WGU C727 - Cybersecurity Management I – Strategic Exam 2022 with complete solution COBIT 5 enablers (CH1) - COBIT 5 is an information security management system (ISMS) backed by ISACA, an international professional association serving a broad range of IT governance professionals and a framework accepted by many assurance and governance professionals.--- begins with principles, policies, and frameworks as mechanisms acting as hand-rails guiding desired behavior for day-to-day management. Processes describe an organized set of practices and activities to achieve certain objectives and produce a set of outputs in support of achieving cybersecurity objectives aligned to enterprise objectives.Organizational structures are the key decision-making entities in an enterprise. Culture, ethics, and behavior of individuals and of the enterprise are a key success factor in governance and management activities. Information is organization pervasive and includes all information produced and used by the enterprise. Information is not only required to keep the organization running and well governed, but is often the key product of the operational enterprise. Services, infrastructure, and applications include the infrastructure, technology, and applications that provide the enterprise with information technology processing and services. People, skills, and competencies are linked to people and are required for successful completion of all activities and for making correct decisions and taking corrective actions. Note that portions of this text are presented both in this course and in Cybersecurity Management II - Tactical.
ISO 31000:2009 (CH1) - Risk management—Principles and guidelines
Maturity (CH1) - Concept relating to the current or future state, fact, or period of evolving development, quality, sophistication, and effectiveness (not necessarily age dependent).Enterprise-wide risk management (ERM) (CH1) - Typically synonymous with risk management for all sectors; also used to emphasize an integrated and holistic "umbrella" approach delivering objectives by managing risk across an organization, its silos, its risk specialist, and other subfunctions and processes.Maturity model (CH1 - A simplified system that "road-maps" improving, desired, anticipated, typical, or logical evolutionary paths of organization actions. The ascending 1 / 4
direction implies progression increases organization effectiveness over time (albeit subject to stasis and regression).Cybersecurity (CH2) - Cybersecurity is the ongoing application of best practices intended to ensure and preserve confidentiality, integrity, and availability of digital information as well as the safety of people and environments Pillars of Security CIA and Safety - The pillars of cybersecurity used to be a triad: confidentiality, integrity, and availability. Safety is the newest member of the roster, making it a lovely quartet, and introduced to address everyday‐life threats posed by the Internet of Things (IoT).Confidentiality - In general, there are three accepted degrees of confidentiality: top secret, secret, and confidential.Disclosure of information could cause: - Disclosure of information could cause: Exceptionally grave prejudice Serious harm Harm Disadvantage To properly protect the confidentiality of data, which of the following is most important to define?-Acceptable use policy -Data Classification -Risk appetite -Encryption algoriths - Data Classification Every organization will approach data confidentiality differently but will require some sort of data classification (e.g., public, confidential, secret, top secret). Without having an established classification scheme, and subsequent proper labeling of the data, it is very difficult to effectively implement data confidentiality.Integrity - Integrity is the set of practices and tools (controls) designed to protect, maintain, and ensure both the accuracy and completeness of data over its entire life cycle.How do you achieve integrity? You do it by implementing digital signatures, write‐once‐ read‐many logging mechanisms, and hashing.Availability - Availability, pillar number 3, is the set of practices and tools designed to ensure timely access to data. If your computer is down, availability is compromised. If your Internet connection is moving at a snail's pace, availability is compromised. How do you ensure availability? In one word? Backup. In two words? Redundancy and backup. 2 / 4
Safety - Finally, term number 4: safety. It is the newest pillar in cybersecurity, but one whose impact is potentially the most critical. This is where cybersecurity incidents could result in injuries, environmental disasters, and even loss of life.You may be a user of a connected medical device, potentially putting you at mortal risk if that device is hacked. Or, you may be in a connected car, plane, or train. Or, you may be in charge of a business that is responsible for water purification for thousands of people, or of a utility that millions of people rely on for life‐sustaining services like electricity.Which scenario is an accurate example of a potential threat to availability?-Jane sends an email to Bob pretending to be Alice.-You are unable to access a file that you are not authorized to open.-John successfully intercepts and reads an email from Alice to Bob.-Your favourite website says it is down for planned maintenance. - -Your favourite website says it is down for planned maintenance.Despite being planned downtime, the website is still unavailable to you when you visit, which impacts the availability of the service. Pretending to be someone else in an email impacts integrity, as the email source has been spoofed and the sender is not verified.Intercepting someone else's email is an example of a confidentiality breach, as John has been able to read a message intended for Bob. Not being able to access a file seems like it could be an availability issue, however availability relates to a service that is down for authorized users. A file that cannot be accessed by an unauthorized user is a security control working as intended.Success in cybersecurity, therefore, will be the absence of impact on confidentiality, integrity, and availability of digital information no matter where it is (stationary/stored, traveling/transmitted, or processed). - Cybersecurity is the ongoing application of best practices intended to ensure and preserve confidentiality, integrity, and availability of digital information as well as the safety of people and environments. - When it comes to cybersecurity the main standards that apply are (alphabetically): - The European Telecommunications Standards Institute (ETSI) TR 103 family of standards The IASME standards for small and medium‐sized enterprises (IASME stands for Information Assurance for Small and Medium‐sized Enterprises) The Information Security Forum (ISF) Standard of Good Practice (SoGP) The International Society for Automation (ISA) ISA62443 standards for industrial automation and control systems The Internet Engineering Task Force (IETF) via their Request For Comments (RFC) 2196 memorandum The Information Systems Audit and Control Association, now known only as ISACA, through their COBIT framework and Cybersecurity Nexus (CSX) resources 3 / 4
The Institute for Security and Open Methodologies (ISECOM) with their Open Source Security Testing Methodology Manual (OSSTMM) and the Open Source Cybersecurity Playbook The ISO 27000 family of standards (ISO 27000-ISO27999) The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) The North American Electric Reliability Corporation (NERC), which via its Critical Infrastructure Protection (CIP) family of standards addresses electric systems and network security NIST CSF Standard: identify, protect, detect, respond, and recover - The identify function is where you develop an understanding of what your risks are, what your assets are, and what your capabilities are.Protect is your set of plans and actions that put in place the right controls (remember: controls do stuff) to protect the assets.Detect is the set of plans and actions that you will use to identify, classify, etc., an attack against your assets.Respond is the set of activities that you engage in response to an attack.Finally, recover refers to whatever plans or protocols you have in place to bring things back to normal after an attack.Here are the five functions of the NIST Cybersecurity Framework - Identify Develop understanding of risks, assets, and capabilities.Protect Create plans and actions for putting adequate controls in place.Detect Identify and classify an attack against assets.Respond Perform activities and actions as the result of an attack.Recover Bring systems and processes back to normal.
Question :
A system administrator has been assigned the responsibility of securing a newly deployed system. As part of her tasks, she disables unneeded ports, protocols, and services, removes unnecessary software, and enables secure communication protocols for system management.What is this an example of?-Reducing the attack surface -Turning on system security -Implementing ISO 27001 -Preventing a denial of service - Reducing the attack surface The attack surface references the potential areas of vulnerability within a system that an attacker may launch an attack against. By reducing the attack surface (such as removing unneeded services or software), the potential attacker has less of a "surface" to attack, making a successful breach more difficult and increasing the overall security posture of the system.
- / 4