Sunday, 12 July 2020

How will the cloud strengthen business continuity?

EC-Council Study Materials, EC-Council Learning, EC-Council Exam Prep

Cloud-based computing and the whole notion of SaaS (Software-as-a-Service) is becoming the most critical expertise for this era. Due to this,business continuity experts should be seeking what this development means for them and its potential impact.

According to a survey, 73% of organizations fall victim to natural disasters and human-made disasters, including malicious hacking and malware. This negatively impacts business operations. It isn’t just enough to back up your data with traditional software packages; you need the cloud.

EC-Council Disaster Recovery Professional (EDRP) certification certifies IT professionals, cybersecurity experts, BC/DR experts, CISOs, IT directors, and other cybersecurity enthusiasts in the field of business continuity and disaster recovery. Having an EDRP certification is a logical ‘next step’ for those who want to further their career in the field of business continuity and disaster recovery.

What exactly is the cloud?


The cloud means different things for different occasions. Cloud computing is a word used to generally define data centers accessible to several people via the internet, delivered on-demand basis to users. Put simply;cloud computing describes the process of storing and retrieving programs and data through the internet rather than using your system’s hard drive. The cloud is a metaphoric description of the internet.

Different forms of cloud computing services exist, including infrastructure as a service (IaaS), platform as a service (PaaS), and software as a service (SaaS). Internet users can benefit a lot from using cloud-based services. These benefits include reduced spending on IT and IT infrastructure, speedy implementation, flexible pricing, and elevated scalability.

What are business continuity planning and disaster recovery?


Disaster recovery and business continuity planning are procedures that assist organizations in preparing for natural and human-made disasters or incidents. These incidents could be a hurricane, tornado, or merely a power outage. The role of an EDRP in this scenario can range from supervising the business continuity and disaster recovery plan to offering input and backing, to executing the plan during an incident or emergency.

While no degree of preparation can avert an incident, however, when a disaster, capable of completely halting the complete business operations occurs, having a disaster recovery program and a business continuity plan can mitigate the attack and keep the business running again.

What is the difference between disaster recovery & business continuity?


Although disaster recovery programs and business continuity plans appear similar, they are not the same thing. Disaster recovery programs are procedures that enable an organization to get all its critical IT infrastructure and business operations running after a disruptive event.

The event may be as catastrophic as an earthquake, Hurricane Katrina, terrorist attacks, or something as minute as a computer virus, supply chain partner problems, or power outage. Most business executives often tend to overlook their cybersecurity disaster recovery programs since disasters are seemingly improbable.

On the other hand, a business continuity plan is a more inclusive process that ensures that the entire organization is fully functioning following a catastrophic event. The aim is to ensure that the organization continues to make money, regardless of the size of the incident. This ensures that HR can easily access vital information about their works, so that customer service representatives can access their CRM applications, and the marketing department can gain authentication to their stored graphics.

While these two concepts are not the same, they are often used interchangeably. The label BC/DR is the umbrella term for these concepts due to their shared considerations. To learn more about BC/DR, visit our webpage on EDRP courses.

Who is responsible for the business continuity plan?

Disaster recovery professionals (DRP) are often responsible for the creation and sustenance of a business continuity plan. They work directly with significant business units to know their business procedures, detect, and assess their risks, and offer technologies or software that will assist in managing and mitigating these potential risks.

Whether your company wants to take up cloud-based disaster recovery programs or cloud-based business continuity solutions, it is more logical to collaborate with business continuity and disaster recovery service provider. A DRP has the needed knowledge to perform a correct business impact analysis, vulnerability assessments, formulate policies, and plans that are most suitable for the organization.

How do cloud-based systems support business continuity?


Since cloud computing services profoundly depend on hardware virtualization tools, it helps organizations to speedily back up their sensitive information and data, operating systems, and applications to the cloud. With quicker uploads and downloads of significant computing features, comes quicker recovery times and business continuity for the organization.

1. Readily Accessible

When it comes to business continuity planning, most organizations perceive SaaS as the available option. Most organizations can benefit from cloud-based business continuity programs, even in remote locations. Members of your IT department can select the suitable services that meet their unique business demands with a wide variety of services that cloud computing offers.

2. Robust Response

When an incident occurs or in an emergency, it is easy to restore and recover your data from the cloud. This ensures business continuity due to the robust response from your cloud computing services. Likewise, traditional business continuity and disaster recovery plans can be burdensome. With cloud computing service, you can ask your service provider to replicate your file to a new location. An EDRP knows to evaluate the specifications of the SaaS provider to familiarize themselves with and get comfortable with the conveniences delivered.

