives are identified as the need arises.
- Costs and benefits of IT security are measured as precisely as practicable.
- Status metrics for the IT security program are established and met.