Showing posts with label CIS. Show all posts
Showing posts with label CIS. Show all posts

Saturday, March 2, 2024

Notes from the Field - CIS Control 18 - Penetration Testing

While working with clients I will review their latest penetration test report. Penetration tests are a great way to obtain independent and unfiltered information about your organization’s vulnerabilities The tests are usually performed by an outside information security firm, giving you an outsider’s view of what’s going on at your company. That view is valuable as outsiders provide another perspective. 

The first thing I look to see is if it’s a real pen test or a typical vulnerability scan. Unfortunately,

Circles in the Sand at Bandon Beach, Oregon
clients often pay for a pen test and receive a vulnerability scan report that they could have produced themselves without having paid tens of thousands of dollars.

A true pen test report will include the scope of the test. The report lists the tools and procedures performed. The pen testers will attempt manual exploitations of vulnerabilities that were identified by scans. Tests should also include phishing and spear-phishing attempts, other social engineering, and physical penetration attempts. Unlike vulnerability scans, which may only take a few hours, pen tests may take several days or weeks, depending on the size and complexity of the organization.

In this post I discuss Center for Internet Security Control 18 - Penetration Testing. This is the 18th and final post in a series on the Center for Internet Security Controls. The document consists of 18 critical information security controls that all organizations and information security professionals should be familiar with and implement to protect their networks and data. The document contains high level information that executives can understand and also has specific details about tools and procedures for technical staff to run with. I recommend it to all my clients for information security guidance. 

 

The Overview for Control 18 - Penetration Testing is - Test the effectiveness and resiliency of enterprise assets through identifying and exploiting weaknesses in controls (people, processes, and technology), and simulating the objectives and actions of an attacker.


Why is this Control Critical? No company is completely secure, even organizations with mature information security policies, tools, procedures, and well trained staff. Existing technologies continuously change. New technologies are released daily. Systems are very complex. New vulnerabilities are discovered every day. Attackers leverage these factors to bypass your company's security controls and trick your employees into giving up their credentials. 


It is imperative that your organization periodically undergo penetration tests by qualified independent internal or external parties. Pen tests can identify gaps in your company’s security tools, configurations or staff training. Use the identified gaps to make adjustments to your environment and provide the additional training needed to improve your organization’s security posture. 


CIS Control 18 has 5 safeguards in support of incident response. They are: 


18.1 Establish and Maintain a Penetration Testing Program - this one is pretty clear in which your organization creates its pen test program, defining the scope of testing. That can include specific networks, web applications, APIs, hosted services, social engineering, physical security. 


18.2 Perform Periodic External Penetration Tests - perform external pen tests at least annually. I recommend pen tests at least twice a year. People often say their environments are static and pen tests more than once a year are unnecessary. But are the environments truly static? Organizations install security updates monthly and deploy application code updates frequently. They also change configurations, sometimes inadvertently. Pen tests will help identify vulnerabilities not detected by regular vulnerability scans.  


18.3 Remediate Penetration Test Findings - this one is also pretty clear. Remediate the findings by updating vulnerable code, installing security patches, correcting configuration issues, better physical security controls, and providing better training for individuals who fell for social engineering efforts. Prioritize remediation according to the severity of the findings. For small environments, there may be a handful of findings that can be resolved quickly. For large environments with many applications and hundreds or thousands of systems, remediation is more involved and time consuming.  


18.4 Validate Security Measures - this involves tasks such as reviewing security controls and tools, WAF rules, and firewall rules. Determine if rules need to be more rigorous or additional tools added to protect your organization.  


18.5 Perform Periodic Internal Penetration Tests - Similar to the frequency with performing external pen tests, do the same with internal pen tests. Again, you may likely meet your security framework requirements by performing internal pen tests annually. But you want to do them at least twice a year to identify code issues, vulnerabilities, and misconfigurations. 


The CIS Control document states that internal and external pen tests should be performed by a qualified party. What is a qualified party? Do pen tests need to be performed by an external security firm? Pen tests do not need to be done by an external company. But the tests should be performed by an organizationally independent team. 


