Book Resources

This resources area contains links to resources and document templates described in the Boardroom Cybersecurity book.

Documents

Third party vetting Questionairre

ACSC Cyber Incident Response Plan Template

Data Inventory Template

Steve Riley - Defending Layer 8 Presentation (Chapter 7)

Sample Cybersecurity Policy for AI and LLM Usage

Links

AICD Resources

Cyber Security Governance Principles Snapshot

AICD Cyber Security Governance Principles (Video)

Cyber Security Checklist for SMEs and NFPs

Regulators Warn Directors to Step Up on Cyber Threats

Cyber Security Governance Principles

Six Principles for Boards on Cyber Risk Governance

ACSC Resources

ACSC: Main Page
ACSC: Cyber assessment tool
ACSC: Cyber Reporting Portal
ACSC: Questions for Boards to Ask About Cyber Security
ACSC: Planning for Critical Vulnerabilities and Major Cyber Security Incidents – What Boards Need to Know

Other Cyber & Risk Resources

ISC2 Cyber Security Reports

Forrester Planning Guide 2024: Security & Risk

ASIC – Cyber Resilience Resources

NCSC Cyber Security Board Toolkit

Overview of Cyber Security Obligations for Corporate Leaders (Australian Cyber and Infrastructure Security Centre)

World Economic Forum: How to prioritize resilience in the face of cyber-attacks

ASD Cyber Security Resources

Essential Eight Mitigation Strategies

Office of the Australian Information Commissioner (OAIC)

Cybersecurity Standards

National Institute of Standards and Technology (NIST)

MITRE ATT&CK

Top Vendor Assessment Questionnaires: Including an ISO 27001 Questionnaire

A CISO's Guide to Cybersecurity, Disclosure & Compliance

Chapter References & Resources

CHAPTER 1

https://en.wikipedia.org/wiki/Supply_chain_attack

https://www.upguard.com/blog/supply-chain-attack

https://cyberint.com/blog/research/recent-supply-chain-attacks-examined/

https://www.dhs.gov/sites/default/files/publications/increasing_threats_of_deepfake_identities_0.pdf

https://www.fortinet.com/resources/cyberglossary/deepfake

https://www.wsj.com/articles/i-cloned-myself-with-ai-she-fooled-my-bank-and-my-family-356bd1a3

https://www.cnbc.com/2024/04/08/state-backed-cyberattacks-ai-deepfakes-top-uk-election-cyber-risks.html

CHAPTER 2

https://cybersecurityventures.com/hackerpocalypse-cybercrime-report-2016/
https://cybersecurityventures.com/cybercrime-to-cost-the-world-8-trillion-annually-in-2023/
https://www.weforum.org/agenda/2024/01/cybersecurity-cybercrime-system-safety/

CHAPTER 3

https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-11-app-11-security-of-personal-information
https://www.oaic.gov.au/privacy/notifiable-data-breaches/about-the-notifiable-data-breaches-scheme
https://www.legislation.gov.au/C2004A00818/latest/text

CHAPTER 4-5

https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/essential-eight

https://www.cyber.gov.au/sites/default/files/2023-11/PROTECT%20-%20Essential%20Eight%20Maturity%20Model%20%28November%202023%29.pdf
https://www.nist.gov/cyberframework
https://www.cisecurity.org/controls
https://cloudsecurityalliance.org/research/cloud-controls-matrix
https://aemo.com.au/en/initiatives/major-programs/cyber-security/aescsf-framework-and-resources
https://www.isaca.org/resources/cobit

CHAPTER 6-7

https://www.crest-approved.org/Boardroom Duty – Mastering Cyber Security
https://owasp.org/www-project-application-security-verification-standard/
https://www.nist.gov/privacy-framework/nist-sp-800-115
https://mas.owasp.org/MASTG/
http://www.pentest-standard.org/index.php/PTES_Technical_Guidelines
https://www.isecom.org/OSSTMM.3.pdf
https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator
https://attack.mitre.org/
https://www.tenable.com/products/nessus

CHAPTER 8-9

https://www.nist.gov/privacy-framework/nist-sp-800-61
https://www.metasploit.com/
https://exploitpack.com/
https://www.coresecurity.com/products/core-impact
https://www.exploit-db.com/
https://0day.today/search
https://bugtraq.securityfocus.com/archive
https://www.nist.gov/privacy-framework/nist-sp-800-61

Data Management Resources

INIST Data Classification Concepts

ONDC Guide to developing a data inventory

Book Glossary

Access Control: Restricting access to systems and data based on user permissions.