3. Reduced Costs

Traditional BC/DC solutions are extremely expensive to manage. They usually involve purchasing and sustaining a comprehensive set of hardware that harmonizes or reflects the critical systems of a business, such as adequate storage to accommodate a broad duplicate of the entire organization’s business data.

However, cloud-based business continuity plans or strategies are affordable, lucrative, and economical for all business sizes. Business continuity planning that is cloud-based eliminates the requirement for costly remote production centers. Similarly, organizations are given the choice of tailoring their business continuity plan, since they can subscribe solely to necessary services. Companies can then decide to modify their subscription plans as they expand their business operations.

CLOUD AND DISASTER RECOVERY: THE 5 W’S


How can potential risks be transferred to cloud providers?


When you use the services of unauthorized cloud providers, it could compromise your network or devices through data exfiltration and malware infections, since the enterprise cannot secure resources with which it is not conversant. Using unlicensed cloud providers might also compromise your network’s visibility and administration of business data and networks.

One of the major recognized potential risks for cloud computing, which affects not just the organization but also the cloud providers, includes compliance and jurisdictional risks, lack of data security and privacy, availability risks, unauthorized access.

1. Compliance And Jurisdictional Risks

Some industries are highly regulated, including banking, auditing, healthcare, and government organizations. Several business information security regulations and compliance are needed to safeguard specific data. Cloud providers are bound by these regulations and required to not only secure the data of their consumers but also to know how the data is defended, who has authorized access, and the location of the data. A company without suitable legal protections, suffer the consequences when there is a breach at the cloud.

2. Lack Of Data Security and Privacy

In a way, you place the entirety of your business in the hands of the cloud providers. You supply them with access to sensitive information, including mailing lists, payment data, user ID, and so on. Most people are unaware of who their cloud providers are, their integrity, the data access they have, and the type of security solution being used. Can you vouch for the reputation of your client?

3. Availability Risks

There is no complete uptime guarantee from any provider. When you depend on your cloud providers for essential business operations, then you entrust your business sustainability to your ISP and cloud providers. When you suffer a downtime, your cloud provider also suffers. Your cloud providers can also suffer downtime from DDoS and DoS attacks, SQL injection attacks, or even bad weather. Availability risks are less severe but still detrimental.

4. Unauthorized Access

Internal threats and external threats aggregate cloud computing risks. When you outsource your business tasks to other cloud vendors, not only should you be worried about your staff but also the staff of your vendors. Government intrusion risks also intensify when you use the services of cloud providers.

Why do you need disaster recovery certification courses?


From Hurricane Katrina to the WannaCry debacle and currently, to the COVID-19 pandemic, the business landscape has been battered by one form of disaster or the other. The frightening aspect of all this is that the rate of recurrence is growing aggressively in the past few years, owing to the mounting volumes of cyberattacks.

It is even more amazing when statistics demonstrate that, at most, 2 out of every 5 business lacks a solid disaster recovery and business continuity plan. Even out of those that do have this, only a handful test the plan regularly for flaws and relevance. This is what disaster recovery certification courses are created for.

EC-Council Disaster Recovery Professional (EDRP) certification is designed to educate and validate an applicant’s proficiency to strategize, plan, execute, and sustain viable business continuity and disaster recovery plan. Regardless of the size of your organization, you need an EDRP to stay relevant in this age. This dearth can be remedied by BC/DR experts who do not only recognize the significance of cloud services as a business continuity and disaster recovery plan but are also proficient to guarantee that your business incurs minimal costs when an incident occurs.

Source: eccouncil.org

Saturday, 11 July 2020

Open-Source Intelligence Makes Pentesting Very Easy

EC-Council Study Material, EC-Council Guides, EC-Council Certification, EC-Council Exam Prep

Pentesters have to work with large amounts of information. Finding this information can be done manually – that’s Option A. But this can be time-consuming since you’d have to sort this data by yourself because it might not be in a preferable format. Option B relies on open-source intelligence, or OSINT, which is the go-to method for most Penetration Testers off late.

Take Google Maps or even its Search Engine – the intelligence community refers to such publicly available sources of information as Open–Source Intelligence (OSINT). Tools that simplify OSINT gathering are powerful for Penetration Testing as they speed up and simplify workflow. However, it is ideal for a Penetration Tester to go through a Certification Program like EC-Council’s Certified Security Analyst (ECSA) Program before acquiring any of these tools. ECSA guarantees a thorough understanding of what OSINT is and how it is used in penetration testing.

