Showing posts with label SETA. Show all posts
Showing posts with label SETA. Show all posts

Monday, February 8, 2021

Third-party Governance for DevSecOps

For orgs that rely heavily upon outsourced development/technical resources (IT Outsourcing: ITO), it's important to ensure that contracts include covenants for the vendor to provide cyber (security) education, training & awareness (SETA).

Furthermore, a right to audit clause should be included as well that allows for the client to review SETA content, as well as attendance & scoring.    

Wednesday, July 19, 2017

Test Your "Active Shooter" Response

Outside of your physical security response, BCP / DRP planning should also be involved.

Don't forget about training / SETA resources too.

Monday, May 15, 2017

Ransomware & Incident Response: Thoughts from WannaCry, WannaCry2, & WannaCrypt0r

Lots of content has been created for detecting & dealing with ransomware; however, these past few days have seen a flurry of different attacks & thus require some specific after-action reports (AAR).

So, here are some observations / thoughts / notes:


  • Many orgs do not have the budget to ward off ransomware, including: 
    • Advanced threat protection (ATP) via: EDR, UBA / UEBA, UTM / NGFW / NGIPS / NGIDS
    • Virtualization to segment legacy tech: SDN, SDS, hyperconvergence
    • SIEM & TI
  • SETA & CSIRT awareness notifications were slow & ineffective
  • Close the patching gap....no more excuses
  • We'll see this level of pandemic / infestation again...this is just a start.
So, folks will see this level of attack again & its up to them to be proactive & respond accordingly.

Monday, October 10, 2016

Data Breach Fatigue & Security Training

Apparently, there is "data breach fatigue" out there and recommendations on cutting down security education, training, & awareness (SETA) is gaining traction.

The question comes with to scale back SETA activities due to this fatigue?

The answer is based on the maturity of the information security (InfoSec) program, jurisdiction / market, industry, and the organization's culture.  Frankly, a CISO / CIO / CTO should negotiate freedoms (e.g., local administrative access, open Internet / Web / email access) pursuant to SETA.  Meaning, that if users have carte blanche then SETA is required, necessary, and regularly conducted.

Also, less SETA should equate to more budget for preventive / detective capabilities.   

Wednesday, September 14, 2016

Incident Response vs Digital Forensics

When an incident / event has happened that may turn into a full-scale breach it is best to ascertain (via a defined process / guide like 800-61) whether or not to engage in digital forensics or not.

However, beyond firing up forensic kits / tools like Sleuth / Autopsy, forensic activities may have adverse consequences as operations may be affected.

Many orgs want to be safe vs sorry, so they engage in forensics to check if there was a breach, though this may be not needed and may even be construed as impetuous.

Predicated on a quick notification on the event due to proper security education, awareness, and training (SETA); initial, cursory actions may be all that is needed.  At least, initially.