Compliance Hub

Compliance, mapped to
real security work

Frameworks tell you what good security looks like. This hub shows how River Security helps you get there, control by control, mapping every article to the services that deliver it: Attack Surface Management, Penetration Testing, CISO as a Service, and Incident Response.

6Frameworks & regulations
488Controls mapped
4Services aligned

Framework explorer

Pick a framework

Governance frameworks set the standard you choose to meet; regulations are the law you must comply with. Select one to see coverage and drill into individual controls.

Regulation
Governance

Regulation

DORA

The Digital Operational Resilience Act (DORA) is an EU regulation aimed at strengthening the cybersecurity and operational resilience of financial institutions. It sets requirements for managing ICT risks, incident reporting, and third-party risk management to ensure that financial entities can withstand, respond to, and recover from cyber threats. DORA aims to standardize digital resilience practices across the EU financial sector, reducing fragmentation and enhancing the sector's ability to handle disruptions.

53 of 53 controls directly addressed by a River Security service.

Service coverage

Strengths

  • Enhanced Resilience: Improves the financial sector's ability to withstand and recover from cyber incidents.
  • Standardization: Creates a unified framework for digital resilience across the EU, reducing regulatory fragmentation.
  • Risk Management: Strengthens ICT risk management practices and third-party oversight.
  • Compliance Clarity: Provides clear requirements for financial entities to follow, simplifying regulatory adherence.
  • Incident Reporting: Establishes consistent incident reporting standards, improving response coordination.

Trade-offs

  • Implementation Costs: Can be costly for organizations, especially smaller entities, to meet compliance requirements.
  • Complexity: Requires significant effort to integrate new processes and reporting standards.
  • Third-Party Challenges: Increased oversight of third-party providers may complicate vendor relationships.
  • Regulatory Burden: Adds to the existing regulatory obligations for financial institutions, potentially straining resources.
Controls & how we help
DirectPartialNot mapped
5Governance and organisationCISO-aaS

DORA puts ICT risk in the boardroom. Our CISO as a Service gives management the framework and accountability the regulation demands of them directly.

  • CISO as a ServiceCISO as a Service plays a crucial role in establishing governance and organizational structures required for compliance. It provides expert guidance in developing and implementing policies, procedures, and frameworks that align with regulatory requirements. This service ensures that the organization has a robust governance structure in place to manage and oversee its information security program effectively.
6ICT risk management frameworkASMPentestCISO-aaSIR

The framework is the backbone of DORA. We find and test the risks, set the framework, and build the response capability it must contain.

  • .2Shall include at least strategies, policies, procedures, ICT protocols and tools that are necessary to duly and adequately protect all information assets and ICT assets
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps identify and manage external threats to information and ICT assets, ensuring the organization has the necessary tools and protocols to protect these assets. It provides continuous monitoring and vulnerability assessment, which is crucial for maintaining a robust security posture.
    • Penetration TestingInternal Penetration Testing uncovers vulnerabilities within the organization's internal network, ensuring that all ICT assets are adequately protected. This aligns with the requirement for tools and procedures to protect information assets.
    • CISO as a ServiceCISO as a Service assists in developing and implementing comprehensive strategies, policies, and procedures tailored to protect information and ICT assets. This service ensures that the organization adheres to compliance requirements by maintaining up-to-date security documentation and protocols.
    • Incident ResponseIncident Response provides the handling and recovery capability the framework must build in and rehearse.
  • .3Shall minimize the impact of ICT risk by deploying appropriate strategies, policies, procedures, ICT protocols and tools.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps minimize ICT risk by continuously monitoring the external attack surface, identifying vulnerabilities, and detecting new assets. By proactively managing these risks, EASM can prevent incidents before they occur, thereby reducing potential impacts.
    • Penetration TestingInternal Penetration Testing uncovers vulnerabilities within the organization’s internal network. By identifying and mitigating these internal risks, the organization can minimize the impact of potential ICT threats.
    • CISO as a ServiceCISO as a Service provides expert guidance in developing and implementing strategies, policies, and procedures tailored to minimizing ICT risk. This ensures that the organization has a robust framework for risk management in place.
    • Incident ResponseIncident Response provides the handling and recovery capability the framework must build in and rehearse.
  • .5Following supervisory instructions or conclusions derived from relevant digital operational resilience testing or audit processes. It shall be continuously improved on the basis of lessons derived from implementation and monitoring.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementThe External Attack Surface Monitorings offensive nature is a continues testing of the digital operational resilience, it provides instructions on how to correct the specific problem but also often reveals a broader weakness, as weak patchmanagement or similar
    • Penetration TestingAn internal pentest has a much slower cadence than EASM but will provide valuable insights to its given scope, these will continualy improve what is being tested with revealin weak points
    • CISO as a ServiceCISO as a Service designs and documents the ICT risk-management framework, policies and processes.
    • Incident ResponseIncident Response provides the handling and recovery capability the framework must build in and rehearse.
  • .8gImplementing digital operational resilience testing, in accordance with Chapter IV of this Regulation.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps ensure compliance by continuously monitoring and testing the external attack surface. This proactive identification of vulnerabilities and potential threats enables the organization to address issues before they can be exploited, thus contributing to digital operational resilience.
    • Penetration TestingInternal Penetration Testing ensures compliance by rigorously testing the internal systems and networks for vulnerabilities. This helps in identifying and mitigating risks within the organization's internal environment, thereby enhancing overall digital operational resilience.
    • CISO as a ServiceCISO as a Service designs and documents the ICT risk-management framework, policies and processes.
    • Incident ResponseIncident Response provides the handling and recovery capability the framework must build in and rehearse.
  • .9Define a holistic ICT multi-vendor strategy, at group or entity level, showing key dependencies on ICT third-party service providers and explaining the rationale behind the procurement mix of ICT third-party service providers.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps in identifying third-party ICT service providers and assessing their potential risks. This information is critical in defining a multi-vendor strategy by highlighting key dependencies and identifying the risk profile of each vendor.
    • Penetration TestingPenetration testing proves the exploitable risks the framework must manage.
    • CISO as a ServiceCISOaaS provides expert guidance in creating and documenting a holistic ICT multi-vendor strategy. The service helps in identifying key dependencies, evaluating vendors, and defining the rationale behind the procurement mix of ICT third-party service providers.
    • Incident ResponseIncident Response provides the handling and recovery capability the framework must build in and rehearse.
7ICT systems, protocols and toolsASMPentestCISO-aaS

Resilient systems have to be reliable and secure by design. We set the standards and continuously monitor and test the systems that carry your operations.

  • Attack Surface ManagementActive Focus monitors the exposed ICT systems and tools for weaknesses and drift.
  • Penetration TestingPenetration testing checks that ICT systems, protocols and tools hold up under attack.
  • CISO as a ServiceCISO as a Service helps ensure that ICT systems, protocols, and tools are compliant by designing and implementing security strategies, policies, and procedures. This service provides expert guidance to maintain up-to-date and effective security measures that align with compliance standards.
8IdentificationASMPentestCISO-aaS

You can't manage risk on assets you haven't found. Active Focus continuously identifies your ICT assets and exposures; we frame the risk around them.

  • .1Shall identify, classify, and adequately document all ICT-supported business functions, roles and responsibilities, the information assets and ICT assets supporting those functions, and their roles and dependencies in relation to ICT risk
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps by continuously scanning and identifying new and existing ICT assets, thus providing a comprehensive view of the external attack surface. This identification is crucial for understanding the assets supporting business functions and their associated risks.
    • Penetration TestingInternal Penetration Testing assists in uncovering hidden or undocumented assets and vulnerabilities within the organization. This ensures a thorough classification and documentation of all ICT assets and their associated risks.
    • CISO as a ServiceCISO as a Service provides expert guidance in developing and maintaining policies, procedures, and documentation. This service ensures that all ICT-supported business functions, roles, responsibilities, and assets are adequately documented and classified, aligning with compliance requirements.
  • .2On a continuous basis, identify all sources of ICT risk, in particular, the risk exposure to and from other financial entities, and assess cyber threats and ICT vulnerabilities relevant to their ICT-supported business functions, information assets, and ICT assets.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps in continuously identifying all sources of ICT risk by performing vulnerability scanning, detecting new assets, and assessing potential risks from third parties. This proactive approach helps in preemptively identifying potential incidents.
    • Penetration TestingInternal Penetration Testing uncovers assets, vulnerabilities, and risks within the organization. By identifying internal threats and weaknesses, it helps in mitigating risks to ICT-supported business functions, information assets, and ICT assets.
    • CISO as a ServiceCISOaaS assists in building out strategies, policies, and procedures that support continuous identification and assessment of ICT risks. An expert consultant can help in establishing a robust risk management framework tailored to the organization's specific needs.
  • .3Shall perform a risk assessment upon each major change in the network and information system infrastructure, in the processes or procedures affecting their ICT-supported business functions, information assets, or ICT assets.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM ensures compliance by continuously monitoring and assessing the external attack surface for vulnerabilities and new assets upon each major change, providing a proactive risk assessment.
    • Penetration TestingInternal Penetration Testing aids compliance by identifying and evaluating internal vulnerabilities and risks associated with changes in the network and information system infrastructure.
    • CISO as a ServiceCISO as a Service supports compliance by developing and updating risk assessment policies and procedures to ensure they are followed for each significant change in the ICT environment.
  • .4Shall identify all information assets and ICT assets, including those on remote sites, network resources, and hardware equipment, and shall map those considered critical.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps in identifying external assets and potential risks associated with them. It continuously monitors and discovers new assets, including third-party components, which can be critical for compliance with asset identification requirements.
    • Penetration TestingInternal Penetration Testing uncovers internal assets, vulnerabilities, and risks. This service helps in mapping critical assets within the organization, including network resources and hardware equipment, thereby supporting compliance.
    • CISO as a ServiceCISOaaS assists in developing comprehensive strategies and documentation for asset management. An expert consultant ensures that all information and ICT assets are identified and mapped correctly, including those at remote sites.
  • .5All processes that are dependent on ICT third-party service providers, and shall identify interconnections with ICT third-party service providers.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps identify third-party service providers and their interconnections by continuously scanning the external attack surface. It detects new assets and potential risks associated with third-party dependencies, ensuring preemptive identification of incidents.
    • Penetration TestingPenetration testing surfaces unknown assets and dependencies encountered during an engagement.
    • CISO as a ServiceCISOaaS aids in building comprehensive strategies, policies, and procedures that document dependencies on third-party service providers and outline their interconnections. This ensures that all third-party risks are managed and compliance requirements are met.
  • .6Shall maintain relevant inventories and update them periodically and every time any major change
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps maintain an up-to-date inventory of external assets by continuously scanning for new assets, changes, and vulnerabilities. This ensures that any major change is promptly detected and the inventory is updated accordingly.
    • Penetration TestingPenetration testing surfaces unknown assets and dependencies encountered during an engagement.
    • CISO as a ServiceCISOaaS provides expert guidance in developing and maintaining policies and procedures for inventory management. This includes setting up processes for periodic updates and ensuring that inventories are revised after any major changes.
9Protection and preventionASMPentestCISO-aaSIR

Prevention is cheaper than recovery. We set the protective controls, monitor the exposed surface, and prove the controls hold under attack.

  • .1Shall continuously monitor and control the security and functioning of ICT systems and tools and shall minimize the impact of ICT risk on ICT systems through the deployment of appropriate ICT security tools.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM ensures continuous monitoring of the external attack surface, identifying vulnerabilities and new assets in real-time. This proactive approach helps in controlling the security and functioning of ICT systems by preemptively addressing potential risks.
    • Penetration TestingInternal Penetration Testing uncovers vulnerabilities within the organization's internal network, allowing the organization to mitigate these risks and ensure the security and proper functioning of ICT systems.
    • CISO as a ServiceCISOaaS helps in the development and implementation of comprehensive security policies and procedures, ensuring continuous monitoring and control of ICT systems. The expertise provided by a CISO ensures that appropriate ICT security tools are deployed effectively.
    • Incident ResponseIncident Response capabilities are crucial for minimizing the impact of ICT risks. In the event of a security breach, IR services help in containing and recovering from the incident, thereby ensuring the continuity and security of ICT systems.
  • .2Financial entities shall design, procure and implement ICT security policies, procedures, protocols and tools that aim to ensure the resilience, continuity, and availability of ICT systems….whether at rest, in use, or in transit.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps ensure compliance by continuously scanning for vulnerabilities and detecting new assets, thus proactively identifying potential risks to ICT systems. This helps in maintaining the resilience, continuity, and availability of systems by preemptively addressing vulnerabilities.
    • Penetration TestingInternal Penetration Testing supports compliance by uncovering internal vulnerabilities and risks within the organization. By identifying and mitigating these risks, it ensures the resilience and security of ICT systems, whether at rest, in use, or in transit.
    • CISO as a ServiceCISO as a Service sets the protection and prevention controls and standards.
    • Incident ResponseIncident Response readiness backs up prevention for when a control is bypassed.
  • .3bUnauthorized access and technical flaws that may hinder business activity.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps identify unauthorized access attempts and technical flaws in external-facing assets through continuous monitoring and vulnerability scanning. By detecting these issues preemptively, EASM helps prevent potential disruptions to business activity.
    • Penetration TestingInternal Penetration Testing uncovers vulnerabilities within the organization's internal network that could lead to unauthorized access or technical flaws. By identifying and mitigating these risks, the organization can ensure its business activities are not hindered by internal security issues.
    • CISO as a ServiceCISO as a Service sets the protection and prevention controls and standards.
    • Incident ResponseIncident Response readiness backs up prevention for when a control is bypassed.
  • .3cPrevent the lack of availability, the impairment of the authenticity and integrity, the breaches of confidentiality and the loss of data.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementExternal Attack Surface Management (EASM) helps prevent breaches of confidentiality and loss of data by continuously scanning for vulnerabilities and new assets. It identifies potential risks preemptively, ensuring that threats are mitigated before they can affect availability, authenticity, or integrity.
    • Penetration TestingInternal Penetration Testing uncovers vulnerabilities within the internal network and systems, helping to prevent breaches of confidentiality, data loss, and impairment of authenticity and integrity. This proactive approach ensures internal defenses are robust.
    • CISO as a ServiceChief Information Security Officer as a Service (CISOaaS) aids in developing and implementing strategies, policies, and procedures that align with compliance requirements. This includes measures to ensure availability, authenticity, integrity, and confidentiality of data.
    • Incident ResponseIncident Response (IR) capabilities ensure that, in the event of a security incident, rapid containment and recovery actions are taken. This helps to minimize the impact on availability, authenticity, integrity, and confidentiality of data, ensuring swift restoration of normal operations.
  • .4bEstablish a sound network and infrastructure management structure using appropriate techniques, methods and protocols.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps in identifying vulnerabilities and potential risks in the network and infrastructure by continuously monitoring the external attack surface. It preemptively detects new assets and vulnerabilities, ensuring the management structure is robust and up-to-date.
    • Penetration TestingInternal Penetration Testing uncovers internal vulnerabilities and risks within the organization's network and infrastructure. It helps in identifying weaknesses and provides actionable insights to fortify the internal management structure.
    • CISO as a ServiceCISO as a Service aids in establishing comprehensive strategies, policies, and procedures that align with best practices for network and infrastructure management. This service ensures that the techniques, methods, and protocols used are appropriate and compliant with regulatory requirements.
    • Incident ResponseIncident Response readiness backs up prevention for when a control is bypassed.
  • .4eImplement documented policies, procedures and controls for ICT change management….in order to ensure that all changes to ICT systems are recorded, tested, assessed, approved, implemented and verified in a controlled manner.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps in identifying and recording changes to ICT systems by continuously monitoring the external attack surface. It ensures that new assets and vulnerabilities are detected and assessed preemptively, which supports the testing and verification aspects of change management.
    • Penetration TestingInternal Penetration Testing supports the testing and assessment phases of change management by uncovering vulnerabilities and risks associated with changes within the organization's ICT systems. This ensures changes are thoroughly tested before implementation.
    • CISO as a ServiceCISO as a Service is crucial for developing and implementing documented policies, procedures, and controls for ICT change management. The expert consultant can help create a structured approach to ensure all changes are recorded, assessed, approved, implemented, and verified in a controlled manner.
    • Incident ResponseIncident Response readiness backs up prevention for when a control is bypassed.
10DetectionASMPentestCISO-aaSIR

Attackers rely on going unseen. We set the detection strategy, add outside-in monitoring, and test whether intrusions actually get caught.

  • .1Including ICT network performance issues and ICT-related incidents, and to identify potential material single points of failure.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps identify potential single points of failure by continuously monitoring the external attack surface and detecting new assets, vulnerabilities, and third-party risks. This proactive approach helps in preemptively identifying and addressing ICT network performance issues and incidents.
    • Penetration TestingInternal Penetration Testing uncovers vulnerabilities and risks from within the organization. By simulating attacks internally, it helps identify single points of failure and other weaknesses in the ICT network that could lead to performance issues or incidents.
    • CISO as a ServiceCISO as a Service provides expert guidance in developing strategies, policies, and procedures that address ICT network performance issues and potential single points of failure. This service ensures that the organization has a robust framework for identifying and mitigating these risks.
    • Incident ResponseIncident Response acts on what detection surfaces.
11Response and recoveryASMPentestCISO-aaSIR

When resilience is tested for real, speed matters. We run the response and recovery and rehearse the plan against realistic attacks.

  • .1Periodically test appropriate ICT business continuity plans, notably with regard to critical or important functions outsourced or contracted through arrangements with ICT third-party service providers.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps ensure compliance by continuously monitoring and testing external attack surfaces, including those of third-party service providers. This helps identify potential vulnerabilities and threats, ensuring that business continuity plans can address external risks effectively.
    • Penetration TestingInternal Penetration Testing ensures compliance by identifying vulnerabilities and risks within the internal network, which is crucial for testing the robustness of ICT business continuity plans. This includes uncovering potential issues that could disrupt critical functions.
    • CISO as a ServiceCISOaaS assists in developing, reviewing, and periodically updating ICT business continuity plans. The expert guidance ensures that the plans are comprehensive and align with compliance requirements, particularly for functions outsourced to third-party providers.
    • Incident ResponseIncident Response services ensure compliance by providing a framework for responding to and recovering from incidents. This includes testing the effectiveness of business continuity plans in real-world scenarios, ensuring that critical functions can be restored quickly and efficiently.
12Backup policies and procedures, restoration and recovery procedures and methodsASMPentestCISO-aaS

Backups are your last line — but only if an attacker can't reach or destroy them. We set the strategy, find exposed backups, and test their resilience.

  • Attack Surface ManagementActive Focus hunts for backup stores and consoles exposed to the internet, so recovery data is not itself a target.
  • Penetration TestingInternal Penetration Testing can help ensure compliance by identifying vulnerabilities in backup systems and procedures. This ensures that any weaknesses in the backup processes are uncovered and can be mitigated, thereby improving the overall resilience of the backup and recovery mechanisms.
  • CISO as a ServiceCISO as a Service (CISOaaS) can help ensure compliance by developing comprehensive backup policies and procedures. This includes creating detailed restoration and recovery procedures that are aligned with compliance requirements. The service provides expertise in drafting, implementing, and maintaining these critical policies and procedures.
13Learning and evolvingASMPentestCISO-aaSIR

Resilience is a moving target. We feed real findings and incident lessons back into a programme that keeps improving.

  • .1Shall have in place capabilities and staff to gather information on vulnerabilities and cyber threats, ICT-related incidents, in particular cyber-attacks, and analyze the impact they are likely to have on their digital operational resilience.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementIs uniqly positioned to analyze and test information on vulnerabilities on the external attack surface. The collation of CTI and testing expertise makes the EASM the perfect tool to test external operational resilience
    • Penetration TestingSimilar to the EASM, but less frequently and ont the internal attack surface. It will, with the correct scope, test the internal operational resilience to prevent cyber attacks
    • CISO as a ServiceCISO as a Service (CISOaaS) can help companies create procedures and frameworks to establish the correct sensors. These will in turn gather the most relevant information for the above. This could include but is not limited to tools like EASM, CTI providers, vulnerability scans etc.
    • Incident ResponseIncident Response post-incident reviews turn real incidents into concrete lessons.
  • .3Lessons derived from the digital operational resilience testing carried out in accordance with Articles 26 and 27 and from real-life ICT-related incidents, in particular cyber-attacks.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continually surfaces new exposures that drive improvement of the programme.
    • Penetration TestingInternal Penetration Testing helps ensure compliance by simulating cyber-attacks within the organization to identify vulnerabilities and weaknesses. The lessons learned from these tests can be used to improve digital operational resilience.
    • CISO as a ServiceCISO as a Service aids in compliance by developing and refining policies, procedures, and documentation based on insights gained from digital operational resilience testing and real-life incidents. This ensures that the organization is well-prepared and adheres to regulatory requirements.
    • Incident ResponseIncident Response services ensure compliance by providing expertise in handling real-life ICT-related incidents, especially cyber-attacks. The lessons learned from these incidents help in refining the organization's resilience strategies and recovery plans.
  • .4They shall map the evolution of ICT risk over time, analyze the frequency, types, magnitude, and evolution of ICT-related incidents, in particular cyber-attacks and their patterns, with a view to understanding the level of ICT risk exposure, in particular in relation to critical or important functions, and enhance the cyber maturity and preparedness of the financial entity.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continually surfaces new exposures that drive improvement of the programme.
    • Penetration TestingInternal Penetration Testing helps identify vulnerabilities and risks within the organization's internal network over time. By performing regular internal penetration tests, the organization can analyze the evolution of ICT-related risks, understand their frequency, and identify patterns of potential cyber-attacks. This process contributes to mapping the evolution of ICT risk and enhancing the organization's cyber maturity and preparedness.
    • CISO as a ServiceCISO as a Service provides expert guidance in developing comprehensive strategies for risk management and incident analysis. The CISOaaS consultant can assist in mapping the evolution of ICT risk, analyzing the frequency and types of incidents, and understanding the organization's risk exposure. Their expertise helps in enhancing the cyber maturity and preparedness of the financial entity by implementing appropriate policies, procedures, and documentation.
    • Incident ResponseIncident Response services play a crucial role in analyzing and mitigating ICT-related incidents. By responding to and documenting incidents, the IR team can provide valuable insights into the frequency, types, and patterns of cyber-attacks. This information is essential for understanding the level of ICT risk exposure and improving the organization's cyber maturity and preparedness. The IR team also aids in the recovery process, ensuring that the organization can quickly return to normal operations after an incident.
14CommunicationCISO-aaSIR

Clear communication in a crisis is a control of its own. We set the crisis-communication plan and act as your technical voice during an incident.

  • CISO as a ServiceCISO as a Service provides expert guidance in developing comprehensive strategies comunication
  • Incident ResponseIncident Response acts as your technical voice in communications during and after an incident.
15Further harmonisation of ICT risk management tools, methods, processes and policiesASMPentestCISO-aaS

We translate DORA's technical standards into working controls — and continuously monitor and test the tools that implement them.