What is Open-Source Intelligence? 


According to the U.S. public law, open-source intelligence is –

◉ Publicly available data
◉ Collected and analyzed timely to a targeted audience
◉ Used in an intelligence context

The term “open” refers to overt, which means “publicly available.” It is different from open-source software. Majorly, the data is obtained through various search engines. But with the existence of “deep web,” which covers billions of websites, databases, files, login pages, and a variety of paywalls, the content is far beyond the reach of Google, Bing, Yahoo, or any other search engine.


A data to qualify for being open-source intelligence, it should be available – 

◉ For public audience (for instance, news media content) 
◉ On public demand (for example, survey data) 
◉ By subscription or purchase (for example, industry journals) 
◉ In plain sight for casual observers 

It is indeed an unimaginable quantity of information that is rapidly growing, thus, making it a challenge to pace up with it. A security analyst must possess the required skills to deal with such a vast amount of data.  

What is closed source intelligence? 


Some intelligence collection is directly associated with sensitive data that can jeopardize the privacy of individuals involved. Closed source intelligence deals with private data, maintained and managed by the government, or is available through open enquires only. The intelligence only uses the data which is not publicly available. 

Is open-source intelligence an ethical issue? 

One of the primary traits of OSINT sources that they are legally available to public use and consuming them for intel does not breach any copyright or privacy laws. But it is a must that the organization using open–source intelligence should comply with all the applicable institutional standards.  

3 Best Ways to Use Open-Source Intelligence 


There are three major use cases of OSINT – 

Ethical Hacking  

Open–source is a part of the ethical hacking process, especially the reconnaissance phase. Reconnaissance or preparatory phase is where ethical hackers collect information about their target before executing an attack. Well, certified ethical hackers use open–source intelligence to gather information about an organization or an individual. It helps in profiling the target. 

Penetration Testing 

Generally, an information security analyst examines an organization’s system and network for security gaps and vulnerabilities capable of leading to unauthorized access. As it is just a subset of ethical hacking, the professionals do not try to exploit the vulnerabilities. The process ensures that the existing weaknesses will be remediated before threat actors can take advantage of them. OSINT helps in identifying these five major weaknesses –  

◉ Accidental data exposure  
◉ Open ports or unsecured internet-connected devices 
◉ Out of date software  
◉ Websites using old versions of CMS products 
◉ Data leaks 

A penetration tester ensures that the organization won’t suffer at the hands of cybercriminals. 

Listen to Online Chatter for Intel 

OSINT helps in identifying external threats by intercepting the “chatter” of cybercriminals from different publicly available sources. The professionals closely monitor open conversations on social media channels, forums, and other online platforms to identify the next target. For instance, several perpetrators like to brag before launching an attack. With the use of OSINT, security analysts can stop potential cyberattacks beforehand. 

Using this intelligence, security professionals can prioritize and eliminate the existing vulnerabilities of their organizations. To do so, the experts identify and correlate multiple data points for validating a genuine threat. For example, a warning post on social media platforms regarding upcoming cyber-attacks could be ignored, but what if it is a pattern of a known threat group. For such data, InfoSec analysts need OSINT. 

Note: Open-source intelligence is often combined with other intelligence forms for better results.  

Who uses OSINT? 


Professionals from national security and law enforcement are the primary consumers of OSINT. Apart from that, security analysts use it to retrieve data for addressing classified as well as unclassified intel requirements.  

What is Open-Source Intelligence Tools? 


There is a wide range of OSINT tools that help security analysts to carry out their responsibilities. One of the frequently used ones is Google – a search engine that reveals a lot than one can think of. Professionals also use Nmap in their OSINT strategy. Nmap is a popular network mapping tool that audits and discovers local and remote open network ports. 

Open-source intelligence is beneficial for all security disciplines. Yet, it requires the right combination of tools and techniques to suit the requirements of an organization. Apart from that, the successful use of OSINT demands the presence of a clear strategy with set objectives.

Source: eccouncil.org

Thursday, 9 July 2020

Modernizing Your Network Security Policy Post COVID-19

EC-Council Study Material, EC-Council Guides, EC-Council Exam Prep, EC-Council Learning

It is not enough to have a resilient traditional plan to survive the COVID-19 pandemic. You need an all-inclusive business continuity plan (BCP) that encompasses the restoration of your business operations and technology in the event of an unplanned incident. Your BCP or incidence response plan should include rapid response to security breaches and business restoration in case of a natural or man-made disaster.

