Google Cybersec Recap
Chronicle was one of those parts of the course that made me realise how much information security teams can have to work with.
I came across dashboards for IoC matches, rule detections, data ingestion, user sign-ins, all helping make sense of security data.
Basically, less doing everything manually and more having the right tools work together when an incident happens.
Another one from Play It Safe: Manage Security Risks. ๐
#Cybersecurity#SOAR
A SIEM can help you spot something suspicious.
But then what?
You have to respond to it, and this is where I came across SOAR, Security Orchestration, Automation and Response. The idea is to bring different security tools and processes together and automate parts of the response.
A SIEM tool doesn't just collect logs and leave you staring at thousands of events.
It brings the data together in dashboards, where security teams can monitor activity, track metrics and spot potential issues more easily.
@MattEnglerDC I approached it through the control assessment exercises in the course, looking at the control, the evidence available, and the gaps identified.
Google Cybersecurity Recap | Course 2 ๐
Security controls can look perfect on paper.
But how do you know they actually work?
Thatโs where SECURITY AUDITS come in. I learned about scope, goals, risk assessment and what can shape an audit.
#Cybersecurity#GRC
Thatโs where SIEM comes in.
A SIEM tool (Security Information and Event Management) collects and analyses security data from different sources, helping security teams spot patterns, investigate events and identify potential threats.
#Cybersecurity#SIEM#Googlecourse#Imfosec
Google Cybersecurity Recap | Course 2 ๐
A LOG is a record of activity that happens on a system or network.
But with so many logs coming from different sources, how do you actually make sense of them?
It was interesting seeing that cybersecurity isn't only about protecting systems from attacks.
There are also specific security standards and compliance requirements for protecting sensitive data like payment card information.
Another part of course 2.
#Cybersec#GRC#Payments
You enter your card details online to buy something.
Your card number, expiration date and other payment information are now part of a system that needs to be protected.
So who makes sure organisations handle that data securely?
Thatโs where the PAYMENT CARD INDUSTRY DATA SECURITY STANDARD (PCI DSS) comes in.
It provides security requirements for organisations that store, process or transmit payment card data.
DETERRENT controls are meant to discourage unwanted actions.
I liked seeing how different controls can serve different purposes depending on the security risk.
#Cybersecurity#GRC
Google Cybersecurity Recap | Course 2 ๐
Security controls can also be grouped by what they're meant to do.
I came across four types:
PREVENTIVE
DETECTIVE
CORRECTIVE
DETERRENT
PREVENTIVE controls are designed to stop an incident before it happens.
DETECTIVE controls help identify when something has happened or is happening.
CORRECTIVE controls help fix an issue or reduce its impact.
Google Cybersecurity Recap | Course 2 ๐
Then I came across OWASP.
It focuses on improving the security of web applications and helping security professionals identify common web application risks.
Another concept from Play It Safe: Manage Security Risks.
Google Cybersecurity Recap | Course 2 ๐
The NIST Cybersecurity Framework has six functions:
GOVERN
IDENTIFY
PROTECT
DETECT
RESPOND
RECOVER
GOVERN was newly added in CSF 2.0 to bring more focus to cybersecurity governance.
#Cybersecurity#NIST#GRC
Then there are ADMINISTRATIVE CONTROLS ๐
These include policies, procedures and other organisational measures that guide how security is managed.
Different controls, different purposes, but all part of protecting an organisation.
#Cybersecurity#GRC
Google Cybersecurity Recap | Course 2 ๐
So, how does an organisation actually protect itself?
One answer is through security controls. And they aren't all firewalls and fancy security software.
There are THREE main types ๐
PHYSICAL CONTROLS ๐
Think locks, security cameras and other measures that protect physical spaces, equipment and people.
TECHNICAL CONTROLS ๐ป
These use technology to protect systems and data, like encryption, authentication and authorization.