Feb 21 2020

Hunting For Privilege Escalation in Windows Environment

Category: Windows SecurityDISC @ 10:33 pm


Privilege Escalation FTW
httpv://www.youtube.com/watch?v=yXe4X-AIbps

Windows Privilege Escalation Techniques (Local)
httpv://www.youtube.com/watch?v=PC_iMqiuIRQ

Learn System Hacking E13: Windows 10 Privilege Escalation
httpv://www.youtube.com/watch?v=5Q6vEyLY7kY



Subscribe to DISC InfoSec blog by Email


Jan 29 2020

Tokenization vs. Encryption vs. Aliasing – How to Truly Minimize Compliance Risk

Category: Cryptograghy,Information SecurityDISC @ 10:17 pm

 

https://en.wikipedia.org/wiki/Tokenization_(data_security)

Source: Tokenization vs. Encryption vs. Aliasing – How to Truly Minimize Compliance Risk

The tokenization of things | Matthew Roszak | TEDxSanFrancisco
httpv://www.youtube.com/watch?v=Rto-earGcxg


Subscribe to DISC InfoSec blog by Email


Jan 19 2020

NIST Releases Version 1.0 of Privacy Framework

Category: NIST PrivacyDISC @ 11:08 pm

Source: NIST Releases Version 1.0 of Privacy Framework

Tool will help optimize beneficial uses of data while protecting individual privacy

The best practice guide for an effective privacy function

Practice Guide

Open a PDF file NIST Releases Version 1.0 of Privacy Framework

Developing the NIST Privacy Framework – Part 1
httpv://www.youtube.com/watch?v=W-snx9jRFf4

Developing the NIST Privacy Framework – Part 2
httpv://www.youtube.com/watch?v=gZ7ED0t09zk

Developing the NIST Privacy Framework – Part 3
httpv://www.youtube.com/watch?v=x6lTHu1VbiM



Subscribe to DISC InfoSec blog by Email


Jan 03 2020

The Cybersecurity Guide For Leaders in Today’s Digital World

Category: cyber securityDISC @ 10:55 am

The Cybersecurity Guide For Leaders in Today’s Digital World – World Economic Forum

[pdf-embedder url=”https://blog.deurainfosec.com/wp-content/uploads/2020/01/WEF_Cybersecurity_Guide_for_Leaders.pdf”]


The best practice guide for an effective infoSec function

Practice Guide

Open a PDF file The Cybersecurity Guide For Leaders in Today’s Digital World.




Annual Meeting on Cybersecurity 2019 | Enabling Leadership for a Secure Digital Future | World Economic Forum


Cybersecurity in a Digital World. The Future is Bright
httpv://www.youtube.com/watch?v=Tu1dkliqpHQ






Subscribe to DISC InfoSec blog by Email


Dec 30 2019

Threat Modeling for Data Protection

Category: Threat ModelingDISC @ 10:52 pm

 

Threat Modeling for Data Protection

When evaluating the security of an application and data model ask the questions:

  • What is the sensitivity of the data?
  • What are the regulatory, compliance, or privacy requirements for the data?
  • What is the attack vector that a data owner is hoping to mitigate?
  • What is the overall security posture of the environment, is it a hostile environment or a relatively trusted one?

Data When threat modeling, consider the following common scenarios:

Source: Threat Modeling for Data Protection



Threat Modeling in 2019
httpv://www.youtube.com/watch?v=ZoxHIpzaZ6U






Subscribe to DISC InfoSec blog by Email


Dec 19 2019

ISO/IEC 27701 2019 Standard and Toolkit

Category: GDPR,Information Privacy,ISO 27kDISC @ 12:35 pm

ISO/IEC 27701 is the international standard that serves as an extension to an ISO 27001/ ISO 27002 #ISMS (information security management system). It provides guidelines for implementing, maintaining, and continually improving a #PIMS (privacy information management system).

Develop a privacy information management system as an extension to your ISO 27001-conformant ISMS with ISO/IEC 27701. Supports GDPR compliance.

