Categories of Cybersecurity Frameworks

Categories of Cybersecurity Frameworks

Assessment

Presentation

Computers

9th - 12th Grade

Practice Problem

Hard

Created by

Riley Williams

FREE Resource

22 Slides • 7 Questions

1

media

Categories of Cybersecurity Frameworks

Cybersecurity 1A

2

Tech Tip Time!

3

Class Objectives

​Learners Can:

​Vocabulary:

  • Recognize uses for the three categories of cybersecurity frameworks

  • Identify the correct framework to use based on an organizations needs

  • Control framework

  • Program framework

  • Risk framework

media

4

Engage

  • There are many different cybersecurity frameworks.

  • Each organization usually chooses the right one for its company.

  • Consider the specific security needs of a hospital versus a school.

  • Think about the unique information these two organizations protect.

media
media

5

Drag and Drop

Question image
What information would a hospital want to protect?​​
Drag these tiles and drop them in the correct blank above
medical records
insurance information
enrollment history
academic transcripts
disciplinary records

6

Remember...

  • A security framework includes specific guidelines, standards, and best practices designed to lower security risks

    • The goal is to provide a comprehensive approach to managing an organization's cyber risks and ensuring the security of its systems and data.

  • Think back to the needs of a school and a hospital. Both have valuable data they need to protect.

    • School - protect personal records of learners

    • Hospital - protect patients' personal health and medical data

7

Three Categories of Cybersecurity Frameworks

​1. Control Frameworks

​2. Program Frameworks

​3. Risk Frameworks

8

Control Framework

​Imagine that you bought your very first house, and you need to put some things in place to keep it safe. You might install:

  • New locks on your doors;

  • Security cameras; or

  • Alarm systems

media

​Think of keeping your computer secure like you would your home!

9

Control Framework

  • Control framework: focuses on the technical tools needed to keep computer systems and information safe and ensures the company meets industry security standards

  • To protect data accessed through a computer, organizations might:

    • Require strong passwords;

    • Install firewalls to block certain websites and applications; or

    • Use encryption to send communications

media

10

Multiple Choice

Question image

What is an example of something a control framework uses to keep a system secure?

1

Giving employees access to all company files by default

2

Using firewalls to block unauthorized access

3

Setting up a company mission statement

4

Writing a policy for handling employee vacations

11

Program Framework

​Imagine that you are about to open your town's newest restaurant. Before you open the doors, you need a plan in place. Your plan might include:

  • Deciding what to put on the menu;

  • Hiring cooks and servers; and

  • Setting hours of operation.

media

A program framework helps you organize plans like this.

12

Program Framework

  • Program framework: helps you organize plans that everyone in your organization follows to keep information safe

  • Widespread efforts in a program framework to keep information safe might include:

    • Mandatory training on cybersecurity every 6 to 12 months;

    • Pushed updates to computers to keep the software current; and

    • Creating and testing steps for disaster recovery

media

13

Multiple Choice

Question image

Which of the following best fits into the purpose of a program framework?

1

Organizing a company-wide team-building event

2

Creating a marketing strategy for product launch

3

Writing a policy for password complexity

4

Carrying out a cybersecurity incident response drill

14

Risk Framework

Imagine that you are the supervisor of a fire department. It is your job to make sure the town is safe. You might:

  • Put warning signs around town when conditions are dry;

  • Go to schools to teach children about fire safety; and

  • Organize community events to clear debris from properties

media

Risks must also be considered in cybersecurity!

15

Risk Framework

  • Risk framework: works to identify dangers, so they can be slowed down or stopped

  • Organizations that use risk frameworks might:

    • Regularly evaluate the safety of current systems;

    • Employ monitoring tools that detect suspicious activity; or

    • Purchase cyber insurance to minimize the potential financial impacts a threat may cause.

media

16

Multiple Choice

Question image

What is an example of a risk that risk management frameworks look to identify?

1

The risk of unauthorized access to sensitive company data

2

The risk of a competitor launching a similar product

3

The risk of a printer running out of ink

4

the risk of power outages affecting the office building

17

Framework Selection

​Understanding what is needed is critical to an organizations decision in choosing one of the three categories of cybersecurity frameworks.

​Control Framework

  • Need to provide a baseline group of security controls.

  • Need to prioritize the implementation of security controls.

  • Need to construct a complete cybersecurity program.

  • Need to measure your program's security.

​Program Framework

  • Need to construct define the necessary processes for risk assessment and management.

  • Need to identify, measure, and quantify the organization's security risks.

​Risk Framework

18

​Let's practice choosing the right framework.

19

Scenario 1:

An e-commerce platform is growing quickly and wants to focus on identifying and managing risks associated with its customer data and online transactions.

The company needs a framework that can help assess and prioritize cybersecurity risks and pinpoint cyberthreats before they occur.

20

Scenario 1:

An e-commerce platform is growing quickly and wants to focus on identifying and managing risks associated with its customer data and online transactions.

The company needs a framework that can help assess and prioritize cybersecurity risks and pinpoint cyberthreats before they occur.

​A risk framework works best for this e-commerce company because it will help the organization identify, assess, and prioritize cybersecurity risks.

21

Scenario 2:

A bank is looking to establish rigorous internal security applications and software to comply with industry regulations.

The bank needs a framework that will guide it on the specific security tools and measures it must use to protect bank members' data and transactions.

22

Scenario 2:

A bank is looking to establish rigorous internal security applications and software to comply with industry regulations.

The bank needs a framework that will guide it on the specific security tools and measures it must use to protect bank members' data and transactions.

​A control framework is ideal for this bank because it provides detailed security measures and specific guidelines for regulatory compliance.

23

Scenario 3:

A national energy provider is focusing on establishing a robust cybersecurity policy to ensure the security and continuity of critical information.

The company needs a framework that helps organize its security practices and policies across various departments.

24

Scenario 3:

A national energy provider is focusing on establishing a robust cybersecurity policy to ensure the security and continuity of critical information.

The company needs a framework that helps organize its security practices and policies across various departments.

​A program framework is best suited for this energy provider because it offers a programmatic approach to managing policies across the organization.

25

​Let's review what we have learned!

26

Match

Question image

Match the categories of cybersecurity frameworks with their corresponding descriptions.

Focuses on the technical tools needed to keep computer systems and information safe

Helps you to organize plans that everyone in your organization follows to keep information safe

Works to identify dangers, so they can be slowed or stopped

Control framework

Program framework

Risk framework

27

Multiple Choice

Question image

To ensure both the security of customer data and the integrity of their applications, a company is looking to implement a comprehensive cybersecurity plan throughout its software development phase. This plan needs to address secure coding practices, vulnerability testing, and data protection mechanisms, ensuring that every team member follows security best practices from design to deployment.

Which category of cybersecurity frameworks is best for the software development company?

1

Risk framework

2

Control framework

3

Software framework

4

Program framework

28

Open Ended

Question image

Imagine your classmate missed today's lesson, and they need a rundown of the three categories of cybersecurity frameworks.

What is a tip you can provide to your classmate to help them remember the differences?

29

Class Recap!

What did we do?

Looking ahead to 1.1.3...

  • Recognized uses for the three categories of cybersecurity frameworks; and

  • Identified the correct framework to use based on an organization's needs

  • Learn about the NIST Cybersecurity Framework

media
media

Categories of Cybersecurity Frameworks

Cybersecurity 1A

Show answer

Auto Play

Slide 1 / 29

SLIDE