Session 2_ 2024 FRSecure CISSP Mentor Program
Session 2_ 2024 FRSecure CISSP Mentor Program
Session 2_ 2024 FRSecure CISSP Mentor Program
INTRODUCTION
2024
Class #2 – Domain 1
Christophe Foulon
Founder CPF Coaching & vCISO
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 1
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 1
#MissionBeforeMoney
INTRODUCTION
Agenda –
• Welcome
• Introduction
• Questions
• Policies
• Business Continuity
• Personnel
• Third-party / Supply Chain controls
• Risk Management
• Security Awareness
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 2
#MissionBeforeMoney
WHOAMI
Christophe Foulon
Founder CPF Coaching & vCISO
https://www.linkedin.com/in/christophefoulon/
@Chris_Foulon
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 3
#MissionBeforeMoney
WHO I AM?
I love Baby Yoda
Outside of being a security practitioner focused on helping businesses tackle their
cybersecurity risks while minimizing friction resulting in increased resiliency and helping
to secure people and processes with a solid understanding of the technology involved.
I am a dad, dog dad and career coach. I love helping other to achieve their best.
Through this channel, I help veterans with their transitions and others via non-profits like
Whole Cyber Human Initiative, Boots2Books and others.
I give back by producing a podcast focused on helping people who are “Breaking into
Cybersecurity” by sharing the stories of those who have done it in the past 5 years to
inspire those looking to do it now.
Co-authored:
“Develop Your Cybersecurity Career Path: How to Break into Cybersecurity at Any Level”
“Hack the Cybersecurity Interview: A complete interview preparation guide for
jumpstarting your cybersecurity career”
And advised on “Understand, Manage, and Measure Cyber Risk”
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 4
CISSP® MENTOR PROGRAM – SESSION THREE
GETTING GOING…
Managing Risk!
Studythrough
We’re Tips: Chapters 1, 2, 3, and part way into Chapter
4!• Study in small amounts frequently (20-30 min)
••Check-in.
Flash card and practice test apps help
••How many
Take napshave read
after Chapter
heavy 1, 2(aka
topics & 3?Security Models)
Write things down, say them out loud
••Questions?
• Use the Discord Channels
• Exercise or get fresh air in between study sessions
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 5
#MissionBeforeMoney
QUESTIONS.
The most common questions have been
about:
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 6
#MissionBeforeMoney
QUESTIONS.
The most common questions have been
about:
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 7
#MissionBeforeMoney
QUESTIONS.
The most common questions have been
about:
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 8
#MissionBeforeMoney
INTRODUCTION
Before we get too deep into this.
Yeah, I know.
That’s dumb.
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 9
#MissionBeforeMoney
INTRODUCTION
Cornerstone Information Security Concepts
Definition of “information security” (don’t forget):
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 10
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 11
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 12
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 13
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 15
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 16
#MissionBeforeMoney
Guidelines
(FYI)
Procedures
(HOW, WHO)
Standards
(WHAT)
Policies
(WHY, WHEN)
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 17
#MissionBeforeMoney
Guidelines
(FYI)
Procedures
BASELINES
(HOW, WHO)
MinimumStandards
level
(WHAT)
Policies
(WHY, WHEN)
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 18
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 19
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 20
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 21
#MissionBeforeMoney
*not testable
OMG—The feeling you will have executing the BCP plan
FML—what you shout if you didn’t print out the BCP plan
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 22
#MissionBeforeMoney
*not testable
OMG—The feeling you will have executing the BCP plan
FML—what you shout if you didn’t print out the BCP
plan
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 23
#MissionBeforeMoney
Disaster
RPO RTO
MTD
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 24
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 25
#MissionBeforeMoney
Management Support
“C”-level managers:
• Must agree to any plan set forth
• Must agree to support the action items listed in the plan if an emergency event occurs
• Refers to people within an organization like the chief executive officer (CEO), the chief
operating officer (COO), the chief information officer (CIO), and the chief financial officer
(CFO)
• Have enough power and authority to speak for the entire organization when dealing with
outside media
• High enough within the organization to commit resources
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 26
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 27
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 28
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 29
#MissionBeforeMoney
Example Scope
Critical business functions
Threats, vulnerabilities, and risks
Data backup and recovery plan
BCP personnel
Communications plan
BCP testing requirements
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 30
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 31
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 32
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 33
#MissionBeforeMoney
Technologies
• Tech fails plan for it
• Backups are the #1 way to address this risk
• BCP should account for redundancy (power, water, telco, internet)
• Multiple locations for backups (on-prem and cloud)
• Need to account for external disaster (ISP, Bank, SaaS provider, etc.)