Larger organizations often have internal security internal departments with pen test teams that are independent of the departments they test. Smaller organizations may need to engage a security firm to perform the testing. In any event, the person or team performing the testing should not be the same individual or team responsible for managing the systems. The pen test reports need to be delivered to the senior manager as well as the team that manages the systems as well as to the team. It’s important for senior management to be aware of the risks to the organization identified in the report and provide appropriate oversight. I’ve seen cases where the pen tests are only delivered to the individuals that manage the systems. Management is not information about the threats the company faces. 


The CIS Controls document lists as a resource the The PCI Security Standards Council. It discusses pen test methodology, scope, reports, case studies, and discusses the qualifications for pen testers in its Penetration Test Guidance publications. The document also lists as an additional resource OSSTMM 3 - the Open Source Security Testing Methodology Manual.


Penetration testing, combined with the other CIS Controls will help your organization better protect your company and customer data.

Sunday, January 14, 2024

Notes from the Field - CIS Control 17 - Incident Response Management

The client I was working with had a SaaS application hosted in AWS. When we discussed how they would respond if their data were compromised, they said that wasn’t a serious concern as the data the company collected was of little value. Nobody would want it. It didn’t have personally identifiable information (PII), such as social security numbers, license numbers or medical information. When I raised the prospect of a ransomware attack and the damage it could do to their operations and reputation, they began to realize the potential consequences of their lack of preparation. Most companies understand that they could be the target of an attack. Some don’t. But all need incident response processes in place for when an incident occurs.

Castillo San Felipe del Morro, San Juan, Puerto Rico

In this post I discuss the Center for Internet Security Control 17 - Incident Response Management. The Center for Internet Security Controls are 18 critical information security controls that all organizations and information security professionals should be familiar with and implement to protect their networks and data. The document contains high level information that executives can understand and also has specific details about tools and procedures for technical staff to run with. I recommend it to all my clients for information security guidance. 

The Overview for Control 17 is - Establish a program to develop and maintain an incident response capability (e.g., policies, plans, procedures, defined roles, training, and communications) to prepare, detect, and quickly respond to an attack.


Why is this Control Critical? Companies often don't have incident response and recovery capabilities even when they have detection and prevention controls in place. If such a company does have a compromise or other incident, they may not have people with the appropriate skills and experience to contain the incident and keep it from spreading. Without a full understanding of such attacks, incident responders will be in a perpetual state of being a step behind attackers. Even with a good plan and people, it's important that that regular training be provided to staff that will respond to incidents. 


Control 17 has 9 safeguards in support of incident response. They are: 


17.1 Designate Personnel to Manage Incident Handling

17.2 Establish and Maintain Contact Information for Reporting Security Incidents

17.3 Establish and Maintain an Enterprise Process for Reporting Incidents

17.4 Establish and Maintain an Incident Response Process
17.5 Assign Key Role and Responsibilities 

17.6 Define Mechanisms for Communicating During Incident Response

17.7 Conduct Routine Incident Response Exercises

17.8 Conduct Post-Incident Reviews

17.9 Establish and Maintain Security Incident Thresholds


Let's take a look at a few of these starting with 17.1 Designate Personnel to Manage Incident Handling. Smaller and mid-size companies I've worked with often don't have a dedicated Security Operations Center (SOC). Incident response falls to the DevOps or IT teams. But the roles are not formally assigned. The individuals who must respond often don't know they are responsible until there is an incident. Their regular duties don't include responding to incidents. When one happens they are unprepared to take appropriate action.  


17.4 Establish and Maintain an Incident Response Process and 17.5 Assign Key Roles and Responsibilities - you can combine these two safeguards and potentially the first five safeguards. This is where you document an incident response policy and process. You identify the specific roles and responsibilities for responding to incidents. Establish processes for how individuals will report incidents and the activities to respond.    


17.7 Conduct Routine Incident Response Exercises is key for all companies, particularly those without a SOC or other personnel who routinely respond to incidents. It's important for teams to engage in monthly or quarterly training to run through attack scenarios and how they would respond. Each team member would become more and more familiar with their role in incident response processes and what action to take. While not a replacement for actual experience, the individuals involved will understand what to do rather than try to figure it out during an actual incident. 


17.8 Conduct Post-Incident Reviews is where teams use lessons learned from an incident to determine how to improve their response procedures in advance of the next incident. What could they have done differently or would the response have been better if the tasks were performed in a different order? Did any steps slow down the response process? What controls can they put in place now to prevent or mitigate this same type of attack from occurring in the future?  What tools do they need to better respond? Agree among the team on next steps going forward, such as updating the incident response checklist or playbook. 