  • Attack Surface ManagementEASM helps ensure compliance by continuously monitoring and managing the external attack surface, identifying vulnerabilities, and detecting new assets. This proactive approach contributes to the harmonisation of ICT risk management tools by providing real-time data and insights, which can be integrated into existing risk management processes and policies.
  • Penetration TestingInternal Penetration Testing supports compliance by identifying and addressing vulnerabilities within the internal network. This service uncovers hidden risks and helps harmonise risk management methods by ensuring that internal security measures are robust and aligned with best practices.
  • CISO as a ServiceCISOaaS aids in compliance by providing expert guidance in developing and harmonising ICT risk management policies, procedures, and documentation. This service ensures that all aspects of ICT risk management are aligned with regulatory requirements and industry standards.
16Simplified ICT risk management frameworkASMPentestCISO-aaSIR

Smaller entities still carry the risk. We deliver a right-sized version of the full framework — find, test, govern and respond.

  • .1cminimise the impact of ICT risk through the use of sound, resilient and updated ICT systems, protocols and tools which are appropriate… adequately protect availability, authenticity, integrity and confidentiality of data in the network and information systems
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps ensure compliance by continuously monitoring the external attack surface, identifying vulnerabilities, and detecting new assets. This proactive approach helps in minimizing ICT risks and ensures that the systems are sound, resilient, and up-to-date. By identifying potential incidents preemptively, EASM helps protect the availability, authenticity, integrity, and confidentiality of data.
    • Penetration TestingInternal Penetration Testing uncovers vulnerabilities and risks within the organization's internal network. This helps in minimizing ICT risks by identifying and mitigating internal threats. Ensuring that internal systems, protocols, and tools are resilient and updated helps protect the availability, authenticity, integrity, and confidentiality of data.
    • CISO as a ServiceCISO as a Service delivers a proportionate ICT risk-management framework for smaller entities.
    • Incident ResponseIncident Response provides the response capability the simplified framework must include.
  • .1eIdentify key dependencies on ICT third-party service providers.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously discovers assets and vulnerabilities feeding the simplified framework.
    • Penetration TestingInternal Penetration Testing can help identify dependencies on ICT third-party service providers by uncovering internal systems, applications, and data flows that rely on external services. This can highlight critical third-party dependencies.
    • CISO as a ServiceCISO as a Service delivers a proportionate ICT risk-management framework for smaller entities.
    • Incident ResponseIncident Response provides the response capability the simplified framework must include.
  • .1gTest, on a regular basis, the plans and measures referred to in point (f), as well as the effectiveness of the controls implemented in accordance with points (a) and (c).
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps ensure compliance by regularly scanning and identifying vulnerabilities and new assets, thereby testing the effectiveness of controls from an external perspective. This continuous monitoring and testing align with the requirement to test plans and measures regularly.
    • Penetration TestingInternal Penetration Testing evaluates the effectiveness of internal controls and security measures by simulating attacks within the organization. Regular internal tests validate the implementation and efficacy of security controls, addressing the compliance requirement to test plans and measures.
    • CISO as a ServiceCISOaaS provides expert guidance to create and implement effective security policies and procedures. This service ensures that there are structured plans and measures in place and that they are regularly reviewed and tested for effectiveness, meeting compliance requirements.
    • Incident ResponseIncident Response (IR) services include regular testing of incident response plans through simulations and drills. These activities ensure that the plans are effective and that the organization is prepared for potential incidents, aligning with the compliance requirement to test the effectiveness of controls.
17ICT-related incident management processPentestCISO-aaSIR

A defined process is what turns chaos into response. We build the incident-management process and rehearse it against realistic attacks.

  • Penetration TestingPenetration testing and attack simulation rehearse the incident-management process end to end.
  • CISO as a ServiceThe CISO as a Service (cisoaas) can help establish a robust ICT-related incident management process by developing comprehensive incident response policies, procedures, and documentation. This ensures that the organization is prepared to handle incidents effectively and in compliance with relevant regulations.
  • Incident ResponseIncident Response (IR) services are crucial for managing ICT-related incidents. They provide the expertise and resources needed to contain, mitigate, and recover from incidents, ensuring that the organization can respond effectively and minimize the impact of such events. This directly supports compliance with the requirement for an ICT-related incident management process.
18Classification of ICT-related incidents and cyber threatsCISO-aaSIR

Getting severity right drives everything that follows. We set the classification criteria and apply them accurately when it matters.

  • CISO as a ServiceCISOaaS can help ensure compliance by developing and implementing comprehensive strategies, policies, and procedures for the classification of ICT-related incidents and cyber threats. An expert consultant can provide the necessary framework and guidelines for consistent and effective classification.
  • Incident ResponseIncident Response (IR) services ensure compliance by providing expertise in the containment, analysis, and classification of ICT-related incidents and cyber threats. IR teams can help categorize incidents based on severity, type, and impact, facilitating a structured response and recovery process.
19Reporting of major ICT-related incidents and voluntary notification of significant cyber threatsCISO-aaSIR

DORA's reporting deadlines are tight. We prepare the templates and drive the reports as your technical partner with the authorities.

  • CISO as a ServiceCISO as a Service (CISOaaS) can help ensure compliance with this control by establishing and maintaining robust incident reporting procedures and threat notification processes. The service can aid in developing the necessary documentation, protocols, and training required for timely and accurate reporting of ICT-related incidents and threats.
  • Incident ResponseIncident Response drives the reports and acts as technical partner in dialogue with the authorities.
20Harmonisation of reporting content and templatesCISO-aaSIR

Consistent reporting saves precious time under pressure. We build reusable templates aligned to DORA’s required content.

  • CISO as a ServiceIn tandem with IR inhouse team and provider the CISO provides valuable insights and structure to develop these SOP's
  • Incident ResponseIncident Response services can help ensure compliance by providing structured and standardised reporting during and after an incident. These services often include detailed documentation and templates that can be harmonised to meet regulatory requirements.
21Centralisation of reporting of major ICT-related incidentsCISO-aaSIR

One reporting channel, done right. We set up the process so submissions to the central hub are timely and complete.

  • CISO as a ServiceCISO as a Service (CISOaaS) can help ensure compliance with the centralisation of reporting major ICT-related incidents by developing and implementing robust reporting policies and procedures. They can create a centralized system for incident reporting, ensuring that all incidents are documented, tracked, and communicated to the relevant stakeholders in a consistent and compliant manner.
  • Incident ResponseIncident Response supplies the incident detail the centralised report depends on.
22Supervisory feedbackCISO-aaSIR

Regulator feedback is only useful if you act on it. We turn supervisory findings into concrete improvements.

  • CISO as a ServiceCISO as a Service turns supervisory feedback into a prioritised improvement plan.
  • Incident ResponseIncident Response (IR) can help ensure compliance with supervisory feedback by providing comprehensive post-incident analysis and reporting. In the event of an incident, IR teams can document the response process, identify root causes, and propose improvements. This documentation and analysis can be presented to supervisory bodies as evidence of compliance and proactive improvement efforts. Furthermore, IR teams can incorporate supervisory feedback into their incident response plans and procedures, ensuring that any identified weaknesses or gaps are addressed and rectified in future incidents.
23Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers, and electronic money institutionsCISO-aaSIR

Payment incidents carry their own obligations. We handle them and manage the specific reporting they trigger.

  • CISO as a ServiceCISO as a Service sets the process for operational and security payment-related incident obligations.
  • Incident ResponseIncident Response (IR) is highly relevant. IR services help manage and mitigate operational or security payment-related incidents by containing the incident, recovering systems, and ensuring a return to normal operations. This ensures compliance by addressing the specific control requirements related to payment-related incidents.
24General requirements for the performance of digital operational resilience testingASMPentestCISO-aaS

Testing is where DORA gets real. We build the testing programme and run the assessments that prove your resilience — not just assert it.

  • .1Establish, maintain, and review a sound and comprehensive digital operational resilience testing programme as an integral part of the ICT risk-management framework.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus contributes continuous assessment data to the resilience-testing programme.
    • Penetration TestingInternal Penetration Testing ensures compliance by identifying and mitigating internal vulnerabilities and risks, which is a critical component of a comprehensive digital operational resilience testing program.
    • CISO as a ServiceCISO as a Service helps ensure compliance by aiding in the establishment, maintenance, and review of policies, procedures, and documentation needed for a robust digital operational resilience testing program.
  • .2The digital operational resilience testing programme shall include a range of assessments, tests, methodologies, practices, and tools.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus contributes continuous assessment data to the resilience-testing programme.
    • Penetration TestingInternal penetration testing ensures compliance by conducting thorough assessments of internal systems, identifying vulnerabilities, and providing actionable insights to enhance resilience. This helps cover the 'assessments' and 'tests' aspects of the control.
    • CISO as a ServiceCISO as a Service helps ensure compliance by developing and implementing a comprehensive digital operational resilience testing programme. This includes creating policies, procedures, and documentation that outline the necessary methodologies, practices, and tools, thereby covering the broader scope of the control.
  • .3shall follow a risk-based approach taking into account the criteria set out in Article 4(2) duly considering the evolving landscape of ICT risk, any specific risks to which the financial entity concerned is or might be exposed, the criticality of information assets and of services provided
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus contributes continuous assessment data to the resilience-testing programme.
    • Penetration TestingInternal Penetration Testing helps ensure compliance by identifying vulnerabilities and risks within the organization's internal network. By uncovering and mitigating these risks, the organization can better understand and address the specific ICT risks to which it is exposed, thus supporting a risk-based approach.
    • CISO as a ServiceCISO as a Service (CISOaaS) helps ensure compliance by providing expert guidance in developing and implementing a risk-based approach. This includes creating strategies, policies, and procedures that take into account the evolving ICT risk landscape and the criticality of information assets and services. CISOaaS ensures that the organization is aligned with the criteria set out in Article 4(2).
  • .4Shall ensure that tests are undertaken by independent parties, whether internal or external.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus contributes continuous assessment data to the resilience-testing programme.
    • Penetration TestingInternal penetration testing ensures compliance by conducting thorough assessments of the organization's internal systems and networks by independent parties, identifying vulnerabilities and providing actionable insights to mitigate risks.
    • CISO as a ServiceCISO as a Service ensures compliance by facilitating the development and implementation of testing strategies and policies, and by coordinating with independent parties to perform these tests effectively. They ensure that tests are unbiased and meet regulatory requirements.
  • .5Shall establish procedures and policies to prioritise, classify and remedy all issues revealed throughout the performance of the tests and shall establish internal validation methodologies to ascertain that all identified weaknesses, deficiencies or gaps are fully addressed
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus contributes continuous assessment data to the resilience-testing programme.
    • Penetration TestingInternal Penetration Testing can uncover assets, vulnerabilities, and other risks within the organization. This helps prioritize, classify, and remedy issues found during testing by providing detailed reports on identified weaknesses, deficiencies, and gaps.
    • CISO as a ServiceCISO as a Service helps in establishing comprehensive procedures and policies needed to prioritize, classify, and remedy identified issues. They also aid in creating internal validation methodologies to ensure all identified weaknesses, deficiencies, or gaps are fully addressed.
25Testing of ICT tools and systemsASMPentestCISO-aaS

Vulnerability scans, assessments, penetration tests — this is core River. We continuously test your ICT tools and systems and act on what we find.

  • .1Execution of appropriate tests, such as vulnerability assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews, questionnaires and scanning software solutions, source code reviews where feasible, scenario-based tests, compatibility testing, performance testing, end-to-end testing and penetration testing.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM ensures compliance by performing continuous vulnerability assessments, open source analyses, and network security assessments. It helps identify new assets and vulnerabilities in real-time, providing ongoing protection and proactive management of the external attack surface.
    • Penetration TestingInternal Penetration Testing contributes to compliance by uncovering internal vulnerabilities and risks within the organization. It includes network security assessments, gap analyses, and scenario-based tests, ensuring a thorough evaluation of internal security measures.
    • CISO as a ServiceCISOaaS supports compliance by developing and implementing strategies, policies, and procedures for executing various security tests. It ensures that all necessary tests such as vulnerability assessments, penetration testing, and gap analyses are conducted regularly and effectively.
  • .3Duly considering the need to maintain a balanced approach between the scale of resources and the time to be allocated to the ICT testing provided for in this Article, on the one hand, and the urgency, type of risk, criticality of information assets and of services provided.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps maintain a balanced approach by continuously monitoring and testing the external attack surface, identifying vulnerabilities and risks in real-time. This allows for efficient allocation of resources and timely responses to urgent threats.
    • Penetration TestingInternal Penetration Testing ensures that critical internal assets and services are regularly assessed for vulnerabilities, helping to balance resource allocation based on the criticality and risk associated with these assets.
    • CISO as a ServiceCISO as a Service provides strategic guidance to ensure that policies and procedures are in place to balance resources and time for ICT testing, considering the urgency and criticality of information assets.
26Advanced testing of ICT tools, systems and processes based on TLPT(TIBER)ASMPentestCISO-aaSIR

TLPT is threat-led penetration testing — literally our craft. We run intelligence-led red-team tests against your live systems to DORA's standard.

  • .1Shall carry out at least every 3 years advanced testing by means of TLPT.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus maps the live attack surface that threat-led penetration testing then targets in depth.
    • Penetration TestingInternal Penetration Testing can directly fulfill this requirement by conducting advanced testing within the organization to uncover vulnerabilities and risks.
    • CISO as a ServiceCISO as a Service can help in planning, scheduling, and ensuring that TLPT is conducted every 3 years, as well as integrating the findings into the overall security strategy.
    • Incident ResponseIncident Response can help in the aftermath of TLPT by addressing any vulnerabilities or issues identified during testing, though it does not directly fulfill the testing requirement itself.
  • .2Shall cover several or all critical or important functions of a financial entity, and shall be performed on live production systems supporting such functions.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus maps the live attack surface that threat-led penetration testing then targets in depth.
    • Penetration TestingInternal penetration testing ensures that critical and important functions of the financial entity are tested for vulnerabilities in live production systems. This helps identify and mitigate risks that could impact these functions.
    • CISO as a ServiceCISO as a Service helps develop and implement strategies, policies, and procedures that ensure critical functions are properly managed and protected. The service can guide compliance with the requirement to cover all essential functions and ensure that testing is appropriately conducted on live systems.
    • Incident ResponseIncident Response services ensure that if a critical function is compromised, there are predefined processes for containment and recovery. This helps maintain compliance by ensuring that live production systems can be quickly restored to normal operations.
  • .3(amended)It shall employ appropriate and proportionate systems, resources and procedures, including ICT systems managed in accordance with Regulation.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps ensure that external attack surfaces are continuously monitored and managed, identifying vulnerabilities and potential risks preemptively. This proactive management supports the requirement for appropriate and proportionate ICT systems.
    • Penetration TestingInternal Penetration Testing identifies vulnerabilities and risks within internal systems, ensuring that the organization’s ICT systems are robust and compliant with regulatory requirements.
    • CISO as a ServiceCISO as a Service provides expert guidance in developing and managing policies, procedures, and resources, ensuring that all systems and processes are compliant with the relevant regulations.
    • Incident ResponseIncident Response ensures that the organization has the necessary procedures and resources to effectively respond to and recover from security incidents, maintaining compliance with regulatory requirements.
27Requirements for testers for the carrying out of TLPTASMPentestCISO-aaSIR

DORA sets a high bar for who may test. We are exactly the kind of qualified, independent testers the regulation requires.

  • .1Ethical framework
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus is delivered by the same qualified team that meets the tester requirements.
    • Penetration TestingRiver Security's pentesters work in accordance with the industry ethical standards
    • CISO as a ServiceRiver Security's consultants work in accordance with the industry ethical standards
    • Incident ResponseIncident Response responders support engagements as part of a qualified testing team.
  • .3Indemnity insurance
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus is delivered by the same qualified team that meets the tester requirements.
    • Penetration TestingThe pentesters are under the relevant insurance
    • CISO as a ServiceConsultants are under the relevant insurance
    • Incident ResponseConsultants are under the relevant insurance
28General principlesASMCISO-aaS

Your providers' risk is your risk under DORA. We set the third-party risk principles and monitor the exposure they bring.

  • .1Identify and assess all relevant risks in relation to the contractual arrangement, including the possibility that such contractual arrangement may contribute to reinforcing ICT concentration risk as referred to in Article 29.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps identify external assets and third-party dependencies, assessing risks related to ICT concentration and external vulnerabilities. It also continuously monitors and updates the risk landscape to ensure ongoing compliance.
    • CISO as a ServiceCISOaaS assists in developing and implementing policies and procedures to identify and assess risks, including those related to ICT concentration. The service provides expert guidance on maintaining compliance with relevant regulations such as Article 29.
  • .2Circumstances identified throughout the monitoring of ICT third-party risk that are deemed capable of altering the performance of the functions provided through the contractual arrangement, including material changes that affect the arrangement or the situation of the ICT third-party service provider.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps by continuously monitoring the external attack surface, which includes identifying new third-party assets and vulnerabilities. This proactive approach helps detect changes in third-party risk that could impact the performance of their functions.
    • CISO as a ServiceCISO as a Service aids in establishing comprehensive risk management policies and procedures, including those for monitoring and managing third-party risks. This ensures that the organization is equipped to identify and respond to changes in third-party risk effectively.
29Preliminary assessment of ICT concentration risk at entity levelASMCISO-aaS

Over-reliance on one provider is a systemic risk. We help assess concentration risk and watch those critical providers’ exposure.

  • Attack Surface ManagementActive Focus monitors the exposure of critical providers that concentration risk depends on.
  • CISO as a ServiceCISOaaS does not directly address ICT concentration risk assessment. However, a CISO could indirectly assist by creating policies and frameworks for risk assessment.
30Key contractual provisionsASMCISO-aaS

The contract is where third-party resilience is won or lost. We shape the required provisions and monitor whether providers live up to them.

  • .2A clear and complete description of all functions and ICT services
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps identify and document all external assets, including services and functions that are exposed to potential threats. This supports the creation of a clear and complete description of all ICT services by providing an inventory of external assets.
    • CISO as a ServiceCISOaaS provides expert guidance in documenting and describing all functions and ICT services. This service includes the creation of policies and procedures that ensure all ICT functions are clearly and comprehensively described.

Regulation

NIS2

NIS2 is an EU directive aimed at enhancing cybersecurity across essential and important sectors, such as energy, healthcare, and digital services. It expands on the original NIS Directive by setting stricter security requirements, incident reporting obligations, and risk management measures for a broader range of organizations. NIS2 aims to improve the EU's overall cyber resilience by harmonizing cybersecurity practices and strengthening cross-border collaboration.

15 of 15 controls directly addressed by a River Security service.

Service coverage

Strengths

  • Enhanced Cybersecurity: Strengthens security measures across essential and important sectors.
  • Harmonization: Promotes uniform cybersecurity standards across the EU, reducing regulatory fragmentation.
  • Broader Coverage: Expands the scope to include more organizations, increasing overall resilience.
  • Incident Reporting: Establishes consistent incident reporting requirements, improving response and coordination.
  • Cross-Border Cooperation: Encourages stronger collaboration between EU member states on cybersecurity matters.

Trade-offs

  • Compliance Costs: May impose significant financial and resource burdens, especially on smaller organizations.
  • Complex Implementation: Requires organizations to adapt to new requirements and reporting standards.
  • Potential Overreach: Expanding the scope may include organizations not traditionally seen as critical, increasing regulatory burden.
  • Enforcement Challenges: Variability in how member states implement and enforce the directive can affect consistency.
  • Resource Constraints: Smaller entities may struggle with the resources needed to meet the directive's requirements.
Controls & how we help
DirectPartialNot mapped
20GovernanceCISO-aaS

NIS2 makes cybersecurity a board-level legal responsibility. Our CISO as a Service gives management the governance framework, oversight and the training the directive now demands of them personally.

  • CISO as a ServiceCISOaaS is highly relevant as it helps in building and maintaining comprehensive governance frameworks, including strategies, policies, and procedures.
21Cybersecurity risk-management measuresASMPentestCISO-aaSIR

Article 21 is the heart of NIS2 — the technical and organisational measures themselves. It's where all four River services converge: we find and test the risks, set the measures, and stand ready to respond.

