Sign In Start Free Trial
Account

Add to playlist

Create a Playlist

Modal Close icon
You need to login to use this feature.
  • Book Overview & Buying A CISO Guide to Cyber Resilience
  • Table Of Contents Toc
  • Feedback & Rating feedback
A CISO Guide to Cyber Resilience

A CISO Guide to Cyber Resilience

By : Debra Baker
5 (12)
close
close
A CISO Guide to Cyber Resilience

A CISO Guide to Cyber Resilience

5 (12)
By: Debra Baker

Overview of this book

This book, written by the CEO of TrustedCISO with 30+ years of experience, guides CISOs in fortifying organizational defenses and safeguarding sensitive data. Analyze a ransomware attack on a fictional company, BigCo, and learn fundamental security policies and controls. With its help, you’ll gain actionable skills and insights suitable for various expertise levels, from basic to intermediate. You’ll also explore advanced concepts such as zero-trust, managed detection and response, security baselines, data and asset classification, and the integration of AI and cybersecurity. By the end, you'll be equipped to build, manage, and improve a resilient cybersecurity program, ensuring your organization remains protected against evolving threats.
Table of Contents (20 chapters)
close
close
Free Chapter
1
Part 1: Attack on BigCo
3
Part 2: Security Resilience: Getting the Basics Down
13
Part 3: Security Resilience: Taking Your Security Program to the Next Level

Third-party risk management

Third-party risk management is critical. If a critical vendor you rely on is compromised, then the breach may also affect your company. We have talked in Chapter 8 about using Snyk’s renovate package to ensure your open source code is up to date and patched. Also, use GitHub’s static application security testing (SAST) code scanning tool to ensure your code doesn’t have vulnerabilities. What if the tool you use has been compromised? This is exactly what happened with the SolarWinds attack. This is why third-party risk management, also known as supply chain management, is so critical.

SolarWinds attack

SolarWinds has a network Monitoring product called Orion. It was used throughout the commercial and federal government. SolarWinds suffered a major cyber-attack in 2020. What makes the SolarWinds attack so devastating is that the attackers were able to gain access to their source code and introduce malware that would allow them to...

Unlock full access

Continue reading for free

A Packt free trial gives you instant online access to our library of over 7000 practical eBooks and videos, constantly updated with the latest in tech
bookmark search playlist font-size

Change the font size

margin-width

Change margin width

day-mode

Change background colour

Close icon Search
Country selected

Close icon Your notes and bookmarks

Delete Bookmark

Modal Close icon
Are you sure you want to delete it?
Cancel
Yes, Delete

Confirmation

Modal Close icon
claim successful

Buy this book with your credits?

Modal Close icon
Are you sure you want to buy this book with one of your credits?
Close
YES, BUY