CIS Control 17 is a good way to get started with incident response management. In the next post, I will cover the final control, Center for Internet Security Control 18 - Penetration Testing.  

Friday, December 30, 2022

Notes from the Field - Center for Internet Security Control 11 - Data Recovery

The client I was working with had undergone a management shakeup over the previous year. The CIO left, replaced by someone who brought in several new managers. The result was a lot of IT and DevOps staff turnover. Many skilled staff who knew how everything worked at the company left amid the uncertainty. There were not enough senior people left to train all of the new hires. Without direction, new hires didn't always know what was important. A lot of things fell through the cracks, including data recovery. 

Sun Compass in the Ridge and Valley Sculpture the Arboretum at Penn State
The Compass from the Ridge and Valley Sculpture
at the Arboretum at Penn State
While reviewing the data backups, we determined that not all the data the company needed to backup was actually getting backed up. Nor was the backup data retention as long as required by company policy. They had a cloud environment and an on-premises server room with some legacy apps and data. Different backup tools were used for each.

In the AWS environment, the RDS databases were automatically backed up and retained for 1 to 35 days, depending on the method used to create the RDS database. The company's backup procedures had the RDS snapshots copied to S3 buckets, where they were required to be retained for three months. But the task to copy the backups to the S3 buckets stopped functioning months before. After investigating they determined the task of copying the backups to the buckets was tied to an AWS IAM role that had been modified in error, removing the role's ability to write the data to the bucket. Configuration management issues like this occur, especially in dynamic environments.

For the on-premises environment the company used Veeam to backup systems to on-site storage devices for short-term storage. The backups were copied to AWS S3 buckets for longer retention. Unfortunately, a set of the Veeam backup jobs were unsuccessful each day. Alerts had been emailed to the IT team but they were ignored. The dedicated backup administrator had left amid the company changes. A team with many other pressing responsibilities was assigned to oversee the backups. It wasn't a high priority for them.

These issues were easily correctable with a few hours work but could have been very costly if staff at the company inadvertently deleted data or had been targeted by a ransomware gang. In both cases, the company would not have been able to restore critical business data. We discussed the Center for Internet Security Controls, specifically Control 11 - Data Recovery. We also discussed the basics of data backup and recovery to better protect company and customer data.

The Overview for CIS Control 11 is - Establish and maintain data recovery practices sufficient  to restore in-scope enterprise assets to a pre-incident and trusted state.

Control 11 includes 5 safeguards. They are:

11.1 Establish and Maintain a Data Recovery Process
11.2 Perform Automated Backups
11.3 Protect Recovery Data
11.4 Establish and Maintain an Isolated Instance of Recovery Data
11.5 Test Data Recovery

Why is this control critical? Organizations need and use data to make decisions and provide services to customers. If data is not available or loses its integrity, the organization and its customers could be negatively impacted. The CIS Controls Document refers to an example of an attacker encrypting a company's data for ransom. In such a case, the company would need to have backup data prior to the point when it was encrypted by the attacker. Unfortunately, many organizations find their backup data retention is not long enough to protect them from this attack.  

Other challenges that companies face regarding data recovery is that they have so much data, they may not have an effective method to restore it in a timely fashion. It might take them weeks to restore the data, which could result in lost business.

In my own work, it's common for companies to have lax practices around their data backup and recovery testing. 
The CIS Controls document recommends that on a quarterly basis or when new data sources or technologies are introduced, companies evaluate their backups and attempt to restore data in a test environment. It's necessary to verify that data can successfully be restored in a reasonable time period in case of a serious incident and that the systems and applications can be restored.

The news is replete with stories of ransomware gangs compromising companies and holding their data hostage. You can better protect your company from becoming the next target by implementing the CIS Critical Controls. Review your data backup strategy regularly to determine it is current. Test your data recovery practices to verify you can restore data in case of accidental deletion or a ransomware attack. 

Next month I'll discuss Center for Internet Security Control 12 - Network Infrastructure Management. 