SECURITY TECHNIQUES — EXTENSION TO ISO/IEC 27001 AND ISO/IEC 27002 FOR PRIVACY INFORMATION MANAGEMENT SYSTEM #PIMS

Key features:

* The Standard includes mapping to the GDPR, ISO/IEC 29100, ISO/IEC 27018, and ISO/IEC 29151
* Integrates with other management system standards, including the information security standard, ISO/IEC 27001
* Provides PIMS-specific guidance for ISO/IEC 27002
* Specifies requirements and provides guidance for establishing, implementing, maintaining, and continually improving a PIMS
* Supports compliance with the GDPR and DPA 2018
* Provides guidance for data controllers and processors responsible for processing personal data


ISO 27701 Gap Analysis Tool


Achieve full compliance with ISO 27701:2019
The ISO 27701 Gap Analysis Tool has been created to help organizations identify whether they are meeting the requirements of the Standard and where they are falling short. Note that this tool assumes that you have a complete and functioning ISO 27001:2013 ISMS (information security management system).

It helps organizations prioritise work areas in order to expand an existing ISMS to take account of privacy. It also gives organizations direction, helping project managers identify where to start.


What does the tool do?

  • Contains a set of sample audit questions
  • Lists all ISO 27701:2019 requirements, identifying where documentation is mandatory for compliance
  • Provides a clear, colour-coded report on the state of compliance
  • The executive summary displays the results of compliance in a clear table so that you can report on your results and measure the closure of gaps.

  • The tool is designed to work in any Microsoft environment. It does not need to be installed like software, and it does not depend on complex databases; it relies on human involvement.



    ISO 27701 The New Privacy Extension for ISO 27001
    httpv://www.youtube.com/watch?v=-NUfTDXlv30

    Quick Guide to ISO/IEC 27701 – The Newest Privacy Information Standard
    httpv://www.youtube.com/watch?v=ilw4UmMSlU4

    General Data Protection Regulation (GDPR) | The California Consumer Privacy Act (CCPA)

    Subscribe to DISC InfoSec blog by Email

    Tags: CCPA, gdpr, iso 27001, iso 27002, ISO 27701, ISO27701, PIMS


    Dec 15 2019

    Global Threat Detection Report

    Category: Cyber Threats,Threat detectionDISC @ 1:22 pm



    2019 Global Threat Detection Report

    2019 Global Threat Detection Report

    via CrowdStrike





    The best practice guide for an effective infoSec function

    Practice Guide

    Open a PDF file 2019 Global Threat Detection Report.




    2019 Global Threat Report- The 1-10-60 Rule
    httpv://www.youtube.com/watch?v=y70R2vUbvls

    World Economic Forum Global Risks Report 2019
    httpv://www.youtube.com/watch?v=kwQMsBWd-jo


    “Threat Detection & Prevention” appliances




    Subscribe to DISC InfoSec blog by Email


    Dec 13 2019

    Data Security Solutions for Fintech Startups

    Category: data securityDISC @ 11:33 am

    By Ena Kadribasic on Security

    The fintech sector has brought consumers an endless stream of modern offerings that have enabled them to ditch several outdated banking and lending products.

    Companies now have advanced B2B payment solutions at their fingertips, and online financial solutions have never been more convenient – largely thanks to the progress made by fintech startups.

    But, despite being on the cutting edge of digital financial products, young fintech companies are at a disadvantage in a wildly important arena: data security.

    With limited resources, growing compliance regulations around the world, and a constantly-evolving list of increasingly dangerous cyber threats, fintech startups face a uniquely difficult uphill battle.

    And, with data breaches continuing to leer as an ever-present security threat, fintech firms are turning to new and advanced approaches to data privacy.

    But, first, what do we mean when we talk about data security for startups?

