25
SHOW & TELL: METHODS AND METRICS TO IMPROVE YOUR INFORMATION SECURITY PROGRAM

Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

Embed Size (px)

Citation preview

Page 1: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

SHOW & TELL: METHODS AND METRICS TO

IMPROVE YOUR INFORMATION SECURITY PROGRAM

Page 2: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

LEARNING OBJECTIVES

1. Teams in Place 2. Tools Used By Firms To Enforce and Monitor

Data Security3. Checklists 4. Metrics5. Methods To Track Emerging Threats6. Methods To Tracking Client and Compliance

Requirements

Page 3: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

TEAMS IN PLACE

• InfoSec• Network Engineering• Server/Storage/AD/Messaging• Desktop• Development• HelpDesk• DDM• Leadership

Page 4: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

TOOLS IN PLACEEndPoint Network SIEM Monitoring Vulnerability

ScannerOther

SymantecCarbon BlackCylanceTrendSophosDLP

Whitelisting

MobileIronAirWatchBlackberry

CheckpointCisco ASAPalo AltoFortinetTrend IPSWebsenseDLP

Log RhythmQradarAlien VaultSplunk

SolarWinds(Orion)LanSweeper

NessusDDI FrontlineNmap

FireEye ATPFireEye SMTPDarktraceOffice365 ATPSCCMMSSP (Third Party)

PhishMeKnowb4Wombat

VaronisCyberArkAvecto DefendPoint

ProofpointMessageLabs

Page 5: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

FIREEYE ATP

• Inline to internet gateway• Receive Alerts in email• Known/Unknown threats blocked or

sandboxed

Page 6: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

AIRWATCH - MDM

Page 7: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

PROCESS: DAILY, WEEKLY, MONTHLY

1. Create Technical reference/documentation2. Develop SOC Runbook/Operational processes3. Create check-out processes (daily, weekly, monthly, etc.)4. Create HW/Network monitoring and capacity management

system and process5. Create Incident Management System6. Monitor these 24/7

Page 8: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

MORE ON PROCESS….• Daily cyber hygiene report

– List all Administrator group changes (add/remove) over previous 24 hours– List all accounts deactivated over previous 24 hours– List all accounts unused for 30 or more days

• Weekly patch velocity report– Percentage of critical patches successfully deployed– Percentage of important patches successfully deployed– Percentage of moderate patches successfully deployed– Percentage of low patches successfully deployed

• Monthly cyber hygiene report– Percentage of your staff who have completed cybersecurity training– Percentage of staff actively using a password manager– Percentage of your computers using ad blockers in their web browsers– Percentage of new customer contractual requirements that have been successfully incorporated

into your SOPs• Annual cyber hygiene report

– Risk assessment completed?– Percentage of policies reviewed?

Page 9: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and
Page 10: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and
Page 11: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

SOPHOS ANTI-VIRUS

• Check alert status and config issues• Daily and weekly reports

Page 12: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

METRICS AND REPORTINGType Description

Management Reports Monthly InfoSec report with statistics

Dashboards Phishing, ATP, Vulnerability Scanners, etc.

Incident Management System Internal and external incidents

ISO27001 Reports Compliance

Page 13: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

METRICS: MANAGEMENT REPORTSystem / Software Category 2017-Jan 2017-Feb Mar-17 17-Apr

FW Firewall - Blocked 87,177,436 70,789,864 124,708,413 105,237,826

ATP Threats - Blocked 6 23 79 12

SMTP/ATP Malware - Blocked 31 102 86 58

HelpDesk Security Incident 196 136 139 197

Incident Management System Total Incidents 167 105 104 120

SPAM/Cloud Spam / Malware detected 193,000 181,276 204,523 185,342

MSSP Incidents 68 80 79 84

Trad AV Malware - Blocked 13 35 97 18

IPS IPS - Blocked 82,934 307,975 225,414 91,813

Exch AV Malware / Spam / URLs detected 168 62 290 197

WAP DLP - Blocked 0 0 0 0

WAP Web - Blocked 36,775 53,629 82,801 48,442

Total Detected / Blocked 87,490,794 71,333,287 125,222,025 105,564,109

Page 14: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

DDI FRONTLINE VULN SCANNER

• Internal/External Scans• Run reports• Periodic scanner updates (3 in May)

Page 15: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

VULNERABILITY MANAGEMENT REPORT

Page 16: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

PHISHME CAMPAIGN (1 OF 3)

Page 17: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

PHISHME CAMPAIGN (2 OF 3)

Page 18: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

PHISHME CAMPAIGN (3 OF 3)

Page 19: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

PHISHING SIMULATION REPORT

Page 20: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

Risk

Cost

Too muchJust right!

Not enough

HOW TO MEASURE SECURITY?

Page 21: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and
Page 22: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

TRACKING EMERGING THREATS

• CarbonBlack Threat Feeds• Infragard (Not usually very timely)• MSSP Feeds• LS-ISAO• Twitter and other real time “news” feeds

• @TheHackerNews, @taviso, @HackingDave, @demonslay335, @e_kaspersky, @briankrebs, @SwiftOnSecurity

Page 23: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and
Page 24: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

TRACKING CLIENT REQUIREMENTS

• Intranet for organization of client assessments• Spreadsheets for tracking common Q&A• ISO 27001 compliance requirements

Page 25: Show & Tell: Methods and Metrics to Improve Your ... Show and... · METHODS AND METRICS TO IMPROVE YOUR INFORMATION ... Create Technical reference/documentation 2. ... Methods and

QUESTIONS

• ????