  • .1Appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other services
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps ensure compliance by continuously monitoring the external attack surface, identifying vulnerabilities, and detecting new assets. This proactive approach helps manage risks and prevent incidents, thereby minimizing their impact on services.
    • Penetration TestingInternal Penetration Testing helps ensure compliance by identifying and mitigating vulnerabilities within the internal network and systems. This reduces the risk of incidents and helps maintain the security of network and information systems.
    • CISO as a ServiceCISO as a Service designs and documents the technical and organisational measures, policies and procedures the article requires.
    • Incident ResponseIncident Response delivers the handling, containment and recovery capability the measures must include, and rehearses it.
  • .2All-hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously monitors the external attack surface, discovering assets and vulnerabilities so risks are managed before they become incidents.
    • Penetration TestingInternal Penetration Testing helps ensure compliance by uncovering vulnerabilities within the organization's internal network and systems. This proactive approach allows the organization to mitigate risks before they can be exploited, thereby protecting network and information systems from potential incidents.
    • CISO as a ServiceCISO as a Service (CISOaaS) provides expert guidance in developing comprehensive strategies, policies, and procedures that encompass an all-hazards approach. This service ensures that the organization has a robust framework to protect its network and information systems, as well as the physical environment of those systems, from a wide range of potential incidents.
    • Incident ResponseIncident Response delivers the handling, containment and recovery capability the measures must include, and rehearses it.
  • .2aPolicies on risk analysis and information system security
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM provides continuous monitoring and assessment of external threats and vulnerabilities, which is integral to performing effective risk analysis. It helps in identifying and managing risks associated with external attack surfaces, thus supporting the organization's information system security policies.
    • Penetration TestingPenetration testing identifies and proves the exploitable weaknesses inside the risk-management measures, so they can be fixed.
    • CISO as a ServiceCISO as a Service provides expert guidance to develop comprehensive policies on risk analysis and information system security, ensuring they align with compliance requirements.
    • Incident ResponseIncident Response delivers the handling, containment and recovery capability the measures must include, and rehearses it.
  • .2bIncident handling
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously monitors the external attack surface, discovering assets and vulnerabilities so risks are managed before they become incidents.
    • Penetration TestingPenetration testing identifies and proves the exploitable weaknesses inside the risk-management measures, so they can be fixed.
    • CISO as a ServiceCISO as a Service designs and documents the technical and organisational measures, policies and procedures the article requires.
    • Incident ResponseIncident Response (IR) is crucial for handling security incidents. It includes activities such as containment, eradication, and recovery, ensuring that the organization can effectively respond to and recover from security incidents, thereby maintaining compliance with incident handling requirements.
  • .2cBusiness continuity, such as backup management and disaster recovery, and crisis management
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously monitors the external attack surface, discovering assets and vulnerabilities so risks are managed before they become incidents.
    • Penetration TestingPenetration testing identifies and proves the exploitable weaknesses inside the risk-management measures, so they can be fixed.
    • CISO as a ServiceCISOaaS helps ensure compliance by developing and implementing comprehensive business continuity plans, including backup management, disaster recovery strategies, and crisis management procedures.
    • Incident ResponseIR does not directly address business continuity, backup management, but is vital in disaster recovery and crisis management.
  • .2dSupply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps ensure compliance by continuously monitoring and assessing the external attack surface, including third-party suppliers and service providers. It identifies vulnerabilities and risks associated with these external entities, helping to preemptively manage and mitigate potential threats within the supply chain.
    • Penetration TestingPenetration testing identifies and proves the exploitable weaknesses inside the risk-management measures, so they can be fixed.
    • CISO as a ServiceCISOaaS supports compliance by helping to develop and implement comprehensive supply chain security policies and procedures. This includes defining security requirements for suppliers and service providers, conducting risk assessments, and ensuring ongoing compliance with security standards.
    • Incident ResponseIncident Response delivers the handling, containment and recovery capability the measures must include, and rehearses it.
  • .2eSecurity in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps in the acquisition, development, and maintenance phases by continuously scanning for vulnerabilities and detecting new assets. It also identifies potential risks from third parties, allowing for proactive vulnerability handling and disclosure.
    • Penetration TestingInternal Penetration Testing ensures that vulnerabilities within the organization are identified and mitigated. This service plays a crucial role in the development and maintenance phases by providing insights into internal security weaknesses.
    • CISO as a ServiceCISOaaS provides expertise in creating and implementing policies and procedures for secure acquisition, development, and maintenance of information systems. It ensures that vulnerability handling and disclosure practices are in place and compliant with regulations.
    • Incident ResponseIncident Response is essential for handling vulnerabilities that lead to security incidents. It ensures that vulnerabilities are contained, managed, and disclosed appropriately, thereby supporting the overall security lifecycle.
  • .2fPolicies and procedures to assess the effectiveness of cybersecurity risk-management measures
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps ensure compliance by continuously monitoring and assessing the external attack surface for vulnerabilities. This ongoing assessment provides valuable insights into the effectiveness of current cybersecurity measures, allowing for real-time adjustments and improvements.
    • Penetration TestingPenetration testing identifies and proves the exploitable weaknesses inside the risk-management measures, so they can be fixed.
    • CISO as a ServiceCISOaaS is instrumental in developing and implementing comprehensive policies and procedures for assessing cybersecurity risk management. The expert guidance ensures these policies are aligned with industry standards and regulatory requirements.
    • Incident ResponseIncident Response delivers the handling, containment and recovery capability the measures must include, and rehearses it.
  • .2gBasic cyber hygiene practices and cybersecurity training
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps ensure basic cyber hygiene by continuously scanning for vulnerabilities, identifying new assets, and potential risks which can inform training programs.
    • Penetration TestingInternal Penetration Testing uncovers internal vulnerabilities and risks, which can be addressed through improved cyber hygiene practices and targeted training.
    • CISO as a ServiceCISOaaS assists in developing and implementing comprehensive cybersecurity policies, procedures, and training programs to promote basic cyber hygiene.
    • Incident ResponseIncident Response delivers the handling, containment and recovery capability the measures must include, and rehearses it.
  • .2hPolicies and procedures regarding the use of cryptography and, where appropriate, encryption
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously monitors the external attack surface, discovering assets and vulnerabilities so risks are managed before they become incidents.
    • Penetration TestingPenetration testing identifies and proves the exploitable weaknesses inside the risk-management measures, so they can be fixed.
    • CISO as a ServiceCISOaaS can help develop comprehensive policies and procedures for the use of cryptography and encryption. This service ensures that the company's cryptographic practices align with regulatory requirements and industry standards, providing the necessary documentation and guidance to support compliance.
    • Incident ResponseIncident Response delivers the handling, containment and recovery capability the measures must include, and rehearses it.
  • .2iHuman resources security, access control policies and asset management
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps by continuously monitoring and managing the external attack surface, identifying unauthorized or unmanaged assets, and assessing vulnerabilities. This proactive approach ensures that access control policies can be enforced and that any potential external threats to human resources and asset management are identified and mitigated.
    • Penetration TestingPenetration testing identifies and proves the exploitable weaknesses inside the risk-management measures, so they can be fixed.
    • CISO as a ServiceCISOaaS provides expert guidance on developing and implementing comprehensive human resources security policies, access control policies, and asset management procedures. This service ensures that the organization adheres to best practices and compliance requirements by establishing robust governance frameworks and documentation.
    • Incident ResponseIncident Response delivers the handling, containment and recovery capability the measures must include, and rehearses it.
23Reporting obligationsCISO-aaSIR

NIS2's reporting clock is brutal — 24 hours to an early warning, 72 to a full report. We help you prepare the templates and act as your technical partner in the dialogue with authorities when it counts.

  • .124 hour reporting
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISOaaS can help develop tempates for reporting with the required format and content
    • Incident ResponseThis service will help you manage the incident, utilize predifined reporting templates and serve as a technical partner in dialouge with relevant authorities
  • .272 hour reporting
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISOaaS can help develop tempates for reporting with the required format and content
    • Incident ResponseThis service will help you manage the incident, utilize predifined reporting templates and serve as a technical partner in dialouge with relevant authorities
  • .31 month reporting
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISOaaS can help develop tempates for reporting with the required format and content
    • Incident ResponseThis service will help you write out the final report and serve as a technical partner in dialouge with relevant authorities

Regulation

NO DIGITAL SECURITY ACT

The *"Digital sikkerhetslov"* primarily aligns with the original NIS1 Directive rather than NIS2. While it incorporates elements from NIS2, such as defining which entities are covered and setting incident reporting obligations, it does not fully adopt the broader and stricter requirements of NIS2. The law mainly focuses on updating Norway's cybersecurity framework to enhance risk management and incident handling for entities considered essential under NIS1, with some updates inspired by NIS2.

9 of 10 controls directly addressed by a River Security service, plus 1 supported partially.

Strengths

  • Enhanced Security: Strengthens the cybersecurity framework for critical infrastructure and essential services.
  • Clear Obligations: Provides defined requirements for risk management and incident reporting.
  • Improved Incident Handling: Standardizes incident reporting processes, improving response coordination.
  • Alignment with EU Standards: Incorporates aspects of NIS1, with some updates inspired by NIS2, aligning Norway's framework with EU practices.
  • Public-Private Collaboration: Encourages cooperation between sectors to enhance national digital resilience.

Trade-offs

  • Partial Alignment with NIS2: Does not fully adopt the more comprehensive requirements of NIS2, potentially limiting the law's impact.
  • Implementation Costs: Imposes additional compliance costs on organizations, particularly smaller entities.
  • Regulatory Overlap: May lead to complexity when combined with existing regulations.
  • Resource Challenges: Smaller organizations may struggle to meet the new requirements due to limited resources.
  • Incremental Update: As an update to NIS1, it may not go far enough to address emerging cybersecurity challenges.
Controls & how we help
DirectPartialNot mapped
§ 7RisikovurderingASMPentestCISO-aaS

Risikovurdering krever at du kjenner angrepsflaten din. Active Focus kartlegger verdier og sårbarheter kontinuerlig, og vi setter rammeverket for å vurdere og prioritere risikoen.

  • gen kartlegging av virksomhetens nettverk og informasjonssystemer og hvilken betydning disse har for leveransen av den samfunnsviktige tjenesten
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM provides a comprehensive view of the organization's external attack surface, identifying and assessing the significance of network and information systems critical to delivering essential services. By continuously monitoring for new assets and vulnerabilities, EASM ensures that these systems are mapped and understood in the context of their importance to the organization's operations.
    • Penetration TestingPenetration testing helps reveal internal dependencies and integration points, supporting the assessment of how reliant the organisation is on others.
    • CISO as a ServiceCISO as a Service helps organizations understand the strategic importance of their network and information systems by assisting in the development of policies and procedures that align with compliance requirements. This service ensures that the mapping of these systems is thorough and reflects their significance to the delivery of essential services.
  • ihvilke sårbarheter som er knyttet til virksomhetens nettverk og informasjonssystemer
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM is instrumental in identifying vulnerabilities associated with the organization's network and information systems. It continuously monitors the external attack surface, detects new vulnerabilities, and assesses risks from third parties, thereby providing a proactive approach to vulnerability management.
    • Penetration TestingPenetration testing helps reveal internal dependencies and integration points, supporting the assessment of how reliant the organisation is on others.
    • CISO as a ServiceCISO as a Service sets the framework and process for assessing and prioritising risk across network and information systems.
  • li hvilken grad virksomheten er avhengig av andre virksomheter for å fungere som den skal
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously maps the organisation's exposed network and information systems and their vulnerabilities, feeding directly into the risk assessment.
    • Penetration TestingInternal Penetration Testing can help identify dependencies on other businesses by uncovering integration points and shared resources within the internal network. This can highlight areas where the organization's operations may be reliant on external entities, thereby assisting in understanding and managing these dependencies.
    • CISO as a ServiceCISO as a Service sets the framework and process for assessing and prioritising risk across network and information systems.
§ 10Teknologiske sikkerhetstiltakASMPentestCISO-aaS

Tekniske tiltak må virke i praksis, ikke bare på papiret. Active Focus overvåker det eksponerte, penetrasjonstesting beviser at tiltakene holder, og vi setter de tekniske standardene.

  • btilgangskontroll til innhold i nettverk og informasjonssystemer basert på tjenstlig behov
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps identify unauthorized access points and vulnerabilities that could be exploited to bypass access controls. It ensures that only necessary services are exposed externally, which aligns with the principle of access control based on a business need.
    • Penetration TestingPenetration testing proves whether segmentation, least-privilege and access controls actually hold under attack.
    • CISO as a ServiceCISO as a Service aids in designing and implementing access control policies and procedures based on business needs. It ensures that access is granted appropriately and monitored effectively, which is crucial for compliance with access control requirements.
  • dtiltak for segmentering av tjenester basert på et prinsipp om minste minimum av rettigheter
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM primarily focuses on external threats and asset management, which is not directly related to service segmentation and least privilege principles. Therefore, it is not applicable for this specific control.
    • Penetration TestingInternal Penetration Testing is crucial for assessing whether the implemented segmentation and access controls are effective. It helps identify vulnerabilities and misconfigurations that could violate the principle of least privilege, ensuring services are adequately segmented.
    • CISO as a ServiceCISO as a Service sets the technical security standards and hardening requirements the measures must meet.
  • ftiltak som skal sikre at nettverk og informasjonssystemer har tilstrekkelig kapasitet til å tåle overbelastning og utstyrssvikt
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM can help identify potential vulnerabilities and external threats that could lead to network overloads or equipment failures. By continuously monitoring and managing the external attack surface, EASM ensures that the organization is aware of potential risks that could impact network capacity and resilience.
    • Penetration TestingInternal Penetration Testing helps identify weaknesses within the organization's internal network infrastructure that could lead to overload or equipment failure. By uncovering these vulnerabilities, the organization can implement necessary measures to enhance network capacity and resilience.
    • CISO as a ServiceCISO as a Service sets the technical security standards and hardening requirements the measures must meet.
  • gtiltak som skal sikre at nettverk og informasjonssystemer videreutvikles kontinuerlig, herunder at oppdateringer kvalitetssikres, installeres og testes fortløpende
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM assists in ensuring that network and information systems are continuously developed by identifying vulnerabilities and potential threats in real-time. It helps in the quality assurance of updates by detecting new assets and changes, which can then be tested and validated to maintain security integrity.
    • Penetration TestingInternal Penetration Testing supports the continuous development and testing of network and information systems by simulating attacks within the organization. This helps in identifying weaknesses before updates are deployed, ensuring that updates are thoroughly tested and do not introduce new vulnerabilities.
    • CISO as a ServiceCISO as a Service sets the technical security standards and hardening requirements the measures must meet.
§ 13Hendelseshåndtering og beredskapPentestCISO-aaSIR

Når krisen kommer, teller tempo. Vi håndterer hendelsen og bygger og øver beredskapsplanen før dere trenger den.

  • Penetration TestingPenetration testing and attack simulation rehearse the response, testing the preparedness plan against realistic intrusions.
  • CISO as a ServiceCISO as a Service is instrumental in establishing an effective incident handling and response plan. It assists in developing policies and procedures for incident response and business continuity, ensuring compliance with regulations that require organizations to prepare for and manage incidents.
  • Incident ResponseIncident Response services are directly relevant as they provide the expertise and resources needed to effectively manage and respond to security incidents. These services ensure that the organization can contain, mitigate, and recover from incidents, aligning with compliance requirements for incident handling and preparedness.
§ 14Oppfølgingsplikt-3.partsASMCISO-aaS

Leverandørenes svakheter blir dine. Vi overvåker tredjeparts eksponering og setter kravene til oppfølging av leverandørene.

  • Attack Surface ManagementEASM assists in fulfilling third-party monitoring obligations by continuously identifying and assessing external threats, including those posed by third-party vendors and partners. It helps in mapping the external attack surface and understanding how third parties interact with the organization, thus aiding in the assessment of third-party risks.
  • CISO as a ServiceCISO as a Service sets the requirements and follow-up process for third-party suppliers and service providers.
§ 17VarslingspliktCISO-aaSIR

Varslingsplikten har korte frister. Vi hjelper dere å etablere varslingsrutiner og er teknisk partner i dialogen med myndighetene når noe skjer.

  • CISO as a ServiceCISO as a Service can help ensure compliance with the 'Varslingsplikt' or notification obligation by establishing and maintaining incident reporting procedures. This service ensures that the organization has the necessary policies and processes in place to quickly and accurately notify relevant authorities and stakeholders in the event of a security breach or incident.
  • Incident ResponseIncident Response (IR) services are crucial for fulfilling the 'Varslingsplikt' by providing the capability to quickly respond to security incidents. IR teams help in identifying the scope and impact of an incident, ensuring that the organization can notify the necessary parties in a timely manner, thereby complying with notification obligations.

Governance

ISO27001 Controllers

ISO 27001 is a global standard for managing information security, providing a framework to establish and maintain an Information Security Management System (ISMS). It focuses on risk assessment, implementing controls, and continuous improvement to protect data. The standard aligns with regulations like NIS2 and DORA, enhancing cybersecurity and compliance. However the third party requirements in DORA are more comprehensive

105 of 119 controls directly addressed by a River Security service, plus 8 supported partially.

Service coverage

Strengths

  • Enhanced Security: Provides a systematic approach to managing and protecting information.
  • Compliance: Helps meet regulatory requirements and industry standards.
  • Risk Management: Focuses on identifying and mitigating security risks.
  • Reputation: Certification boosts trust and credibility with clients and partners.

Trade-offs

  • Cost: Certification and maintenance can be expensive, especially for smaller organizations.
  • Resource Intensive: Requires significant time and effort to implement and maintain.
  • Complexity: Involves detailed documentation and processes that can be cumbersome.
  • Ongoing Commitment: Needs regular audits and updates to keep certification valid.
Controls & how we help
DirectPartialNot mapped
A5.1Management direction for information securityCISO-aaS

Security only sticks when leadership sets the direction. Our CISO as a Service turns board intent into the policy framework, ownership and cadence that ISO 27001 expects — and that auditors look for.

  • .1Policies for information security
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service is instrumental in developing and implementing policies for information security. It provides expert guidance to establish a comprehensive information security policy framework that aligns with compliance requirements and industry best practices.
  • .2Review of the policies for information security
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service is instrumental in reviewing and updating information security policies. The service provides expert guidance to ensure that policies remain relevant, effective, and compliant with current regulations and standards.
A6.1Internal organisationASMCISO-aaSIR

We define who owns security and how the organisation talks to authorities and peers — then keep those lines live through incident response and continuous asset visibility.

  • .1Information security roles and responsibilities
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service plays a crucial role in defining and assigning information security roles and responsibilities within an organization. By providing expert guidance, this service ensures that the organizational structure supports security objectives and compliance requirements. It helps in developing a clear framework for roles and responsibilities, aligning them with industry standards and regulations.
  • .2Segregation of duties
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service helps design and implement effective segregation of duties by developing policies and procedures that define roles and responsibilities clearly. This service ensures that duties are separated to prevent conflicts of interest and reduce the risk of fraud or error, aligning with compliance requirements.
  • .3Contact with authorities
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service provides expertise in establishing and maintaining communication protocols with relevant authorities. This service ensures that the organization has established relationships and procedures for timely and effective communication with authorities, which is crucial for compliance.
    • Incident ResponseIncident Response services are crucial in maintaining contact with authorities during and after a security incident. IR teams can assist in managing communication with authorities to ensure compliance with reporting requirements and other legal obligations.
  • .4Contact with special interest groups
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service helps establish and maintain contact with special interest groups by identifying relevant groups, facilitating communication, and ensuring the organization stays informed about the latest security trends and threats. This service aids in aligning the organization's security posture with industry best practices and compliance requirements.
    • Incident ResponseIncident Response teams often benefit from contact with special interest groups as these groups can provide valuable insights and intelligence on emerging threats and vulnerabilities. By maintaining these contacts, the IR team can enhance its readiness and response capabilities, aligning with the requirement to engage with external groups.
  • .5Information security in project management
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps ensure that external threats to project management processes are identified and managed, especially when projects involve new or changed external-facing systems. By continuously monitoring for vulnerabilities, EASM supports the security of projects that may introduce new external attack surfaces.
    • CISO as a ServiceCISO as a Service supports the integration of information security into project management by helping develop policies and procedures that ensure security considerations are included from project inception through completion. This service ensures that security is a fundamental component of the project management lifecycle, aligning with compliance requirements.
A6.2Mobile devices and teleworkingASMCISO-aaS

Remote work widens the attack surface. We set the mobile and teleworking policy and continuously watch the internet-facing access points it creates.

  • .1Mobile device policy
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service assists in developing a comprehensive mobile device policy by leveraging expert knowledge to create policies that align with industry standards and compliance requirements. This service helps in defining the scope, usage guidelines, security controls, and monitoring processes for mobile devices within the organization.
  • .2Teleworking
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementAttack Surface Management does not write the teleworking policy, but it continuously discovers and monitors the internet-facing remote-access services (VPNs, gateways, published apps) that teleworking depends on, flagging exposed or misconfigured entry points before they are abused.
    • CISO as a ServiceCISO as a Service can help in developing and implementing a teleworking policy that aligns with compliance requirements. It involves identifying risks associated with remote work, establishing secure remote access procedures, and ensuring that all teleworking practices are documented and communicated effectively to employees. This service also assists in maintaining up-to-date security protocols and training for remote work scenarios.
A7.1Human resource securityCISO-aaS

People are hired before they are trusted. We build the screening and contractual security controls so personnel risk is managed from day one.

  • .1Prior to employment
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service helps develop and implement pre-employment screening policies, procedures, and documentation that comply with regulatory requirements. This service ensures that the organization establishes effective security practices before hiring employees, including background checks and security awareness training.
  • .1.1Screening
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service is instrumental in developing and implementing comprehensive employee screening policies and procedures. This service can provide guidance on best practices for screening, including background checks and security clearances, ensuring the organization meets compliance requirements for personnel security.
  • .1.2Terms and conditions of employment
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service can assist in ensuring compliance with employment terms and conditions by helping to develop and maintain policies and procedures that align with legal and regulatory requirements. This service can provide expert guidance in drafting employment contracts and ensuring they include necessary security and compliance clauses.
A7.2During employmentASMPentestCISO-aaS

Awareness is a control, not a poster. We run the training and management-responsibility programme and use real findings from testing to make it concrete for staff.

  • .1Management responsibilities
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service is instrumental in defining and assigning management responsibilities related to information security. This service provides guidance on establishing clear roles and responsibilities within the organization, ensuring that management is adequately informed and accountable for security policies and compliance obligations.
  • .2Information security awareness, education and training
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementAttack Surface Management does not deliver training, but the real exposures it surfaces give the programme concrete, organisation-specific examples of what an attacker sees — making awareness content relevant rather than generic.
    • Penetration TestingPenetration testing indirectly supports awareness: the weaknesses it uncovers become vivid, real-world training scenarios. It is a source of material for the programme rather than the delivery mechanism itself.
    • CISO as a ServiceCISO as a Service is instrumental in developing and delivering a comprehensive information security awareness, education, and training program. This service can tailor training materials, conduct workshops, and ensure that security awareness is embedded in the organizational culture.
  • .3Disciplinary process
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service can assist in developing and implementing a disciplinary process by providing expert guidance on best practices and compliance requirements. This service ensures that the organization has clear policies and procedures in place for addressing security breaches or non-compliance issues among employees, aligning with regulatory standards.
A7.3Termination and change of employmentCISO-aaS

Offboarding is where access quietly lingers. We put the process in place so rights and assets are revoked cleanly when people move on.

  • .1Termination or change of employment responsibilities
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service can help ensure compliance with termination or change of employment responsibilities by developing and maintaining policies and procedures that govern the secure handling of employee transitions. This includes ensuring that access rights are appropriately modified or revoked, and that all organizational information and assets are returned or secured.
A8Responsibility for assetsASMPentestCISO-aaS

You can't protect what you can't see. We keep a live inventory of your internet-facing assets, prove ownership, and set the classification and handling rules around them.