With the growing dependence on cloud technology, it is becoming more critical that organizations secure every aspect of their online information and data. Since the pandemic has already had negative impacts on the global economy, the question now is whether organizations should redesign their network security policy post-COVID-19 pandemic or not.

A shabby network security policy is of no use to your organization. It merely renders your security an ad hoc process regulated by the network administrator at that particular moment. A solid network security policy keeps malicious operators out and also exercises control over likely dangerous users within your organization. Thus, you need a Certified Network Defender (CND) to assist with the construction and implantation of a well-rounded network security policy.

What is a network security policy?

Network security policy is a complex document that outlines the organization’s expectations regarding its security goals, scope, and responsibilities. The document itself is typically formulated by a committee and it is usually more than a few pages long. The network security policy summaries the organization’s security processes, mission statements, attitude to risks, and the penalties to be faced when the policies are flouted. However, this security policy goes beyond the mere notion of “keeping the bad guys out.”

It is a multifaceted document intended to regulate data access, applications of passwords and encryption, web-browsing behaviors, and email attachments, among others. The security policy stipulates these rules for persons or groups across the organization. These policies could be conveyed as a set of instructions that could be recognized by special purpose network hardware designed to secure the organization’s network.

Network security policies can be divided into two broad categories:

User Policies

Generally, user policies outline the boundaries of a user or group of users concerning the network or computer resources within the office environment. For instance, this policy states what employees are permitted to install in their computers and whether they can operate removable storages or not within the workplace.

IT Policies 

IT policies are generally constructed for the IT department and it outlines their limits towards the network resources in the organization. This security policy aims to secure the functions and procedures of IT departments.

Why is a network security policy important?


When working over the internet, LAN, WAN, or other internet-connected systems, network security is one of the most vital things to consider regardless of the size of your company. It is the responsibility of your organization to secure the physical assets, users, and data that operate within or travels across your networks.


Furthermore, the task gets more demanding as networks become more complex. According to some Gartner analysts, the more networks increase, the more difficult it is to implement the correct security policies at the appropriate network control points. Network security policy management helps your organization increase its visibility across all distributed environment. It also systematizes and regulates these policies to expand business security. 

What is the purpose of a network security policy? 


The purpose of a solid network security policy includes: 

◉ Defends users and information

◉ Outlines steps to follow in case of a security incident or breach 

◉ Authorizes employees to check, review, and investigate 

◉ Describes the form of technologies to apply and those that cannot be included in the network. 

◉ Serves as a standard for the next step in the development of network security 

◉ Designs the guidelines for expected behavior 

◉ Outlines the penalties of violations 

What should be in a network security policy? 


Creating and supervising a security package is a process that most businesses grow into after a long while. The first step is often to assign an incident responder or an employee that would oversee cybersecurity issues. Cybersecurity issues often follow the top-down method. This suggests that the security expectations are deliberated, outlined, and sanctioned by the top management committee. 

Most often, a single document may probably not resolve the demands of the whole users within a large organization. You need to ensure that the components of your network security policy are consistent with the needs of your audience. The fundamental requirements for network security policies are listed below: 

Acceptable Use Policy (AUP) 

Acceptable use policy (AUP) or appropriate use policy, is one of the most common security policy components. AUP outlines what users are permitted or not permitted to do on the many components of the system within an organization. This covers the kind of traffic that is permissible on the networks. For instance, an AUP may itemize the groups of banned websites. 

Incident Response (IR) Policy

An incident response policy is a prearranged procedure to how the organization will tackle an incident and mitigate its impacts. The objective of this policy is to define the procedure for managing an incident with regards to restricting the harm to consumers, business operations, and minimizing recovery costs and time. 

Access Control Policy (ACP) 

An access control policy (ACP) stipulates the access obtainable to workers as regards the company’s information and data systems. ACP also outlines issues such as the complexity of corporate passwords, network access controls, specifications for user access, and operating system software controls. An example of ACP is IAPP, also some ACP topics are stated in the NIST Access Control and Implementation Guide. 

Information Security Policy 

The information security policy of an organization is intended for workers. This helps them realize that certain regulations are in place that would hold them ransom when IT infrastructure and other sensitive corporate information and data are compromised. 

Business Continuity Plan 

A business continuity plan (BCP) is a unique business plan, which each organization exploits to communicate how they will respond in case of an emergency. The BCP will direct all endeavors throughout the organization and will implement the disaster recovery plan to reinstate data, hardware, and applications considered vital for business continuity. 