• Testing and updating
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 34
#MissionBeforeMoney
Technologies
• Tech fails plan for it
• Backups are the #1 way to address this risk
• BCP should account for redundancy (power, water, telco, internet)
• Multiple locations for backups (on-prem and cloud)
• Need to account for external disaster (ISP, Bank, SaaS provider, etc.)
• Testing and updating
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 35
#MissionBeforeMoney
Technologies
• Why didn’t the IT
team set up their
remote office from the
beach?
Yeah, I know.
That’s dumb.
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 36
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 37
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 38
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 39
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 40
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 41
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 42
#MissionBeforeMoney
Yeah, I know.
That’s dumb.
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 43
#MissionBeforeMoney
Risk
Threat
Asset Vulnerability
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 44
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 45
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 46
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 47
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 48
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 49
#MissionBeforeMoney
Asset
3rd Party Cloud
Data
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 50
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 51
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 52
#MissionBeforeMoney
Risk Identification
• Asset discovery (hardware, software, network, data, people)
• Asset valuation (business value of asset)
• Classification (how sensitive, how critical)
• Vulnerabilities and Threats to asset
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 53
#MissionBeforeMoney
Risk Analysis
Should begin with a vulnerability assessment (more in chapter 6)
and threat analysis (more on this later in this chapter)
The goal of risk analysis is to evaluate how likely identified threats are
to exploit weaknesses (i.e., vulnerabilities)
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 54
#MissionBeforeMoney
Risk Analysis
Likelihood—Probability that event will occur.
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 55
#MissionBeforeMoney
Risk Analysis
• Qualitative – based upon professional opinion; High,
Medium, Low…
• Quantitative – based on real values; dollars. Pure
quantitative analysis is nearly impossible (lack of data).
• Risk Analysis Matrix – Qualitative risk analysis table;
likelihood on one side, impact on the other.
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 56
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 57
#MissionBeforeMoney
INTRODUCTION
Terms and Definitions to Memorize
• Risk – The likelihood of something bad happening and the impact if it
did; threats (source) and vulnerabilities (weakness)
• Annualized Loss Expectancy (or ALE) - the cost of loss due to a risk over
a year
• Safeguard (or “control”) - a measure taken to reduce risk
• Total Cost of Ownership (or TCO) – total cost of a safeguard/control
• Return on Investment (or ROI) - money saved by deploying a safeguard
Another term is Return on Security Investment or “ROSI”.
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 59
#MissionBeforeMoney
INTRODUCTION
Terms and Definitions to Memorize
• Risk – The likelihood of something bad happening and the impact if it
did; threats (source) and vulnerabilities (weakness)
• Annualized Loss Expectancy (or ALE) - the cost of loss due to a risk over
a year
• Safeguard (or “control”) - a measure taken to reduce risk
• Total Cost of Ownership (or TCO) – total cost of a safeguard/control
• Return on Investment (or ROI) - money saved by deploying a safeguard
Another term is Return on Security Investment or “ROSI”.
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 60
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 61
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 62
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 63
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 65
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 66
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 68
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 69
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 70
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 72
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 73
#MissionBeforeMoney
Just Kidding
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 74
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 75
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 76
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 77
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 78
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 80
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 81
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 82
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 83
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 84
#MissionBeforeMoney
• Attacker-centric
• Identify various actors' characteristics, skillset, and
motivation
• Profile attackers to specific attacks
• Generally, part of a BCP/DR planning process
• Understanding how the attacker operates
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 85
#MissionBeforeMoney
• Asset-centric
• Identify asset value to organization and to the attacker
• The means by which the asset is managed, manipulated,
used, and stored
• Evaluate and identify how an attacker might compromise
the asset
• Many compliance regimes focus on asset protection
(HIPAA,GDPR, PCI-DSS)
• Helpful in protecting other assets such as intellectual
property
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 86
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 87
#MissionBeforeMoney
• STRIDE
• Spoofing
• Tampering
• Repudiation
• Information disclosure
• Denial of service
• Elevation of privilege
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 88
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 89
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 90
#MissionBeforeMoney
• Damage
• Reproducibility
• Exploitability
• Affected users
• Discoverability
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 91
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 92
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 93
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 94
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 95
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 96
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 97
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 98
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 99
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 100
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 101
#MissionBeforeMoney
• Social Engineering
• Security Champions
• Gamification
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 102
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 103
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 104
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 105
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 106
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 107
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 108
#MissionBeforeMoney
INTRODUCTION
Before we get too deep into this.
How about a dumb dad joke?
Yeah, I know.
That’s dumb.
😂😂😂
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 109
CISSP® MENTOR PROGRAM – SESSION THREE
DOMAIN 1 REVIEW
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 110
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 111
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 112
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 113
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 114
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 115
#MissionBeforeMoney
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. 116