Advanced Security: Difference between revisions
From GCA ACT
Jump to navigationJump to search
No edit summary |
No edit summary |
||
Line 2: | Line 2: | ||
|- | |- | ||
| rowspan="3" style="border: none; background-color: transparent; text-align: center; vertical-align: middle; width: 20%;" | [[File:Elephants.png|frameless|225px|center|link=Advanced_Protection]] | | rowspan="3" style="border: none; background-color: transparent; text-align: center; vertical-align: middle; width: 20%;" | [[File:Elephants.png|frameless|225px|center|link=Advanced_Protection]] | ||
| style="border: none; background-color: #EBEBEB; vertical-align: top; text-align: center; width: 20%;" | | | style="border: none; background-color: #EBEBEB; vertical-align: top; text-align: center; width: 20%; text-weight: bold;" | | ||
Network Segmentation | |||
<br><br> | <br><br> | ||
[[File:network-segmentation.png|frameless|40px|center]] | [[File:network-segmentation.png|frameless|40px|center]] | ||
<br> | <br> | ||
<div style="text-align: left; text-size: 75%;">Divide networks into smaller, isolated segments to limit the impact of a potential breach.</div> | <div style="text-align: left; text-size: 75%;">Divide networks into smaller, isolated segments to limit the impact of a potential breach.</div> | ||
| style="border: none; background-color: transparent; vertical-align: top; text-align: center; width: 20%;" | | | style="border: none; background-color: transparent; vertical-align: top; text-align: center; width: 20%; text-weight: bold;" | | ||
Intrusion Detection & Prevention Systems | |||
<br> | <br> | ||
[[File:intrusion-protection.png|frameless|40px|center]] | [[File:intrusion-protection.png|frameless|40px|center]] | ||
<br> | <br> | ||
<div style="text-align: left; text-size: 75%;">Deploy advanced systems to detect and prevent network intrusions.</div> | <div style="text-align: left; text-size: 75%;">Deploy advanced systems to detect and prevent network intrusions.</div> | ||
| style="border: none; background-color: #EBEBEB; vertical-align: top; text-align: center; width: 20%;" | | | style="border: none; background-color: #EBEBEB; vertical-align: top; text-align: center; width: 20%; text-weight: bold;" | | ||
Endpoint Protection | |||
<br> | <br> | ||
<br> | <br> | ||
Line 21: | Line 21: | ||
<br> | <br> | ||
<div style="text-align: left; text-size: 75%;">Implement robust antivirus and endpoint security solutions to safeguard individual devices.</div> | <div style="text-align: left; text-size: 75%;">Implement robust antivirus and endpoint security solutions to safeguard individual devices.</div> | ||
| style="border: none; background-color: transparent; vertical-align: top; text-align: center; width: 20%;" | | | style="border: none; background-color: transparent; vertical-align: top; text-align: center; width: 20%; text-weight: bold;" | | ||
Security Information & Event Management | |||
<br> | <br> | ||
[[File:security-information-event-management.png|frameless|40px|center]] | [[File:security-information-event-management.png|frameless|40px|center]] | ||
Line 28: | Line 28: | ||
<div style="text-align: left; text-size: 75%;">Utilize SIEM tools to monitor and analyze security events across the network.</div> | <div style="text-align: left; text-size: 75%;">Utilize SIEM tools to monitor and analyze security events across the network.</div> | ||
|- | |- | ||
| style="border: none; background-color: transparent; vertical-align: top; text-align: center; width: 20%;" | | | style="border: none; background-color: transparent; vertical-align: top; text-align: center; width: 20%; text-weight: bold;" | | ||
Vulnerability Management | |||
<br> | <br> | ||
<br> | <br> | ||
Line 35: | Line 35: | ||
<br> | <br> | ||
<div style="text-align: left; text-size: 75%;">Conduct regular assessments to identify and address system vulnerabilities.</div> | <div style="text-align: left; text-size: 75%;">Conduct regular assessments to identify and address system vulnerabilities.</div> | ||
| style="border: none; background-color: #EBEBEB; vertical-align: top; text-align: center; width: 20%;" | | | style="border: none; background-color: #EBEBEB; vertical-align: top; text-align: center; width: 20%; text-weight: bold;" | | ||
Penetration Testing | |||
<br> | <br> | ||
<br> | <br> | ||
Line 42: | Line 42: | ||
<br> | <br> | ||
<div style="text-align: left; text-size: smaller;">Simulate real-world attacks to evaluate the security of a system or network.</div> | <div style="text-align: left; text-size: smaller;">Simulate real-world attacks to evaluate the security of a system or network.</div> | ||
| style="border: none; background-color: transparent; vertical-align: top; text-align: center; width: 20%;" | | | style="border: none; background-color: transparent; vertical-align: top; text-align: center; width: 20%; text-weight: bold;" | | ||
Incident Response Planning | |||
<br> | <br> | ||