Change Management Policy 

Change management policy is a formal procedure for amending software development, IT security, and other security operations. The objective of this policy is to upsurge the consideration and responsiveness of the projected amendments across the organization. A change management policy also makes certain that all amendments are handled systematically to lessen any unpleasant effect on consumers and services. 

Disaster Recovery Policy 

A disaster recovery plan is generally designed as part of the grander organization’s continuity strategy and it covers both the inputs of cybersecurity and IT teams. Here, both the incident response plan and business continuity plan might be required. 

Remote Access Policy 

A remote access policy describes a document that describes and summaries the appropriate guidelines for employees to remotely connect to the organization’s internal networks. No one anticipated the COVID-19 pandemic and now most businesses are forced to operate remotely. The move to the cloud is not without its risks. Insufficient cybersecurity policies can render an organization’s network vulnerable and exposed to risks. 

What is network security policy management? 


IT teams and network administrators apply network security policy management to regulate their network situations and defend their businesses against growing risks. Most businesses are faced with widespread security policies or even manifold policies, which are almost impossible to sustain and hard to implement manually. Overly complex businesses and those that operate in a deeply controlled industry experience this difficulty more intensely. 

Even smaller companies tussle with locating the right time and resources to authenticate policy compliance. However, the fundamentals of a network security policy are to provide more visibility and control into system environments and user endeavor. This can only be reached if you have an operative process to accomplish your security policy. 

The most effective means of ensuring that your network security policy is up-to-speed, meet your policy expectations, and identifies and corrects anomalies rapidly, is to give your staffs’ network certification training or employ the services of a certified network security administrator

How can network certification training help you? 


If you want to secure your network against attackers, you need a solid network certification training. A well-organized network security training will expose you to the numerous routes and methods cybercriminals exploit to compromise your network and computers. You will also get hands-on training that allows you to think beyond the regular security techniques to the advanced security techniques.  

About CND: Certified Network Defender 

The Certified Network Defender (CND) is a certification program that creates savvy network administrators who are well-trained in identifying, defending, responding, and mitigating all network-related vulnerabilities and attacks. The CND certification program involves hands-on labs constructed through notable network security software, tools, and techniques that will provide the certified network administrator with real-world and up-to-date proficiencies about network security technologies and operations.

Source: eccouncil.org

Tuesday, 7 July 2020

5 Ways to Stop Network Security Threats

EC-Council Study Materials, EC-Council Guides, EC-Council Exam Prep

Countless network security breaches had occurred in the internet space over the years, leaving behind devastating consequences. According to a study, the odds of experiencing a data breach are 1 out of 4. The same study also revealed that, on average, businesses are spending $7.2 million on security breaches. That goes to show how hazardous network security threats can be for your business if left unchecked.

Since cybersecurity breach is an unforeseeable threat, as a business owner – whether you own a corporation or small to medium-sized business – you should build strong network security defenses around your company’s network.

The most effective way to combat network security threats is to know the various threat-proof techniques that are most applicable for your business and be proactive at implementing them. At the same time, you can always sign up for a network security engineer course, which will teach you everything you need to know about network security.

Popular Network Threats



How to Stop Network Security Threats 


1.  Boost physical security  

If you install your network server(s) within the premise of your company, ensure you secure the facility tightly. You may need to hire security guards to protect and prevent insider incidents. You may also install a reliable digital lock, strong enough to discourage network intruders from having physical access to your servers.  

2.  Educate Your Employees About Security Measures 

Taking up an advanced network security course such as Certified Network Defender will upskill your network administrator with adequate network security skills to defend your organization against vicious attacks. This is the perfect way to ensure they’re up to date with the newest technologies. Apart from your network administrator, you should provide training to all your employees. Incentivize them on network various types of network security attacks, how to identify threats, and whom to contact. Follow up on the training, updating your employees about the latest potential security threats. 

3.  Reinforce Your Security Access Control 

Often, network security breaches occur when an unauthorized person gained access to the company’s passwords. In that case, ensure you create a unique password for each system, using a combination of lower case letters, upper case letters, special characters, and numeric characters. Ensure that all default passwords are changed to secure passwords. In many instances, change your passwords frequently, and always keep them away from authorized eyes. You can also adopt multilevel authentication alongside the fingerprint scanner. This can serve as an additional layer of security to further bolster the overall network security of your company. 

