Cyber Security Strategy and Implementation Guide for Australian Essentials 8 via Microsoft Intune.

Cyber Security Strategy

Cybersecurity has become a critical concern for businesses of all sizes and industries. The increasing sophistication and frequency of cyber attacks highlight the need for organizations to implement effective cybersecurity measures to protect their operations, assets, and reputation.

The purpose of this Cyber Security Strategy is to provide a comprehensive framework for protecting our organization against cyber threats. This strategy is based on the Australian Cyber Security Centre (ACSC) Essential Eight framework, which outlines eight essential security controls that organizations should implement to mitigate cybersecurity risks.

Objectives:

The objectives of our Cyber Security Strategy are:

  1. To protect the confidentiality, integrity, and availability of our organization’s information and assets.
  2. To ensure that our organization is compliant with relevant laws, regulations, and standards.
  3. To reduce the risk of cyber threats, including malware, ransomware, phishing, and other types of cyber attacks.
  4. To ensure that our employees are trained in cybersecurity best practices and are aware of their roles and responsibilities in protecting the organization’s assets and operations.

Security Controls:

Our Cyber Security Strategy will focus on implementing the first four security controls of the Essential Eight framework, as these are considered the most effective at mitigating cybersecurity risks. These controls are:

  1. Application Whitelisting: We will implement application whitelisting to allow only approved applications to run on our systems, preventing the execution of malicious software.
  2. Patching Applications: We will keep applications up-to-date with the latest security patches to prevent vulnerabilities from being exploited.
  3. Patching Operating Systems: We will regularly patch operating systems to prevent known vulnerabilities from being exploited.
  4. Restricting Administrative Privileges: We will limit administrative privileges to reduce the risk of unauthorized access to critical systems and data.

In addition to implementing these security controls, we will also establish policies and processes to ensure that they are maintained and updated regularly.

Risk Management:

Our Cyber Security Strategy will include a risk management approach to identify and prioritize cybersecurity risks. We will conduct regular risk assessments to identify potential threats and vulnerabilities, and develop plans to mitigate these risks.

Training and Awareness:

We recognize that employees are a critical component of our cybersecurity strategy. We will provide regular training and awareness programs to educate employees on cybersecurity best practices and their roles and responsibilities in protecting the organization’s assets and operations.

Monitoring and Reporting:

We will establish monitoring and reporting processes to ensure that our security controls are effective and to identify any security incidents or breaches. We will conduct regular reviews of our cybersecurity measures to ensure that they are up-to-date and aligned with emerging threats and industry best practices.

Australian Essentials Eight

The Australian Cyber Security Centre (ACSC) has developed the Essential Eight framework, which outlines eight essential security controls that organizations should implement to mitigate cybersecurity risks. These security controls are practical and effective, and align with the maturity level 2 of the Essential Eight framework.

Essential Eight framework includes maturity levels that organizations can use to measure their implementation of the Essential Eight controls. These maturity levels provide a structured approach to implementing cybersecurity measures and help organizations to progressively improve their cybersecurity posture.

The Essential Eight maturity levels are as follows:

  1. Ad Hoc: Organizations at this level have ad hoc security measures in place that are reactive and not based on any formal risk management or security framework.
  2. Developed: Organizations at this level have implemented some security measures, but these measures are not consistent or fully integrated into the organization’s risk management framework.
  3. Defined: Organizations at this level have a defined security posture, with security measures fully integrated into the organization’s risk management framework.
  4. Managed: Organizations at this level have a managed security posture, with regular monitoring and reporting of security measures and incidents.
  5. Established: Organizations at this level have established a culture of security, with a proactive approach to cybersecurity and regular testing and improvement of security measures.
  6. Mature: Organizations at this level have a mature security posture, with a continuous improvement approach to cybersecurity and a strong focus on risk management.
  7. Adaptive: Organizations at this level have an adaptive security posture, with the ability to quickly respond to emerging threats and adapt security measures accordingly.

By implementing the Essential Eight controls and progressing through the maturity levels, organizations can reduce the risk of cyber threats and protect their business operations, assets, and reputation. Our proposed cybersecurity plan will help your organization to achieve maturity level 2 of the Essential Eight framework, which includes the implementation of the first four security controls.