    Source: Data Security Solutions for Fintech Startups


    Subscribe to DISC InfoSec blog by Email

    Tags: Data security solution, Fintech


    Dec 07 2019

    NIST CyberSecurity Framework and ISO 27001

    Category: Information Security,ISO 27k,NIST CSFDISC @ 6:54 pm

    NIST CyberSecurity Framework and ISO 27001

    [pdf-embedder url=”https://blog.deurainfosec.com/wp-content/uploads/2019/12/NIST_ISO_Green_Paper_NEW_V3___Final_Edits.pdf”]

    How to get started with the NIST Cybersecurity Framework (CSF) – Includes Preso

    Written Information Security Program (WISP) – ISO 27002, NIST Cybersecurity Framework & NIST 800-53
    httpv://www.youtube.com/watch?v=B8QjwD6f4rc

    What is ISO 27001?
    httpv://www.youtube.com/watch?v=AzSJyfjIFMw

    Virtual Session: NIST Cybersecurity Framework Explained
    httpv://www.youtube.com/watch?v=nFUyCrSnR68





    Enter your email address:

    Delivered by FeedBurner

    Tags: iso 27001, NIST CSF, NIST RMF


    Nov 30 2019

    Cybersecurity Through the CISO’s Eyes

    Category: CISO,vCISODISC @ 12:52 pm

    infographic via Rafeeq Rehman

    PERSPECTIVES ON A ROLE

    Cybersecurity Through the CISO’s Eyes

    Cybersecurity CISO Secrets with Accenture and ISACA

    Cybersecurity Talk with Gary Hayslip: Aspiring Chief Information Security Officer? Here are the tips

    So you want to be a CISO, an approach for success By Gary Hayslip


    Our most recent articles in the CISO category.

    Explore latest Chief Information Security Officer titles

    Tags: CISO, Gary Hayslip, vCISO


    Nov 21 2019

    Five Keys for Building a Security program

    Category: Information SecurityDISC @ 11:00 pm


    https://www.sans.org/media/critical-security-controls/Poster_CIS-Security-Controls_2018.pdf
    The best practice guide for an effective infoSec function

    Five Keys for Building a Security program

    Open a PDF file Five Keys for Building a Security Program.

     


    Enter your email address:

    Delivered by FeedBurner


    Nov 18 2019

    CISO or vCISO? The Benefits of a Contractor C-level Security Role

    Category: CISODISC @ 12:40 pm

    Read how a virtual chief information security officer (vCISO) can help you uplift a struggling information security program.

    Source: CISO or vCISO? The Benefits of a Contractor C-level Security Role

    Webinar: vCISO vs CISO – Which is the right path for you?
    httpv://www.youtube.com/watch?v=HIvuIIQob7o

    CISO as a Service or Virtual CISO
    httpv://www.youtube.com/watch?v=X8XSe3ialNk

    The Benefits of a vCISO
    httpv://www.youtube.com/watch?v=jQsG-65wxyU


    Subscribe to DISC InfoSec blog by Email

    Tags: vCISO


    Oct 21 2019

    6 Essential Pillars for InfoSec Prioritization

    Category: Information SecurityDISC @ 11:22 am

    It may be time to Think Differently in security.

    Do you know which of your vulnerabilities are critical, those which can wait a day, vs ones that are just noise? Read this handy guide to get the 6 essential pillars for comprehensive InfoSec prioritization:



    The Five Laws of Cybersecurity | Nick Espinosa | TEDxFondduLac
    httpv://www.youtube.com/watch?v=_nVq7f26-Uo

    Your 5 Year Path: Success in Infosec
    httpv://www.youtube.com/watch?v=Uv-AfK7PkxU

    Top 20 Security Controls for a More Secure Infrastructure


    Subscribe to DISC InfoSec blog by Email

    Tags: isms, Secure Infrastructure


    Oct 16 2019

    CyberSecurity for Digital Operations

    Category: cyber security,data securityDISC @ 1:09 pm

    DigitalSecurity

     
    This report examines the general state of security within business today, exploring the hurdles that are preventing companies from an ideal security posture and suggesting the steps that can lead to improved security in the digital economy.

    As the technology industry enters the next phase of maturity, there are more questions about the implications of emerging trends operating on a global scale. Aside from social impact ramification, utmost reliance on digital data and the sweeping collection of personal information are highlighting the critical nature of information security and privacy.