4.  Use Network Protection Measures 

Network security protection measures are part of your first line of defense against cyber attackers. Take note of the following actions that’ll help enhance your network security: 

◉ Conduct proper maintenance, such as updating outdated software
◉ Install a firewall 
◉ Use IDS/IPS to help tract potential packet floods 
◉ Use network segmentation 
◉ Install a Virtual Private Network (VPN) 

5.  Install Network Monitoring Software 

Network monitoring software provides early warning at the slightest instance of detecting a threat. It does this by keeping track of the entire IT infrastructure, establishing contact with all devices, and the system. 

The network monitoring software covers three critical areas of your network: 

◉ Monitors the entire security systems: It regularly scans your system firewalls and virus scanners to ensure operational reliability. 

◉ Measures bandwidth bottlenecks: Malware attack could slow down system response time, allowing the attacker to steal or control sensitive data. The monitoring software checks for inconsistency on your system and report them, allowing the administrator to analyze the data and quickly act on it. 

◉ Inspects environmental parameters: Network monitoring software enables surveillance to check all surrounding areas. Some monitoring software is built with sensory technology to detect smoke or gas formation. 

Some of these specialized devices can be configured to trigger an alarm once it detects security breaches such as when the door or window of your server is opened.

Source: eccouncil.org

Saturday, 4 July 2020

Why do you need a CISO in the Boardroom?

EC-Council Study Materials, EC-Council Tutorial and Material, EC-Council Cert Exam

Many companies are beginning to realize the significant role of a Chief Information Security Officer (CISO) in business decisions, especially with the increase in network security mishaps. Besides dealing with daily threats, organizations are struggling to meet the ever-changing security regulations. However, for CISOs to perform at their top level, they must be equipped not only with the technical expertise and leadership skills. Still, they must understand every section of a company’s security model from a business perspective.

While this is something that can easily be explained, the skills needed for this role can only be attained through years of experience and a recommended training designed specifically for chief information security officers.

Who is a CISO? What is the role of a CISO?


A CISO is an executive in charge of Business Information Security, specializing in the management of technical security issues. The primary role of CISO is to oversee and ensure that the business unit of an organization recognizes that information security is an integral part of every business. Also, the executive helps in implementing and translating security policies and procedures. Other roles of CISOs includes:

◉ Analyzes immediate threats in real-time and triages when an organization is under attack.

◉ Prevents fraud by ensuring that no internal staff steals or misuse a company’s data.

◉ Ensures that all staff knows more about the governance risk and compliance, providing investigation and forensics.

◉ Evaluates and ensures that only authorized people get access to classified information.

What are the duties and responsibilities of CISO?


The following are the general duties and job responsibilities of a CISO, depending on the size of the organization:

◉ Evaluates, develops a rapport, and advises other executives on how to address security threats while working on a risk management program for an actionable plan.

◉ Performs a risk assessment plan that can reveal vulnerable areas within the organization.

◉ Performs asset assessment plan to classify organization assets based on their criticality and business level.

◉ Strategically develops a security roadmap consisting of budget size and prioritized initiatives.

◉ Ensuring that the organization complies with security policies and procedures.

◉ Develops, maintains, and updates security training and awareness plan.

◉ Prepares and communicates a response to security incidents.

◉ Examines the security architecture of the company for new projects and applications.

◉ Managing the organization’s compliance and governance as per the regulations in the country.

How to effectively discuss security as a competitive advantage and positive element for the organization to embrace:


What makes a good CISO?  


Here are a few key attributes of a CISO: 

Leadership 

A good CISO is friendly, can communicate, and is approachable. Thier leadership skills become evident in areas like developing, planning, and managing thier team of security experts, establishing a positive working condition. They take the lead in supervising all security-related operations. They must have the ability to listen and make risk-based business-oriented decisions. 

Excellent security knowledge 

For a CISO to be effective, they must understand and be able to interpret complex and analytical security problems and can provide a practical solution. They must be able to communicate and explain technical details understandable to other executives. They can also tolerate risk, owing to his high social engineering skill. They are highly patient, as changing everything in an organization takes patience and endurance. 

Excellent business knowledge 

CISOs security knowledge must balance with the business goals of the organization in a way that security risk can be managed without disrupting business operations. This will require a high level of knowledge to understand business operations required to secure the organization’s data. 

If you are an aspiring CISO then this session is for you: 


About Certified CISO Certification 


EC-Council’s Certified CISO program provides first of its kind security training to produce top-level security executives, focusing majorly on the application of technical knowledge. Bringing together all the components required for C-Level positions, the CCISO program combines audit management, governance, IS controls, human capital management, strategic program development, and the financial expertise vital to leading a highly successful IS program.