Monday, November 28, 2022

Notes from the Field - Center for Internet Security Control 10 - Malware Defenses

The client I was working with had a web application hosted on a Windows server with the anti-virus software disabled. When I asked the head of Information Technology about it, he said the company's web application didn't work when anti-virus was running, so they couldn't enable it. They weren't concerned about it as they had a firewall in place with malware protection. I strongly advised them to reconsider that decision. Instead of disabling anti-virus, I recommended they determine why the web application did not work and correct it. They were the only client I had worked with that did not have anti-virus enabled on a Windows web application server. The risk of a Windows server being infected by a virus is high, especially one with a public facing IP address. Additionally, the server did not have recent security patches installed. It was only a matter of time before attackers compromised their web server. 

It's commonly accepted that Windows systems must have anti-malware software installed to protect them while Linux and macOS don't need it. That view has been changing the last several years. Linux and macOS are targeted more and more by ransomware and cryptojacking malware. In this post I discuss what I see in my work as an information security auditor in my work clients regarding Center for Internet Security Control 10 - Malware Defenses.

Back of Old Botany Building along Pattee Mall at Penn State in Autumn
The Center for Internet Security Controls are 18 critical information security controls that all
organizations and information security professionals should be familiar with and implement to protect their networks and data. The free but valuable document contains high level information that executives can understand and also has specific details about tools and procedures for technical staff to run with. I recommend it to all of my clients for information security guidance. 

The Overview for Control 10 is - Prevent or control the installation, spread, and execution of malicious applications, code, or scripts on enterprise assets

Control 10 includes 7 sub-controls or safeguards. They are:

10.1 Deploy and Maintain Anti-Malware Software
10.2 Configure Automatic Anti-Malware Signature Updates
10.3 Disable Autorun and Autoplay for Removable Media
10.4 Configure Automatic Anti-Malware Scanning of Removable Media
10.5 Enable Anti-Exploitation Features
10.6 Centrally Manage Anti-Malware Software
10.7 Use Behavior-Based Anti-Malware Software

Why is this control critical? Malicious software is one of the biggest threats to your company and customer data. Malware can be used to capture user credentials to further exploit your network. Malware can be used by attackers to encrypt and delete your data, preventing you from accessing it unless you pay a ransom for it. Attackers leverage machine learning tools to make more sophisticated and effective malware. Malware enters company networks through vulnerabilities, phishing, and many other avenues. It's necessary to have comprehensive malware defenses to protect your systems and data. 

Larger clients I work with generally have good practices in place for preventing malware. They have anti-malware or endpoint detection and response (EDR) tools installed on all of their servers, workstations, and laptops. They manage the tools centrally with a team that checks the status of systems. The team follows up on systems that are not reporting their status to the console, not receiving updates or have been infected by malware. 

Some of the most widely used anti-malware/EDR tools by larger clients are from Trend Micro, SentinelOne, CrowdStrike, Symantec, and McAfee. Additionally, network firewalls include filtering of malware traffic prior to reaching endpoints.  

Smaller to mid-size clients often don't have much in place to protect systems from malware. They lack the budget or staff resources to manage a centralized anti-malware tool. They rely on the default tools that are installed with the operating systems, such as Windows Defender for Microsoft Windows server and end user systems and XProtect for Apple macOS. Are Defender and XProtect enough? Maybe. But is maybe good enough to protect your company and customer data? 

You want assurance that if new malware is spreading across the internet, your systems are fully protected. You also want to know if your systems are affected. Without a central management console for your anti-malware tool, it's difficult to know for sure what is going on in your company's network. Was one system affected or hundreds? It's important to know so you can take immediate action, such as isolate systems, block ports on your network or push out a new security patch. 

For Linux servers, most small to mid-sized companies and even some larger companies I work with generally do not deploy anti-malware software. When they do, it's often ClamAV. That's sufficient to protect systems but it does not have centralized management features. Logging and alerting for ClamAV can be leveraged using a SIEM tool if one is in place to get a full picture of the status of systems. Sometimes companies deploy OSSEC, a host intrusion detection tool, to their Linux systems instead of or in addition to deploying ClamAV. OSSEC is not a dedicated anti-malware tool but does include root-kit and malware detection. 

OSSEC and popular anti-virus/EDR tools have intrusion detection and file integrity monitoring features to identify changed files. This helps track activity and potential damage or deletion of files. Some of the tools can also stop processes completely based on behavior to better protect your systems and data. 

Anti-malware defenses combined with the other CIS Controls can help protect your network, systems, and data. Read the CIS Controls document today. 

