dfm covers
 
 

Cyber Security Situational Awareness

Cyber Security Situational Awareness

Ian Murphy


Cyber Security and Security Operations are fast becoming the latest areas for investment by CSO’s to ensure that they are able to respond when events occur. This article takes a look at how Situational Awareness fits into this and how Digital Forensics tools and techniques are used as a result.


Introduction

Cyber Security Situational Awareness (CyberSSA) is a not so new field in the way information about past, current and future threats to an organisation are displayed.  Its origins are well founded in the battlefield strategies of national governments and are beginning to percolate into large global organisations.  


But what is CyberSSA and why should we care about its presence (or not) or its effectiveness?  


To answer this question I think it is best to consider current challenges faced by Chief Security Officers (CSO) and why organisations should consider CyberSSA.  


Today’s CSO is ever more being asked to do more with less, there are a myriad of external compliance schemes as well as an organisations internal governance necessary to meet executive board responsibilities.  Some of the top agenda items for a CSO are:


1. Demonstrating security value to the business

2. Developing and communicating a security strategy that supports business objectives

3. Complying with regulatory requirements (both internal and external)


So how could CyberSSA assist with these challenges and what should we expect of this “new” arena?


The overarching tenet of CyberSSA is “knowing what is going on around you”.  When applied to organisations, this translates in being able to determine the security health of your environment, down to the endpoint.  This task is further complicated by the heterogeneous nature of a modern organisation and the already expensive investments made into the latest and greatest silver bullets from the security world. So CyberSSA should be aiming to provide the CSO and their teams with a view currently not provided within the Information Security world, a "view from the bridge" to coin an old naval phrase. 


Apart from the detailed security health of the environment, CSO’s are also interested in a different view on the same kind of data. A view, that provides answers not only to technical questions but also on business questions. In most cases, consoles provide a good overview about the technical status of the solution, but who provides an answer about the health of the entire infrastructure? CSO’s are not interested in technical details like the number of detected viruses on a particular system, but they are interested if the risk to the business is within the defined parameters. 

Is the business fulfilling the defined SLA’s?

How does the individual threat landscape look like?

How does the threat landscape look like over time?


Want to know the answers? Subscribe today and receive issue 6. The sooner you subscribe, the less you'll have to wait.


 
Please make cache directory writable.
 

Submit an Article

Call for Articles

We are keen to publish new articles from all aspects of digital forensics. Click to contact us with your completed article or article ideas.

Featured Book

Learning iOS Forensics

A practical hands-on guide to acquire and analyse iOS devices with the latest forensic techniques and tools.

Meet the Authors

Noemi Kuncik

Noemi Kuncik is an IT Forensics Specialist at Grant Thornton

 

Coming up in the Next issue of Digital Forensics Magazine

Coming up in Issue 38 on sale from February 2019:


Crowd Sourcing Digital Evidence The Risk v The Reward

All digital devices used today can be considered as a potential source for digital evidence. Andrew Ryan investigates the current state in the art of crowd sourced digital evidence. Read More »

Recovery of Forensic Artifacts from Deleted Jump-List in Windows 10

Jump-Lists are widely discussed in forensics community since the release of Windows 7 and are having more capabilities to reveal forensics artifacts in Windows 10. Read More »

Subscribe today


Operacion Bitcoin

The article is an actual case study of an Interpol investigation carried out in association with CertUY that has been ongoing for some months. It is written by the first hacker sent to prison in Uruguay who is currently out on bail pending sentencing. Read More »

Every Issue
Plus the usual Competition, Book Reviews, 360, IRQ, Legal

Click here to read more about the next issue