dfm covers
 
 

Cyber Security Situational Awareness

Cyber Security Situational Awareness

Ian Murphy


Cyber Security and Security Operations are fast becoming the latest areas for investment by CSO’s to ensure that they are able to respond when events occur. This article takes a look at how Situational Awareness fits into this and how Digital Forensics tools and techniques are used as a result.


Introduction

Cyber Security Situational Awareness (CyberSSA) is a not so new field in the way information about past, current and future threats to an organisation are displayed.  Its origins are well founded in the battlefield strategies of national governments and are beginning to percolate into large global organisations.  


But what is CyberSSA and why should we care about its presence (or not) or its effectiveness?  


To answer this question I think it is best to consider current challenges faced by Chief Security Officers (CSO) and why organisations should consider CyberSSA.  


Today’s CSO is ever more being asked to do more with less, there are a myriad of external compliance schemes as well as an organisations internal governance necessary to meet executive board responsibilities.  Some of the top agenda items for a CSO are:


1. Demonstrating security value to the business

2. Developing and communicating a security strategy that supports business objectives

3. Complying with regulatory requirements (both internal and external)


So how could CyberSSA assist with these challenges and what should we expect of this “new” arena?


The overarching tenet of CyberSSA is “knowing what is going on around you”.  When applied to organisations, this translates in being able to determine the security health of your environment, down to the endpoint.  This task is further complicated by the heterogeneous nature of a modern organisation and the already expensive investments made into the latest and greatest silver bullets from the security world. So CyberSSA should be aiming to provide the CSO and their teams with a view currently not provided within the Information Security world, a "view from the bridge" to coin an old naval phrase. 


Apart from the detailed security health of the environment, CSO’s are also interested in a different view on the same kind of data. A view, that provides answers not only to technical questions but also on business questions. In most cases, consoles provide a good overview about the technical status of the solution, but who provides an answer about the health of the entire infrastructure? CSO’s are not interested in technical details like the number of detected viruses on a particular system, but they are interested if the risk to the business is within the defined parameters. 

Is the business fulfilling the defined SLA’s?

How does the individual threat landscape look like?

How does the threat landscape look like over time?


Want to know the answers? Subscribe today and receive issue 6. The sooner you subscribe, the less you'll have to wait.


 
Please make cache directory writable.
 

Submit an Article

Call for Articles

We are keen to publish new articles from all aspects of digital forensics. Click to contact us with your completed article or article ideas.

Featured Book

Learning iOS Forensics

A practical hands-on guide to acquire and analyse iOS devices with the latest forensic techniques and tools.

Meet the Authors

Noemi Kuncik

Noemi Kuncik is an IT Forensics Specialist at Grant Thornton

 

Coming up in the Next issue of Digital Forensics Magazine

Coming up in Issue 33 on sale from November 2017:


Triage Solution for Sex Offender Managers

This article considers a proof of concept triage solution for sex offender managers for a local police force which if successful could simplify and modify the way that sex offenders are managed. Read More »

Advancements in Windows Hibernation File Forensics

Brian Gerdon looks at how the windows hibernation files can be a valuable source of information for digital forensic investigators. Read More »

Subscribe today


Why Are Cybercriminals Attracted To Commit Crimes

Individuals who engage in cybercrime have a psychological mindset that is attuned to it. This paper discusses the motives behind cybercrime and what makes cybercrime attractive to cybercriminals. Read More »

Every Issue
Plus the usual Competition, Book Reviews, 360, IRQ, Legal

Click here to read more about the next issue