Next month, I will discuss Center for Internet Security Control 11 - Data Recovery.    


Sunday, October 2, 2022

Notes from the Field - Center for Internet Security Control 09 - Email and Web Browser Protections

A small SaaS (Software as a Service) client I worked with recently mentioned an information security incident they experienced a year ago in which the email account of one of their sales representatives was compromised via a phishing attack. The attackers gained the credentials of the sales rep, obtained email addresses of customers, and sent emails to the company's customers with false offers to buy discounted services. The attackers had scraped the company's website and set up an identical site with a similar URL, which tricked customers into believing the website was legitimate. Some customers visited the site and entered their credit card numbers to purchase what they thought were legitimate services. The compromise occurred on a Friday morning. It wasn't until Monday afternoon that the sales rep began to hear from customers that something was very wrong. Their credit cards were used for many bogus purchases on multiple websites after using their credit cards on what they thought was the company website.  

Sun Mosaic at Bandon, Oregon
The IT department was able to block the attackers access to the email account of the sales rep. But that was just the beginning. Did the attackers gain access to other accounts and elevate their credentials? Did the attackers now have customer credentials? If so, how many and which ones? As the IT team began to isolate the incident, the senior executive team, including legal counsel and communications, was brought in to determine how to notify customers and what to tell them.

The company's reputation was damaged. It lost customers and revenue. Since the incident, the company requires multi-factor authentication for remote access and all email and cloud services. The company also implemented annual information security awareness training for all staff. I suggested additional technical controls the company can put in place to better protect the company and its customers from similar attacks in the future.
 
In this post I discuss the Center for Internet Security Control 09 - Email and Web Browser Protections. The Center for Internet Security Controls are 18 critical information security controls that all organizations and information security professionals should be familiar with and implement to protect their networks and data. The document contains high level information that executives can understand and also has specific details about tools and procedures for technical staff to run with. I recommend it to all my clients for information security guidance. 

The Overview for Control 09 - Email and Web Browser Protections is - Improve protections and detections of threats from email and web vectors, as these are opportunities for attackers to manipulate human behavior through direct engagement.

Why is this control critical? Attackers continue to successfully target email and web browsers as most people in organizations use the two tools for much of their day-to-day work. Email and web browsers expose employees to untrusted environments, where attackers can use social engineering and malicious code to trick individuals into giving up their company logon credentials and data. Once attackers gain a foothold with user credentials, they can expand to other targets.

Control 09 includes 7 sub-controls or safeguards. They are:
9.1 Ensure Use of Only Fully Supported Browsers and Email Clients
9.2 Use DNS Filtering Services
9.3 Maintain and Enforce Network-Based URL Filters
9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions
9.5 Implement Domain-based Message Authentication, Reporting, and Conformance (DMARC)
9.6 Block Unnecessary File Types
9.7 Deploy and Maintain Email Server Anti-Malware Protections
 
The above sub-controls will go a long way to protect your network and users from email and browser related attacks. I'm going to address a few of the controls that would have protected against the phishing attack on the SaaS company. 

Using DNS filtering services, control 9.2, protects your network by blocking DNS queries for malicious websites. For example, if an employee opens a phishing email and clicks on a link for a known malicious site, the DNS filtering does not allow the employee's browser to go to the site as the site's domain is listed on a block list. 

Control 9.3 is similar in that URL filtering is done of websites that contain content that is not approved by a company. Filtering databases are used to classify URLs by content. URLs with appropriate content are approved for access. URLs for inappropriate content are blocked. Those URLs marked as phishing are blocked by an employer. The employee's browser will be redirected to a page notifying the individual that the URL is blocked.    

Implementing DMARC, control 9.5, would have also helped the SaaS company from being compromised. DMARC and related tools can be used and combined for verifying the authenticity of emails. The tools include Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM). 

SPF identifies emails that are from trusted sources and those that are from untrusted sources. SPF allows your email administrator to apply rules to untrusted emails, such as block them or mark them as spam. This reduces the likelihood of successful phishing attempts via a company's email system. 

DKIM helps identify spammers and attackers from spoofing legitimate domains. It's easy for anyone to change the from field of their emails to make them appear as if they are coming from a different domain. Attackers use this to send phishing attack emails. The email recipient believes the email is from an individual at a company they do business with when, in fact, the email is a phishing attempt. DKIM verifies the identity of the email server sending the email by using digital signatures or the email servers. 

