1 of 57

NCDPI K-12 Cybersecurity Program ��Essential Cyber Hygiene �for PSUs with CIS Controls

Digital Leaders Exchange 2024 �Data Privacy and Cybersecurity

Tim Wease, NCDPI

Samuel Carter, Friday Institute

September 2024

2 of 57

Essential Cyber Hygiene for �PSUs with CIS Controls

NCDPI established the K-12 Cybersecurity Program with a purpose of organizing and aligning business and technical cybersecurity functions holistically across the state and to help all PSUs achieve essential cyber hygiene. Specifically, the program has been strategically aligned with the CIS Critical Security Controls, Implementation Group 1 which is considered "Essential Cyber Hygiene." This session will walk PSUs through the general concepts of what CIS Controls are, how the K-12 cybersecurity programs and services provided to PSUs by NCDPI support this goal, and how PSUs can measure their progress. ��This session also discusses how essential cyber hygiene supports the NCDPI Digital Learning Plan, CoSN Trusted Learning Environment Seals, and �the FCC Cybersecurity Pilot Program.

2

3 of 57

About Tim Wease

  • PSU IT Security Specialist at NCDPI�
  • One of the original founding members of the K-12 Cybersecurity Advisory Council (CAC) in 2021�
  • Leading NCDPI K-12 Cybersecurity Program and the core teams/partners who provide the various cybersecurity services and resources to the PSUs

  • 19 years experience (15 in PSU and 4 at DPI)�

3

4 of 57

About Samuel Carter

  • Systems Architect, Friday Institute
  • College of Education, N.C. State University
    • 13 years (10+3)�
  • Adjunct Professor, Computer Science
  • College of Engineering, N.C. State University
    • 19 years�
  • Planning, design, procure, implement, and support �of large statewide technology services
    • e.g. NCVPS, NCEdCloud, K-12 Cybersecurity�
  • Extensive background in Cybersecurity with a specialization in Identity and Access Management

4

5 of 57

Agenda

  • Part I - Understanding CIS
    • NCDPI K-12 Cybersecurity Program Overview Recap
    • CIS Critical Security Controls Overview
    • Essential Cyber Hygiene �
  • Part II - Support and Alignment with CIS
    • NCDPI K-12 Cybersecurity Program Services and Resources�
  • Part III - CIS Control Assessments
    • CIS Controls Self Assessment Tool (CIS CSAT)

5

6 of 57

NCDPI K-12 Cybersecurity Program Focus Recap

NCDPI established the K-12 Cybersecurity Program with a purpose of organizing and aligning business and technical cybersecurity functions holistically across the state and to help all PSUs achieve Essential Cyber Hygiene. Specifically, the program has been strategically aligned with the �CIS Critical Security Controls (CIS), Implementation Group 1as the primary guidelines for achieving the goal.

�For 2024-2025, the program team will be focusing on helping PSUs better understand what essential hygiene controls and safeguards are, how the K-12 cybersecurity programs and services provided to PSUs specifically support and align with this goal, and how PSUs can measure their ongoing progress.

6

7 of 57

Sanity Check

Why do we care and/or need to do this stuff?�

  1. Almost everything and everyone in a school is connected to the internet and without basic cybersecurity protections, threat actors would severely impact a PSUs ability to conduct school operations.�
  2. There are various local, state, and federal policies, regulations, and laws that require PSUs to protect data.�

7

8 of 57

Sanity Check

3. Legislatures want/need data that shows current status (i.e. how good/bad are things?) and what is required (i.e. how much money?) to improve the cybersecurity posture status?��4. Without data, legislatures like to hire very expensive consulting groups to perform assessments that tells us what we already know but don’t have data to show it.

8

9 of 57

Part I - Understanding CIS

9

10 of 57

NCDPI K-12 Cybersecurity Program Overview Recap

10

11 of 57

Program Purpose and Goal (1/3)

NCDPI established the K-12 Cybersecurity Program with a purpose of organizing and aligning business and technical cybersecurity functions holistically across the state so that PSU and NCDPI stakeholders have greater visibility into the people, processes, and technologies deployed and have a measurable way to determine whether those efforts are sufficient and correct for current and future needs.