[[File:incident-response.png|frameless|40px|center]] | [[File:incident-response.png|frameless|40px|center]] | ||
<br> | <br> | ||
<div style="text-align: left; text-size: 75%;">Develop and test an incident response plan to efficiently handle cybersecurity incidents.</div> | <div style="text-align: left; text-size: 75%;">Develop and test an incident response plan to efficiently handle cybersecurity incidents.</div> | ||
| style="border: none; background-color: #EBEBEB; vertical-align: top; text-align: center; width: 20%;" | | | style="border: none; background-color: #EBEBEB; vertical-align: top; text-align: center; width: 20%; text-weight: bold;" | | ||
Secure Configuration Management | |||
<br> | <br> | ||
[[File:configuration-management.png|frameless|40px|center]] | [[File:configuration-management.png|frameless|40px|center]] | ||
Line 55: | Line 55: | ||
<div style="text-align: left; text-size: 75%;">Establish and maintain secure configuration settings for all systems and devices.</div> | <div style="text-align: left; text-size: 75%;">Establish and maintain secure configuration settings for all systems and devices.</div> | ||
|- | |- | ||
| style="border: none; background-color: #EBEBEB; vertical-align: top; text-align: center; width: 20%;" | | | style="border: none; background-color: #EBEBEB; vertical-align: top; text-align: center; width: 20%; text-weight: bold;" | | ||
Change Management | |||
<br> | <br> | ||
<br> | <br> | ||
Line 62: | Line 62: | ||
<br> | <br> | ||
<div style="text-align: left; text-size: 75%;">Implement structured processes to manage changes in a controlled and efficient manner.</div> | <div style="text-align: left; text-size: 75%;">Implement structured processes to manage changes in a controlled and efficient manner.</div> | ||
| style="border: none; background-color: transparent; vertical-align: top; text-align: center; width: 20%;" | | | style="border: none; background-color: transparent; vertical-align: top; text-align: center; width: 20%; text-weight: bold;" | | ||
Identity & Access Management | |||
<br> | <br> | ||
<br> | <br> | ||
Line 69: | Line 69: | ||
<br> | <br> | ||
<div style="text-align: left; text-size: 75%;">Implement proper user access controls, management processes, and regularly review user privileges.</div> | <div style="text-align: left; text-size: 75%;">Implement proper user access controls, management processes, and regularly review user privileges.</div> | ||
| style="border: none; background-color: #EBEBEB; vertical-align: top; text-align: center; width: 20%;" | | | style="border: none; background-color: #EBEBEB; vertical-align: top; text-align: center; width: 20%; text-weight: bold;" | | ||
Patch Management | |||
<br> | <br> | ||
<br> | <br> | ||
Line 76: | Line 76: | ||
<br> | <br> | ||
<div style="text-align: left; text-size: 75%;">Establish processes to apply patches and updates to systems and applications in a timely manner.</div> | <div style="text-align: left; text-size: 75%;">Establish processes to apply patches and updates to systems and applications in a timely manner.</div> | ||
| style="border: none; background-color: transparent; vertical-align: top; text-align: center; width: 20%;" | | | style="border: none; background-color: transparent; vertical-align: top; text-align: center; width: 20%; text-weight: bold;" | | ||
Security Awareness Training & Testing | |||
<br> | <br> | ||
[[File:security-awareness.png|frameless|40px|center]] | [[File:security-awareness.png|frameless|40px|center]] |
Revision as of 00:38, 7 August 2023
Network Segmentation
Divide networks into smaller, isolated segments to limit the impact of a potential breach.
|
Intrusion Detection & Prevention Systems
Deploy advanced systems to detect and prevent network intrusions.
|
Endpoint Protection
Implement robust antivirus and endpoint security solutions to safeguard individual devices.
|
Security Information & Event Management
Utilize SIEM tools to monitor and analyze security events across the network.
| |
Vulnerability Management
Conduct regular assessments to identify and address system vulnerabilities.
|
Penetration Testing
Simulate real-world attacks to evaluate the security of a system or network.
|
Incident Response Planning
Develop and test an incident response plan to efficiently handle cybersecurity incidents.
|
Secure Configuration Management
Establish and maintain secure configuration settings for all systems and devices.
| |
Change Management
Implement structured processes to manage changes in a controlled and efficient manner.
|
Identity & Access Management
Implement proper user access controls, management processes, and regularly review user privileges.
|
Patch Management
Establish processes to apply patches and updates to systems and applications in a timely manner.
|
Security Awareness Training & Testing
Provide regular training and education on cybersecurity best practices to all personnel; and periodically test that knowledge.
|