  • .1Information classification
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service aids in the development and implementation of information classification policies and procedures. This service helps ensure that the organization classifies its data appropriately, adhering to compliance requirements by maintaining comprehensive and updated classification documentation.
  • .1.1Inventory of assets
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM provides a continuous and automated approach to discovering and inventorying external assets. This service helps organizations maintain an accurate inventory of external assets that could potentially be accessed or exploited by attackers.
    • CISO as a ServiceCISO as a Service aids in establishing and maintaining comprehensive asset inventory policies and procedures, ensuring that all assets are documented and managed according to compliance requirements.
  • .1.2Ownership of assets
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM assists in identifying and cataloging external assets, which can help in establishing ownership by providing visibility into what assets are exposed and potentially owned by the organization. This process is crucial for maintaining an accurate inventory of assets.
    • CISO as a ServiceCISO as a Service can help develop and implement policies and procedures that define ownership of assets. This includes creating documentation and guidelines that ensure assets are assigned to specific owners, aligning with compliance requirements for asset management.
  • .1.3Acceptable use of assets
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM can identify unauthorized or risky uses of assets exposed to the external environment, helping enforce acceptable use policies and protect against external threats.
    • Penetration TestingPenetration testing can surface misuse or misconfiguration of internal assets that breaches acceptable-use rules, but it samples behaviour at a point in time rather than enforcing the policy — it is a check on the rule, not the rule itself.
    • CISO as a ServiceCISO as a Service helps develop and enforce policies and procedures regarding the acceptable use of assets, ensuring they align with compliance requirements.
  • .1.4Return of assets
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM primarily focuses on external threats and vulnerabilities. While it does not directly address acceptable use policies, it helps ensure that external access to assets is secured, indirectly supporting the enforcement of acceptable use by preventing unauthorized access.
    • Penetration TestingInternal Penetration Testing can identify improper use or misconfiguration of assets that could violate acceptable use policies. By uncovering these issues, organizations can take corrective actions to align with their acceptable use standards.
    • CISO as a ServiceCISO as a Service can develop and implement acceptable use policies, ensuring that all employees and stakeholders understand and adhere to these guidelines. This service provides strategic guidance and documentation to support compliance with acceptable use standards.
  • .2Information classification
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service is instrumental in establishing and maintaining an information classification scheme. This service helps organizations develop policies and procedures that define how information is categorized based on its sensitivity and criticality. It ensures that the organization has a structured approach to information classification, which is crucial for compliance with various security frameworks.
  • .2.1Classification of information
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service is instrumental in developing and implementing an information classification policy. This service ensures that information is categorized based on its sensitivity and criticality, aligning with compliance requirements. The CISOaaS can guide the organization in defining classification levels, labeling protocols, and handling procedures, ensuring that information management aligns with organizational and regulatory standards.
  • .2.2Labelling of information
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service assists in developing and implementing comprehensive policies and procedures for the labeling of information. This service ensures that the organization has a consistent and compliant approach to labeling sensitive information, which is crucial for maintaining confidentiality and data integrity.
  • .2.3Handling of assets
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps identify and manage external assets that may be overlooked, ensuring that they are included in asset management processes. This continuous identification and monitoring are essential for handling assets appropriately, especially those that are exposed to external threats.
    • Penetration TestingPenetration testing can uncover hidden or unlisted internal assets that fall outside handling procedures, but it complements the handling controls rather than defining them.
    • CISO as a ServiceCISO as a Service aids in establishing and maintaining asset management policies and procedures, ensuring that all organizational assets are properly identified, classified, and handled according to compliance requirements. This service ensures alignment with best practices for asset management.
  • .3Media handling
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service can help develop and implement policies and procedures for secure media handling, ensuring compliance with data protection regulations. This includes guidance on classification, storage, transfer, and disposal of media to protect sensitive information.
  • .3.1Management of removable media
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service can help establish and enforce policies and procedures for the management of removable media. This includes developing guidelines for the proper use, storage, and disposal of removable media, as well as training employees on these policies to ensure compliance.
  • .3.2Disposal of media
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service can help in developing and implementing policies and procedures for the secure disposal of media. This includes ensuring compliance with relevant regulations and standards, training staff on proper disposal methods, and maintaining documentation of disposal activities.
  • .3.3Physical media transfer
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service helps establish and enforce policies and procedures for the secure transfer of physical media. This includes identifying risks associated with physical media transfers and implementing controls to mitigate these risks, ensuring compliance with relevant regulations and standards.
A9.1Business requirements of access controlASMPentestCISO-aaS

Access control starts as a policy decision and ends as a tested reality. We write the rules and then verify they actually hold at the network and service layer.

  • .1Access control policy
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service is instrumental in developing an access control policy as it provides expert guidance in crafting policies that align with industry standards and compliance requirements. The service helps in establishing procedures for managing access rights, ensuring that only authorized personnel have access to sensitive information, which is crucial for compliance.
  • .2Access to networks and network services
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM secures the external edge of network access by continuously finding unauthorized or exposed access points, but the internal access controls themselves are proven by penetration testing — so ASM's role here is supporting rather than complete.
    • Penetration TestingInternal Penetration Testing is crucial for identifying vulnerabilities within the internal network infrastructure. It assesses access controls and helps in ensuring that only authorized personnel have access to sensitive network services, aligning with the control's requirements.
    • CISO as a ServiceCISO as a Service aids in developing and implementing robust access control policies and procedures. It ensures that the organization has a structured approach to managing network access, maintaining compliance with relevant regulations and standards.
A9.2User access managementPentestCISO-aaS

Joiners, movers and leavers are where access sprawl happens. We govern the lifecycle and pen-test whether privileged rights and access reviews are enforced in practice.

  • .1User registration and de-registration
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service helps establish and implement robust user registration and de-registration procedures. This service can guide the organization in developing policies and workflows to ensure that user accounts are created and removed following compliance standards, reducing the risk of unauthorized access.
  • .2User access provisioning
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingInternal Penetration Testing helps identify and assess vulnerabilities related to user access controls within the organization's internal network. This service ensures that unauthorized access paths are detected and mitigated, which is crucial for effective user access provisioning.
    • CISO as a ServiceCISO as a Service provides expert guidance in developing and implementing robust user access provisioning policies and procedures. This service ensures that the organization maintains proper documentation and adheres to compliance requirements regarding access control management.
  • .3Management of privileged access rights
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingInternal Penetration Testing can identify vulnerabilities in the management of privileged access rights by simulating attacks that exploit improper access control mechanisms. This helps ensure that access rights are correctly managed and that unauthorized access is prevented.
    • CISO as a ServiceCISO as a Service assists in developing and implementing policies and procedures for managing privileged access rights. This includes defining roles, responsibilities, and processes for granting, reviewing, and revoking access, ensuring compliance with security standards and regulations.
  • .4Management of secret authentication information of users
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingInternal Penetration Testing can identify weaknesses in the management of secret authentication information, such as password storage methods, access controls, and authentication mechanisms. By uncovering these vulnerabilities, organizations can enhance their security measures to protect user authentication information.
  • .5Review of user access rights
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingInternal Penetration Testing can identify excessive or inappropriate user access rights during its assessment of internal systems. By simulating attacks from within, it can reveal weaknesses in access controls and ensure that user access rights are aligned with security policies.
  • .6Removal or adjustment of access rights
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service can help develop and implement policies and procedures related to the management of access rights. This includes ensuring that there are processes in place for the timely removal or adjustment of access rights when employees change roles or leave the organization, which is crucial for compliance with access control requirements.
A9.3User responsibilitiesCISO-aaS

We define how users must handle credentials — MFA, password hygiene, no sharing — so the human side of authentication is covered.

  • .1Use of secret authentication information
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service helps in developing policies and procedures for managing secret authentication information. This includes creating guidelines for secure password management, implementing multi-factor authentication, and ensuring compliance with best practices for protecting authentication credentials.
A9.4System and application access controlASMPentestCISO-aaS

We make sure systems enforce least privilege at the technical level — secure log-on, protected admin tooling, guarded source code — and prove it through testing.

  • .1Information access restriction
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM provides visibility into external access points and potential vulnerabilities, helping to identify unauthorized access attempts and ensuring that only permitted entities can access the organization's information systems. This proactive approach aids in restricting information access to authorized users only.
    • Penetration TestingInternal Penetration Testing evaluates the effectiveness of existing access controls within the organization's internal network. It helps identify weaknesses in access restrictions, such as misconfigured permissions or insufficient segregation of duties, ensuring that access to information is appropriately restricted.
    • CISO as a ServiceCISO as a Service provides guidance in establishing and enforcing access control policies and procedures. This service ensures that the organization has a well-documented and implemented access management framework, maintaining compliance with information access restriction requirements.
  • .2Secure log-on procedures
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM can help ensure secure log-on procedures by identifying potential vulnerabilities in external-facing authentication mechanisms. By continuously monitoring and testing these entry points, EASM assists in maintaining the security of log-on procedures from external threats.
    • Penetration TestingInternal Penetration Testing evaluates the security of log-on procedures within the organization's internal network. This service helps identify vulnerabilities in authentication processes and ensures that secure log-on procedures are implemented and effective.
    • CISO as a ServiceCISO as a Service provides strategic guidance on implementing secure log-on procedures, ensuring that policies and procedures align with compliance requirements. This service helps develop and maintain robust authentication practices and documentation.
  • .3Password management system
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service can assist in developing and implementing a robust password management policy that aligns with industry best practices and compliance requirements. This service provides guidance on secure password creation, storage, and periodic review of password policies to ensure they remain effective and compliant.
  • .4Use of privileged utility programs
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingInternal Penetration Testing can assess the security of privileged utility programs by simulating attacks and identifying vulnerabilities that could be exploited. This ensures that these programs are adequately protected against unauthorized access or misuse, aligning with compliance requirements.
  • .5Access control to program source code
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM can help identify unauthorized access points or vulnerabilities in external-facing applications that could lead to unauthorized access to program source code, thereby indirectly supporting access control measures.
    • Penetration TestingInternal Penetration Testing is crucial for uncovering vulnerabilities within the organization's internal systems, including those that may allow unauthorized access to program source code. By simulating attacks, internal pentests help validate and strengthen access control mechanisms.
A10CryptographyASMPentestCISO-aaS

Weak crypto is invisible until it's exploited. We set the crypto and key-management policy, watch your external TLS and certificate posture, and test implementations for real-world weaknesses.

  • .1Cryptographic controls
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM can assist in identifying and monitoring external threats and vulnerabilities related to cryptographic controls. By continuously scanning and assessing the external attack surface, EASM ensures that cryptographic measures are not exposed to potential threats, helping maintain their integrity.
    • Penetration TestingInternal Penetration Testing evaluates the effectiveness of cryptographic controls within the organization's internal network. It can identify weaknesses in encryption implementations, key management practices, and other cryptographic protocols, ensuring they are robust and compliant with security standards.
  • .2Policy on the use of cryptographic controls
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service aids in developing and implementing a comprehensive policy on the use of cryptographic controls. The service provides expert guidance on selecting appropriate cryptographic methods and ensuring they align with compliance requirements. This includes drafting policies, procedures, and training materials to ensure all stakeholders understand the importance and application of cryptographic controls.
  • .3Key management
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service helps in establishing and maintaining effective key management policies and procedures. This service ensures that the organization has the necessary guidelines and documentation in place to securely manage cryptographic keys, which is crucial for compliance.
A11.1Secure areasPentestCISO-aaS

Physical security is still security. We set the policy for secure areas and can stress-test whether those controls actually keep unauthorised people out.

  • .1Physical security perimeter
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingInternal Penetration Testing can help ensure compliance with physical security perimeter controls by testing for vulnerabilities that might arise from physical security weaknesses, such as unauthorized access points or insufficient access controls within the organization's premises. This helps identify potential risks that could compromise the physical security of ICT assets.
    • CISO as a ServiceCISO as a Service can assist in developing and implementing policies and procedures related to physical security perimeters. This includes guidance on establishing secure zones, implementing access control measures, and maintaining documentation that supports compliance with physical security requirements.
  • .2Physical entry controls
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingInternal Penetration Testing can help ensure compliance by assessing the effectiveness of physical security measures from a technical perspective. Pen testers may attempt to bypass physical security to gain unauthorized access to systems, thus highlighting potential weaknesses in physical entry controls.
    • CISO as a ServiceCISO as a Service can assist in developing and implementing policies and procedures for physical security. This includes advising on best practices for physical entry controls, ensuring these controls align with regulatory requirements and organizational security objectives.
  • .3Securing offices, rooms and facilities
    ASMPentestCISO-aaSIR
  • .4Protecting against external and environmental threats
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingInternal Penetration Testing evaluates the organization's resilience to internal threats and vulnerabilities that could be exploited by external factors. By identifying and mitigating these vulnerabilities, the organization enhances its defense against potential external and environmental threats.
  • .5Working in secure areas
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingInternal Penetration Testing helps identify vulnerabilities and potential threats within secure areas of the organization. It ensures that access controls and security measures in these areas are robust and effective, aligning with the requirement to maintain security in working areas.
  • .6Delivery and loading areas
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingInternal Penetration Testing can be useful in assessing the security of physical access points such as delivery and loading areas. By simulating potential internal threats, it can help identify vulnerabilities in access control systems or procedures at these locations, ensuring they are secure against unauthorized access.
A11.2EquipmentASMPentestCISO-aaS

Devices leak data when they're lost, reused or left unattended. We cover the equipment lifecycle policy and probe the physical and off-premises risks around your hardware.

  • .1Siting and protection of equipment
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingInternal Penetration Testing can identify vulnerabilities related to the physical security of equipment within the organization. This includes assessing the potential for unauthorized access to equipment, ensuring that equipment siting does not expose it to unnecessary risks.
  • .2Supporting utilities
    ASMPentestCISO-aaSIR
  • .3Cabling security
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingInternal Penetration Testing can help ensure compliance with cabling security by identifying vulnerabilities or weaknesses in the physical security of cabling infrastructure. Testers may assess the risks associated with unauthorized access to cables, eavesdropping, or data interception, and provide recommendations for securing these physical assets.
  • .4Equipment maintenance
    ASMPentestCISO-aaSIR
  • .5Removal of assets
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service can help establish and enforce policies and procedures for the secure removal of assets. This includes ensuring compliance with data protection regulations and standards when decommissioning hardware or software, and maintaining records of asset disposal.
  • .6Security of equipment and assets off-premises
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementAttack Surface Management can flag off-premises and remote equipment that surfaces on the internet, but the physical and endpoint controls for kit outside the office are largely enforced through policy rather than external monitoring.
    • Penetration TestingPenetration testing can simulate compromise of off-premises equipment to check the controls hold, but it tests these scenarios at a point in time rather than continuously securing remote assets.
    • CISO as a ServiceCISO as a Service can develop specific policies and procedures for securing off-premises equipment. This service ensures that security measures are documented, communicated, and enforced, aligning with compliance requirements for protecting assets outside the main premises.
  • .7Secure disposal or reuse of equipment
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service can help develop and implement policies and procedures for the secure disposal or reuse of equipment. This includes ensuring compliance with data protection regulations by establishing guidelines for data erasure and proper documentation of disposal processes.
  • .8Unattended user equipment
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingInternal Penetration Testing can help identify vulnerabilities related to unattended user equipment by simulating scenarios where unauthorized access might be attempted on such equipment. This service ensures that security controls are in place to prevent unauthorized access and protect sensitive data when equipment is left unattended.
    • CISO as a ServiceCISO as a Service can aid in developing policies and procedures to manage risks associated with unattended user equipment. This includes creating guidelines for locking devices, automatic screen locking, and secure storage practices, ensuring compliance with the control by mitigating risks of unauthorized access.
  • .9Clear desk and clear screen policy
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service can assist in developing and implementing a clear desk and clear screen policy by providing expert guidance on best practices, policy formulation, and employee training. This service ensures that the organization has a well-defined policy in place, which is crucial for protecting sensitive information and maintaining compliance.
A12.1Operational procedures and responsibilitiesASMPentestCISO-aaS

Consistent operations are secure operations. We document the procedures and use continuous monitoring and testing to catch when a change quietly breaks them.

  • .1Documented operating procedures
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service is crucial for creating and maintaining documented operating procedures. This service provides expertise in developing comprehensive policies and procedures that align with compliance standards, ensuring all operational activities are well-documented and structured according to industry best practices.
  • .2Change management
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps ensure compliance with change management by continuously monitoring and identifying changes in the external attack surface. It provides visibility into new vulnerabilities and configuration changes that could impact the organization's security posture, allowing for timely updates and adjustments in line with change management policies.
    • Penetration TestingInternal Penetration Testing supports change management by evaluating the impact of changes within the organization's internal environment. It identifies potential vulnerabilities introduced by new systems or updates, ensuring that changes do not compromise the security of internal assets.
    • CISO as a ServiceCISO as a Service aids in developing a robust change management framework, including policies and procedures that align with compliance requirements. This service ensures that all changes are documented, assessed for risk, and implemented in a controlled manner, maintaining the integrity and security of the organization's information systems.
  • .3Capacity management
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service can assist in establishing and maintaining policies and procedures for effective capacity management. This includes ensuring that the organization has the necessary strategies in place to monitor and manage resource usage and forecast future capacity needs, which is crucial for maintaining operational efficiency and compliance.
  • .4Separation of development, testing and operational environments
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM can help identify external threats or misconfigurations that may arise if development, testing, and operational environments are not properly separated. By continuously monitoring and detecting changes in the attack surface, EASM ensures that these environments are not inadvertently exposed to external risks.
    • CISO as a ServiceCISO as a Service provides guidance on best practices for structuring and maintaining separate environments for development, testing, and operations. This includes developing and enforcing policies and procedures that ensure these environments are adequately segregated to maintain security and compliance.
A12.2Protection from malwareASMPentestIR

Malware is a when, not an if. We help harden the entry points, test defences against simulated attacks, and stand ready to contain and eradicate when it lands.

  • .1Controls against malware
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps identify and manage external threats, including potential malware threats, by continuously scanning and monitoring the organization's attack surface. This proactive approach aids in detecting and mitigating malware before it can infiltrate the network.
    • Penetration TestingInternal Penetration Testing assesses the organization's internal defenses against malware by simulating attacks. This helps identify vulnerabilities and weaknesses in the network that could be exploited by malware, allowing for the implementation of stronger protective measures.
    • Incident ResponseIncident Response is crucial for managing and mitigating the effects of a malware attack. IR teams can quickly contain and eradicate malware, minimizing damage and ensuring a swift return to normal operations, which is vital for maintaining control against malware.
A12.3BackupASMPentestCISO-aaS

Backups are your last line against ransomware — but only if an attacker can't reach or destroy them. We set the recovery strategy, hunt for exposed backup stores, and test whether your backups would actually survive a breach.

  • .1Information backup
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementAttack Surface Management continuously checks whether backup repositories, snapshots or management consoles are reachable from the internet, so exposed backups are caught and closed off.
    • Penetration TestingPenetration testing verifies that backups can withstand an intruder — that they can't be reached, altered or deleted from a compromised host — because a backup that dies with the primary system is no backup at all.
    • CISO as a ServiceCISO as a Service can provide guidance on establishing a robust information backup strategy by developing policies and procedures that ensure data is backed up regularly and securely. This service can help ensure that backup processes align with compliance standards and best practices, including data retention and recovery requirements.
A12.4Logging and monitoringASMCISO-aaS

You can't respond to what you can't see. We set the logging and monitoring policy and add continuous external monitoring so threats surface early.

  • .1Event logging
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service can help ensure compliance with event logging requirements by assisting in the development and implementation of logging policies and procedures. This service provides expertise in identifying critical events that need to be logged and ensures that logging practices align with compliance standards. Additionally, CISO as a Service can help in setting up the necessary infrastructure for secure and effective event logging.
  • .2Protection of log information
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service helps in developing and implementing policies and procedures for the secure management and protection of log information. This includes ensuring that logs are appropriately stored, access is controlled, and logs are reviewed regularly to detect any unauthorized access or anomalies, thus supporting compliance with log protection requirements.
  • .3Administrator and operator logs
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service assists in developing and implementing policies and procedures for logging and monitoring activities of administrators and operators. This includes ensuring that logs are properly maintained, secured, and reviewed in compliance with relevant regulations.
  • .4Clock synchronisation
    ASMPentestCISO-aaSIR
A12.5Control of operational softwareASM

Unknown software is unmanaged risk. Attack Surface Management continuously identifies the software and versions running on your operational, internet-facing systems, so unauthorised or outdated components are spotted and controlled.

  • .1Installation of software on operational systems
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementAttack Surface Management detects software installed on operational, internet-facing systems and flags installs that are unauthorised, unexpected or known-vulnerable, helping keep only trusted software in production.
A12.6Technical vulnerability managementASMPentestCISO-aaS

Vulnerability management is our home turf. We continuously discover external weaknesses, pen-test the internal ones, and put the process in place to fix them in priority order.

  • .1Management of technical vulnerabilities
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM is instrumental in managing technical vulnerabilities by continuously monitoring and scanning for vulnerabilities in the external attack surface. It identifies new assets and potential threats, enabling proactive management and remediation of vulnerabilities before they can be exploited.
    • Penetration TestingInternal Penetration Testing helps identify vulnerabilities within the organization's internal systems and networks. By uncovering these vulnerabilities, the organization can prioritize and address them, thereby managing technical vulnerabilities effectively.
    • CISO as a ServiceCISO as a Service provides expert guidance in developing and implementing vulnerability management policies and procedures. This service ensures that the organization has a structured approach to identifying, assessing, and mitigating technical vulnerabilities, which is critical for compliance.
  • .2Restrictions on software installation
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service provides expertise in developing and implementing policies and procedures for managing software installations. By establishing clear guidelines and restrictions on software installation, CISOaaS ensures that only authorized and secure software is used within the organization, thus aligning with compliance requirements.
A12.7Information systems audit considerationsASMPentestCISO-aaS

Audits shouldn't disrupt live systems. We help define audit controls and provide the technical testing evidence auditors rely on.

  • .1Information systems audit controls
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM aids in identifying and managing external threats to information systems. While it primarily focuses on external assets, its continuous monitoring capabilities can complement audit controls by providing insights into the organization's external exposure and potential vulnerabilities.
    • Penetration TestingInternal Penetration Testing is crucial for evaluating the effectiveness of internal controls within the information systems. It helps uncover vulnerabilities and weaknesses that may be missed by regular audits, thus supporting the audit process by ensuring that controls are robust and effective.
    • CISO as a ServiceCISO as a Service is instrumental in developing and maintaining comprehensive audit controls for information systems. This service provides expert guidance in establishing policies and procedures that align with compliance requirements, ensuring that audit controls are well-documented and effectively implemented.
A13.1Network security managementASMPentestCISO-aaS

Flat networks let one breach become total. We design the segmentation and controls, watch the external network edge, and test whether the boundaries actually hold.

  • .1Network controls
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingInternal Penetration Testing is crucial for network controls as it identifies vulnerabilities and weaknesses within the internal network infrastructure. This service helps ensure that network controls are effective in protecting against unauthorized access and potential breaches.
    • CISO as a ServiceCISO as a Service aids in the development and implementation of comprehensive network control policies and procedures. This service ensures that the organization has a strategic approach to network security, aligning with compliance requirements by maintaining and updating documentation and protocols for network controls.
  • .2Security of network services
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM provides continuous monitoring and assessment of external network services, identifying vulnerabilities and potential threats in real-time. This proactive approach helps ensure the security of network services by preemptively addressing issues before they can be exploited.
    • Penetration TestingInternal Penetration Testing evaluates the security of internal network services by simulating attack scenarios within the organization's environment. This helps identify and mitigate vulnerabilities, ensuring that network services are secure from internal threats.
  • .3Segregation in networks
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps identify external network connections and potential points of unauthorized access. By continuously monitoring and assessing vulnerabilities, it assists in ensuring that network segregation is maintained by identifying changes or weaknesses in network boundaries.
    • Penetration TestingInternal Penetration Testing is crucial for validating the effectiveness of network segregation within the organization. It identifies vulnerabilities and misconfigurations that could allow unauthorized access across segregated network segments, ensuring that network controls are functioning as intended.
A13.2Information transferPentestCISO-aaS

Data in motion is data at risk. We set the rules and agreements for transferring information and test the channels that carry it.