The goal is to help all PSUs achieve Essential Cyber Hygiene!

11

12 of 57

Program Services and Resources (2/3)

12

13 of 57

Program Strategy (3/3)

The K-12 Cybersecurity Program aligns with the following three major components:

The goal is to help all PSUs achieve Essential Cyber Hygiene!

13

14 of 57

CC Model of Cybersecurity

14

Layers of Controls

  • Prevent
  • Detect
  • Respond

4 Ways to Manage Risk

  • Avoid
  • Transfer
  • Minimize
  • Accept

Assets

  • Devices
  • Software
  • Data
  • Users
  • Network
  • Documentation

Threats

  • Internal and External
  • Passive and Active

Threat agents

  • Hacktivist
  • Hackers
  • Cyber Criminals
  • State Sponsored

15 of 57

What countermeasures/controls should you pick to manage risk?

  • There are a variety of cybersecurity Frameworks and Controls
    • NIST CSF, NIST 800-53r5, CIS Controls v8.1, ISO 27XXX, etc.
    • What is mandated? Controls versus regulations
    • Formal versus informal�
  • Crosswalk / Mappings between if needed�
  • For NC K-12, we looked at our stakeholders, previous and current states, and used some common sense�
  • The CIS Critical Security Controls were the best fit for K-12

15

16 of 57

CIS Critical Security Controls Overview

16

17 of 57

CIS Critical Security Controls

  • Developed by Center for Internet Security (CIS), the Critical Security Controls (CIS Controls) are a prioritized set of Safeguards to mitigate the most prevalent cyber-attacks against systems and networks. �
  • They are mapped to and referenced by multiple legal, regulatory, and policy frameworks.�
  • Current version is 8.1 releases in June 2024�
  • 5 Key Terms to Know: Control, Safeguard, Implementation Group, Asset Type, and Security Function

17

18 of 57

CIS Key Term 1 - Control

  • Control - a specific safeguard or countermeasure designed to protect an organization’s information systems and data
    • CIS has 18 Controls�

18

19 of 57

CIS Key Term 2 - Safeguard

  • Safeguards - a specific security measure or mechanism implemented to protect an organization’s information systems and data from various threats and vulnerabilities
    • Each Control has multiple Safeguards
    • CIS has 153 Safeguards

19

20 of 57

CIS Key Term 3 - Implementation Group

  • Implementation Group - the recommended guidance to prioritize implementation of the CIS Controls
    • CIS has 3 IGs (IG1,IG2,IG3)�
  • They are based on the risk profile and resources an org has available to them to implement the CIS Controls

20

21 of 57

CIS Key Term 3 - Implementation Group

21

22 of 57

CIS Key Term 4 - Asset Classes

  • Asset class - a group of information assets that are evaluated as one set based on their similarity.
    • Devices
    • Software
    • Data
    • Users
    • Network
    • Documentation�
  • Each Safeguard has an asset type

22

23 of 57

CIS Key Term 5 - Security Functions

  • Security Functions - the broad categories of activities or mechanisms that are implemented to protect information systems and data.
    • Each Safeguard has a Security Function�
  • NIST CSF 2 Core define 6 Security Functions
    • Govern
    • Identify
    • Protect
    • Detect
    • Respond
    • Recover

23

24 of 57

CIS Critical Security Controls (v8.1)

  • 18 Controls, 153 Safeguards, 3 Implementation Groups, 6 Asset Types, 6 Security Functions

24

25 of 57

Essential Cyber Hygiene

25

26 of 57

IG1 = Essential Cyber Hygiene

26

27 of 57

Program Purpose and Goal (1/3)

NCDPI established the K-12 Cybersecurity Program with a purpose of organizing and aligning business and technical cybersecurity functions holistically across the state so that PSU and NCDPI stakeholders have greater visibility into the people, processes, and technologies deployed and have a measurable way to determine whether those efforts are sufficient and correct for current and future needs.

The goal is to help all PSUs achieve Essential Cyber Hygiene!