Active Directory (AD): A directory service from Microsoft that stores information about network resources like users, groups, computers, and printers. It controls access to these resources and simplifies network administration.

ACSC Essential Eight: An Australian cybersecurity framework developed by the Australian Cyber Security Centre (ACSC) focusing on eight essential mitigation strategies to address common cyber threats.

Air Gap: A security measure that isolates a network from the internet to prevent external attacks.

APRA (Australian Prudential Regulation Authority): The Australian regulator responsible for the prudential supervision of banks, credit unions, insurers, and superannuation entities.

ASIC (Australian Securities and Investments Commission): The Australian corporate regulator responsible for regulating financial markets, consumer credit, and investment activities

Assume Breach Testing: A simulated attack where the tester has a pre-determined entry point on a device and tests how far they can move laterally within the network.

Attack Methods: Techniques used by cybercriminals to gain unauthorized access to computer systems or data. Examples include phishing, malware, and denial-of-service attacks.

Australian Energy Sector Cyber Security Framework (AESCSF): A framework for the Australian energy sector to improve cybersecurity posture and protect critical infrastructure.

Australian Government Protective Security Policy Framework (PSPF): A framework for Australian government entities to safeguard people, information, and assets through information security, physical security, and personnel security measures.

Authentication: The process of verifying a user's identity before granting access to a system or data.

Authorisation: The process of determining and granting a user or system permission to access specific resources or perform certain actions.

Backdoor: A hidden method of gaining access to a computer system, often created by attackers to bypass security controls.

Benchmarking: The process of comparing your organisation's performance against industry best practices or your own past performance.

Biometrics: Using unique physical or behavioural characteristics (fingerprint, facial recognition) for authentication.

Board Oversight: The responsibility of the board of directors to supervise the management of an organisation, including its cybersecurity posture.

Breach Simulation Exercise: Similar to Assume Breach Testing but may involve a broader scope and potentially involve social engineering techniques.

Breach: An incident where sensitive or confidential data is accessed and disclosed in an unauthorised manner.

Brute Force Attack: A trial-and-error method of attempting to guess a password by trying a large number of possibilities.

Business Continuity and Disaster Recovery (BCDR): Plans to ensure an organisation can continue operations after a disaster or security incident.

Business Continuity: The ability of an organisation to maintain critical business functions in the event of a disruption, such as a cyberattack.

Business Impact Analysis (BIA): An assessment of the potential financial and operational impact of cyberattacks on critical business processes.

Business Interruption: The disruption of normal business operations due to a cyberattack.

CIS Controls: A prioritised set of best practices developed by the Center for Internet Security (CIS) to address the most prevalent cyber vulnerabilities. These controls are organised into six pillars.

Cloud Assessment: Testing of cloud-based services for vulnerabilities that could expose data stored there.

Cloud Controls Matrix (CCM): A framework developed by the Cloud Security Alliance (CSA) specifically designed to assess the security of cloud computing environments.

Cloud Security: Securing data and applications stored or running in the cloud

Compliance: Meeting industry standards or regulations to ensure data security and privacy.

Conditional Access: A feature in Azure Active Directory that allows organisations to control access to cloud resources based on pre-defined conditions. These conditions may include the device type, location, and user risk level.

Control Objectives for Information Technology (COBIT): A framework from ISACA that helps organisations govern and manage information technology (IT) effectively, with a focus on IT governance and best practices.

Corrective Action Plan: A documented plan outlining steps to address nonconformities and OFIs identified during an ISO audit. This plan should include timelines and assign responsibility for implementing corrective actions.

Critical Vulnerability: A vulnerability with a high CVSS score (typically 9.0-10.0) that poses a very high risk of exploitation and requires immediate remediation.

CVSS (Common Vulnerability Scoring System): An industry-standard method for assessing the severity of security vulnerabilities. It considers exploitability, impact, and scope to generate a score (0.0-10.0).

Cyber Resilience: The ability to withstand and recover from cyberattacks.