CIS Control 9 and its sub-controls will help protect your company from email and web browser attacks. Implement them to reduce the likelihood of incidents at your organization. 

Next month I will discuss Center for Internet Security Control 10 - Malware Defenses.  
 

Sunday, February 27, 2022

Notes from the Field - CIS Control 04 - Secure Configuration of Enterprise Assets and Software

This is the fourth in a series of posts I'm writing on the Center for Internet Security (CIS) Controls Version 8. The CIS Controls are 18 information security controls that all organizations and information security professionals should be familiar with and implement to protect their networks and data from attackers. In this post I discuss what I see in my work as an information security auditor with clients regarding Control 04 - Secure Configuration of Enterprise Assets and Software. 

The CIS overview for Secure Configuration of Enterprise Assets and Software isEstablish and maintain the secure configuration of enterprise assets (end-user devices, including portable and mobile; network devices; non-computing/IoT devices; and servers) and software (operating systems and applications).


Why is this a critical control? The CIS Controls document states this control is critical as systems and software are designed for ease of use and deployment, not for security. Default system and software configurations are generally insecure. Attackers can exploit systems and software that have default user accounts and passwords, default protocols, other insecure settings. The security settings and configurations need to be maintained over the life of the system or software. Changes to configurations need to be tracked for compliance purposes. The document includes consideration of services providers as they may implement looser controls to support their many customers. 

The CIS Controls document lists security configuration checklists that systems administrators and security professionals can use to secure their systems, such as the NIST National Checklist Program and the CIS Benchmarks Program. It then lists 11 steps for developing secure baselines. The document lists a number of safeguards or sub-controls in support of this control. They include:
  • Establish and Maintain a Secure Configuration Process
  • Configure Automatic Session Locking on Enterprise Assets
  • Implement and Manage a Firewall on Servers
  • Manage Default Accounts on Enterprise Assets and Software 
  • Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • Configure Trusted DNS Servers on Enterprise Assets
  • Enforce Automatic Device Lockout on Portable End-User Devices
Penn State Law Building Framed By the Arch at the Arboretum
Penn State Law Building, Framed by the Arch at the Arboretum
In my work as an information security auditor, I see some clients doing very good work in this area. They have detailed security configurations for their operating systems, software, and network devices. Others are not as diligent. On a recent gap analysis engagement with a client that provides a web application explained how they secure their servers. They install the latest security patches, install anti-virus software, and change the administrator password. They also enable the firewall on their servers. I asked if they do anything beyond that. Unfortunately, they do not.
 
Let's face it, that does not qualify as actually securing a system. I asked the company's information security manager if he would feel confident using a vendor which had such minimal controls in place. He grimaced for a few seconds and finally said no. He expects much more. Just as his company's customers expect more from him and the information security team to secure their data. 

I discussed how other companies have much more rigorous controls. They may have a checklist of 20 or 30 security settings they change. Still others implement hundreds of individual security settings from Security Technical Implementation Guides (STIGs) or the CIS Benchmarks for operating systems, software, and network devices. Normally implementing this number of controls is done via scripts or Group Policy. There are also tools that can verify systems always maintain the desired configuration. For Linux systems, clients often use Chef or Puppet. In AWS they may use Terraform to deploy and maintain secure configurations. In support of securing their systems, organizations run vulnerability scans to further identify weaknesses and take appropriate action.  

With a background in a Department of Defense environment, I have spent a lot of time implementing controls from STIGs and the CIS Benchmarks for Windows, Linux, and VMware. I highly recommend the CIS Benchmarks to clients to review and implement. The CIS produces the benchmarks for many operating systems, network devices, software, and the cloud environments. 
 
The PDF document that lists the controls for Windows 2019 Server, for example, is over 900 pages long. It gets into every detail of securing a Windows Server. The benchmark for Amazon Linux 2 is almost 400 pages long. The benchmarks can help guide the way to securing systems for information technology professionals that don't know where to begin regarding properly secure their organization's systems. Securely configuring enterprise assets and software also demonstrates a level of due diligence in support of protecting your company's and customers data and systems. 


Next month, I'll discuss the Center for Internet Security Control 5 - Account Management. 

Sunday, October 25, 2020

The Center for Internet Security Controls

Where can individuals and companies go to get a list of specific information security that they should implement? 