Source: eccouncil.org

Thursday, 2 July 2020

How to secure your business with honeypots

EC-Council Certification, EC-Council Guides, EC-Council Certifications, EC-Council Learning, EC-Council Exam Prep

Do you ever wonder how cybersecurity professionals hunt cyber criminals down on the internet? ‘Honeypot’ could be the answer. As a security measure to restrict intruders’ access, you might strengthen network security. Contrary to this, cyber professionals use ‘honeypots’ to attract cybercriminals. A honeypot is a computer system that detects attacks or diversifies from a legitimate target. It is intended to mimic expected targets of cyberattacks. It is also used to gain information on the operations of cybercriminals.

The concept of a honeypot is quite simple. It does not chase attackers, rather it attracts them through a false illegitimate target. Hence, the name, ‘Honeypot.’

Watch this to understand what honeypot is and how it works: 


What does a honeypot do? 


In a hypothetical scenario, a finance company manager may set up a honeypot in the form of the company’s network for outsiders. Similarly, it goes with other businesses like banks, healthcare, etc. having internet-connected systems. These businesses monitor traffic to such honeypots and, consequently, understand the movement of cybercriminals. Significantly, you can determine the security measures and the ones that you must take to improve your business. 

A honeypot can be configured resembling anything on the network—for example, web server, file server, print server, etc. When a cyber attacker comes across a potential honeypot probing to be a legitimate target, they perform similarly as if they have dealt with the legitimate one. 

A honeypot solution is applicable even when an Artificial Intelligence (AI) or Machine Learning (ML) methodologies exist at the endpoint. Honeypots can be inexpensively deployed, and as they receive manageably less traffic, while their logs are of immense value. Any alert or information received may be either a malicious activity or a misconfigured system on the network. Though the information helps in identifying bad elements lurking on the network; it also assists you in understanding whether anything has been misconfigured. 

While researchers use honeypots to study the methods of attackers, they are of more significance to defenders.  

5 advantages that honeypots bring to the business – 


1. Greater scope of success – 

The cyber attackers, as a practice test against the effectiveness of their malware against the popular anti-malware scanners and other security measures. Whereas further observation shows that the advanced attackers have the resources and means of deploying their attacks successfully. This is where honeypots play an important role. They fill the gaps because attackers seek time to predict the use and to counter the defenses. Simultaneously, production honeypots will have a low false-positive rate due to the non-accessibility of legitimate users.  

2. Creates a confused scenario – 

Honeypots can also trap the users and make them slow down within the company’s network. Otherwise, with the help of a virtual system, the company can create decoys to distract the attackers. In turn, it delays the objective of attackers from finding valuable data. To understand decoys, they move the threats from real assets to fake ones and subsequently alert the defenders about the threats.  

A significant approach would be using honey tokens to replace fake data in the database records. The same is achieved by instructing firewalls to alert on the unique packets. Consequently, a company can detect how the user accesses the information or downloads the same. 

3. Though time-consuming, it is effective – 

There are two types of honeypots that any company can deploy. The first being a research honeypot, where a virtual system hosting a vulnerable operating system is assigned to a network having connected to an internet connection. However, research honeypots consume a lot of time. But they consider as a best practice to learn about the attackers and their movements. The research honeypots are watched for threats, and then the first line defense team analyzes the attack logs or behavior. Such honeypots are rarely used in businesses unless otherwise, the core process is security. Another type of honeypot is a production honeypot that emulates value addition to the business. They can be in the form of a workstation, database, web server, or document. Due to the low-interactive nature of production honeypots, they do not require continuous monitoring. The security team establishes the honeypots and then gets along with other tasks until SOC analysts raise an alert. 

4. Help training your security team – 

As the cybersecurity workforce is in short supply, honeypots serve as training tools. By watching the attackers’ movements, the defenders can learn new techniques. The security teams often deploy honeypots to learn the attackers’ behavior. The SOC analysts follow the footsteps of the cyber attackers and study their movements to understand how the attacks can be combated at the intermediary stages in their network. 

5. Other ancillary options

There are other free tools and technologies to adopt and implement a honeypot mechanism. 

Source: eccouncil.org

Tuesday, 30 June 2020

Network Protocols – Why do you need them?

EC-Council Study Materials, EC-Council Guides, EC-Council Learning, EC-Council Prep

A network protocol includes the pre-defined rules and conventions for communication between network and devices connected. These include identifying and establishing connections among devices. Besides, there are formatting rules specifying packaging, sending, and receiving messages. Additionally, there are protocols for message acknowledgment and data compression too. It also enables the establishment of reliable and high-performing network communication.