Cyber Risk Appetite: The level of cyber risk the board is willing to accept in pursuit of business objectives. Boards should define and periodically review their cyber risk appetite.

Cyber Risk: The potential for a cyberattack to damage an organisation's systems, data, or reputation.

Cyber Threat: An attempt to gain unauthorised access to computer systems or networks or to disrupt or damage them.

Cybercrime: Criminal activity that targets computer systems, networks, and electronic data.

Cybercriminal: A person who commits crimes using computers or networks.

Cybersecurity Awareness Training: Educational programs for employees to educate them on cybersecurity threats and best practices. Boards should ensure adequate training is provided.

Cybersecurity Awareness: Educating users about cybersecurity threats and best practices.

Cybersecurity Ecosystem: The interconnected network of actors involved in cybercrime, including attackers, developers of malware, and facilitators of cybercrime activities.

Cybersecurity Framework: A set of guidelines and best practices for managing cybersecurity risks.

Cybersecurity Governance: The framework for managing and overseeing an organisation's cybersecurity posture.

Cybersecurity Hygiene: Best practices for maintaining good cybersecurity habits, such as using strong passwords, being cautious about clicking on links in emails, and keeping software up to date. (Chapter 2)

Cybersecurity Insurance: An insurance policy that helps organisations cover financial losses associated with cyberattacks.

Cybersecurity Strategy: The high-level plan outlining how the organisation will manage and mitigate cyber risks. Boards should be involved in approving the cybersecurity strategy.

Cybersecurity: The practices and technologies used to protect computer systems, networks, and data from unauthorised access, use, disclosure, disruption, modification, or destruction.

Darknet: (or darkweb) A hidden part of the internet that is not indexed by search engines and requires specific software to access.

Data Breach Notification: The legal requirement to inform individuals and regulators when their personal data has been compromised. Boards should be informed of any potential breaches and understand reporting obligations.

Data Breach: An incident where sensitive or confidential data is accessed and disclosed in an unauthorised manner.

Data Loss Impact: The negative consequences of losing access to or control over data. This could include financial losses, reputational damage, and legal liabilities.

Data Loss Prevention (DLP): Technology that helps organisations prevent sensitive data from being accidentally or intentionally shared outside the organisation.

Decryption: Unscrambling encrypted data back to its original form.

Denial-of-Service (DoS) Attack: An attempt to overwhelm a system with traffic, making it unavailable to legitimate users.

Digital Certificates: Electronic documents that verify the identity of a person or organisation online.

Direction: The setting of cybersecurity goals and objectives by the board of directors.

Distributed Denial-of-Service (DDoS) Attack: A DoS attack launched from multiple compromised computers across the internet.

Downtime: The period of time during which a system, network, or application is unavailable.

Due Diligence: Taking reasonable steps to ensure that an action or course of action is prudent and responsible.

Eligible Data Breach: A data breach that meets the criteria for notification under the NDB scheme. This means there has been unauthorised access or disclosure of personal information, and it's likely to result in serious harm.

Encryption at Rest: Secures data when it is stored on a device.

Encryption in Transit: Secures data while it is being transmitted over a network.

Encryption: Scrambling data to make it unreadable without a decryption key.

Endpoint Security: Protecting devices like laptops, desktops, and mobile phones from cyber threats.

Endpoint Protection: (Also called EDR) A software solution that protects devices like laptops, desktops, and mobile phones from malware, viruses, and other cyber threats. Endpoint protection typically includes features like antivirus scanning, application whitelisting, and intrusion detection.

Executive Management Team (EMT): The team responsible for the day-to-day implementation of the cybersecurity strategy. Boards should receive regular updates from the EMT.

Exploit: A specific flaw or vulnerability in software that can be leveraged by attackers to gain unauthorised access to a system.

Exploitation: The act of using an exploit to gain unauthorised access or control of a computer system or network.

Extortion: The act of threatening to inflict harm unless a ransom is paid. In a cyber context, this could involve threatening to release stolen data if a ransom is not paid.

Firewalls: Software or hardware that controls incoming and outgoing network traffic based on security rules.

Gamification: The use of game design elements to make learning more engaging.

Governance Principles: Broad guidelines that set the overall direction for an organisation's cybersecurity posture. They address leadership commitment, risk management, and cultural aspects of security.