Official frameworks for NIST, SOC 2, and others can be hundreds of pages long. They may leave the reader overwhelmed, wondering how to even get started. I recommend my clients read the Center for Internet Security (CIS) Controls to learn about about specific controls and also to understand the big picture in terms of information security.  

The CIS Controls V 7.1 is a free 78 page document that outlines 20 controls that "collectively form a defense-in-depth set of best practices that mitigate the most common attacks against systems and networks." The Center for Information Security is a non-profit dedicated to making "the connected world a safer place..." The controls are developed by experienced information technology professionals from a variety of industry backgrounds.  

Bridge over the Allegheny River in Pittsburgh

The CIS Controls document includes images and charts that help explain information security at a high level for executive-level readers in terms they can understand. It also contains specific steps so that the readers with technical skills and responsibilities have enough information to move forward. 

The clients I work with are often new to compliance frameworks or are smaller organizations. They don't always understand the need to implement some security controls to meet requirements. They may only have a handful of developers and a systems administrator whose experience may be limited to the most basic of security controls. They know they don't want their applications and servers to get hacked. But they don't know what to do beyond having proper firewall rules, patched systems, and strong passwords to protect their environment.  

Some clients undergo annual pen tests of their web applications. The rest of the time they are focused on continuously updating code and running their business. They don't know why it's necessary to have an up to date inventory of systems or why they need file integrity monitoring. 

The flip side of that are larger companies that have big IT and information security departments with dedicated teams that work in silos. While the individual team members are very experienced and skilled in specific control areas, they may not be knowledgeable or even aware of control topics outside of their specialization. The CIS document brings it all together.    

The CIS Controls provides the 20 controls in order so that management, information technology, and information security staff can see a clear roadmap. The document organizes the controls into three areas – Basic, Foundational, Organizational. Inventory of assets and software fall under Basic. Boundary Defense and Data Protection fall under the Foundational controls category. Incident Response and Management are an Organizational control. Let's take a look at the entire list. 

Basic Controls                                                                                         

1. Inventory and Control of Hardware Assets

2. Inventory and Control of Software Assets

3. Continuous Vulnerability Management

4. Controlled Use of Administrative Privileges

5. Secure Configuration for Hardware and Software on Mobile Devices, Laptops, Workstations and Servers

6. Maintenance, Monitoring and Analysis of Audit Logs

Foundational Controls

7. Email and Web Browser Protections

8. Malware Defenses

9. Limitation and Control of Network Ports, Protocols and Services
   
10. Data Recovery Capabilities

11. Secure Configuration for Network Devices, such as Firewalls, Routers and Switches

12. Boundary Defense

13. Data Protection

14. Controlled Access Based on the Need to Know

15. Wireless Access Control

16. Account Monitoring and Control 

Organizational Controls

17. Implement a Security Awareness and Training Program

18. Application Software Security

19. Incident Response and Management

20. Penetration Tests and Red Team Exercises

Each control is listed with a short explanation and why it is critical. It also explains how hackers can take advantage when the control is not in place. Each control includes a chart with sub-controls. A Procedures and Tools section for each control provides additional recommendations as to which security tools would be useful, such as Intrusion Detection Systems/Intrusion Prevention Systems for Control 12 - Boundary Defense.

The CIS Controls document states that while these are the 20 controls all organizations should implement, they are not a one-size-fits-all-solution. You must understand them in context to what is critical to your business and take into account how the controls may impact your operations. 

The controls includes Implementation Groups with sub-controls that apply to organizations based on their size. Implementation Group 1 is for small business. They would implement sub-controls based on the data they are protecting and their staffing resources. 

Implementation Group 2 is for medium-sized organization that have dedicated IT departments and more resources. They would implement more sub-controls than small business. 

Implementation Group 3 is for larger companies with large IT departments, expertise in information security, and manage more sensitive data. They would implement all of the sub-controls for each major control. For example, for Control 4 - Controlled Use of Administrative Privileges, a small company would implement only 2 of the 9 sub-controls. A large company would implement all 9 sub-controls.

Whether your are an individual just getting started in information security or a seasoned professional, the CIS Controls document is a great resource. I frequently reference and share it. It distills principles and practices from cybersecurity books and frameworks into 20 succinct and easy to understand controls. You can obtain the CIS Controls at: