NCDPI K-12 Cybersecurity Program ��Essential Cyber Hygiene �for PSUs with CIS Controls
Digital Leaders Exchange 2024 �Data Privacy and Cybersecurity
Tim Wease, NCDPI
Samuel Carter, Friday Institute
September 2024
Essential Cyber Hygiene for �PSUs with CIS Controls
NCDPI established the K-12 Cybersecurity Program with a purpose of organizing and aligning business and technical cybersecurity functions holistically across the state and to help all PSUs achieve essential cyber hygiene. Specifically, the program has been strategically aligned with the CIS Critical Security Controls, Implementation Group 1 which is considered "Essential Cyber Hygiene." This session will walk PSUs through the general concepts of what CIS Controls are, how the K-12 cybersecurity programs and services provided to PSUs by NCDPI support this goal, and how PSUs can measure their progress. ��This session also discusses how essential cyber hygiene supports the NCDPI Digital Learning Plan, CoSN Trusted Learning Environment Seals, and �the FCC Cybersecurity Pilot Program.
2
About Tim Wease
3
About Samuel Carter
4
Agenda
5
NCDPI K-12 Cybersecurity Program Focus Recap
NCDPI established the K-12 Cybersecurity Program with a purpose of organizing and aligning business and technical cybersecurity functions holistically across the state and to help all PSUs achieve Essential Cyber Hygiene. Specifically, the program has been strategically aligned with the �CIS Critical Security Controls (CIS), Implementation Group 1 �as the primary guidelines for achieving the goal.
�For 2024-2025, the program team will be focusing on helping PSUs better understand what essential hygiene controls and safeguards are, how the K-12 cybersecurity programs and services provided to PSUs specifically support and align with this goal, and how PSUs can measure their ongoing progress.
6
Sanity Check
Why do we care and/or need to do this stuff?�
7
Sanity Check
3. Legislatures want/need data that shows current status (i.e. how good/bad are things?) and what is required (i.e. how much money?) to improve the cybersecurity posture status?��4. Without data, legislatures like to hire very expensive consulting groups to perform assessments that tells us what we already know but don’t have data to show it.
8
Part I - Understanding CIS
9
NCDPI K-12 Cybersecurity Program Overview Recap
10
Program Purpose and Goal (1/3)
NCDPI established the K-12 Cybersecurity Program with a purpose of organizing and aligning business and technical cybersecurity functions holistically across the state so that PSU and NCDPI stakeholders have greater visibility into the people, processes, and technologies deployed and have a measurable way to determine whether those efforts are sufficient and correct for current and future needs.
The goal is to help all PSUs achieve Essential Cyber Hygiene!
11
Program Services and Resources (2/3)
12
Program Strategy (3/3)
The K-12 Cybersecurity Program aligns with the following three major components:�
The goal is to help all PSUs achieve Essential Cyber Hygiene!
13
CC Model of Cybersecurity
14
Layers of Controls
4 Ways to Manage Risk
Assets
Threats
Threat agents
What countermeasures/controls should you pick to manage risk?
15
CIS Critical Security Controls Overview
16
CIS Critical Security Controls
17
CIS Key Term 1 - Control
18
CIS Key Term 2 - Safeguard
19
CIS Key Term 3 - Implementation Group
20
CIS Key Term 3 - Implementation Group
21
CIS Key Term 4 - Asset Classes
22
CIS Key Term 5 - Security Functions
23
CIS Critical Security Controls (v8.1)
24
Essential Cyber Hygiene
25
IG1 = Essential Cyber Hygiene
26
Program Purpose and Goal (1/3)
NCDPI established the K-12 Cybersecurity Program with a purpose of organizing and aligning business and technical cybersecurity functions holistically across the state so that PSU and NCDPI stakeholders have greater visibility into the people, processes, and technologies deployed and have a measurable way to determine whether those efforts are sufficient and correct for current and future needs.
The goal is to help all PSUs achieve Essential Cyber Hygiene!
27
CC Model of Cybersecurity
28
Layers of Controls
4 Ways to Manage Risk
Assets
Threats
Threat agents
Program Strategy (3/3)
The K-12 Cybersecurity Program aligns with the following three major components:�
The goal is to help all PSUs achieve Essential Cyber Hygiene!