We will work with your organization to develop a comprehensive cybersecurity plan that aligns with the Essential Eight framework and supports your business objectives. Our plan will include technical aspects, policies, and processes, and will be tailored to your organization’s specific needs and requirements.

In this Cyber Security Strategy and Implementation Guide, we will provide a detailed plan for configuring a secure managed cloud environment using Intune, and implementing policies to ensure devices are up-to-date and compliant with the Essential Eight framework maturity level 2.

This guide will cover technical aspects, policies, and processes, and provide business owners with a comprehensive approach to cybersecurity that can help reduce the risk of cyber threats and protect their businesses.

This guide will provide information to help configure a secure managed cloud environment for a customer with 20 seats. The aim is to implement policies that align with Essential Eight Framework maturity level 2 and use Device Management tools like Intune to manage and secure all company-owned devices. This plan will cover technical aspects, policies, and processes necessary for implementing a secure managed cloud environment.

The Essential Eight consists of the following security controls:

  1. Application Whitelisting: Application whitelisting helps prevent the execution of malicious software by allowing only approved applications to run.
  2. Patching Applications: Keeping applications up-to-date with the latest security patches can help prevent vulnerabilities from being exploited.
  3. Patching Operating Systems: Regularly patching operating systems can help prevent known vulnerabilities from being exploited.
  4. Restricting Administrative Privileges: Limiting administrative privileges can help reduce the risk of unauthorized access to critical systems and data.
  5. Multi-factor Authentication: Using multi-factor authentication (MFA) can help prevent unauthorized access to systems and data by requiring additional forms of authentication.
  6. Backups: Regularly backing up critical data can help protect against data loss in the event of a cyber attack or other disaster.
  7. Network Segmentation: Network segmentation can help reduce the impact of a cyber attack by limiting the spread of malware and other threats.
  8. User Education: Educating users on how to identify and respond to cyber threats can help prevent security incidents caused by human error.

Implementing these security controls can help protect businesses against a wide range of cyber threats, including malware, ransomware, phishing, and other types of cyber attacks. Business owners should ensure that their organizations have appropriate cybersecurity measures in place, and regularly review and update these measures to stay ahead of evolving threats.

The ACSC recommends that organizations implement the Essential Eight framework in a prioritized manner, starting with the first four security controls, as these are considered the most effective at mitigating cybersecurity risks. The framework also includes maturity levels that organizations can use to measure their implementation of the Essential Eight controls.

In addition to implementing the Essential Eight framework, organizations should also regularly review and update their cybersecurity measures to stay ahead of evolving threats. They should also ensure that their employees are trained in cybersecurity best practices and are aware of their roles and responsibilities in protecting the organization’s assets and operations.

By implementing the Essential Eight framework and regularly reviewing and updating their cybersecurity measures, organizations can reduce the risk of cyber threats and protect their business operations, assets, and reputation.

Essentials Eight Implementation Guide using Microsoft Intune.

The technical aspects of implementing a secure managed cloud environment involve the following steps:

  1. Device Management Tool: As per the requirement, Intune will be the device management tool to be used to manage and secure all company-owned devices. Intune provides various features like device management, application management, and conditional access, among others.
  2. Configuration of Devices: The first step in configuring devices is to join them to Azure AD. This will allow for seamless management of devices from Intune. The next step is to configure policies for devices. The following policies will be implemented:

a. Password Policy: A password policy will be implemented that enforces strong passwords and password expiration every 90 days. This policy will help prevent unauthorized access to devices.

b. Device Compliance Policy: A device compliance policy will be implemented that ensures that devices are compliant with security standards. This policy will check if devices have the latest OS updates, anti-virus software installed, and if devices are jailbroken/rooted. Devices that do not meet the compliance requirements will be prevented from accessing company resources. As direct internet connectivity has been stipulated, applications will be set to auto update. Firmware can be update if an executable file is packaged and deployed via Intune.

c. Encryption Policy: An encryption policy will be implemented that requires all devices to be encrypted. This policy will ensure that data stored on devices is protected in case of loss or theft.

