Forwarded from yug🦠slavskiy
Команда ATT&CK выпустила матрицу для сетевых устройств:
https://attack.mitre.org/matrices/enterprise/network/
https://attack.mitre.org/matrices/enterprise/network/
New NICE Strategic Plan Includes Focus on Discovery of Cybersecurity Careers, Transforming Learning, and Modernizing Talent Management | NIST
https://www.nist.gov/news-events/news/2020/10/new-nice-strategic-plan-includes-focus-discovery-cybersecurity-careers
https://www.nist.gov/news-events/news/2020/10/new-nice-strategic-plan-includes-focus-discovery-cybersecurity-careers
NIST
New NICE Strategic Plan Includes Focus on Discovery of Cybersecurity Careers, Transforming Learning, and Modernizing Talent Management
The National Initiative for Cybersecurity Education (NICE) today released the
Understanding and Addressing CISO Burnout
https://www.isaca.org/resources/news-and-trends/isaca-podcast-library/understanding-and-addressing-ciso-burnout
https://www.isaca.org/resources/news-and-trends/isaca-podcast-library/understanding-and-addressing-ciso-burnout
ISACA
Understanding and Addressing CISO Burnout
A recent survey found that 90 percent of CISOs would take a pay cut if it meant better work/life balance. There are many reasons for CISO burnout, and a broader cultural shift is needed to combat the excessive pressure put on CISOs. In this podcast episode…
Bringing PRE into Enterprise. Integrating the scope of PRE-ATT&CK… | by Adam Pennington | MITRE ATT&CK® | Oct, 2020 | Medium
https://medium.com/mitre-attack/the-retirement-of-pre-attack-4b73ffecd3d3
https://medium.com/mitre-attack/the-retirement-of-pre-attack-4b73ffecd3d3
Medium
Bringing PRE into Enterprise
Integrating the scope of PRE-ATT&CK into Enterprise ATT&CK
AI security: This project aims to spot attacks against critical systems before they happen | ZDNet
https://www.zdnet.com/article/ai-security-this-project-aims-to-spot-attacks-against-critical-systems-before-they-happen/
https://www.zdnet.com/article/ai-security-this-project-aims-to-spot-attacks-against-critical-systems-before-they-happen/
ZDNet
AI security: This project aims to spot attacks against critical systems before they happen | ZDNet
Microsoft has unveiled a new open-source "matrix" that hopes to identify all the existing attacks that threaten the security of machine-learning applications.
Mapping ATT&CK Data Sources to Security Events via OSSEM 🛡⚔️ | by Jose Luis Rodriguez | Open Threat Research | Oct, 2020 | Medium
https://medium.com/threat-hunters-forge/mapping-att-ck-data-sources-to-security-events-via-ossem-%EF%B8%8F-b606d99e738c
https://medium.com/threat-hunters-forge/mapping-att-ck-data-sources-to-security-events-via-ossem-%EF%B8%8F-b606d99e738c
Medium
Mapping ATT&CK Data Sources to Security Events via OSSEM 🛡⚔️
The MITRE-ATT&CK team just released the last entry of a two-part blog series where they propose a new methodology to start defining…
10 Ways to Reduce IT Costs Quickly
https://www.gartner.com/smarterwithgartner/10-ways-to-quickly-reduce-it-costs/
https://www.gartner.com/smarterwithgartner/10-ways-to-quickly-reduce-it-costs/
Gartner
10 Ways to Quickly Reduce IT Costs
IT cost cuts may be coming - In fact, 39% of CFOs polled in May said they would cut costs in 4Q22 if high #inflation persisted. Here’s 🔟 ways to quickly reduce IT costs. #GartnerIT
Бизнес без опасности: Чеклист организации, выстраивающей стратегию безопасного удаленного доступа (презентация и видео)
https://lukatsky.blogspot.com/2020/10/blog-post_28.html?m=1
https://lukatsky.blogspot.com/2020/10/blog-post_28.html?m=1
Blogspot
Чеклист организации, выстраивающей стратегию безопасного удаленного доступа (презентация и видео)
Блог Алексея Лукацкого "Бизнес без опасности"
SP 800-53B, Control Baselines for Information Systems and Organizations | CSRC
https://csrc.nist.gov/publications/detail/sp/800-53b/final
https://csrc.nist.gov/publications/detail/sp/800-53b/final
CSRC | NIST
NIST Special Publication (SP) 800-53B, Control Baselines for Information Systems and Organizations
This publication provides security and privacy control baselines for the Federal Government. There are three security control baselines (one for each system impact level—low-impact, moderate-impact, and high-impact), as well as a privacy baseline that is…
Open Source Security Foundation launches a new certification program on edX | ZDNet
https://www.zdnet.com/article/open-source-security-foundation-launches-a-new-certification-program-on-edx/
https://www.zdnet.com/article/open-source-security-foundation-launches-a-new-certification-program-on-edx/
ZDNet
Open Source Security Foundation launches a new certification program on edX
The Linux Foundation's OpenSSF is introducing a suite of security classes and a certification for open-source programmers.
Draft EU Legislation to Stop Banks Using Insecure Tech Suppliers – Team Cymru
https://team-cymru.com/blog/2020/10/28/draft-eu-legislation-to-stop-banks-using-insecure-tech-suppliers/
https://team-cymru.com/blog/2020/10/28/draft-eu-legislation-to-stop-banks-using-insecure-tech-suppliers/
Team Cymru
Draft EU Legislation to Stop Banks Using Insecure Tech Suppliers
The Wall Street Journal reports that national regulators in EU member states could be given the authority to force financial institutions to drop existing tech suppliers, if they fail to address cybersecurity problems. The WSJ
10 Best XDR Solutions: Extended Detection & Response Service
https://www.softwaretestinghelp.com/xdr-security-solutions/amp/
https://www.softwaretestinghelp.com/xdr-security-solutions/amp/