27

28 of 57

CC Model of Cybersecurity

28

Layers of Controls

  • Prevent
  • Detect
  • Respond

4 Ways to Manage Risk

  • Avoid
  • Transfer
  • Minimize
  • Accept

Assets

  • Devices
  • Software
  • Data
  • Users
  • Network
  • Documentation

Threats

  • Internal and External
  • Passive and Active

Threat agents

  • Hacktivist
  • Hackers
  • Cyber Criminals
  • State Sponsored

29 of 57

Program Strategy (3/3)

The K-12 Cybersecurity Program aligns with the following three major components:

The goal is to help all PSUs achieve Essential Cyber Hygiene!

29

30 of 57

NCDPI K-12 Cybersecurity Program Focus Recap

NCDPI established the K-12 Cybersecurity Program with a purpose of organizing and aligning business and technical cybersecurity functions holistically across the state and to help all PSUs achieve Essential Cyber Hygiene. Specifically, the program has been strategically aligned with the �CIS Critical Security Controls (CIS), Implementation Group 1as the primary guidelines for achieving the goal.

�For 2024-2025, the program team will be focusing on helping PSUs better understand what essential hygiene controls and safeguards are, how the K-12 cybersecurity programs and services provided to PSUs specifically support and align with this goal, and how PSUs can measure their ongoing progress.

30

31 of 57

Part II - Support and Alignment with CIS

31

32 of 57

NCDPI K-12 Cybersecurity Program Services and Resources

32

33 of 57

Program Services and Resources (2/3)

33

34 of 57

CIS Controls Coverage

The NCDPI K-12 Cybersecurity Program Services and Resources provide full or partial coverage for ~76 of 153 CIS Safeguards across all three Implementation Groups �

  • 35 of 56 CIS IG1 Safeguards (Essential Cyber Hygiene)
  • 31 of 74 CIS IG2 Safeguards�
  • 10 of 23 CIS IG3 Safeguards

34

35 of 57

CIS Critical Security Controls Demo

35

36 of 57

Alignment and Support

36

37 of 57

NCDPI K-12 Cybersecurity Program Focus Recap

NCDPI established the K-12 Cybersecurity Program with a purpose of organizing and aligning business and technical cybersecurity functions holistically across the state and to help all PSUs achieve Essential Cyber Hygiene. Specifically, the program has been strategically aligned with the �CIS Critical Security Controls (CIS), Implementation Group 1as the primary guidelines for achieving the goal.

�For 2024-2025, the program team will be focusing on helping PSUs better understand what essential hygiene controls and safeguards are, how the K-12 cybersecurity programs and services provided to PSUs specifically support and align with this goal, and how PSUs can measure their ongoing progress.

37

38 of 57

Part III - CIS Control Assessments

38

39 of 57

Recall Sanity Check

3. Legislatures want/need data that shows current status (i.e. how good/bad are things?) and what is required (i.e. how much money?) to improve the cybersecurity posture status?��4. Without data, legislatures like to hire very expensive consulting groups to perform assessments that tells us what we already know but don’t have data to show it.

39

We need a mechanism to monitor, measure, and show our overall progress for how we are improving cybersecurity posture

40 of 57

CIS Controls Assessment Proposal

Option 1

Leverage the CIS CSAT assessment tool�

Option 2

Perform tracking via individual PSU spreadsheet (template)�

Option 3

Request funding for an external entity to perform a formal assessments on a recurring basic

40

41 of 57

CIS Controls Self Assessment Tool (CIS CSAT)

41

42 of 57

CIS Controls Self Assessment Tool (CIS CSAT)

  • CSAT is a tool to assess, track and prioritize your implementation of the CIS Controls by helping PSUs identify where CIS Controls Safeguards are already well-implemented and where there are weak points that could be improved �
  • This can be useful information as PSUs decide where to devote their limited cybersecurity resources

42

43 of 57

CIS Controls Self Assessment Tool (CIS CSAT)

There are two versions of CIS CSAT: Hosted and Pro (On-Prem)

  • CIS-Hosted CSAT
    • CIS-hosted CSAT is a web-based portal version of CSAT hosted by CIS. It is free to every SLTT organization for use in a non-commercial capacity to conduct an assessment of their organization's own implementation of the CIS Controls.�
  • CIS CSAT Pro
    • CIS CSAT Pro is the on-premises version of the tool and is available exclusively to CIS SecureSuite Members.