29
NCDPI K-12 Cybersecurity Program Focus Recap
NCDPI established the K-12 Cybersecurity Program with a purpose of organizing and aligning business and technical cybersecurity functions holistically across the state and to help all PSUs achieve Essential Cyber Hygiene. Specifically, the program has been strategically aligned with the �CIS Critical Security Controls (CIS), Implementation Group 1 �as the primary guidelines for achieving the goal.
�For 2024-2025, the program team will be focusing on helping PSUs better understand what essential hygiene controls and safeguards are, how the K-12 cybersecurity programs and services provided to PSUs specifically support and align with this goal, and how PSUs can measure their ongoing progress.
30
Part II - Support and Alignment with CIS
31
NCDPI K-12 Cybersecurity Program Services and Resources
32
Program Services and Resources (2/3)
33
CIS Controls Coverage
The NCDPI K-12 Cybersecurity Program Services and Resources provide full or partial coverage for ~76 of 153 CIS Safeguards across all three Implementation Groups �
34
CIS Critical Security Controls Demo
Direct Controls Guide: https://learn.cisecurity.org/cis-controls-v8-1-guide-pdf
CIS Controls Navigator: https://www.cisecurity.org/controls/cis-controls-navigator
35
Alignment and Support
36
NCDPI K-12 Cybersecurity Program Focus Recap
NCDPI established the K-12 Cybersecurity Program with a purpose of organizing and aligning business and technical cybersecurity functions holistically across the state and to help all PSUs achieve Essential Cyber Hygiene. Specifically, the program has been strategically aligned with the �CIS Critical Security Controls (CIS), Implementation Group 1 �as the primary guidelines for achieving the goal.
�For 2024-2025, the program team will be focusing on helping PSUs better understand what essential hygiene controls and safeguards are, how the K-12 cybersecurity programs and services provided to PSUs specifically support and align with this goal, and how PSUs can measure their ongoing progress.
37
Part III - CIS Control Assessments
38
Recall Sanity Check
3. Legislatures want/need data that shows current status (i.e. how good/bad are things?) and what is required (i.e. how much money?) to improve the cybersecurity posture status?��4. Without data, legislatures like to hire very expensive consulting groups to perform assessments that tells us what we already know but don’t have data to show it.
39
We need a mechanism to monitor, measure, and show our overall progress for how we are improving cybersecurity posture
CIS Controls Assessment Proposal
Option 1
Leverage the CIS CSAT assessment tool�
Option 2
Perform tracking via individual PSU spreadsheet (template)�
Option 3
Request funding for an external entity to perform a formal assessments on a recurring basic
40
CIS Controls Self Assessment Tool (CIS CSAT)
41
CIS Controls Self Assessment Tool (CIS CSAT)
42
CIS Controls Self Assessment Tool (CIS CSAT)
There are two versions of CIS CSAT: Hosted and Pro (On-Prem)
43
Safeguard Evaluation
44
Evaluation Categories and Levels
45
Evaluation Categories and Levels
46
CSAT Demo
https://csat.cisecurity.org/
47
CIS Controls Self Assessment via Spreadsheet
48
CIS Controls Self Assessment via Spreadsheet Demo
49
CIS Controls Assessment Proposal?
Option 1
Leverage the CIS CSAT assessment tool �Solo or Comanaged Pilot?�
Option 2
Perform tracking via individual PSU spreadsheet (template)
Solo or Comanaged Pilot?�
Option 3
Request funding for an external entity to perform a formal assessments on a recurring basic (Pilot?)
50
NCDPI K-12 Cybersecurity Program Focus Recap
NCDPI established the K-12 Cybersecurity Program with a purpose of organizing and aligning business and technical cybersecurity functions holistically across the state and to help all PSUs achieve Essential Cyber Hygiene. Specifically, the program has been strategically aligned with the �CIS Critical Security Controls (CIS), Implementation Group 1 �as the primary guidelines for achieving the goal.
�For 2024-2025, the program team will be focusing on helping PSUs better understand what essential hygiene controls and safeguards are, how the K-12 cybersecurity programs and services provided to PSUs specifically support and align with this goal, and how PSUs can measure their ongoing progress.
51
Summary
52
Summary
53
Summary
54
Resources
55
Resources
56
Questions?
Samuel Carter
North Carolina State University
swcarter@ncsu.edu
Timothy Wease
NCDPI
timothy.wease@dpi.nc.us