  • .1Information transfer policies and procedures
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service is crucial for developing and implementing information transfer policies and procedures. It provides expert guidance to ensure that the policies are comprehensive, align with regulatory requirements, and are effectively communicated and enforced within the organization. This service aids in the creation of documentation and compliance frameworks that support secure and compliant information transfer.
  • .2Agreements on information transfer
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service is instrumental in drafting and reviewing agreements related to information transfer. This service ensures that all agreements comply with relevant regulations and standards, and incorporate necessary security measures, such as encryption and data protection clauses.
  • .3Electronic messaging
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingInternal Penetration Testing helps ensure the security of electronic messaging systems by identifying vulnerabilities within the internal network that could be exploited. This proactive measure aids in maintaining the confidentiality and integrity of electronic communications.
  • .4Confidentiality or nondisclosure agreements
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service can assist in crafting and reviewing confidentiality or nondisclosure agreements (NDAs) to ensure they are comprehensive and align with legal and regulatory requirements. This service provides expertise in establishing policies that incorporate confidentiality agreements as part of the organization's security strategy, ensuring that sensitive information is adequately protected and that all employees and third parties understand their obligations.
A14.1Security requirements of information systemsASMPentestCISO-aaS

Security has to be designed in, not bolted on. We help specify security requirements up front and test public-facing services and transactions before attackers do.

  • .1Information security requirements analysis and specification
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service is instrumental in analyzing and specifying information security requirements. This service provides expert guidance in identifying the necessary security controls, developing policies, and ensuring that these requirements align with compliance standards and business objectives. The CISO will work closely with the organization to understand its unique needs and develop tailored security specifications.
  • .2Securing application services on public networks
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps secure application services on public networks by continuously monitoring for vulnerabilities and new assets that might be exposed to the internet. It provides proactive identification and assessment of external threats, ensuring that public-facing applications are protected against potential cyber threats.
    • Penetration TestingInternal Penetration Testing, although primarily focused on internal assets, can help in securing application services on public networks by identifying vulnerabilities that could be exploited from within the organization. This ensures a comprehensive security posture by addressing both internal and external threats.
  • .3Protecting application services transactions
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps protect application services transactions by continuously monitoring and assessing the external attack surface for vulnerabilities and threats. This proactive approach ensures that potential risks to application transactions are identified and mitigated before they can be exploited.
    • Penetration TestingInternal Penetration Testing is crucial for identifying vulnerabilities within the organization's internal network and application services. By simulating attacks on application transactions, this service helps uncover security weaknesses that could be exploited, allowing the organization to address them and protect sensitive transactions.
A14.2Security in development and support processesASMPentestCISO-aaS

Secure software doesn't happen by accident. We set the secure-development policy and put real security testing into your build and change process.

  • .1Secure development policy
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service plays a crucial role in developing a secure development policy by providing expert guidance on best practices and standards for secure software development. This service assists organizations in establishing and maintaining policies and procedures that ensure secure coding, development, and deployment processes, thereby aligning with compliance requirements.
  • .2System change control procedures
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM assists in identifying changes to the external attack surface and ensures that any new or altered assets are assessed for vulnerabilities. This continuous monitoring supports system change control procedures by providing early detection of unauthorized or unexpected changes, which are critical for maintaining system integrity.
    • CISO as a ServiceCISO as a Service helps in developing and implementing robust system change control procedures. This includes documenting processes, setting up approval workflows, and ensuring that changes are tracked and audited, thereby supporting compliance with change management requirements.
  • .3Technical review of applications after operating platform changes
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM can identify changes in the external attack surface that result from operating platform changes, allowing for proactive measures to secure applications. It continuously monitors for vulnerabilities that may arise due to these changes.
    • Penetration TestingInternal Penetration Testing is crucial for assessing how operating platform changes affect the security posture of applications. It helps in identifying new vulnerabilities introduced by these changes and ensures that internal defenses remain robust.
    • CISO as a ServiceCISO as a Service supports the organization in developing policies and procedures for conducting technical reviews after operating platform changes. This service ensures that such reviews are thorough and align with compliance requirements.
  • .4Restrictions on changes to software packages
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps in identifying unauthorized or vulnerable software changes on externally facing systems, ensuring that any change to software packages is monitored and controlled. This service can detect changes that might introduce vulnerabilities or compliance issues.
    • CISO as a ServiceCISO as a Service aids in developing and enforcing policies and procedures for managing and restricting changes to software packages. This includes defining change management processes that ensure all modifications are assessed for security implications before implementation.
  • .5Secure system engineering principles
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service can guide the development and integration of secure system engineering principles into the organization's processes. This service ensures that security is embedded in system design and development, aligning with compliance requirements. The CISO consultant can provide expertise and strategies to implement these principles effectively.
  • .6Secure Development Environment
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service is instrumental in establishing a secure development environment by helping to create and enforce security policies, procedures, and guidelines tailored for the development process. This service ensures that security best practices are integrated into the development lifecycle, thereby supporting compliance with the requirement for a secure development environment.
  • .7Outsourced development
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service can provide guidance on managing outsourced development by ensuring that third-party developers adhere to the organization's security policies and compliance requirements. This service can assist in drafting and maintaining contracts and security agreements that include clauses on data protection and secure development practices, ensuring compliance with relevant standards and regulations.
  • .8System security testing
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM provides continuous monitoring and vulnerability scanning of external systems. By identifying vulnerabilities and potential threats in the external attack surface, it ensures that any weaknesses are addressed promptly, contributing to the overall system security testing process.
    • Penetration TestingInternal Penetration Testing plays a critical role in system security testing by simulating attacks within the organization's network. This helps in identifying internal vulnerabilities and weaknesses, ensuring that internal systems are robust and secure.
    • CISO as a ServiceCISO as a Service aids in establishing comprehensive security testing protocols and policies. It ensures that systematic security testing is conducted regularly and that the results are used to enhance the organization's security posture, aligning with compliance requirements.
  • .9System acceptance testing
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service can help in establishing a robust system acceptance testing process by creating policies and procedures that ensure all systems meet security and compliance requirements before being put into production. They can guide the organization in defining acceptance criteria that align with industry standards and regulatory requirements, ensuring that systems are thoroughly tested for security vulnerabilities and compliance issues.
A14.3Test dataASMPentestCISO-aaS

Real data in test environments is a breach waiting to happen. We set the rules for protecting test data and check those environments aren't exposed.

  • .1Protection of test data
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps identify and manage external threats to environments where test data might be exposed, ensuring that the organization is aware of and can mitigate vulnerabilities that could lead to unauthorized access to test data.
    • Penetration TestingInternal Penetration Testing evaluates the security controls within the organization's internal network where test data resides. It identifies vulnerabilities and potential misuse of test data, ensuring adequate protection mechanisms are in place.
    • CISO as a ServiceCISO as a Service provides expert guidance in creating and enforcing policies and procedures for the secure handling of test data. This service ensures that the organization adheres to best practices and compliance requirements in test data protection.
A15.1Information security in supplier relationshipsASMCISO-aaS

Your suppliers' weaknesses become yours. We set supplier security requirements and monitor third-party exposure that could reach you.

  • .1Information security policy for supplier relationships
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service is instrumental in developing and implementing an information security policy for supplier relationships. This service provides expert guidance in creating comprehensive policies and procedures that ensure suppliers adhere to the organization's security standards and compliance requirements.
  • .2Addressing security within supplier agreements
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM can help identify and assess the risks associated with third-party suppliers by continuously monitoring and evaluating the external attack surface. This includes identifying any vulnerabilities or potential threats introduced by suppliers, ensuring they are addressed in the supplier agreements.
    • CISO as a ServiceCISO as a Service aids in developing comprehensive supplier agreements that incorporate security requirements. This service ensures that the organization has robust policies and procedures in place to manage supplier-related security risks, aligning with compliance requirements.
  • .3ICT supply chain
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps in identifying and managing risks associated with third-party vendors and suppliers in the ICT supply chain. By continuously monitoring for vulnerabilities and changes in the external attack surface, it ensures that any risks introduced by third parties are promptly identified and addressed, thereby maintaining the security of the supply chain.
    • CISO as a ServiceCISO as a Service provides expertise in developing and implementing supply chain security policies and procedures. It ensures that the organization has a robust framework to evaluate and manage risks associated with suppliers, thereby enhancing compliance with ICT supply chain security requirements.
A15.2Supplier service delivery managementASMPentestCISO-aaS

Supplier risk doesn't stop at signing. We help monitor and review supplier services and test the impact when they change.

  • .1Monitoring and review of supplier services
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps in identifying third-party suppliers and assessing the potential risks they pose to the organization. By continuously monitoring the external attack surface, EASM can detect vulnerabilities and changes in the supplier's security posture, aiding in the effective monitoring and review of supplier services.
    • CISO as a ServiceCISO as a Service provides expertise in developing and implementing policies and procedures for supplier management. This includes setting up frameworks for monitoring and reviewing supplier services to ensure they meet compliance and security standards.
  • .2Managing changes to supplier services
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps in identifying and managing changes to supplier services by continuously monitoring the external attack surface, which includes third-party suppliers. It can detect new vulnerabilities or risks introduced by changes in supplier services, providing early warnings and allowing the organization to take proactive measures.
    • Penetration TestingInternal Penetration Testing can evaluate the impact of changes in supplier services on the internal network. By simulating attacks, it helps uncover vulnerabilities that may have been introduced due to changes in supplier services, ensuring that these changes do not compromise the security of the organization's internal environment.
    • CISO as a ServiceCISO as a Service assists in managing changes to supplier services by developing and maintaining policies and procedures for supplier management. This includes assessing the security posture of suppliers, ensuring that changes are aligned with compliance requirements, and that risks associated with supplier changes are managed effectively.
A16.1Management of information security incidents & improvementsASMPentestCISO-aaSIR

When something goes wrong, speed matters. We run the incident response — contain, eradicate, recover and learn — and help you build the plan before you need it.

  • .1Responsibilities and procedures
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service helps in establishing and maintaining clear information security responsibilities and procedures. This service provides expert guidance to develop, document, and implement security policies and procedures, ensuring that all roles and responsibilities related to information security are clearly defined and communicated within the organization.
    • Incident ResponseIncident Response services can assist in defining and implementing procedures for responding to security incidents. They ensure that responsibilities are clearly assigned and that there are established processes for handling incidents effectively, aligning with the need for well-defined responsibilities and procedures.
  • .2Reporting information security events
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM continuously monitors the external attack surface, which can help in the early detection of information security events. By identifying potential threats and vulnerabilities externally, it provides valuable intelligence that can be reported as security events, contributing to proactive incident management.
    • CISO as a ServiceCISO as a Service assists in establishing formal processes and procedures for reporting information security events. This includes developing communication protocols, training staff on reporting procedures, and ensuring that reporting aligns with compliance requirements.
    • Incident ResponseIncident Response services are critical for effectively reporting information security events. They provide expertise in documenting incidents, analyzing them, and communicating them appropriately to stakeholders, ensuring timely and accurate reporting as required by compliance frameworks.
  • .3Reporting information security weaknesses
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM aids in identifying potential security weaknesses from an external perspective, providing insights into vulnerabilities that need to be reported and addressed to prevent exploitation.
    • Penetration TestingInternal Penetration Testing identifies weaknesses within the organization's internal systems and networks, facilitating the reporting and remediation of these vulnerabilities to strengthen internal security.
    • CISO as a ServiceCISO as a Service helps in establishing a structured process for reporting information security weaknesses. This includes developing policies and procedures that encourage timely and effective reporting of vulnerabilities.
    • Incident ResponseIncident Response teams can provide insights into reported weaknesses and incidents, helping to document and analyze them to prevent future occurrences. However, their primary role is more focused on response rather than reporting.
  • .4Assessment of and decision on information security events
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM provides continuous monitoring of the external attack surface, allowing for early detection and assessment of potential information security events. This proactive approach helps in identifying and evaluating threats before they can escalate, supporting the organization in making informed decisions about these events.
    • CISO as a ServiceCISO as a Service aids in establishing a structured process for assessing and making decisions on information security events. This includes developing incident response plans and risk assessment methodologies that align with compliance requirements, ensuring a consistent approach to handling security events.
    • Incident ResponseIncident Response services are crucial for effectively assessing and responding to information security events. They provide expertise in evaluating the severity and impact of incidents, enabling informed decision-making and facilitating swift containment and recovery actions.
  • .5Response to information security incidents
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM can help identify potential threats and vulnerabilities that could lead to information security incidents, allowing for proactive measures to be taken to prevent such incidents. This proactive stance is crucial in minimizing the risk of security incidents occurring.
    • CISO as a ServiceCISO as a Service provides strategic oversight and guidance in establishing incident response plans and procedures. This service ensures that the organization is well-prepared to respond to information security incidents effectively and in compliance with relevant standards and regulations.
    • Incident ResponseIncident Response services are directly applicable as they provide the necessary expertise and resources to handle information security incidents. This includes containment, eradication, and recovery efforts, ensuring incidents are managed efficiently and in accordance with best practices.
  • .6Learning from information security incidents
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service is instrumental in facilitating learning from information security incidents by establishing a structured process for incident analysis and knowledge sharing. This service helps in developing policies and procedures to document incidents and lessons learned, ensuring that the organization continuously improves its security posture.
    • Incident ResponseIncident Response services are crucial for learning from information security incidents. They provide expertise in analyzing incidents, identifying root causes, and recommending corrective actions. This service ensures that lessons learned are documented and integrated into the organization's security policies and practices, enhancing future incident preparedness and response.
  • .7Collection of evidence
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM can assist in identifying potential evidence related to external threats and vulnerabilities, providing a proactive approach to understanding what information may need to be collected in case of a security incident. However, its primary function is not evidence collection.
    • CISO as a ServiceCISO as a Service helps in establishing and maintaining policies and procedures for evidence collection, ensuring that the organization complies with legal and regulatory requirements when gathering and handling digital evidence.
    • Incident ResponseIncident Response is crucial for evidence collection as it provides structured procedures to collect, preserve, and analyze evidence during and after a security incident, ensuring that it is admissible and reliable for any potential legal or compliance proceedings.
A17.1Information security continuityASMPentestCISO-aaS

Security has to survive a crisis. We build the continuity plans and test that your security controls keep working when things go wrong.

  • .1Planning information security continuity
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM provides continuous monitoring of external threats and vulnerabilities, which is critical for planning information security continuity. By identifying potential threats in advance, the organization can incorporate this intelligence into its continuity planning, ensuring preparedness against external disruptions.
    • CISO as a ServiceCISO as a Service is instrumental in planning information security continuity by developing and implementing strategic policies and procedures. This service ensures that the organization has a structured approach to maintaining security operations during disruptions, aligning with compliance requirements.
  • .2Implementing information security continuity
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM assists in identifying potential external threats and vulnerabilities that could disrupt information security continuity. By continuously monitoring and assessing the attack surface, EASM helps in preemptively addressing issues that could affect the continuity of information security.
    • CISO as a ServiceCISO as a Service plays a crucial role in developing and implementing a comprehensive information security continuity plan. This service ensures that the organization has the necessary policies, procedures, and strategies in place to maintain information security continuity in the face of potential disruptions.
  • .3Verify, review and evaluate information security continuity
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps verify and review information security continuity by continuously monitoring the external attack surface for vulnerabilities and changes. This proactive identification and management of threats support the evaluation of security measures' effectiveness over time.
    • Penetration TestingInternal Penetration Testing contributes to evaluating information security continuity by simulating attacks on internal systems, identifying vulnerabilities, and testing the effectiveness of existing security controls. This ensures that the organization's security posture remains robust and continuous.
    • CISO as a ServiceCISO as a Service supports the verification and evaluation of information security continuity by developing and maintaining policies and procedures that ensure continuous alignment with security best practices and compliance requirements. It involves regular reviews and updates to the security strategy.
A17.2RedundanciesNot mapped
  • .1Availability of information processing facilities
    ASMPentestCISO-aaSIR
A18.1Compliance with legal and contractual requirementsASMPentestCISO-aaS

Compliance is a legal obligation, not just good practice. We help you identify what applies and prove your technical controls actually meet it.

  • .1Identification of applicable legislation and contractual requirements
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service is instrumental in identifying applicable legislation and contractual requirements. The service provides expert guidance on compliance obligations, helping the organization understand the legal and contractual landscape. It ensures that the organization's policies and procedures are aligned with these requirements, thereby facilitating compliance.
  • .2Intellectual property rights
    ASMPentestCISO-aaSIR
  • .3Protection of records
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingInternal Penetration Testing helps ensure the protection of records by identifying vulnerabilities within the internal network where records are stored or processed. By uncovering these vulnerabilities, the organization can take steps to mitigate risks and enhance the security of its records.
  • .4Privacy and protection of personally identifiable information
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM aids in the identification and management of external threats that could compromise personally identifiable information (PII). By continuously monitoring for vulnerabilities and new assets, EASM helps ensure that PII is protected from external attacks.
    • Penetration TestingInternal Penetration Testing identifies vulnerabilities within the organization's internal network that could lead to unauthorized access or breaches of PII. This service helps ensure that internal systems are robust and secure, reducing the risk of data leaks.
  • .5Regulation of cryptographic controls
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service can help ensure compliance with the regulation of cryptographic controls by developing and implementing policies and procedures that govern the use of cryptographic technologies. This includes establishing guidelines for encryption standards, key management practices, and ensuring that cryptographic controls meet regulatory and industry standards.
A18.2Information security reviewsASMPentestCISO-aaS

An independent eye finds what internal teams miss. We provide the technical reviews and testing that prove your security actually works.

  • .1Independent review of information security
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM can provide an external perspective on the organization's attack surface, identifying potential vulnerabilities and threats that might not be visible internally. This helps ensure that the information security measures are effective from an outside-in perspective, contributing to an independent review.
    • Penetration TestingInternal Penetration Testing offers an independent assessment of the security posture by simulating attacks within the organization's network. This helps validate the effectiveness of internal security controls and uncovers vulnerabilities that need addressing, aligning with the requirement for an independent review.
  • .2Compliance with security policies and standards
    ASMPentestCISO-aaSIR
    Why & how we help
    • CISO as a ServiceCISO as a Service plays a critical role in ensuring compliance with security policies and standards by developing, implementing, and maintaining comprehensive security strategies. This service helps organizations create and enforce security policies and standards that align with regulatory and compliance requirements. It also ensures that these policies are regularly reviewed and updated to address evolving threats and organizational changes.
  • .3Technical compliance review
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingInternal Penetration Testing is crucial for a technical compliance review as it helps identify vulnerabilities and weaknesses within the organization's internal systems. By simulating attacks and assessing the network's defenses, internal pentesting ensures that the organization adheres to security standards and compliance requirements.
    • CISO as a ServiceCISO as a Service provides expert guidance in conducting technical compliance reviews by developing and implementing the necessary policies, procedures, and controls. The service ensures the organization stays aligned with compliance mandates through continuous monitoring and updates to security strategies.

Governance

CIS TOP 18

CIS Top 18 is a set of cybersecurity best practices from the Center for Internet Security, featuring 18 prioritized actions to enhance cyber defense. It covers key areas like asset management, vulnerability management, and incident response. The framework is practical and aligns with standards like ISO 27001 and regulations such as NIS2 and DORA. It's known for its simplicity, though it may be less suitable for specialized environments.

142 of 153 controls directly addressed by a River Security service, plus 11 supported partially.

Service coverage

Penetration Testing
30%46 +100~/153
CISO as a Service
92%140 +13~/153
Incident Response
10%16 +23~/153

Strengths

  • Practical Guidance: Offers actionable and straightforward steps for improving cybersecurity.
  • Prioritization: Focuses on the most critical controls first, making implementation easier.
  • Scalability: Suitable for organizations of all sizes, from small businesses to large enterprises.
  • Alignment: Works well with other standards and regulations, such as ISO 27001, NIS2, and DORA.
  • Continuous Improvement: Encourages ongoing enhancement of security measures through regular updates.

Trade-offs

  • Generalization: May not cover highly specialized or industry-specific security needs.
  • Resource Requirements: Implementing all 18 controls can still require significant time and effort.
  • Maturity Level Assumptions: Assumes a certain baseline of security maturity, which may not fit all organizations.
  • Adaptability: Some controls may need customization to fit unique organizational contexts.
Controls & how we help
DirectPartialNot mapped
1Inventory and Control of Enterprise AssetsASMPentestCISO-aaS

You can't secure what you don't know you have. Active Focus continuously discovers your internet-facing assets so your inventory reflects reality, not last quarter's spreadsheet.

  • .1Establish and maintain a detailed and updated inventory of enterprise assets that store or process data. The assets can be connected to the infrastructure remotely, physically, or virtually.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM is instrumental in identifying and cataloging external assets that are part of the organization's attack surface. By providing continuous monitoring and asset discovery, EASM ensures that the inventory of assets, including those that are remotely connected, is always up-to-date and comprehensive.
    • Penetration TestingInternal Penetration Testing is not directly involved in maintaining an asset inventory but can identify unknown or unlisted internal assets during testing, indirectly contributing to a more comprehensive asset inventory.
    • CISO as a ServiceCISO as a Service helps establish the necessary policies and procedures to maintain an up-to-date inventory of enterprise assets. This service ensures that the organization has the right frameworks in place for accurate asset management, aligning with compliance requirements.
  • .2Implement processes to remove, deny, or quarantine unauthorized assets.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously discovers internet-facing enterprise assets, so the inventory reflects what is actually exposed right now rather than a static list.
    • Penetration TestingPenetration testing surfaces unknown or forgotten assets encountered during an engagement, feeding back into a more complete inventory — a useful by-product rather than the primary control.
    • CISO as a ServiceCISO as a Service can help design and implement robust processes and policies for managing unauthorized assets. The service ensures compliance by creating procedures to identify, remove, deny, or quarantine assets that are not authorized, aligning with best practices and regulatory requirements.
  • .3Use an active discovery tool to identify assets connected to the network and configure it to execute as often as needed.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM is not applicable as it primarily focuses on external threats and monitoring rather than internal network asset discovery.
    • Penetration TestingInternal Penetration Testing is not directly applicable as it focuses on identifying vulnerabilities rather than conducting continuous asset discovery.
    • CISO as a ServiceCISO as a Service is not directly applicable because it focuses on developing policies and strategies rather than active discovery of network assets.
  • .4Use Dynamic Host Configuration Protocol (DHCP) logging or Internet Protocol (IP) address management tools to update the inventory.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously discovers internet-facing enterprise assets, so the inventory reflects what is actually exposed right now rather than a static list.
    • Penetration TestingPenetration testing surfaces unknown or forgotten assets encountered during an engagement, feeding back into a more complete inventory — a useful by-product rather than the primary control.
    • CISO as a ServiceCISO as a Service establishes the asset-management policy, ownership and processes that keep the inventory accurate and authorised.
  • .5Use a passive asset directory tool to identify assets connected to the network.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM provides continuous monitoring and discovery of external assets, which can complement passive asset directory tools in identifying assets that are connected to the network, especially those that are externally accessible.
    • Penetration TestingPenetration testing surfaces unknown or forgotten assets encountered during an engagement, feeding back into a more complete inventory — a useful by-product rather than the primary control.
    • CISO as a ServiceCISO as a Service establishes the asset-management policy, ownership and processes that keep the inventory accurate and authorised.
2Inventory and Control of Software AssetsASMPentestCISO-aaS

Unknown software is unmanaged risk. We continuously fingerprint the software and services running on your exposed systems and help you control what belongs there.

