Cybersecurity
the "preservation of confidentiality, integrity and availability of information in the Cyberspace"
Cyberspace
the complex environment resulting from the interaction of people, software and services on th
...
Cybersecurity
the "preservation of confidentiality, integrity and availability of information in the Cyberspace"
Cyberspace
the complex environment resulting from the interaction of people, software and services on the Internet
by means of technology devices and networks connected to it, which does not exist in any physical form
NIST Cybersecurity Framework
Identify—Use organizational understanding to minimize risk to systems, assets, data and capabilities.
Protect—Design safeguards to limit the impact of potential events on critical services and infrastructure.
Detect—Implement activities to identify the occurrence of a cybersecurity event.
Respond—Take appropriate action after learning of a security event.
Recover—Plan for resilience and the timely repair of compromised capabilities and services.
Lines of Defense
The first line is ownership, implementation and execution.
The second line is risk management, including monitoring/measurement.
The third line is independent testing and assurance.
The objectives of a cybersecurity audit are to:
Provide management with an independent assessment of the effectiveness of cybersecurity processes,
policies, procedures, governance and other controls
Identify security control concerns that could affect the confidentiality, integrity or availability of the
information assets due to weaknesses and vulnerabilities in the system of internal controls, including
key security controls
Evaluate the effectiveness of response and recovery programs
Evaluate compliance with cybersecurity relevant laws and regulations
Governance
the responsibility of the board of directors and senior management of the enterprise.
Goals of a governance program
•Provide strategic direction •Ensure that objectives are achieved
[Show More]