
Cyber Intelligence-Driven Risk
Description
Alles über E-Books | Antworten auf Fragen rund um E-Books, Kopierschutz und Dateiformate finden Sie in unserem Info- & Hilfebereich.
Cyber Intelligence-Driven Risk provides a solution to one of the most pressing issues that executives and risk managers face: How can we weave information security into our business decisions to minimize overall business risk?
In today's complex digital landscape, business decisions and cyber event responses have implications for information security that high-level actors may be unable to foresee. What we need is a cybersecurity command center capable of delivering, not just data, but concise, meaningful interpretations that allow us to make informed decisions.
Building, buying, or outsourcing a CI-DR(TM) program is the answer. In his work with executives at leading financial organizations and with the U.S. military, author Richard O. Moore III has tested and proven this next-level approach to Intelligence and Risk. This book is a guide to:
* Building, buying, or outsourcing a cyber intelligence-driven risk program
* Understanding the functional capabilities needed to sustain the program
* Using cyber intelligence to support Enterprise Risk Management
* Reducing loss from cyber events by building new organizational capacities
* Supporting mergers and acquisitions with predictive analytics
Each function of a well-designed cyber intelligence-driven risk program can support informed business decisions in the era of increased complexity and emergent cyber threats.
More details
Other editions
Additional editions

Person
Content
Acknowledgments xi
Introduction xv
Chapter 1: Objectives of a Cyber Intelligence-Driven Risk Program 1
Notes 5
Chapter 2: Importance of Cyber Intelligence for Businesses 7
Notes 14
Chapter 3: Military to Commercial Viability of the CI-DR¯(TM) Program 15
Notes 23
Chapter 4: CI-DR¯(TM) Security Program Components 25
Notes 39
Chapter 5: Functional Capabilities of the CI-DRTM Program 41
Notes 54
Chapter 6: CI-DR¯(TM) Key Capability Next-Generation Security Operations Center 55
Introduction by Kiran Vangaveti - CEO of BluSapphire 55
Notes 60
Chapter 7: CI-DR¯(TM) Key Capability Cyber Threat Intelligence 63
Notes 70
Chapter 8: CI-DR¯(TM) Key Capability Forensic Teams 71
Dr. Steven Johnson
Notes 85
Chapter 9: CI-DR¯(TM) Key Capability Vulnerability Management Teams 87
By Derek Olson
Notes 103
Chapter 10: CI-DR¯(TM) Key Capability Incident Response Teams 105
By Dr. Steven Johnson
Notes 122
Chapter 11: CI-DR¯(TM) Collection Components 123
Notes 125
Chapter 12: CI-DR¯(TM) Stakeholders 127
By Steve Dufour, CEO
Notes 133
Conclusion 135
Glossary 139
About the Author and Chapter Authors 145
Index 149
Introduction
It is even better to act quickly and err than to hesitate until the time of action is past.
- Carl von Clausewitz
THIS BOOK is designed for business leaders who are looking to unwrap the "cyber black box" and understand how cyber intelligence can improve their business decisions. For the cybersecurity professional who is trying to find an entry point to provide value to executives, and for the cybersecurity teams looking to raise their level of sophistication, this book will address the fundamental issues facing businesses and individuals today. First, organizations are still failing to respond to cyber threats due to inconsistent decisions and poor cyber hygiene. Second, both organizations and cybersecurity professionals are struggling with compliance frameworks, international legislation, and local legislative and other privacy requirements while still trying to make revenue through technology advantages. All of the frameworks, compliance, and privacy items are focused on the technology and not on how the organization should be looking at operational risk. By the end of this book, we will explain to the reader why the CI-DRT is the center of gravity for decisions that business leaders should be taking advantage of. Business leaders in every organization are consistently being asked how the organization is dealing with cybersecurity issues, whether it can respond to cyber losses, and what the shareholders need to know should a cybersecurity breach or cyber loss leading to financial consequences occur. Most of the cybersecurity issues that current business models outline are reactive in nature and are usually actioned without much analysis or debate, leaving biased opinions and hasty approaches that ultimately detract from logical decisions.
Operational risk losses or consequences are defined in the IEC/ISO 310101 documentation and is where we begin to leverage the language needed to bring the CI-DR "knowledge" to the risk management professionals. To have a seat at the table as cyber professionals we need to be able to speak the same taxonomy as our business risk managers. Throughout the book we provide some real-world examples of how a CI-DR program assisted organizations where these capabilities were implemented and matured to assist in the business decision-making process. As you read the examples, our intent is to have you think about the role you hold at your company, or your next role, and the types of information you would want to assist you in making decisions. To be successful, it is key to have the data and knowledge, coupled with curiosity and the desire to be of value that will ultimately lead to being granted access to the internal decision-making for your organization.
With every chapter we provide the business need for a CI-DR program with a real-world example of the cybersecurity issues that many organizations have faced in the past. As you may recall, the year 2012 was very troubling for the financial services, banking, and cybersecurity practitioners. Starting in the month of September and continuing into the new year, a sympathetic nation-state of malicious actors known as QCF (Cyber Fighters of Izz ad-Din al Qassam, also known as Qassam Cyber Fighters) began to methodically stop banks from financially transacting with customers, through an attack known as a Distributed Denial of Service (DDoS). This is essentially a technical mechanism that consumes and overwhelms systems and networks, rendering them unavailable or useless for the purposes they were designed for. Many of these banking institutions leveraged their membership in the Financial Services Information Sharing and Analysis Center (FS-ISAC)2 to gain an understanding of how the attack started and to provide a secure forum for discussing best strategies to defend the banks against this adversary, helping to set the foundations for many cyber programs and processes in use today.
