Adaptive Cybersecurity Risk Assessments
This session provides practical advice to conduct cybersecurity assessments. It details the end-to-end process including: scoping, 15 steps to develop work papers, scheduling and on-site assessment. Includes techniques to add risk opportunistic controls and for new assessments year-over-year. Concludes with assessment report and slide deck frameworks, including tips for briefing executives.
This session provides practical advice to conduct cybersecurity assessments. It details the end-to-end process including: scoping, 15 steps to develop work papers, scheduling, on-site assessment, report preparation and presentation.
The first assessment example leverages the NIST Cybersecurity Framework for coverage across security domains. Sample scoping questions are provided, with tips and examples to create testing procedures based on cyber threat intelligence, business processes, insider threat and fraud.
The scoping methodology is risk opportunistic to adapt assessments year-over-year. There is focus on areas that have not been evaluated recently and areas that may require enhanced controls due to the presence of valuable data. Attendees are encouraged to evaluate lines of business and to take deep dives into critical functions.
The session provides an assessment report framework. There are tips for briefing executives including a slide deck framework covering the threat landscape, assessment methodology, high and moderate-high findings, Strengths, Weaknesses, Opportunities and Threats (SWOT) and next steps.
There are 34 content slides. This is a cybersecurity assessments crash-course. It's hard charging and there are resource links at the end of the deck.
• NIST Cybersecurity Framework v2.0
• NIST CSF v2.0 Core Listing
• I. Assessment Scoping
- Scoping
- Threat Actors (2 Slides)
- Abraham Lincoln Quote
• II. Work Papers - Work Papers - Starting with NIST CSF
- Work Papers - Flesh Out Controls
- Flesh Out Controls - Security Monitoring
- Creating Alerts Referencing the Pyramid of Pain
- Lateral Movement
- New Alerts Based on Adversary Toolkits
- Monitoring for Suspicious Commands
- Flesh Out Controls - Insider Threat
- 9/11 Commission Report Quote
- Work Papers - Attack Centric Controls
- AI Governance and Technical Controls
- ID Access Card System
- Resistance to Breaching Tools
- Work Papers - Results of Scoping
- Interview Techniques - Bad Practices
- Interview Techniques - Survey Questions
- Controls Across Roles and Functions
- Finishing Touches - Work Papers
- Interview List
- Artifact Requests
- 50% Prep / 50% Execution
• III. Report and Present - Assessment Report
- Assessment Presentation
• IV. Future Assessments - Frederick II Quote
- Risk Management
- Albert Einstein Quote
- Line of Business Assessment
- Future Assessments
The participants come away with a significant amount of tips and examples. The goal is to provide information they can leverage upon return to work.
Gideon Rasmussen is a cybersecurity leader with over 20 years of experience in corporate and military organizations. Gideon has designed and led programs including information security (as Chief Information Security Officer), PCI payment card security, third-party risk management, application security and information risk management. Has diverse cybersecurity experience within banking, startups, insurance, pharmaceuticals, DoD/USAF, aerospace and defense, state government, advertising and talent management.
Gideon is a sought-after speaker, addressing audiences at conferences, universities and corporate events. He is the author of Program Architecture: Fight the Good Fight and has written more than 30 articles on cybersecurity and operational risk. A veteran of the United States Air Force, Gideon has completed the Bataan Memorial Death March four times.