    Digital Transformation: From AI and IoT to Cloud, Blockchain, and Cybersecurity | MIT PE
    httpv://www.youtube.com/watch?v=NwwazhND9BA

    Inside the CenturyLink Security Operations Center: Securing Your Digital Business
    httpv://www.youtube.com/watch?v=_UyhYPOnNcY

    The Convergence (and Divergence) of IT and OT Cyber Security


    Subscribe to DISC InfoSec blog by Email


    Oct 14 2019

    The best practice guide for an effective infoSec function

    Building ISMS

    The best practice guide for an effective infoSec function: iTnews has put together a bit of advice from various controls including ISO 27k and NIST CSF to guide you through what’s needed to build an effective information security management system (ISMS) within your organization.

    This comprehensive report is a must-have reference for executives, senior managers and folks interested in the information security management area.

     

    Practice Guide

    Open a PDF file The best practice guide for an effective infoSec function.

    How to Build a Cybersecurity Program based on the NIST Cybersecurity Framework
    httpv://www.youtube.com/watch?v=pDra0cy5WZI

    Beginners ultimate guide to ISO 27001 Information Security Management Systems
    httpv://www.youtube.com/watch?v=LytISQyhQVE

    Conducting a cybersecurity risk assessment


    Subscribe to DISC InfoSec blog by Email

    Tags: isms


    Oct 08 2019

    The Adventures of CISO

    Category: CISODISC @ 11:09 am


    The Adventures of CISO Ed & Co.

    7 Types of Experiences Every Security Pro Should Have

    Ten Must-Have CISO Skills

    What CISO does for a living

    CISOs and the Quest for Cybersecurity Metrics Fit for Business

    CISO’s Library


    Subscribe to DISC InfoSec blog by Email


    Oct 07 2019

    Top 10 Cybersecurity Writing Mistakes

    Category: Cybersecurity WritingDISC @ 12:39 pm

    Want to strengthen your writing in under an hour? Watch the video below to help you avoid the top 10 writing mistakes you may encounter when working as a cybersecurity professional.

    Source: Top 10 Cybersecurity Writing Mistakes

    Top 10 Writing Mistakes in Cybersecurity and How You Can Avoid Them
    httpv://youtu.be/V7lO7UgxQV4

    SANS Writing Course | Writing CheatSheet

    Burying the Main Point – Common Cybersecurity Writing Mistakes
    httpv://www.youtube.com/watch?v=xM6PgakpLgU

    Overstuffing the Paragraphs – Common Cybersecurity Writing Mistakes


    Subscribe to DISC InfoSec blog by Email

    Tags: Cybersecurity Writing


    Oct 06 2019

    A CISO’s Guide to Bolstering Cybersecurity Posture

    iso27032

    When It Come Down To It, Cybersecurity Is All About Understanding Risk

    Risk Management Framework for Information Systems

    How to choose the right cybersecurity framework

    Improve Cybersecurity posture by using ISO/IEC 27032
    httpv://www.youtube.com/watch?v=NX5RMGOcyBM

    Cybersecurity Summit 2018: David Petraeus and Lisa Monaco on America’s cybersecurity posture
    httpv://www.youtube.com/watch?v=C8WGPZwlfj8

    CSET Cyber Security Evaluation Tool – ICS/OT
    httpv://www.youtube.com/watch?v=KzuraQXDqMY


    Subscribe to DISC InfoSec blog by Email

    Tags: cybersecurity posture, security risk management


    Oct 04 2019

    5 Updates from PCI SSC That You Need to Know

    Category: Security ComplianceDISC @ 9:39 pm

    As payment technologies evolve, so do the requirements for securing cardholder data.

    Source: Slideshows – Dark Reading

    PCI DSS: Looking Ahead to Version 4.0

    3 Primary Goals for PCI DSS Version 4.0

    What is PCI DSS? | A Brief Summary of the Standard
    httpv://www.youtube.com/watch?v=szVmMxWORBc

    How to Achieve PCI DSS Compliance on AWS
    httpv://www.youtube.com/watch?v=qx4OwP0VIyU


    Subscribe to DISC InfoSec blog by Email

    Tags: pci dss, PCI SSC


    Oct 01 2019

    CCPA – The California Consumer Privacy Act

    Category: Security ComplianceDISC @ 4:51 pm

    More detail on site: Steps to CCPA Compliance roadmap

    Everything You Need To Know About CCPA 2018



    Subscribe to DISC InfoSec blog by Email

    Tags: CCPA


    « Previous PageNext Page »