In the absence of protocols, devices would not be able to understand the electronic signals that they send while communicating over network connections. Nowadays, protocols use packet switching techniques to send and receive messages in the form of packets. These messages are again divided, collected, and reassembled at their destination. Numerous computer network protocols serve defined purpose and environment.

About Protocols – Ipv4 and IPv6 Explained 


Internet protocols 


Internet Protocols (IP) are popular network protocols. Even other higher-level protocols like TCP, UDP, FTP, and HTTP integrates with IP providing additional capabilities. On the other hand, there are lower-level protocols like ICMP and ARP that again exist with IP. The higher-level protocols interact closely with applications such as web browsers, compared to lower-level protocols. The lower-level protocols, in turn, interact with computer hardware like network adapters. The group of lower and higher levels of network protocols stands as a protocol family.  

Wireless network protocols 

Wireless network protocols are gaining significance due to increasing connectivity with wi-fi, Bluetooth, and LTE. These wireless networks support roaming mobile devices and other electronic devices because they are not directly connected with a wire.  

Network Routing Protocols 

A routing protocol can identify other routers, manage the route between source and destination. It defines the route path to carry network messages and dynamic routing decisions. Examples of routing protocols are OSPF, BGP, and EIGRP. Subsequently, they meet the specific purpose of the network routers on the internet. 

An introduction to the types of network protocols  


1. Transmission Control Protocol (TCP)

It is a popular communication protocol in network communication. TCP protocol divides the message into a series of packets and sends them from source to destination that reassembles at the destination. 

2. Internet Protocol (IP)

IP is an addressing protocol and is mostly used with TCP. Originally, TCP/IP is the most common protocol that connects the networks. Henceforth, the IP protocol addresses communication in packets and helps in routing through different nodes in a network until it reaches the destination system. 

3. Post office Protocol (POP)

POP3 is designed to receive incoming e-mails. 

4. User Datagram Protocol (UDP)

It is used as a substitute communication protocol to Transmission Control Protocol (TCP). Primarily, it creates loss-tolerating and low-latency linking between different applications. 

5. Simple mail transport Protocol (SMTP)

SMTP sends and distributes outgoing e-mail. 

6. File Transfer Protocol (FTP)

FTP transfers files from one system to another. Besides, the types of files that FTP support are program files, multimedia files, text files, and documents, etc. 

7. Telnet

Telnet is based on rules designed to connect two systems. In this case, the connecting process is a remote login. The requesting system for connection is the local computer, and the accepting system is the remote computer. 

8. Hyper-Text Transfer Protocol (HTTP)

HTTP transfers hypertext among two or more systems. It follows client-server principles that enable a client system to establish a connection for a request with the server machine. Following this, the server acknowledges the client’s request and responds accordingly. 

9. Hyper-Text Transfer Protocol Secure (HTTPS)

HTTPS stands for HyperText Transfer Protocol Secure. It is a standard protocol that secures the communication between two machines. Hence, the protocol establishes communication by using the browser and fetching data from a webserver. Similar to HTTP, HTTPS also transfers the data in the hypertext format but the encrypted format. Hence, HTTPS ensures data security throughout the transfer of packets. 

10. Gopher

Gopher works on the client/server principle. It is a collection of rules to implement searching, retrieving as well as displaying documents from isolated sites. 

Implementing network protocols 


The latest operating systems come with in-built software services that support network protocols default way. Previously, web browser applications supporting high-level protocols required to function, contain software libraries. Profoundly, the software libraries, in turn, support web application browser in execution. Similarly, the lower-level TCP and routing protocols support hardware including silicon chipsets to enhance network performance. 

Packets with an encrypted binary data are transmitted over a network. Furthermore, to store information about the sender of the message, many of the protocols come with a header. The network protocols add a description in the beginning about the sender as well as the receiver of the message. Additionally, few protocols also add a footer. Herewith, the network protocols work on its way in identifying the headers and footers while moving the data among devices.  

Are you looking to become a Network Defender?


Certified Network Defender (C|ND) is a vendor-neutral certification which is a comprehensive network security program. Identically, it is a hands-on, lab-intensive, and skill-based program that is based on a job task analysis and cybersecurity education framework, in accordance with NICE. Moreover, C|ND has mapped to the Department of Defense (DoD) job roles and is designed after extensive market research and surveys.

Source: eccouncil.org