  • .1Establish and maintain a detailed inventory of software installed on assets.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus fingerprints the software and versions running on your exposed systems, flagging unauthorised, unexpected or outdated components.
    • Penetration TestingPenetration testing can reveal unmanaged or shadow software in use during an engagement, supporting the software inventory.
    • CISO as a ServiceCISO as a Service helps organizations develop and implement policies and procedures for maintaining a comprehensive software inventory. This service ensures that the organization has a systematic approach to track and document all software installations, which is crucial for compliance and security management.
  • .2Ensure that only supported software is authorized in the inventory.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus fingerprints the software and versions running on your exposed systems, flagging unauthorised, unexpected or outdated components.
    • Penetration TestingPenetration testing can reveal unmanaged or shadow software in use during an engagement, supporting the software inventory.
    • CISO as a ServiceCISO as a Service helps in the development and enforcement of policies and procedures that ensure only supported software is authorized in the inventory. This includes creating guidelines for software procurement, usage, and decommissioning, and ensuring regular audits and reviews are conducted to maintain compliance.
  • .3Remove unauthorized software from the system or document its necessity.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus fingerprints the software and versions running on your exposed systems, flagging unauthorised, unexpected or outdated components.
    • Penetration TestingPenetration testing can reveal unmanaged or shadow software in use during an engagement, supporting the software inventory.
    • CISO as a ServiceCISO as a Service can help establish and enforce policies and procedures for software management, ensuring that only authorized software is installed on systems. This service assists in creating guidelines for documenting the necessity of any unauthorized software that must be retained, supporting compliance with this control.
  • .4Automate the process of discovering and documenting installed software using software inventory tools.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus fingerprints the software and versions running on your exposed systems, flagging unauthorised, unexpected or outdated components.
    • Penetration TestingPenetration testing can reveal unmanaged or shadow software in use during an engagement, supporting the software inventory.
    • CISO as a ServiceCISO as a Service aids in establishing policies and procedures for software inventory management. This service can guide the organization in selecting and implementing appropriate software inventory tools, ensuring that the process of discovering and documenting installed software is automated and compliant with regulatory requirements.
  • .5Ensure that only authorized software can be accessed or executed using technical controls like application allowlisting.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus fingerprints the software and versions running on your exposed systems, flagging unauthorised, unexpected or outdated components.
    • Penetration TestingPenetration testing can reveal unmanaged or shadow software in use during an engagement, supporting the software inventory.
    • CISO as a ServiceCISO as a Service sets the software-inventory and allow-listing policy so only authorised software runs in the environment.
  • .6Ensure that only authorized software libraries are loaded into system processes using technical controls.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus fingerprints the software and versions running on your exposed systems, flagging unauthorised, unexpected or outdated components.
    • Penetration TestingPenetration testing can reveal unmanaged or shadow software in use during an engagement, supporting the software inventory.
    • CISO as a ServiceCISO as a Service sets the software-inventory and allow-listing policy so only authorised software runs in the environment.
  • .7Ensure that only authorized scripts can be executed using technical controls like digital signatures and version control.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus fingerprints the software and versions running on your exposed systems, flagging unauthorised, unexpected or outdated components.
    • Penetration TestingPenetration testing can reveal unmanaged or shadow software in use during an engagement, supporting the software inventory.
    • CISO as a ServiceCISO as a Service sets the software-inventory and allow-listing policy so only authorised software runs in the environment.
3Data ProtectionASMPentestCISO-aaS

Data is what attackers are really after. We set the classification and handling rules and hunt for data that's exposed or reachable.

  • .1Establish and maintain a data management process detailing sensitivity, retention limits, disposal requirements, and owners.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus looks for data stores, backups and interfaces exposed to the internet, catching sensitive data that has leaked outside its intended boundary.
    • Penetration TestingPenetration testing checks whether protected data can actually be reached or exfiltrated once an attacker is inside.
    • CISO as a ServiceCISO as a Service assists in developing and implementing a comprehensive data management process. This includes defining data sensitivity, setting retention limits, establishing disposal requirements, and identifying data owners. The service ensures that the organization's policies and procedures align with compliance standards for data management.
  • .2Establish and maintain a data inventory based on the management process.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus looks for data stores, backups and interfaces exposed to the internet, catching sensitive data that has leaked outside its intended boundary.
    • Penetration TestingPenetration testing checks whether protected data can actually be reached or exfiltrated once an attacker is inside.
    • CISO as a ServiceCISO as a Service is instrumental in establishing and maintaining a data inventory by providing expert guidance in developing data management processes. This includes creating policies and procedures for data classification, storage, and handling, ensuring the organization complies with regulatory requirements and best practices.
  • .3Configure data access controls lists to file systems, databases, and applications.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus looks for data stores, backups and interfaces exposed to the internet, catching sensitive data that has leaked outside its intended boundary.
    • Penetration TestingPenetration testing checks whether protected data can actually be reached or exfiltrated once an attacker is inside.
    • CISO as a ServiceCISO as a Service defines data classification, handling and retention rules, and the controls that enforce them.
  • .4Retain data based on management processes including minimum and maximum timelines.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus looks for data stores, backups and interfaces exposed to the internet, catching sensitive data that has leaked outside its intended boundary.
    • Penetration TestingPenetration testing checks whether protected data can actually be reached or exfiltrated once an attacker is inside.
    • CISO as a ServiceCISO as a Service can assist in developing and implementing data retention policies and management processes. This service helps ensure compliance by creating guidelines for minimum and maximum data retention timelines, aligning with regulatory requirements and best practices.
  • .5Dispose of data securely aligned with the level of sensitivity.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus looks for data stores, backups and interfaces exposed to the internet, catching sensitive data that has leaked outside its intended boundary.
    • Penetration TestingPenetration testing checks whether protected data can actually be reached or exfiltrated once an attacker is inside.
    • CISO as a ServiceCISO as a Service defines data classification, handling and retention rules, and the controls that enforce them.
  • .6Encrypt data deployed on endpoint devices.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus looks for data stores, backups and interfaces exposed to the internet, catching sensitive data that has leaked outside its intended boundary.
    • Penetration TestingPenetration testing checks whether protected data can actually be reached or exfiltrated once an attacker is inside.
    • CISO as a ServiceCISO as a Service defines data classification, handling and retention rules, and the controls that enforce them.
  • .7Establish and maintain a data classification plan based on sensitive, public, or confidential categories.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus looks for data stores, backups and interfaces exposed to the internet, catching sensitive data that has leaked outside its intended boundary.
    • Penetration TestingPenetration testing checks whether protected data can actually be reached or exfiltrated once an attacker is inside.
    • CISO as a ServiceCISO as a Service plays a crucial role in establishing and maintaining a data classification plan by providing expertise in developing policies and procedures that define data categories such as sensitive, public, or confidential. This service ensures that the organization's data classification aligns with compliance requirements and industry best practices.
  • .8Document data flows based on data management processes.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus looks for data stores, backups and interfaces exposed to the internet, catching sensitive data that has leaked outside its intended boundary.
    • Penetration TestingPenetration testing checks whether protected data can actually be reached or exfiltrated once an attacker is inside.
    • CISO as a ServiceCISO as a Service can assist organizations in documenting data flows by providing expert guidance on data management processes. This service helps in creating detailed documentation and policies that outline how data is collected, processed, stored, and shared, ensuring compliance with data protection regulations.
  • .9Encrypt data on removable media.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus looks for data stores, backups and interfaces exposed to the internet, catching sensitive data that has leaked outside its intended boundary.
    • Penetration TestingPenetration testing checks whether protected data can actually be reached or exfiltrated once an attacker is inside.
    • CISO as a ServiceCISO as a Service defines data classification, handling and retention rules, and the controls that enforce them.
  • .10Encrypt data in transit using techniques like Transport Layer Security (TLS) or Open Secure Shell (OpenSSH).
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus looks for data stores, backups and interfaces exposed to the internet, catching sensitive data that has leaked outside its intended boundary.
    • Penetration TestingPenetration testing checks whether protected data can actually be reached or exfiltrated once an attacker is inside.
    • CISO as a ServiceCISO as a Service defines data classification, handling and retention rules, and the controls that enforce them.
  • .11Encrypt sensitive data at rest deployed on servers, applications, or databases using techniques like server-side encryption or application-layer encryption.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus looks for data stores, backups and interfaces exposed to the internet, catching sensitive data that has leaked outside its intended boundary.
    • Penetration TestingPenetration testing checks whether protected data can actually be reached or exfiltrated once an attacker is inside.
    • CISO as a ServiceCISO as a Service defines data classification, handling and retention rules, and the controls that enforce them.
  • .12Segment data processing and storage based on its sensitivity.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus looks for data stores, backups and interfaces exposed to the internet, catching sensitive data that has leaked outside its intended boundary.
    • Penetration TestingPenetration testing checks whether protected data can actually be reached or exfiltrated once an attacker is inside.
    • CISO as a ServiceCISO as a Service can guide the organization in developing and implementing data segmentation strategies, policies, and procedures. The service ensures that data is classified correctly based on its sensitivity and that appropriate controls and segments are applied to protect sensitive data. This aligns with compliance requirements for data protection.
  • .13Use automated tools like Data Loss Prevention (DLP) to identify sensitive data stored, processed, or transmitted via enterprise assets.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus looks for data stores, backups and interfaces exposed to the internet, catching sensitive data that has leaked outside its intended boundary.
    • Penetration TestingPenetration testing checks whether protected data can actually be reached or exfiltrated once an attacker is inside.
    • CISO as a ServiceCISO as a Service defines data classification, handling and retention rules, and the controls that enforce them.
  • .14Maintain a log of sensitive data access that includes modification and disposal.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus looks for data stores, backups and interfaces exposed to the internet, catching sensitive data that has leaked outside its intended boundary.
    • Penetration TestingPenetration testing checks whether protected data can actually be reached or exfiltrated once an attacker is inside.
    • CISO as a ServiceCISO as a Service defines data classification, handling and retention rules, and the controls that enforce them.
4Secure Configuration of Enterprise Assets and SoftwareASMPentestCISO-aaS

Misconfiguration is the most common way in. We continuously check external configuration, pen-test it from the inside, and set the hardening standards.

  • .1Establish and maintain a secure configuration process for enterprise assets and software.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously checks the configuration of internet-facing assets, flagging weak TLS, exposed services and insecure defaults.
    • Penetration TestingPenetration testing validates hardening from the inside, proving whether misconfigurations can be exploited.
    • CISO as a ServiceCISO as a Service aids in the development and implementation of a secure configuration process by providing expert guidance on best practices and compliance requirements. This service helps create and maintain policies, procedures, and documentation that ensure enterprise assets and software are configured securely, reducing vulnerabilities and enhancing the organization's security posture.
  • .2Establish and maintain a secure configuration process for network devices.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously checks the configuration of internet-facing assets, flagging weak TLS, exposed services and insecure defaults.
    • Penetration TestingPenetration testing validates hardening from the inside, proving whether misconfigurations can be exploited.
    • CISO as a ServiceCISO as a Service provides expert guidance in developing and maintaining secure configuration processes for network devices. This service ensures that best practices are followed and that the organization's security policies align with compliance requirements, thus supporting a robust security posture.
  • .3Configure automated session lockout after a defined period of inactivity. The recommended period is 15 minutes for general operating systems and 2 minutes for mobile endpoint devices.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously checks the configuration of internet-facing assets, flagging weak TLS, exposed services and insecure defaults.
    • Penetration TestingPenetration testing validates hardening from the inside, proving whether misconfigurations can be exploited.
    • CISO as a ServiceCISO as a Service sets the secure-configuration baselines and hardening standards the organisation builds to.
  • .4Implement and manage firewalls on supported servers.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously checks the configuration of internet-facing assets, flagging weak TLS, exposed services and insecure defaults.
    • Penetration TestingPenetration testing validates hardening from the inside, proving whether misconfigurations can be exploited.
    • CISO as a ServiceCISO as a Service sets the secure-configuration baselines and hardening standards the organisation builds to.
  • .5Implement and manage a host based firewall or port filtering tool on endpoint devices. Configure the settings to allow only whitelisted traffic.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously checks the configuration of internet-facing assets, flagging weak TLS, exposed services and insecure defaults.
    • Penetration TestingPenetration testing validates hardening from the inside, proving whether misconfigurations can be exploited.
    • CISO as a ServiceCISO as a Service sets the secure-configuration baselines and hardening standards the organisation builds to.
  • .6Securely manage enterprise assets and software using version-controlled infrastructure-as-code and accessing administrative interfaces over secure network protocols like SSH and HTTPS.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously checks the configuration of internet-facing assets, flagging weak TLS, exposed services and insecure defaults.
    • Penetration TestingPenetration testing validates hardening from the inside, proving whether misconfigurations can be exploited.
    • CISO as a ServiceCISO as a Service sets the secure-configuration baselines and hardening standards the organisation builds to.
  • .7Manage default accounts on assets like root, administrator, or pre-configured vendor accounts by disabling or making them inaccessible.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously checks the configuration of internet-facing assets, flagging weak TLS, exposed services and insecure defaults.
    • Penetration TestingPenetration testing validates hardening from the inside, proving whether misconfigurations can be exploited.
    • CISO as a ServiceCISO as a Service sets the secure-configuration baselines and hardening standards the organisation builds to.
  • .8Implement and manage a host-based firewall or port filtering tool on endpoint devices. Configure the settings to allow only whitelisted traffic.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously checks the configuration of internet-facing assets, flagging weak TLS, exposed services and insecure defaults.
    • Penetration TestingPenetration testing validates hardening from the inside, proving whether misconfigurations can be exploited.
    • CISO as a ServiceCISO as a Service sets the secure-configuration baselines and hardening standards the organisation builds to.
  • .9Configure trusted DNS servers. Use only enterprise controlled or trusted externally accessible DNS servers.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously checks the configuration of internet-facing assets, flagging weak TLS, exposed services and insecure defaults.
    • Penetration TestingPenetration testing validates hardening from the inside, proving whether misconfigurations can be exploited.
    • CISO as a ServiceCISO as a Service sets the secure-configuration baselines and hardening standards the organisation builds to.
  • .10Configure automated device lockout following a predetermined number of failed authentication attempts. The suggested number is 20 for laptops and 10 for tablets or smartphones.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously checks the configuration of internet-facing assets, flagging weak TLS, exposed services and insecure defaults.
    • Penetration TestingPenetration testing validates hardening from the inside, proving whether misconfigurations can be exploited.
    • CISO as a ServiceCISO as a Service sets the secure-configuration baselines and hardening standards the organisation builds to.
  • .11Remotely delete data deployed in enterprise owned portable devices if the drive is lost or the assigned owner has exited the org.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously checks the configuration of internet-facing assets, flagging weak TLS, exposed services and insecure defaults.
    • Penetration TestingPenetration testing validates hardening from the inside, proving whether misconfigurations can be exploited.
    • CISO as a ServiceCISO as a Service sets the secure-configuration baselines and hardening standards the organisation builds to.
  • .12Use separate workspaces on mobile and endpoint devices for enterprise and personal application data.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously checks the configuration of internet-facing assets, flagging weak TLS, exposed services and insecure defaults.
    • Penetration TestingPenetration testing validates hardening from the inside, proving whether misconfigurations can be exploited.
    • CISO as a ServiceCISO as a Service sets the secure-configuration baselines and hardening standards the organisation builds to.
5Account ManagementASMPentestCISO-aaS

Every account is a way in. We govern the account lifecycle and test whether dormant, default and over-privileged accounts can be abused.

  • .1Use unique passwords for each asset. Passwords should have at least eight characters if MFA is enabled and 14 characters if not enabled.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus can surface exposed authentication endpoints and leaked or default accounts on internet-facing systems.
    • Penetration TestingPenetration testing tests whether dormant, default, shared or over-privileged accounts can be abused to gain access.
    • CISO as a ServiceCISO as a Service governs the account lifecycle — creation, review and removal — through policy and process.
  • .2Use unique passwords for each asset. Passwords should have at least 8 characters if MFA is enabled and 14 characters if not enabled.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus can surface exposed authentication endpoints and leaked or default accounts on internet-facing systems.
    • Penetration TestingPenetration testing tests whether dormant, default, shared or over-privileged accounts can be abused to gain access.
    • CISO as a ServiceCISO as a Service governs the account lifecycle — creation, review and removal — through policy and process.
  • .3Delete or disable dormant accounts after 45 days of inactivity.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus can surface exposed authentication endpoints and leaked or default accounts on internet-facing systems.
    • Penetration TestingPenetration testing tests whether dormant, default, shared or over-privileged accounts can be abused to gain access.
    • CISO as a ServiceCISO as a Service governs the account lifecycle — creation, review and removal — through policy and process.
  • .4Restrict administrator privileges to administer accounts and conduct general activities from user/non-privileged accounts.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus can surface exposed authentication endpoints and leaked or default accounts on internet-facing systems.
    • Penetration TestingPenetration testing tests whether dormant, default, shared or over-privileged accounts can be abused to gain access.
    • CISO as a ServiceCISO as a Service governs the account lifecycle — creation, review and removal — through policy and process.
  • .5Establish and maintain an inventory of service accounts detailing department owner, review date, and purpose.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus can surface exposed authentication endpoints and leaked or default accounts on internet-facing systems.
    • Penetration TestingPenetration testing tests whether dormant, default, shared or over-privileged accounts can be abused to gain access.
    • CISO as a ServiceCISO as a Service can help establish and maintain an inventory of service accounts by developing policies and procedures that ensure proper documentation of service accounts, including department ownership, review dates, and their purposes. This service ensures compliance by maintaining accurate records and facilitating regular reviews.
  • .6Centralize all account management activities using a directory or identity service.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus can surface exposed authentication endpoints and leaked or default accounts on internet-facing systems.
    • Penetration TestingPenetration testing tests whether dormant, default, shared or over-privileged accounts can be abused to gain access.
    • CISO as a ServiceCISO as a Service can provide guidance on implementing centralized account management activities through the development of policies and procedures that utilize directory or identity services. This service ensures that these processes align with compliance requirements and industry best practices.
6Access Control ManagementASMPentestCISO-aaS

Least privilege only counts if it's enforced. We design the access model and test whether it actually holds.

  • .1Establish a process to manage access privileges for new hires or role changes.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus flags externally reachable systems and services where access controls are the last line of defence.
    • Penetration TestingPenetration testing proves whether least-privilege and access boundaries actually hold, or can be bypassed.
    • CISO as a ServiceCISO as a Service can help establish a robust process for managing access privileges by developing policies and procedures that align with compliance requirements. This service ensures that access controls are appropriately implemented and managed, reducing the risk of unauthorized access.
  • .2Establish a process to manage access removal for role change or termination.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus flags externally reachable systems and services where access controls are the last line of defence.
    • Penetration TestingPenetration testing proves whether least-privilege and access boundaries actually hold, or can be bypassed.
    • CISO as a ServiceCISO as a Service is instrumental in establishing and managing the process for access removal during role changes or terminations. It provides expert guidance in developing policies and procedures that ensure timely and secure access management, thereby supporting compliance with access control requirements.
  • .3Maintain role-based access control based on role-wise access rights to ensure each function can carry out their assigned tasks.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus flags externally reachable systems and services where access controls are the last line of defence.
    • Penetration TestingPenetration testing proves whether least-privilege and access boundaries actually hold, or can be bypassed.
    • CISO as a ServiceCISO as a Service can help in developing and implementing role-based access control policies and procedures. This includes defining roles, access rights, and ensuring that these are aligned with the organization's security and compliance requirements. They provide guidance on best practices for access management and ensure policies are updated to meet compliance standards.
  • .4Enforce MFA for remote network access requests.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus flags externally reachable systems and services where access controls are the last line of defence.
    • Penetration TestingPenetration testing proves whether least-privilege and access boundaries actually hold, or can be bypassed.
    • CISO as a ServiceCISO as a Service provides expert guidance in establishing and enforcing security policies, such as Multi-Factor Authentication (MFA). This service helps in designing, implementing, and maintaining the necessary policies and procedures to ensure that MFA is effectively enforced for remote network access requests, thus aligning with compliance requirements.
  • .5Enforce MFA on all externally managed or third-party accessible applications.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus flags externally reachable systems and services where access controls are the last line of defence.
    • Penetration TestingPenetration testing proves whether least-privilege and access boundaries actually hold, or can be bypassed.
    • CISO as a ServiceCISO as a Service helps in developing and implementing security policies that include enforcing MFA on third-party accessible applications. This service ensures that the organization has robust authentication mechanisms in place as per compliance requirements.
  • .6Establish and maintain an inventory of authentication and authorization systems.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus flags externally reachable systems and services where access controls are the last line of defence.
    • Penetration TestingPenetration testing proves whether least-privilege and access boundaries actually hold, or can be bypassed.
    • CISO as a ServiceCISO as a Service can provide expert guidance in establishing and maintaining an inventory of authentication and authorization systems. This service can help develop policies and procedures to ensure these systems are documented, regularly updated, and aligned with compliance requirements, thereby facilitating efficient access management.
  • .7Centralize access control activities using a directory or SSO provider.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus flags externally reachable systems and services where access controls are the last line of defence.
    • Penetration TestingPenetration testing proves whether least-privilege and access boundaries actually hold, or can be bypassed.
    • CISO as a ServiceCISO as a Service can play a crucial role in centralizing access control activities by helping the organization to establish and implement a robust access control policy. This service can guide the organization in selecting and integrating a directory or SSO provider, ensuring that access control is centralized and aligned with compliance requirements. Additionally, CISOaaS can provide ongoing management and updates to access control procedures, ensuring they remain effective and compliant.
  • .8Maintain a role-based access control based on role-wise access rights to ensure each function can carry out their assigned tasks.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus flags externally reachable systems and services where access controls are the last line of defence.
    • Penetration TestingPenetration testing proves whether least-privilege and access boundaries actually hold, or can be bypassed.
    • CISO as a ServiceCISO as a Service is instrumental in designing and implementing a role-based access control (RBAC) system. This service helps in developing policies and procedures that define access rights based on roles within the organization. By ensuring that access controls are aligned with organizational roles, CISOaaS supports compliance with security standards and minimizes the risk of unauthorized access.
7Continuous Vulnerability ManagementASMPentestCISO-aaS

Vulnerability management is what we do. Active Focus finds external weaknesses continuously, penetration testing proves the internal ones, and we run the process that gets them fixed.