The ISAC provided the necessary connections among cybersecurity professionals, many of whom came from the military intelligence profession, with a forum and location to share threat intelligence as well as the ability to discuss new capabilities and mitigation process to reduce the attacks against their financial institutions without retribution for competitive interests. The Security and Exchange Commission later issued a statement that cybersecurity and threat intelligence cannot be a competitive advantage.3 The larger member institutions had begun building cyber intelligence programs and sharing information on attacks through the membership's cyber intelligence leaders. As executives continued to hear through headlines and peers throughout the banking community, their concerns were how much money they would need to spend to protect their organizations and whether they had the proper staffing and expertise on hand to do that. The action and outcomes of this specific attack played a significant role in the development of the CI-DR program. One of the important processes that was implemented from the sharing of information through the ISAC was the need for cyber intelligence teams to collect, analyze, and produce reporting of attack vectors to the banking management teams for decisions on how to deploy resources.
At different phases of the attack other institutions were doing similar activities, and after months of analysis and the velocity and growth of the attacks, teams using the initial vision of the CI-DR program were able to create a predictive analysis when the attack might occur. Most conversations that were happening in business leadership were not the old similar technology mitigation discussions; the conversations quickly changed focus to discuss whether this attack would impact capital reserves, what other risks might be encountered during this unprecedented cyberattack, and what amount of financial transactions and revenue losses would online banking systems and internet-facing systems incur. As these conversations grew and expanded, our organization had a plan to have the accountants and business analysts review the systems and provide transactional and revenue estimations for eight, sixteen, and twenty-four hours to determine the amount of loss each critical system could incur. Much of this information was derived from work done by the risk management team during their Business Impact Analysis reviews, and the "crown jewels" asset risk assessments conducted by the information security and business technology teams. One of the most difficult assessments that the accountants had to deal with was figuring out potential revenue loss and the number of hours it would take to lose it. This process that was incorporated after the attacks subsided is the original iteration of what is commonly called today a fusion center. A CI-DR fusion center can exist when bringing business owners, accountants, technologists, risk managers, cyber intelligence analysts, and cybersecurity personnel together to solve an organizational problem.
Having generated all available intelligence through the fusion of stakeholders, combined with our analysis of all data brought from the fusion teams, a decision model was presented to the Board of Directors for their agreement that we were doing the right thing. That "knowledge" package painted key cyber intelligence decision points and pinpointed that the organization would be attacked somewhere around January 7 at 14:00, and that the financial loss would be over a million dollars for eight hours of outage time. Additionally, the decision points included mitigation technologies the organization could deploy to remediate the attack and the cost comparison against the impact of loss. The cost-benefit decision weighed with risk options provided two courses of recommended actions. The decision points were to either allow our systems to be overwhelmed and let the attackers think they took us offline, or implement this new unproven Anti-DDoS scrubbing technology, which could still potentially lose some real transactions with an additional cost for ineffective technology. With agreement that executive management had the situation well understood, the decision was made to allow the attackers to shut down our online banking platform and allow it to be unavailable during our anticipated 14:00 to 17:00 outage.
To add additional scrutiny and anxiety for the executives, these plans had to be presented to the US Treasury and our financial regulators, which gave the executive team concern that we would be placed under supervisory letters if our decisions were steadfast. The cyber intelligence analysis from months of attack data was also provided to the Treasury and Regulators so they too could understand that the attackers usually turned off their attacks at 17:00 and that our exposure and loss rate was consistent with our risk models. It was the first time the organization's executives and management felt like they were making cybersecurity decisions and this grew my cyber intelligence program by leaps and bounds. Our intelligence estimates were off by thirty minutes, and we were back online transacting by 17:15 the same day. As the attacks were not subsiding through the spring of that year, the executive team, armed with the information from the collaborative efforts of the fusion team and the cyber intelligence analysis, made the decision to purchase the technology and reduce the financial losses even further. That organization is still using that same approach to mitigating other risks and how they purchase technology today as part of their risk management strategy. By leveraging this proven CI-DR framework it will enhance your cyber program from a pure technology...
System requirements
File format: ePUB
Copy protection: Adobe-DRM (Digital Rights Management)
System requirements:
- Computer (Windows; MacOS X; Linux): Install the free reader Adobe Digital Editions prior to download (see eBook Help).
- Tablet/smartphone (Android; iOS): Install the free app Adobe Digital Editions or the app PocketBook before downloading (see eBook Help).
- E-reader: Bookeen, Kobo, Pocketbook, Sony, Tolino and many more (not Kindle).
The file format ePub works well for novels and non-fiction books – i.e., „flowing” text without complex layout. On an e-reader or smartphone, line and page breaks automatically adjust to fit the small displays.
This eBook uses Adobe-DRM, a „hard” copy protection. If the necessary requirements are not met, unfortunately you will not be able to open the eBook. You will therefore need to prepare your reading hardware before downloading.
Please note: We strongly recommend that you authorise using your personal Adobe ID after installation of any reading software.
For more information, see our ebook Help page.