https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207-draft2.pdf
A blog for Security Architects, CISOs and anyone else responsible for protecting their organisation's information assets
Friday, 8 May 2020
Thursday, 26 December 2019
Friday, 20 December 2019
Sunday, 24 November 2019
We the Sales Engineers
Interesting website / podcast etc. aimed specifically at sales engineers.
https://wethesalesengineers.com
https://wethesalesengineers.com
Sunday, 3 November 2019
Monday, 14 October 2019
Friday, 11 October 2019
Tools to Implement SANS Top 20
A few years out of date, but very cool paper.
https://www.alienvault.com/blogs/security-essentials/free-and-commercial-tools-to-implement-the-sans-top-20-security-controls-part-1/
https://www.alienvault.com/blogs/security-essentials/free-and-commercial-tools-to-implement-the-sans-top-20-security-controls-part-1/
Wednesday, 9 October 2019
NIST standards
800-30 - Guide for Conducing Risk Assessments
https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
800-37: Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy
https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
800-39 - Managing Information Security Risk: Organization, Mission, and Information System View
https://csrc.nist.gov/publications/detail/sp/800-39/final
800-53 - Security and Privacy Controls for Information Systems and Organizations
https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/draft
800-154 - Guide to Data-Centric System Threat Modeling
https://csrc.nist.gov/publications/detail/sp/800-154/draft
800-115 - Penetration Testing
800-60: Volume 1: Guide for Mapping Types of Information and Information Systems to Security Categories
https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-60v1r1.pdf
https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
800-37: Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy
https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
800-39 - Managing Information Security Risk: Organization, Mission, and Information System View
https://csrc.nist.gov/publications/detail/sp/800-39/final
800-53 - Security and Privacy Controls for Information Systems and Organizations
https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/draft
800-154 - Guide to Data-Centric System Threat Modeling
https://csrc.nist.gov/publications/detail/sp/800-154/draft
800-115 - Penetration Testing
800-60: Volume 1: Guide for Mapping Types of Information and Information Systems to Security Categories
https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-60v1r1.pdf
NIST SP 800-53A,Guide for Assessing the Security
Controls in Federal Information Systems
Tuesday, 8 October 2019
Monday, 7 October 2019
Sunday, 6 October 2019
Sunday, 22 September 2019
Microsoft STRIDE
This is a useful blog post for threat modelling.
https://www.microsoft.com/security/blog/2007/09/11/stride-chart/
https://www.microsoft.com/security/blog/2007/09/11/stride-chart/
Sunday, 8 September 2019
Friday, 6 September 2019
NIST Cyber Security Framework
Good 2019 paper on the NIST CSF:
https://www.oas.org/en/sms/cicte/docs/OAS-AWS-NIST-Cybersecurity-Framework(CSF)-ENG.pdf
https://www.oas.org/en/sms/cicte/docs/OAS-AWS-NIST-Cybersecurity-Framework(CSF)-ENG.pdf
The US identified 16 critical infrastructure sectors: Chemical; Commercial Facilities; Communications; Critical Manufacturing; Dams; Defense Industrial Base; Emergency Services; Energy; Financial Services; Food and Agriculture; Government Facilities; Healthcare and Public Health; Information Technology; Nuclear Reactors, Materials, and Waste; Transportation Systems; and Water and Wastewater Systems.
Tuesday, 13 August 2019
MITRE ATT&CK
High level overview of the MITRE ATT&CK model by Exabeam.
https://www.exabeam.com/information-security/what-is-mitre-attck-an-explainer/
https://www.exabeam.com/information-security/what-is-mitre-attck-an-explainer/
Sunday, 9 June 2019
SSL Inspection
The following gives a very good overview of the pros and cons of SSL inspection. Some I hadn't thought about.
https://www.helpnetsecurity.com/2017/03/08/https-interception-dilemma/
Good document from Symantec describing certificate pinning:
https://www.symantec.com/content/dam/symantec/docs/white-papers/certificate-pinning-en.pdf
https://www.helpnetsecurity.com/2017/03/08/https-interception-dilemma/
Good document from Symantec describing certificate pinning:
https://www.symantec.com/content/dam/symantec/docs/white-papers/certificate-pinning-en.pdf
Subscribe to:
Posts (Atom)