  • .1Establish and maintain a documented process to manage vulnerabilities.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously scans your external attack surface for new and known vulnerabilities, so exposures are found and tracked as they appear.
    • Penetration TestingPenetration testing confirms which vulnerabilities are genuinely exploitable and how far they lead, prioritising what actually matters.
    • CISO as a ServiceCISO as a Service helps establish and maintain a documented process to manage vulnerabilities by providing expert guidance in developing policies and procedures. This includes identifying vulnerabilities, assessing their impact, prioritizing remediation efforts, and ensuring continuous improvement of the vulnerability management process. The service ensures that the organization remains compliant with relevant regulations and standards by keeping documentation up-to-date and aligned with best practices.
  • .2Establish and maintain a documented risk remediation plan.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously scans your external attack surface for new and known vulnerabilities, so exposures are found and tracked as they appear.
    • Penetration TestingPenetration testing confirms which vulnerabilities are genuinely exploitable and how far they lead, prioritising what actually matters.
    • CISO as a ServiceCISO as a Service assists in developing and maintaining comprehensive risk management strategies, including the creation of a documented risk remediation plan. This service ensures that the organization has the necessary guidance to identify, prioritize, and address risks in accordance with compliance requirements.
  • .3Conduct automated vulnerability scans (authenticated and unauthenticated) on internal assets using a SCAP-compliant scanning tool.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM primarily focuses on external threats and vulnerabilities, but it can complement internal vulnerability management by providing insights into potential risks that could originate from external assets. However, it does not specifically address the requirement for conducting automated vulnerability scans on internal assets.
    • Penetration TestingPenetration testing confirms which vulnerabilities are genuinely exploitable and how far they lead, prioritising what actually matters.
    • CISO as a ServiceCISO as a Service runs the vulnerability-management process — scanning cadence, risk-based prioritisation and remediation tracking.
  • .4Update applications using automated patch management tools.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously scans your external attack surface for new and known vulnerabilities, so exposures are found and tracked as they appear.
    • Penetration TestingPenetration testing confirms which vulnerabilities are genuinely exploitable and how far they lead, prioritising what actually matters.
    • CISO as a ServiceCISO as a Service can assist in establishing and implementing effective patch management policies and procedures. This service can help ensure that automated patch management tools are correctly configured and aligned with compliance requirements, thus maintaining the security and integrity of applications.
  • .5Conduct automated vulnerability scans (authenticated and unauthenticated) on internal assets using a SCAP compliant scanning tool.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously scans your external attack surface for new and known vulnerabilities, so exposures are found and tracked as they appear.
    • Penetration TestingPenetration testing confirms which vulnerabilities are genuinely exploitable and how far they lead, prioritising what actually matters.
    • CISO as a ServiceCISO as a Service runs the vulnerability-management process — scanning cadence, risk-based prioritisation and remediation tracking.
  • .6Conduct automated vulnerability scans (authenticated and unauthenticated) on external assets using a SCAP-compliant scanning tool.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM services typically include automated vulnerability scanning of external assets as part of their offering. They utilize tools that can be SCAP-compliant to ensure comprehensive coverage of potential vulnerabilities. EASM also provides continuous monitoring and assessment of the external attack surface, which aligns with the need for regular automated scans of external assets.
    • Penetration TestingPenetration testing confirms which vulnerabilities are genuinely exploitable and how far they lead, prioritising what actually matters.
    • CISO as a ServiceCISO as a Service runs the vulnerability-management process — scanning cadence, risk-based prioritisation and remediation tracking.
  • .7Remediate software vulnerabilities using tools and processes.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously scans your external attack surface for new and known vulnerabilities, so exposures are found and tracked as they appear.
    • Penetration TestingPenetration testing confirms which vulnerabilities are genuinely exploitable and how far they lead, prioritising what actually matters.
    • CISO as a ServiceCISO as a Service provides expert guidance in developing and implementing processes and policies for effective vulnerability management. This includes establishing a structured approach for identifying, prioritizing, and remediating software vulnerabilities, ensuring the organization adheres to compliance requirements.
8Audit Log ManagementPentestCISO-aaSIR

Logs are useless if they're incomplete or unprotected. We set the logging policy, test whether attacks actually get recorded, and rely on those logs when responding.

  • .1Establish and maintain a process to collect, review, and retain audit logs.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingPenetration testing checks whether attacks are actually recorded — gaps in logging and detection show up when we simulate an intrusion.
    • CISO as a ServiceCISO as a Service can assist in developing and implementing a robust process for audit log management. This includes defining policies and procedures for collecting, reviewing, and retaining audit logs to ensure compliance with relevant regulations and standards.
    • Incident ResponseIncident Response depends on good logs to reconstruct what happened; we help ensure the right telemetry exists and use it during an incident.
  • .2Centralize audit log collection and retention processes.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingPenetration testing checks whether attacks are actually recorded — gaps in logging and detection show up when we simulate an intrusion.
    • CISO as a ServiceCISO as a Service helps organizations design and implement centralized audit log collection and retention processes. This service ensures that the company has the necessary policies and procedures in place for effective logging, monitoring, and auditing, which are essential for compliance.
    • Incident ResponseIncident Response depends on good logs to reconstruct what happened; we help ensure the right telemetry exists and use it during an incident.
  • .3Ensure adequate storage capabilities in audit log destinations.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingPenetration testing checks whether attacks are actually recorded — gaps in logging and detection show up when we simulate an intrusion.
    • CISO as a ServiceCISO as a Service can assist in ensuring compliance by advising on best practices for audit log management, including the establishment of policies and procedures for adequate storage capabilities. This service helps in designing a logging infrastructure that meets compliance requirements and ensures data integrity and availability.
    • Incident ResponseIncident Response depends on good logs to reconstruct what happened; we help ensure the right telemetry exists and use it during an incident.
  • .4Collect audit logs across assets aligned with the enterprise’s log management process.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingPenetration testing checks whether attacks are actually recorded — gaps in logging and detection show up when we simulate an intrusion.
    • CISO as a ServiceCISO as a Service defines what must be logged, how logs are protected and retained, and how they are reviewed.
    • Incident ResponseIncident Response depends on good logs to reconstruct what happened; we help ensure the right telemetry exists and use it during an incident.
  • .5Collect detailed audit logs for sensitive data that includes event source, date, username, timestamp, address and destination sources, and more to support forensic investigation.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingPenetration testing checks whether attacks are actually recorded — gaps in logging and detection show up when we simulate an intrusion.
    • CISO as a ServiceCISO as a Service defines what must be logged, how logs are protected and retained, and how they are reviewed.
    • Incident ResponseIncident Response depends on good logs to reconstruct what happened; we help ensure the right telemetry exists and use it during an incident.
  • .6Collect DNS query audit logs.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingPenetration testing checks whether attacks are actually recorded — gaps in logging and detection show up when we simulate an intrusion.
    • CISO as a ServiceCISO as a Service defines what must be logged, how logs are protected and retained, and how they are reviewed.
    • Incident ResponseIncident Response depends on good logs to reconstruct what happened; we help ensure the right telemetry exists and use it during an incident.
  • .7Collect URL request audit logs.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingPenetration testing checks whether attacks are actually recorded — gaps in logging and detection show up when we simulate an intrusion.
    • CISO as a ServiceCISO as a Service defines what must be logged, how logs are protected and retained, and how they are reviewed.
    • Incident ResponseIncident Response depends on good logs to reconstruct what happened; we help ensure the right telemetry exists and use it during an incident.
  • .8Collect command line audit logs.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingPenetration testing checks whether attacks are actually recorded — gaps in logging and detection show up when we simulate an intrusion.
    • CISO as a ServiceCISO as a Service defines what must be logged, how logs are protected and retained, and how they are reviewed.
    • Incident ResponseIncident Response depends on good logs to reconstruct what happened; we help ensure the right telemetry exists and use it during an incident.
  • .9Centralize audit log collect and retention processes.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingPenetration testing checks whether attacks are actually recorded — gaps in logging and detection show up when we simulate an intrusion.
    • CISO as a ServiceCISO as a Service can help establish a centralized audit log collection and retention strategy by developing policies and procedures that define how logs are collected, stored, and retained. This service ensures that the organization adheres to compliance requirements by maintaining proper documentation and implementing effective log management practices.
    • Incident ResponseIncident Response depends on good logs to reconstruct what happened; we help ensure the right telemetry exists and use it during an incident.
  • .10Retain audit logs for at least 90 days.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingPenetration testing checks whether attacks are actually recorded — gaps in logging and detection show up when we simulate an intrusion.
    • CISO as a ServiceCISO as a Service defines what must be logged, how logs are protected and retained, and how they are reviewed.
    • Incident ResponseIncident Response depends on good logs to reconstruct what happened; we help ensure the right telemetry exists and use it during an incident.
  • .11Collect audit log reviews to detect anomalous behavior or abnormal events that could be a security threat.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingPenetration testing checks whether attacks are actually recorded — gaps in logging and detection show up when we simulate an intrusion.
    • CISO as a ServiceCISO as a Service defines what must be logged, how logs are protected and retained, and how they are reviewed.
    • Incident ResponseIncident Response depends on good logs to reconstruct what happened; we help ensure the right telemetry exists and use it during an incident.
  • .12Collect service provider logs.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Penetration TestingPenetration testing checks whether attacks are actually recorded — gaps in logging and detection show up when we simulate an intrusion.
    • CISO as a ServiceCISO as a Service defines what must be logged, how logs are protected and retained, and how they are reviewed.
    • Incident ResponseIncident Response depends on good logs to reconstruct what happened; we help ensure the right telemetry exists and use it during an incident.
9Email and Web Browser ProtectionsASMPentestCISO-aaS

Email and the browser are the front door for attackers. Active Focus checks your email security posture and web exposure, and we set the protective policy.

  • .1Run only supported and authorized browsers or email clients. Use only the latest vendor provided version.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM assists in ensuring compliance by continuously monitoring the external attack surface for unauthorized or outdated browsers and email clients. It can detect new or unsupported software versions as they appear in the organization's environment, providing alerts for any deviations from the policy of using only supported and authorized software.
    • Penetration TestingPenetration testing can exercise phishing and browser-based attack paths to show how email and web weaknesses are exploited.
    • CISO as a ServiceCISO as a Service sets the email and browser protection policy, from filtering to allowed content and hardening.
  • .2Use anti-malware systems like attachment scanning or sandboxing to secure email servers.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus checks your email security posture — SPF, DKIM, DMARC — and your exposed web surface, catching gaps that enable phishing and spoofing.
    • Penetration TestingPenetration testing can exercise phishing and browser-based attack paths to show how email and web weaknesses are exploited.
    • CISO as a ServiceCISO as a Service sets the email and browser protection policy, from filtering to allowed content and hardening.
  • .3Use anti-malware systems like attachment scanning or sandboxing to secure email servers.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus checks your email security posture — SPF, DKIM, DMARC — and your exposed web surface, catching gaps that enable phishing and spoofing.
    • Penetration TestingPenetration testing can exercise phishing and browser-based attack paths to show how email and web weaknesses are exploited.
    • CISO as a ServiceCISO as a Service sets the email and browser protection policy, from filtering to allowed content and hardening.
  • .4Use anti-malware systems like attachment scanning or sandboxing to secure email servers.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus checks your email security posture — SPF, DKIM, DMARC — and your exposed web surface, catching gaps that enable phishing and spoofing.
    • Penetration TestingPenetration testing can exercise phishing and browser-based attack paths to show how email and web weaknesses are exploited.
    • CISO as a ServiceCISO as a Service sets the email and browser protection policy, from filtering to allowed content and hardening.
  • .5Use DMARC (Domain-based Message Authentication) policy and verification to minimize email spoofing and email modification.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM helps in identifying and monitoring external threats, including email-based threats. While it may not directly implement DMARC, it can provide insights into potential vulnerabilities and configurations related to email systems, which can support the implementation of DMARC policies.
    • Penetration TestingPenetration testing can exercise phishing and browser-based attack paths to show how email and web weaknesses are exploited.
    • CISO as a ServiceCISO as a Service sets the email and browser protection policy, from filtering to allowed content and hardening.
  • .6Block unnecessary files entering the email gateway.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus checks your email security posture — SPF, DKIM, DMARC — and your exposed web surface, catching gaps that enable phishing and spoofing.
    • Penetration TestingPenetration testing can exercise phishing and browser-based attack paths to show how email and web weaknesses are exploited.
    • CISO as a ServiceCISO as a Service sets the email and browser protection policy, from filtering to allowed content and hardening.
  • .7Use anti-malware systems like attachment scanning or sandboxing to secure email servers.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus checks your email security posture — SPF, DKIM, DMARC — and your exposed web surface, catching gaps that enable phishing and spoofing.
    • Penetration TestingPenetration testing can exercise phishing and browser-based attack paths to show how email and web weaknesses are exploited.
    • CISO as a ServiceCISO as a Service can assist in developing and implementing policies and procedures for using anti-malware systems to secure email servers. This includes selecting appropriate technologies like attachment scanning or sandboxing and ensuring they are integrated into the organization's security infrastructure. CISOaaS also ensures that these systems are regularly updated and tested for effectiveness, aligning with compliance requirements.
10Malware DefensesASMPentestCISO-aaSIR

Malware is a when, not an if. We set the anti-malware policy, harden the entry points, test the defences, and respond when something gets through.

  • .1Deploy and maintain anti-malware software.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus reduces the ways malware gets in by finding exposed and vulnerable internet-facing services.
    • Penetration TestingPenetration testing simulates how malware would land and spread, exposing weak spots in the defences.
    • CISO as a ServiceCISO as a Service sets the anti-malware and EDR policy and ensures it is deployed and maintained.
    • Incident ResponseIncident Response contains, eradicates and recovers when malware gets through, limiting the damage.
  • .2Configure auto update for anti-malware signature files.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus reduces the ways malware gets in by finding exposed and vulnerable internet-facing services.
    • Penetration TestingPenetration testing simulates how malware would land and spread, exposing weak spots in the defences.
    • CISO as a ServiceCISO as a Service sets the anti-malware and EDR policy and ensures it is deployed and maintained.
    • Incident ResponseIncident Response contains, eradicates and recovers when malware gets through, limiting the damage.
  • .3Disable the autorun and autoplay functionality for removable media files.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus reduces the ways malware gets in by finding exposed and vulnerable internet-facing services.
    • Penetration TestingPenetration testing simulates how malware would land and spread, exposing weak spots in the defences.
    • CISO as a ServiceCISO as a Service sets the anti-malware and EDR policy and ensures it is deployed and maintained.
    • Incident ResponseIncident Response contains, eradicates and recovers when malware gets through, limiting the damage.
  • .4Enable anti-exploitation functions on assets and software.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus reduces the ways malware gets in by finding exposed and vulnerable internet-facing services.
    • Penetration TestingPenetration testing simulates how malware would land and spread, exposing weak spots in the defences.
    • CISO as a ServiceCISO as a Service sets the anti-malware and EDR policy and ensures it is deployed and maintained.
    • Incident ResponseIncident Response contains, eradicates and recovers when malware gets through, limiting the damage.
  • .5Centralize anti-malware software management.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus reduces the ways malware gets in by finding exposed and vulnerable internet-facing services.
    • Penetration TestingPenetration testing simulates how malware would land and spread, exposing weak spots in the defences.
    • CISO as a ServiceCISO as a Service can guide the organization in developing a centralized strategy for managing anti-malware software. This includes creating policies and procedures for deploying, updating, and monitoring anti-malware solutions across the organization, ensuring compliance with best practices and regulatory requirements.
    • Incident ResponseIncident Response contains, eradicates and recovers when malware gets through, limiting the damage.
  • .6Use behavior-based anti-malware software.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus reduces the ways malware gets in by finding exposed and vulnerable internet-facing services.
    • Penetration TestingPenetration testing simulates how malware would land and spread, exposing weak spots in the defences.
    • CISO as a ServiceCISO as a Service sets the anti-malware and EDR policy and ensures it is deployed and maintained.
    • Incident ResponseIncident Response contains, eradicates and recovers when malware gets through, limiting the damage.
  • .7Use a behavior based anti malware software.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus reduces the ways malware gets in by finding exposed and vulnerable internet-facing services.
    • Penetration TestingPenetration testing simulates how malware would land and spread, exposing weak spots in the defences.
    • CISO as a ServiceCISO as a Service sets the anti-malware and EDR policy and ensures it is deployed and maintained.
    • Incident ResponseIncident Response contains, eradicates and recovers when malware gets through, limiting the damage.
11Data RecoveryASMPentestCISO-aaS

Recovery is your last line against ransomware — but only if backups survive the attack. We set the recovery strategy, find exposed backups, and test they can’t be reached or destroyed.

  • .1Establish and maintain a data recovery process that includes the scope of activities, prioritization details, and security of backed up data.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus hunts for backup stores and consoles exposed to the internet, so recovery data isn't itself a target.
    • Penetration TestingPenetration testing verifies backups are resilient — that an intruder can't reach, alter or delete them in the same attack.
    • CISO as a ServiceCISO as a Service is crucial in developing a robust data recovery process. This service assists in crafting policies and procedures that define the scope of recovery activities, establish prioritization criteria, and ensure the security of backed-up data. By doing so, it helps organizations align with compliance requirements related to data recovery.
  • .2Backup in scope assets automatically. The frequency should be based on the sensitivity of the data.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus hunts for backup stores and consoles exposed to the internet, so recovery data isn't itself a target.
    • Penetration TestingPenetration testing verifies backups are resilient — that an intruder can't reach, alter or delete them in the same attack.
    • CISO as a ServiceCISO as a Service sets the backup and recovery strategy, including schedules, retention and tested restore procedures.
  • .3Protect recovery data using the same controls as the original data.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus hunts for backup stores and consoles exposed to the internet, so recovery data isn't itself a target.
    • Penetration TestingPenetration testing verifies backups are resilient — that an intruder can't reach, alter or delete them in the same attack.
    • CISO as a ServiceCISO as a Service sets the backup and recovery strategy, including schedules, retention and tested restore procedures.
  • .4Establish and maintain an isolated container of recovery data.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus hunts for backup stores and consoles exposed to the internet, so recovery data isn't itself a target.
    • Penetration TestingPenetration testing verifies backups are resilient — that an intruder can't reach, alter or delete them in the same attack.
    • CISO as a ServiceCISO as a Service can help establish and maintain an isolated container of recovery data by developing policies and procedures that ensure data is properly isolated and protected. The service can also provide guidance on selecting appropriate technologies and controls to secure the recovery data, ensuring compliance with regulations that require data protection and recovery capabilities.
  • .5Test the backup recovery system at frequent intervals.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus hunts for backup stores and consoles exposed to the internet, so recovery data isn't itself a target.
    • Penetration TestingPenetration testing verifies backups are resilient — that an intruder can't reach, alter or delete them in the same attack.
    • CISO as a ServiceCISO as a Service can help establish policies and procedures for regular testing of the backup recovery system. This service ensures that the organization has a structured and documented process for testing backups, which is critical for compliance and maintaining data integrity.
12Network Infrastructure ManagementASMPentestCISO-aaS

Your network is the terrain attackers move through. We design secure network management, watch the external edge, and test the segmentation and controls from the inside.

  • .1Keep network infrastructure updated by running the latest software version and using the currently supported NaaS (network-as-a-service).
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously watches your external network edge for exposed devices, services and misconfigurations.
    • Penetration TestingPenetration testing tests network segmentation and controls from the inside, proving whether boundaries hold.
    • CISO as a ServiceCISO as a Service provides expert guidance in developing and implementing policies and procedures that ensure network infrastructure is consistently updated. This includes advising on the adoption and integration of NaaS solutions, establishing a patch management strategy, and ensuring compliance with industry standards.
  • .2Establish and maintain a secure network architecture to ensure segmentation, implement least privilege, and availability.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously watches your external network edge for exposed devices, services and misconfigurations.
    • Penetration TestingPenetration testing tests network segmentation and controls from the inside, proving whether boundaries hold.
    • CISO as a ServiceCISO as a Service can assist in designing and maintaining a secure network architecture by helping to develop and implement policies and procedures that ensure network segmentation, enforce least privilege, and guarantee availability. This service provides expert guidance on best practices for network security and ensures compliance with regulatory requirements.
  • .3Ensure network infrastructure security using version-controlled-infrastructure-as-code and secure network protocols.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously watches your external network edge for exposed devices, services and misconfigurations.
    • Penetration TestingPenetration testing tests network segmentation and controls from the inside, proving whether boundaries hold.
    • CISO as a ServiceCISO as a Service can help ensure compliance by developing and implementing policies and procedures for managing infrastructure as code (IaC) securely. This includes guidelines for version control, secure coding practices, and the use of secure network protocols. The service can also provide ongoing assessments and updates to these policies to maintain compliance with evolving security standards.
  • .4Establish and maintain an architecture diagram and other necessary network system documents.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously watches your external network edge for exposed devices, services and misconfigurations.
    • Penetration TestingPenetration testing tests network segmentation and controls from the inside, proving whether boundaries hold.
    • CISO as a ServiceCISO as a Service is instrumental in establishing and maintaining an architecture diagram and other necessary network system documents. The service provides expert guidance in documenting the organization's network architecture, ensuring that all necessary components and configurations are accurately represented and updated. This helps in aligning with compliance requirements by ensuring proper documentation and understanding of the network infrastructure.
  • .5Centralize network AAA (Authentication, Authorization, and Auditing).
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously watches your external network edge for exposed devices, services and misconfigurations.
    • Penetration TestingPenetration testing tests network segmentation and controls from the inside, proving whether boundaries hold.
    • CISO as a ServiceCISO as a Service can assist in centralizing network AAA by developing and implementing the necessary policies and procedures. This includes ensuring that authentication, authorization, and auditing processes are aligned with compliance requirements. CISOaaS provides expert guidance on selecting appropriate technologies and frameworks to centralize these functions, ensuring robust security and compliance.
  • .6Use secure network management and communication protocols.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously watches your external network edge for exposed devices, services and misconfigurations.
    • Penetration TestingPenetration testing tests network segmentation and controls from the inside, proving whether boundaries hold.
    • CISO as a ServiceCISO as a Service sets secure network-management standards and change control for the infrastructure.
  • .7Ensure that users authenticate via enterprise managed VPN to access enterprise resources on endpoint devices.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously watches your external network edge for exposed devices, services and misconfigurations.
    • Penetration TestingPenetration testing tests network segmentation and controls from the inside, proving whether boundaries hold.
    • CISO as a ServiceCISO as a Service is instrumental in creating and enforcing policies and procedures that mandate the use of enterprise-managed VPNs for user authentication. This service can help develop a comprehensive authentication strategy and ensure that it aligns with compliance requirements.
  • .8Establish and maintain computing resources segmented from the primary enterprise network and internet connection to manage tasks that require administrative access.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously watches your external network edge for exposed devices, services and misconfigurations.
    • Penetration TestingPenetration testing tests network segmentation and controls from the inside, proving whether boundaries hold.
    • CISO as a ServiceCISO as a Service sets secure network-management standards and change control for the infrastructure.
13Network Monitoring and DefenseASMPentestCISO-aaSIR

Attackers count on not being watched. We set the monitoring and defence strategy, test whether intrusions get detected, and respond when alarms fire.