Hashing: A one-way function that converts data into a unique string (hash) that can't be used to recreate the original data.

Hybrid Working: A flexible work model that combines remote or home work with in-office workdays, allowing employees to split their time between different locations.

Incident Response Plan (IRP): A documented plan that outlines how an organisation will respond to a cyber incident. The plan should include roles and responsibilities for different team members, communication protocols, and data recovery procedures.

Incident Response: The process of identifying, containing, and recovering from a security incident.

Insider Threat: The risk of malicious activity from within an organisation by employees, contractors, or other trusted individuals.

Intrusion Detection System (IDS): Monitors network traffic for suspicious activity that may indicate an attack.

Intrusion Prevention System (IPS): Identifies and blocks malicious network traffic in real-time.

ISO27001: An international standard for information security management systems, outlining best practices for data protection.

Malware: Malicious software designed to harm a computer system.

Man-in-the-Middle (MitM) Attack: An eavesdropping attack where a malicious actor intercepts communication between two parties.

Maturity Model: A framework used to assess an organisation's progress in implementing cybersecurity controls. It defines different levels of maturity (e.g., Zero to Three for the ACSC Essential Eight).

Metrics: Measurable data points used to track the effectiveness of an organisation's cybersecurity program.

Microsoft Azure: A cloud computing platform that offers a wide range of services, including infrastructure, platform, and software as a service (IaaS, PaaS, SaaS). Organisations can use Azure to build, deploy, and manage applications without needing on-premises hardware.

Microsoft 365:  M365is a subscription service offering access to productivity software (like Word, Excel, Outlook) and cloud services (like OneDrive, Teams) for collaboration and communication.

Microsoft Intune: A cloud-based mobile device management (MDM) service that allows organisations to manage and secure mobile devices like smartphones and tablets. Intune can enforce security policies, distribute apps, and remotely wipe lost or stolen devices.

Mitigation Strategies: Actions taken to reduce the risk or impact of a cyber threat. (e.g., application control, patching applications)

Multi-Factor Authentication (MFA): Requires users to provide two or more verification factors to access a system, improving security.

NIST Cybersecurity Framework (CSF): A voluntary, non-prescriptive framework from the National Institute of Standards and Technology (NIST) that helps organisations manage cybersecurity risks across five core functions: Identify, Protect, Detect, Respond, and Recover.

Nonconformity: A deviation from the requirements of the ISO 27001 standard identified during an audit. These can be major (critical security weaknesses) or minor (documentation gaps).

Notifiable Data Breach (NDB): An incident where personal information held by an organisation is lost, accessed, or disclosed without authorisation, and this is likely to result in serious harm to one or more individuals.

OAIC (Office of the Australian Information Commissioner): The independent statutory agency responsible for overseeing privacy laws in Australia, including the Notifiable Data Breaches scheme.

Observation: An informational note from the auditors about practices observed during the audit.

Opportunity for Improvement (OFI): An area in the ISMS identified during an audit that could be strengthened, even if it doesn't violate the ISO 27001 standard.

Oversight: The monitoring of the effectiveness of an organisation's cybersecurity program by the board of directors.

Password Cracking: The process of guessing or forcefully breaking a password to gain unauthorised access.

Patch Management: The process of finding, testing, and deploying security patches to fix vulnerabilities in software and systems.

Patch: A software update that fixes a security vulnerability.

Penetration Testing (Pen Testing): Simulating a cyberattack to identify vulnerabilities in a system and networks.

Penetration Tester: A penetration tester is an ethical hacker who simulates cyberattacks on a computer system or network with permission to identify vulnerabilities that malicious attackers could exploit.

Penetration Testing Report: The documented results of a simulated cyberattack, highlighting vulnerabilities and potential consequences.

Personally Identifiable Information (PII): Information or an opinion that can be used to identify an individual. This can include name, address, email address, phone number, date of birth, bank account details, and health information.

Phishing simulations: Mock phishing attacks sent to employees to test their ability to identify and avoid real phishing attempts.

Phishing: A deceptive email or message designed to trick the recipient into clicking a malicious link or revealing personal information.

Post-Incident Review: A process of examining a cyber incident to identify what went wrong, how the response could be improved, and what lessons can be learned to prevent future incidents.

Preparedness: The actions taken by an organisation to prepare for and mitigate potential cyber threats.

