-
Notifications
You must be signed in to change notification settings - Fork 24
Mastering Control Objectives and Cybersecurity Essentials
Mahesh Shukla edited this page May 31, 2024
·
2 revisions
- Antivirus (AV) Software
- Host Firewall
- Restricted Email Attachments
- URL Filtering
- Sandboxing
- Defense-in-Depth (Layered Security)
- Definition: Defense-in-depth involves designing and implementing multiple overlapping layers of diverse controls to protect information systems.
-
Controls should maintain independence and not be subject to a cascade effect.
-
Consider diversity in control types and associated vendors.
-
Security Control Baselines
-
Definition: Security control baselines establish minimum standards for a given environment, providing a starting point for security implementation.
-
Align control baselines strategically with organizational needs.
-
Baselines should be proportional to asset criticality and sensitivity.
-
Fine-Tuning Controls
-
Definition: Fine-tuning controls involves optimizing security measures to ensure they provide the desired level of protection without unnecessary overhead or false positives.