IT Security Controls: A Guide to Corporate Standards and Frameworks
Book information
Description
Table of Contents About the Authors About the Technical Reviewers Acknowledgments Introduction Please check our GitHub page Chapter 1: The Cybersecurity Challenge Types of Threats Who Are These People? How Do Cyberattacks Happen? What Can We Do? Summary Chapter 2: International Security Standards ISO 27001 and ISO 27002 Information Security Policies (Clause A.5) Organization of Information Security (Clause A.6) Human Resource Security (Clause A.7) Before Hiring Employees Termination and reassignment Asset Management (Clause A.8) Access Control (Clause A.9) Cryptography (Clause A.10) Physical and Environmental Security (Clause A.11) Operations Security (Clause A.12) Communications Security (Clause A.13) System Acquisition, Development, and Maintenance (Clause A.14) Supplier Relationships (Clause A.15) Incident Management (Clause A.16) Business Continuity Management (Clause A.17) Compliance (Clause A.18) ISO 27002 PCI DSS Goal 1: Build and Maintain a Secure Network Goal 2: Protect Cardholder Data Goal 3: Maintain a Vulnerability Management Program Goal 4: Implement Strong Access Control Measures Goal 5: Regularly Monitor and Test Networks Goal 6: Maintain a Policy That Addresses Information Security Prioritization SWIFT: Customer Security Controls Framework Summary Chapter 3: Information Security Frameworks NIST Frameworks NIST SP 800-53: Security and Privacy Controls for Federal Information Systems and Organizations NIST SP 800-37: Guide for Applying the Risk Management Framework to Federal Information Systems NIST Cybersecurity Framework COBIT 5 for Information Security COBIT 5 Process Goals Applied to Information Security Other Regulatory Frameworks CIS Controls Saudi Arabia Monetary Authority (SAMA) Cybersecurity Framework Reserve Bank of India FIFA World Cup Qatar 2022 Monetary Authority of Singapore BDDK Others Summary Chapter 4: IT Security Technical Controls Off-Premises Unmanaged Devices MDM: Mobile Device Management MAM: Mobile Application Management NAC: Network Access Control Multi-Factor Authentication RASP for Mobile Applications Secure Connections OSI Model TCP/IP Model IPsec, SSH, and TLS IPsec SSH TLS Clean Pipes DDoS Mitigation Managed Devices Directory Service Integration Centralized Endpoint Management TPM: Trusted Platform Module VPN Client NAC: Network Access Control Data Classification UAM: User Activity Monitoring Endpoint Protection Phishing Reporting Tool Host IPS or EDR Desktop Firewall Antivirus Antispyware Full-Disk Encryption Application Control and Application Whitelisting Perimeter Security Firewalls Intrusion Detection and Intrusion Protection Systems Proxy and Content (URL) Filtering DLP: Data Loss Prevention Honeypot WAF: Web Application Firewall SSL VPN DNS Internal DNS Servers External DNS Servers Message Security Directory Integration for External Applications Sandbox File Integrity Encrypted Email On-Premises Support Controls Access Control Secure VLAN Segmentation Security Baselines Redundancy Load Balancing Encryption Multi-tier and Multi-layer Multi-layering Multi-tiering TLS Decryption Perimeter Static Routing Heartbeat Interfaces Disaster Recovery Time Synchronization Log Concentrator Routing and Management Networks Management Networks Perimeter Routing Networks Centralized Management Physical Network Segmentation Sinkhole Public Key Infrastructure Security Monitoring and Enforcement Privileged Access Management Security Information and Event Management Database Activity Monitoring Single Sign-on Risk Register Chapter 5: Corporate Information Security Processes and Services Security Governance Policies and Procedures Cybersecurity and Risk Assessment Penetration Testing Red Teaming Code Review and Testing Compliance Scans Vulnerability Scans CVSS: Common Vulnerability Scoring System CVE: Common Vulnerabilities and Exposures CCE: Common Configuration Enumeration CPE: Common Platform Enumeration XCCDF: Extensible Configuration Checklist Description Format OVAL: Open Vulnerability and Assessment Language Vulnerability Scanning Procedures Firewalls and Network Devices Assurance Security Operations Center Incident Response and Recovery Preparation Detection and Analysis Containment, Eradication, and Recovery Post-Incident Activity Threat Hunting Threat Intelligence Security Engineering Asset Management Media Sanitation Configuration and Patch Management Security Architecture Chapter 6: People Security Awareness Security Training Chapter 7: Security Metrics Governance and Oversight Antivirus and Anti-Malware Metrics Clean Pipes Network Security Internet Access: Proxy and Content Filtering Security Awareness and Training Firewall Management Enterprise Mobility Management Incident Management and Response Vulnerability Management Penetration Testing, Code Review, and Security Assessments Change Management Access Control Other Metrics Summary Chapter 8: Case Studies Target Data Breach DynDNS Distributed Denial-of-Service Attack NHS WannaCry Ransomware Chapter 9: Security Testing and Attack Simulation Tools Penetration Testing Tools Information Gathering and Intelligence Sniffers Vulnerability Scanning Web Application Vulnerability Scanning SQL Injection Network Tools Breach and Attack Simulation System Information Tools Password Cracking Session Hijacking Steganography Windows Log Tools Wireless Network Tools Bluetooth Attacks Website Mirroring Intrusion Detection Mobile Devices Social Engineering IoT (Internet of Things) User Awareness: eLearning Forensics and Incident Response HoneyPots Summary Appendix 1: IT Security Technical Controls, Processes, and Services Matrix Appendix 2: Information Security Certifications Appendix 3: Knowledge, Skills and Abilities (KSAs) Appendix 4: Resource Library Index
Similar books
MySQL® Notes for Professionals book
2018 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36
2010 · PDF
THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.
1858 · PDF
Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.
2022 · PDF
The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians
1809 · PDF
Professional Linux kernel architecture ''Wrox programmer to programmer''--Cover. - ''What you are reading right now is the result of an evolution over more than seven years: After two years of writing, the first edition was published in German by Carl Hanser Verlag in 2003. It then described kernel 2.6.0. The test was used as a basis for the low-level design documentation for the EAL4+ security evaluation of Red Hat Enterprise Linux 5, requiring to update it to kernel 2.6.18 (if the EAL acronym does not mean anything to you, then Wikipedia is once more your friend). Hewlett-Packard sponsored the translation into English and has, thankfully, granted the rights to publish the result. Updates to kernel 2.6.24 were then performed specifically for this book''--P. ix
2008 · PDF