43

44 of 57

Safeguard Evaluation

  • For each Control/Safeguard under IG1, a �PSU would evaluate itself across 4 categories
    • Policy Defined
    • Control Implemented
    • Control Automated
    • Control Reported�
  • We are less concerned about any specific score but rather what protections you have in place, where are areas that do not have coverage, and plans to improve any identified gaps.

44

45 of 57

Evaluation Categories and Levels

  • Policy Defined – to what degree is this Safeguard covered by your organization’s policies?
    • No Policy
    • Informal Policy
    • Partially Written Policy
    • Written Policy
    • Approved Written Policy
    • Not Applicable�
  • Control Implemented – to what degree has your organization implemented this Safeguard?
    • Not Implemented
    • Parts of Policy Implemented
    • Implemented on Some Systems
    • Implemented on Most Systems
    • Implemented on All Systems
    • Not Applicable

45

46 of 57

Evaluation Categories and Levels

  • Control Automated – to what degree does your organization enforce this Safeguard through automated means vs. manual/procedural means?
    • Not Automated
    • Parts of Policy Automated
    • Automated on Some Systems
    • Automated on Most Systems
    • Automated on All Systems
    • Not Applicable�
  • Control Reported – to what degree is the state of this Safeguard being reported within your organization, generally to leadership or management?
    • Not Reported
    • Parts of Policy Reported
    • Reported on Some Systems
    • Reported on Most Systems
    • Reported on All Systems
    • Not Applicable

46

47 of 57

CSAT Demo

https://csat.cisecurity.org/

47

48 of 57

CIS Controls Self Assessment via Spreadsheet

48

49 of 57

CIS Controls Self Assessment via Spreadsheet Demo

49

50 of 57

CIS Controls Assessment Proposal?

Option 1

Leverage the CIS CSAT assessment tool �Solo or Comanaged Pilot?�

Option 2

Perform tracking via individual PSU spreadsheet (template)

Solo or Comanaged Pilot?�

Option 3

Request funding for an external entity to perform a formal assessments on a recurring basic (Pilot?)

50

51 of 57

NCDPI K-12 Cybersecurity Program Focus Recap

NCDPI established the K-12 Cybersecurity Program with a purpose of organizing and aligning business and technical cybersecurity functions holistically across the state and to help all PSUs achieve Essential Cyber Hygiene. Specifically, the program has been strategically aligned with the �CIS Critical Security Controls (CIS), Implementation Group 1as the primary guidelines for achieving the goal.

�For 2024-2025, the program team will be focusing on helping PSUs better understand what essential hygiene controls and safeguards are, how the K-12 cybersecurity programs and services provided to PSUs specifically support and align with this goal, and how PSUs can measure their ongoing progress.

51

52 of 57

Summary

52

53 of 57

Summary

  • Goal = Achieve Essential Cyber Hygiene�
  • CIS Controls = Guidelines to strengthen your cybersecurity posture
    • 18 Controls, 153 Safeguards, 3 Implementation Groups, 6 Asset Types, 6 Security Functions
    • IG1 = Essential Cyber Hygiene
  • NCDPI provides full or partial coverage for 35 of 53 CIS IG1 safeguards with current state services and resources�
  • Use the CSAT Tool or Spreadsheet to measure current status and progress

53

54 of 57

Summary

  • For 2024-2025, the program team will be focusing on �
    • helping PSUs better understand what essential hygiene controls and safeguards are, �
    • how the K-12 cybersecurity programs and services provided to PSUs specifically support and align with this goal, and �
    • how PSUs can measure their ongoing progress.

54

55 of 57

Resources

55

56 of 57

Resources

56

57 of 57

Questions?

Samuel Carter

North Carolina State University

swcarter@ncsu.edu

Timothy Wease

NCDPI

timothy.wease@dpi.nc.us