d. Application Policy: An application policy will be implemented that ensures that only approved applications are installed on devices. This policy will help prevent the installation of malicious software on devices. Application whitelisting will prevent all non-approved applications (including malicious code) from executing. WDAC provides all the features of AppLocker with additional functionality and simpler management from within Intune. It is also possible to implement the latest recommended block rules from Microsoft. Only signed macros will be enabled via Intune policies. Web advertisements that are java or flash based will be blocked. ‘Other’ web adverts will not be controlled. Web browsers are configured to block or disable support for Flash content for Internet Explorer and Edge. Web browsers are configured to block Java from the Internet for Internet Explorer and Edge. Office 365 applications block flash content by default. Object Linking and Embedding will be disabled by Intune policy.

e. Conditional Access Policy: A conditional access policy will be implemented that ensures that only authorized devices can access company resources. This policy will require devices to be compliant with device compliance policies and have approved applications installed. Stronger user authentication makes it harder for adversaries to access sensitive information and systems. MFA is enabled for all with a soft token. Hard tokens would require an IaaS server in Azure and will not be implemented.

  1. Monitoring and Reporting: Intune provides various monitoring and reporting capabilities that allow administrators to monitor device compliance and security. Reports can be generated to view the compliance status of devices and track any policy violations. This will help administrators to identify and remediate any security issues.
  2. Daily Backups: Configuration settings of Office 365 and Intune are backed up. Documents, Desktops and Pictures are redirected to OneDrive using Windows Known Folders providing a backup of data to the cloud. Office 365 data is replicated by Microsoft to at least two geographically dispersed data centres. Exchange Online has a recover deleted items from server option. Cloud based files have Recycle bin and Restore options in addition to retention policies. Retention policies are created that ensure that data is retained forever for: * Exchange * SharePoint * OneDrive * Office 365 Groups * Skype for Business * Exchange Public Folders * Teams channel messages * Teams chats Workstation configuration is stored in Intune (AutoPilot rebuild) or SCCM task sequence.

Policies The policies to be implemented are as follows:

  1. Acceptable Use Policy: An Acceptable Use Policy will be implemented that outlines the acceptable use of company-owned devices. The policy will include guidelines on the use of company resources, the installation of software, and the handling of confidential information. This policy will help prevent security incidents caused by employees.
  2. Incident Response Policy: An Incident Response Policy will be implemented that outlines the steps to be taken in case of a security incident. The policy will include guidelines on reporting incidents, containing incidents, and recovering from incidents. This policy will ensure that security incidents are handled efficiently and effectively.
  3. Data Classification Policy: A Data Classification Policy will be implemented that classifies data based on its sensitivity. The policy will include guidelines on how data should be handled based on its classification. This policy will ensure that sensitive data is protected appropriately.
  4. Access Control Policy: An Access Control Policy will be implemented that outlines the procedures for granting and revoking access to company resources. The policy will include guidelines on how access should be granted based on roles and responsibilities. This policy will help prevent unauthorized access to company resources. Restriction of administrative privileges for admin accounts will prevent adversaries using these accounts to gain full access to information and systems. WDAC policies are applied to admin users to prevent the ability to run email and web browsers. Admin users will log on with their normal accounts and then authenticate to the Office 365 tenant for management using their privileged account to administer the system.

The process for implementing a secure managed cloud environment involves the following steps:

  1. Assessment: An assessment will be conducted to identify the current security posture of the organization. The assessment will identify any security gaps and risks.
  2. Planning: Based on the assessment, a plan will be developed to implement a secure managed cloud environment. The plan will.

Cyber Security Strategy provides a comprehensive framework for protecting our organization against cyber threats. By implementing the first four security controls of the Essential Eight framework, establishing policies and processes to maintain and update these controls, and adopting a risk management approach, we can reduce the risk of cyber threats and protect our organization’s assets and operations.

Reference

https://github.com/govau/desktop.gov.au/blob/187a2f71f36578c2abc92d2072bda3119dafca43/blueprint/overview.md#essential-8-maturity

https://acurus.com.au/how-microsoft-aligns-and-matures-essential-8-mitigation-strategies/

https://www.microsoft.com/en-au/business/topic/security/essential-eight/

https://acurus.com.au/how-microsoft-aligns-and-matures-essential-8-mitigation-strategies/