Prudential Standards: Standards set by a regulatory body (like APRA) to ensure the financial stability of institutions it regulates.

Ransomware: A type of malware that encrypts a victim's files, making them inaccessible, and demands a ransom payment to decrypt them.

Remote Access: The ability to access a computer system or network from a remote location, typically using a laptop, tablet, or smartphone over a secure connection.

Return on Security Investment (ROSI): A framework to assess the cost-effectiveness of cybersecurity investments. Boards can use ROSI to evaluate proposed security measures.

Risk Assessment: Evaluating the likelihood and potential impact of a security threat.

Risk Management: The process of identifying, assessing, and prioritising risks to an organisation. In cybersecurity, it refers specifically to risks related to cyber threats.

Security Controls: Measures implemented to safeguard an organization's assets, data, and systems from cyber threats. Controls can be technical (e.g., firewalls, encryption) or non-technical (e.g., security policies, procedures).

Security Information and Event Management (SIEM): A system that collects and analyses security data from various sources to detect threats.

Security Metrics: Measurable data points that track the effectiveness of cybersecurity controls and the overall security posture of the organisation. Boards should receive regular reports on key security metrics.

Social Engineering: The art of manipulating people into revealing confidential information or taking actions that compromise security.

Spear Phishing: Targeted phishing attacks crafted to appear legitimate to a specific person or organisation.

Standards: Documented specifications that provide a benchmark for good practice in a particular area. (e.g., ISO 27001)

Supply Chain Disruption: An interruption in the flow of goods and services due to a cyberattack, impacting delivery timelines, production, and customer satisfaction.

Supply Chain Visibility: Having a clear understanding of all participants in the supply chain, including their security posture, data flows, and potential risks. This helps identify weak links and potential security incidents.

Third-Party Risk Management: The process of evaluating and mitigating cybersecurity risks associated with vendors and other third-party partners. Boards should be informed of significant third-party risks.

Threat Intelligence: Information about cyber threats, attackers, and their methods.

Vendor Management System (VMS): A software system for managing vendor relationships, including security assessments and risk evaluations. This helps track vendor compliance with cybersecurity requirements.

Virtual Private Network (VPN): A secure tunnel that encrypts data traffic over the public internet. It allows users to connect to a private network remotely, such as a company network from a home office.

Vishing: Phishing attacks conducted over the phone, attempting to trick victims into revealing sensitive information.

Vulnerability Management: The process of identifying, prioritising, and remediating security vulnerabilities.

Vulnerability Report: A summary of identified vulnerabilities, their severity, and recommendations for remediation.

Vulnerability Scan: An automated process to identify weaknesses in systems and applications.

Vulnerability: A weakness in a system that can be exploited by attackers.

Webapp: A webapp (web application) is a software application accessed through a web browser, not requiring installation on individual devices, and delivering functionality similar to traditional desktop programs.

Wireless Access Points (WAPs): Devices that create a wireless network (Wi-Fi) connection. Users can connect their devices (laptops, phones, etc.) to the WAP to access the internet or other network resources.

Whaling: A high-level spear phishing attack targeting high-profile individuals within an organisation, often for financial gain.

Zero-Day Exploit: A security vulnerability unknown to software vendors, making it highly dangerous until a patch is developed.

Other Cybersecurity Glossaries

ACSC Glossary

UK National Cyber Security Centre (NCSC) Glossary

(ISC)² Cybersecurity Glossary

SANS Institute Information Security Reading Room

Cloud Security Alliance (CSA) Glossary of Cloud Computing Terms 

Fortinet Cybersecurity Glossary

Palo Alto Networks Cybersecurity Glossary

Saylor Academy Cybersecurity Essentials Glossary

Cybrary Cybersecurity Glossary

Other Technology Glossaries

Techopedia: A comprehensive online encyclopedia with definitions for a vast range of technology terms. https://www.techopedia.com/

PC Magazine Encyclopedia: A well-established resource for explanations of hardware, software, and IT concepts. https://www.pcmag.com/

Webopedia: Another extensive online dictionary dedicated to computer and internet technology terms. https://www.webopedia.com/

Microsoft Docs: Microsoft provides glossaries and documentation for its various programming languages and development tools.

https://learn.microsoft.com/en-us/docs/