  • .1Implement a host-based anti-intrusion solution like EDR (Endpoint Detection and Response) systems or host-based IPS agents on supported or applicable assets.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus adds continuous outside-in monitoring of your attack surface, an early-warning signal that complements internal network detection.
    • Penetration TestingPenetration testing checks whether your monitoring and defences actually detect an intrusion, exposing blind spots.
    • CISO as a ServiceCISO as a Service can help in selecting and implementing the right host-based anti-intrusion solutions, such as EDR systems or host-based IPS agents. This service provides expert guidance on the development of policies and procedures for the deployment, management, and maintenance of these systems, ensuring alignment with compliance requirements.
    • Incident ResponseIncident Response acts on what the monitoring surfaces — investigating, containing and recovering when defences flag an attack.
  • .2Implement a host-based anti-intrusion solution like EDR (Endpoint Detection and Response) systems or host-based IPS agents on supported or applicable assets.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus adds continuous outside-in monitoring of your attack surface, an early-warning signal that complements internal network detection.
    • Penetration TestingPenetration testing checks whether your monitoring and defences actually detect an intrusion, exposing blind spots.
    • CISO as a ServiceCISO as a Service can provide expert guidance on selecting, implementing, and managing host-based anti-intrusion solutions like EDR systems. They ensure the chosen solutions align with compliance requirements and organizational needs, assisting in policy development and integration into the security framework.
    • Incident ResponseIncident Response acts on what the monitoring surfaces — investigating, containing and recovering when defences flag an attack.
  • .3Deploy network intrusion detection systems as applicable like NIDS (Network Intrusion Detection System) or CSP (cloud service provider) service.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus adds continuous outside-in monitoring of your attack surface, an early-warning signal that complements internal network detection.
    • Penetration TestingPenetration testing checks whether your monitoring and defences actually detect an intrusion, exposing blind spots.
    • CISO as a ServiceCISO as a Service can guide the organization in selecting and deploying appropriate network intrusion detection systems (NIDS) or cloud service provider (CSP) services. They help develop policies and procedures for monitoring and managing alerts generated by these systems, ensuring compliance with security standards and best practices.
    • Incident ResponseIncident Response acts on what the monitoring surfaces — investigating, containing and recovering when defences flag an attack.
  • .4Filter traffic between network segments as where applicable.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus adds continuous outside-in monitoring of your attack surface, an early-warning signal that complements internal network detection.
    • Penetration TestingPenetration testing checks whether your monitoring and defences actually detect an intrusion, exposing blind spots.
    • CISO as a ServiceCISO as a Service sets the network monitoring and defence strategy, from detection coverage to alerting and response playbooks.
    • Incident ResponseIncident Response acts on what the monitoring surfaces — investigating, containing and recovering when defences flag an attack.
  • .5Implement a host-based anti-intrusion solution like EDR (Endpoint Detection and Response) systems or host-based IPS agents on supported or applicable assets.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus adds continuous outside-in monitoring of your attack surface, an early-warning signal that complements internal network detection.
    • Penetration TestingPenetration testing checks whether your monitoring and defences actually detect an intrusion, exposing blind spots.
    • CISO as a ServiceCISO as a Service can assist in selecting, implementing, and managing host-based anti-intrusion solutions like EDR or IPS. By providing expertise in cybersecurity strategy and policy development, a CISO can ensure that these solutions are effectively integrated into the organization's security framework, thus meeting compliance requirements.
    • Incident ResponseIncident Response acts on what the monitoring surfaces — investigating, containing and recovering when defences flag an attack.
  • .6Collect network traffic logs for reviewing and altering purposes.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus adds continuous outside-in monitoring of your attack surface, an early-warning signal that complements internal network detection.
    • Penetration TestingPenetration testing checks whether your monitoring and defences actually detect an intrusion, exposing blind spots.
    • CISO as a ServiceCISO as a Service sets the network monitoring and defence strategy, from detection coverage to alerting and response playbooks.
    • Incident ResponseIncident Response acts on what the monitoring surfaces — investigating, containing and recovering when defences flag an attack.
  • .7Implement anti-network intrusion systems like NIPS (Network Intrusion Prevention System) on supported or applicable assets.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus adds continuous outside-in monitoring of your attack surface, an early-warning signal that complements internal network detection.
    • Penetration TestingPenetration testing checks whether your monitoring and defences actually detect an intrusion, exposing blind spots.
    • CISO as a ServiceCISO as a Service assists in the identification of appropriate security technologies like NIPS for the organization's infrastructure. It helps in the development of policies and procedures for implementing and managing these systems, ensuring they align with compliance requirements.
    • Incident ResponseIncident Response acts on what the monitoring surfaces — investigating, containing and recovering when defences flag an attack.
  • .8Implement port-level access control (802.1x or equivalent access control protocols). User and device authentication is recommended.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus adds continuous outside-in monitoring of your attack surface, an early-warning signal that complements internal network detection.
    • Penetration TestingPenetration testing checks whether your monitoring and defences actually detect an intrusion, exposing blind spots.
    • CISO as a ServiceCISO as a Service aids in the implementation of security policies and procedures, including port-level access controls like 802.1x. The service can guide the organization in establishing and maintaining effective user and device authentication protocols, ensuring compliance with access control requirements.
    • Incident ResponseIncident Response acts on what the monitoring surfaces — investigating, containing and recovering when defences flag an attack.
  • .9Manage access control for remotely connected assets. Determine access requirements based on the updated anti-malware solution, configuration compliance with the enterprise’s configuration, and updating operating systems and applications.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus adds continuous outside-in monitoring of your attack surface, an early-warning signal that complements internal network detection.
    • Penetration TestingPenetration testing checks whether your monitoring and defences actually detect an intrusion, exposing blind spots.
    • CISO as a ServiceCISO as a Service can help manage access control for remotely connected assets by developing and enforcing policies that dictate access requirements. This includes ensuring compliance with updated anti-malware solutions, configuration standards, and operating system/application updates. The service provides expert guidance on maintaining secure configurations and access protocols, ensuring compliance with these aspects.
    • Incident ResponseIncident Response acts on what the monitoring surfaces — investigating, containing and recovering when defences flag an attack.
  • .10Filter application layers like proxy filtering, application layer firewall, or gateway.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus adds continuous outside-in monitoring of your attack surface, an early-warning signal that complements internal network detection.
    • Penetration TestingPenetration testing checks whether your monitoring and defences actually detect an intrusion, exposing blind spots.
    • CISO as a ServiceCISO as a Service sets the network monitoring and defence strategy, from detection coverage to alerting and response playbooks.
    • Incident ResponseIncident Response acts on what the monitoring surfaces — investigating, containing and recovering when defences flag an attack.
  • .11Tune security event alerting thresholds on a monthly basis or a higher frequency.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus adds continuous outside-in monitoring of your attack surface, an early-warning signal that complements internal network detection.
    • Penetration TestingPenetration testing checks whether your monitoring and defences actually detect an intrusion, exposing blind spots.
    • CISO as a ServiceCISO as a Service sets the network monitoring and defence strategy, from detection coverage to alerting and response playbooks.
    • Incident ResponseIncident Response acts on what the monitoring surfaces — investigating, containing and recovering when defences flag an attack.
14Security Awareness and Skills TrainingASMPentestCISO-aaS

Your people are a control, not a liability. We build the awareness programme and use real findings from testing to make it concrete.

  • .1Train employees to recognize and report threat incidents.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus surfaces the real exposures an attacker sees, giving awareness training concrete, organisation-specific examples.
    • Penetration TestingPenetration testing findings become vivid, real-world training scenarios that make security awareness tangible.
    • CISO as a ServiceCISO as a Service can develop and implement security awareness training programs tailored to the organization. This service ensures that employees are equipped with the knowledge to recognize and report threat incidents, aligning with compliance requirements.
  • .2Train employees to identify social engineering attacks like phishing, pretexting, and tailgating.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus surfaces the real exposures an attacker sees, giving awareness training concrete, organisation-specific examples.
    • Penetration TestingPenetration testing findings become vivid, real-world training scenarios that make security awareness tangible.
    • CISO as a ServiceCISO as a Service can develop and implement a comprehensive security awareness training program. This includes creating training materials, conducting workshops, and ensuring employees are aware of social engineering tactics. By doing so, it helps the organization meet compliance requirements for employee training.
  • .3Train employees on authentication practices like MFA, credential management, and password composition.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus surfaces the real exposures an attacker sees, giving awareness training concrete, organisation-specific examples.
    • Penetration TestingPenetration testing findings become vivid, real-world training scenarios that make security awareness tangible.
    • CISO as a ServiceCISO as a Service can help ensure compliance with this control by developing and implementing training programs focused on authentication practices. They provide expertise in designing educational materials and sessions that cover multi-factor authentication (MFA), credential management, and password composition, ensuring employees are well-informed about the latest best practices and compliance requirements.
  • .4Train employees to identify, store, transfer, and archive sensitive data including clear screen and desk best practices.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus surfaces the real exposures an attacker sees, giving awareness training concrete, organisation-specific examples.
    • Penetration TestingPenetration testing findings become vivid, real-world training scenarios that make security awareness tangible.
    • CISO as a ServiceCISO as a Service can develop and implement a comprehensive training program for employees, ensuring they understand how to handle sensitive data appropriately. This includes creating policies and procedures for identifying, storing, transferring, and archiving sensitive data, as well as promoting clear screen and desk practices.
  • .5Train employees on accidental data exposure causes.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus surfaces the real exposures an attacker sees, giving awareness training concrete, organisation-specific examples.
    • Penetration TestingPenetration testing findings become vivid, real-world training scenarios that make security awareness tangible.
    • CISO as a ServiceCISO as a Service can help ensure compliance by developing and implementing training programs focused on preventing accidental data exposure. This service provides expert guidance on best practices for data handling and security awareness, ensuring employees are well-informed about potential risks and how to mitigate them.
  • .6Conduct role-based security training and awareness programs.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus surfaces the real exposures an attacker sees, giving awareness training concrete, organisation-specific examples.
    • Penetration TestingPenetration testing findings become vivid, real-world training scenarios that make security awareness tangible.
    • CISO as a ServiceCISO as a Service is instrumental in developing and implementing role-based security training and awareness programs. This service provides expert guidance on tailoring training to specific roles within the organization, ensuring that each employee understands their security responsibilities. CISOaaS can also assist in maintaining compliance by ensuring that training programs are current and align with regulatory requirements.
  • .7Conduct role-based security training and awareness programs.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus surfaces the real exposures an attacker sees, giving awareness training concrete, organisation-specific examples.
    • Penetration TestingPenetration testing findings become vivid, real-world training scenarios that make security awareness tangible.
    • CISO as a ServiceCISO as a Service can design and implement role-based security training and awareness programs tailored to the organization's needs. This service provides expertise in developing training materials and strategies that align with the company's security policies and compliance requirements.
  • .8Train employees to understand the security consequences of connecting to and transmitting data over insecure networks. Remote workers should securely configure their home network infrastructure.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus surfaces the real exposures an attacker sees, giving awareness training concrete, organisation-specific examples.
    • Penetration TestingPenetration testing findings become vivid, real-world training scenarios that make security awareness tangible.
    • CISO as a ServiceCISO as a Service can develop and implement security awareness training programs tailored for employees, including remote workers. This service can guide the creation of training content that emphasizes the risks associated with insecure networks and the importance of secure configuration of home network infrastructure. Additionally, CISO as a Service can ensure that security policies and procedures are updated to reflect best practices for remote work security.
  • .9Conduct role-based security training and awareness programs.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus surfaces the real exposures an attacker sees, giving awareness training concrete, organisation-specific examples.
    • Penetration TestingPenetration testing findings become vivid, real-world training scenarios that make security awareness tangible.
    • CISO as a ServiceCISO as a Service can play a crucial role in developing and implementing role-based security training and awareness programs. This service provides expert guidance on identifying the security training needs of different roles within the organization and helps design tailored programs to address those needs, ensuring compliance with security awareness requirements.
15Service Provider ManagementASMCISO-aaS

Your suppliers' weaknesses become yours. We set supplier security requirements and monitor third-party exposure that could reach you.

  • .1Establish and maintain an inventory of service providers listing all vendors, their classification, and a designated contact.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus extends monitoring to supplier-facing and third-party assets, flagging supplier exposures that could reach you.
    • CISO as a ServiceCISO as a Service can assist in developing and maintaining a comprehensive inventory of service providers. This includes creating policies and procedures for vendor classification and management, ensuring that the organization has a structured approach to tracking all vendors and their designated contacts. This service helps in aligning with compliance requirements by providing expertise in vendor management and documentation.
  • .2Establish and maintain a service provider management policy that addresses classification, inventory, assessment, monitoring, and decommissioning on each vendor.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus extends monitoring to supplier-facing and third-party assets, flagging supplier exposures that could reach you.
    • CISO as a ServiceCISO as a Service can assist in developing and maintaining a comprehensive service provider management policy. This includes creating classification criteria for vendors, maintaining an inventory of service providers, conducting assessments, and setting up continuous monitoring mechanisms. The service can also help establish decommissioning procedures, ensuring compliance with regulatory requirements and best practices.
  • .3Classify service providers based on data sensitivity, data volume, data availability, regulations, inherent risk, and mitigated risk.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus extends monitoring to supplier-facing and third-party assets, flagging supplier exposures that could reach you.
    • CISO as a ServiceCISO as a Service provides expertise in developing a framework for classifying service providers. This includes assessing data sensitivity, volume, and availability, as well as understanding regulatory requirements and evaluating both inherent and mitigated risks. This service ensures that the classification process is thorough, consistent, and aligned with compliance requirements.
  • .4Ensure service providers' contracts include security clauses like breach notification, data encryption, data disposal, and others based on the security policy.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus extends monitoring to supplier-facing and third-party assets, flagging supplier exposures that could reach you.
    • CISO as a ServiceCISO as a Service is instrumental in ensuring compliance with this control by helping to draft, review, and implement security clauses in service provider contracts. The CISO can ensure these contracts align with the organization's security policies and compliance requirements, such as breach notification, data encryption, and data disposal. This service provides expert guidance on best practices and regulatory requirements, ensuring the organization mitigates risks associated with third-party providers.
  • .5Assess service providers based on your management policy to address compliance reports like SOC 2, AoC (Attestation of Compliance) of PCI DSS, custom questionnaires, and others.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM aids in assessing service providers by identifying potential risks and vulnerabilities in their external-facing assets. While EASM does not directly handle compliance reports, it provides valuable insights into the security posture of service providers, which can inform compliance assessments.
    • CISO as a ServiceCISO as a Service is highly applicable as it can help establish a management policy for assessing service providers. This service can guide the organization in evaluating compliance reports like SOC 2, AoC of PCI DSS, and custom questionnaires, ensuring that service providers meet the necessary compliance requirements.
  • .6Monitor service providers based on your management policy to address vendor compliance, vendor release notes, and dark web monitoring.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM can monitor third-party service providers by identifying potential vulnerabilities and threats related to them. It can help in monitoring release notes for vulnerabilities and ensure that vendor assets connected to the organization are continuously assessed, including any findings that may appear on the dark web.
    • CISO as a ServiceCISO as a Service can help establish and maintain comprehensive vendor management policies, which include procedures for monitoring compliance and reviewing vendor release notes. It ensures that the organization has the necessary governance frameworks to effectively manage vendor relationships and compliance.
  • .7Decommission service providers to address user and service account deactivation, data flow termination, data disposal within providers' systems.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus extends monitoring to supplier-facing and third-party assets, flagging supplier exposures that could reach you.
    • CISO as a ServiceCISO as a Service helps in developing and implementing policies and procedures for the decommissioning of service providers. This includes ensuring that there are documented processes for user and service account deactivation, data flow termination, and secure data disposal within providers' systems, which are crucial for maintaining compliance.
16Application Software SecurityASMPentestCISO-aaS

Applications are where the business logic — and the vulnerabilities — live. We test your apps for exploitable flaws, watch the ones exposed to the internet, and set the secure-development standards.

  • .1Analyze the root cause of vulnerabilities to evaluate underlying code issues.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously discovers and monitors your internet-facing applications and their exposed components.
    • Penetration TestingPenetration testing exercises your applications for exploitable flaws — injection, broken access control, logic abuse and more.
    • CISO as a ServiceCISO as a Service sets the secure-development standards and reviews that build security into the application lifecycle.
  • .2Establish and maintain a process to accept and address software vulnerability reports that details the policies, responsible parties, assignment, intake process, remediation, and remediation testing. Additionally, use a vulnerability tracking system.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously discovers and monitors your internet-facing applications and their exposed components.
    • Penetration TestingPenetration testing exercises your applications for exploitable flaws — injection, broken access control, logic abuse and more.
    • CISO as a ServiceCISO as a Service provides expert guidance in developing and maintaining a comprehensive vulnerability management process, including establishing policies, assigning responsibilities, and creating an efficient intake and remediation process. It also helps in implementing a robust vulnerability tracking system to ensure continuous monitoring and remediation of software vulnerabilities.
  • .3Analyze root cause of vulnerabilities to evaluate underlying code issues.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously discovers and monitors your internet-facing applications and their exposed components.
    • Penetration TestingPenetration testing exercises your applications for exploitable flaws — injection, broken access control, logic abuse and more.
    • CISO as a ServiceCISO as a Service sets the secure-development standards and reviews that build security into the application lifecycle.
  • .4Use industry-grade hardening configuration templates for application infrastructure components like databases, web servers, as well as cloud containers, and PaaS or SaaS components.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously discovers and monitors your internet-facing applications and their exposed components.
    • Penetration TestingPenetration testing exercises your applications for exploitable flaws — injection, broken access control, logic abuse and more.
    • CISO as a ServiceCISO as a Service sets the secure-development standards and reviews that build security into the application lifecycle.
  • .5Separate production environments for production and non-production systems.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously discovers and monitors your internet-facing applications and their exposed components.
    • Penetration TestingPenetration testing exercises your applications for exploitable flaws — injection, broken access control, logic abuse and more.
    • CISO as a ServiceCISO as a Service sets the secure-development standards and reviews that build security into the application lifecycle.
  • .6Create a severity rating system to address vulnerabilities in the order of its discovery.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously discovers and monitors your internet-facing applications and their exposed components.
    • Penetration TestingInternal Penetration Testing provides a structured approach to uncovering vulnerabilities within the internal network. While it doesn't create a severity rating system itself, the findings from these tests can be prioritized and rated based on their severity, helping the organization address vulnerabilities systematically.
    • CISO as a ServiceCISO as a Service sets the secure-development standards and reviews that build security into the application lifecycle.
  • .7Use industry grade hardening configuration templates for application infrastructure components like databases, web servers, as well as cloud containers, and PaaS or SaaS components.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously discovers and monitors your internet-facing applications and their exposed components.
    • Penetration TestingPenetration testing exercises your applications for exploitable flaws — injection, broken access control, logic abuse and more.
    • CISO as a ServiceCISO as a Service sets the secure-development standards and reviews that build security into the application lifecycle.
  • .8Separate the environments for production and non-production systems.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously discovers and monitors your internet-facing applications and their exposed components.
    • Penetration TestingPenetration testing exercises your applications for exploitable flaws — injection, broken access control, logic abuse and more.
    • CISO as a ServiceCISO as a Service sets the secure-development standards and reviews that build security into the application lifecycle.
  • .9Train software developers to write secure code, general security principles, and application security practices.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously discovers and monitors your internet-facing applications and their exposed components.
    • Penetration TestingPenetration testing exercises your applications for exploitable flaws — injection, broken access control, logic abuse and more.
    • CISO as a ServiceCISO as a Service can assist in developing and implementing a training program tailored for software developers, focusing on secure coding practices, general security principles, and application security practices. They can provide expertise and resources to ensure the training aligns with industry standards and compliance requirements.
  • .10Use secure principles to design application architectures like least privilege, validate user operation input, check inputs for errors, and minimize the infrastructure attack surface.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously discovers and monitors your internet-facing applications and their exposed components.
    • Penetration TestingPenetration testing exercises your applications for exploitable flaws — injection, broken access control, logic abuse and more.
    • CISO as a ServiceCISO as a Service helps organizations incorporate secure design principles such as least privilege and input validation into their application architectures. This service provides expert guidance on developing and implementing security policies and procedures, ensuring that applications are designed with security in mind and comply with best practices.
  • .11Use vetted modules or services for application security components like identity management, encryption, logging, and auditing.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously discovers and monitors your internet-facing applications and their exposed components.
    • Penetration TestingPenetration testing exercises your applications for exploitable flaws — injection, broken access control, logic abuse and more.
    • CISO as a ServiceCISO as a Service assists in selecting and implementing vetted modules or services for application security components. The service provides expert guidance on best practices for identity management, encryption, logging, and auditing, ensuring these components meet compliance requirements and industry standards.
  • .12Use static and dynamic tools to analyze the application life cycle and ensure secure coding practices.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously discovers and monitors your internet-facing applications and their exposed components.
    • Penetration TestingPenetration testing exercises your applications for exploitable flaws — injection, broken access control, logic abuse and more.
    • CISO as a ServiceCISO as a Service can help establish secure coding practices by developing and implementing policies and procedures that mandate the use of static and dynamic analysis tools throughout the application life cycle. This service ensures that secure coding standards are integrated into the software development process and that developers are trained to adhere to these standards.
  • .13Conduct application pen testings. Authenticated pen tests are recommended for critical applications to identify business logic vulnerabilities over code scanning and automated testing.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously discovers and monitors your internet-facing applications and their exposed components.
    • Penetration TestingInternal Penetration Testing is crucial for conducting application pen tests, especially authenticated ones for critical applications. This service helps identify vulnerabilities, including business logic flaws, that automated code scanning might miss.
    • CISO as a ServiceCISO as a Service can aid in developing a comprehensive pen testing strategy, ensuring that application security testing is conducted regularly and effectively. It helps in prioritizing critical applications for authenticated testing and aligning with compliance requirements.
  • .14Conduct threat modeling to identify and address application design security flaws.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously discovers and monitors your internet-facing applications and their exposed components.
    • Penetration TestingPenetration testing exercises your applications for exploitable flaws — injection, broken access control, logic abuse and more.
    • CISO as a ServiceCISO as a Service can facilitate threat modeling by leveraging their expertise to guide the organization in identifying and mitigating security flaws in application design. This service can help establish best practices, frameworks, and processes for effective threat modeling, ensuring the organization addresses potential vulnerabilities proactively.
17Incident Response ManagementASMPentestCISO-aaSIR

When something goes wrong, speed matters. We run the incident response and build the plan before you need it — rehearsed against realistic attacks.

  • .1Assign one key role and a backup role to manage incidents. If it is handled by a third party service, an internal person should oversee their work.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus provides early warning of exposures and threats, helping detect the conditions for an incident before it escalates.
    • Penetration TestingInternal Penetration Testing is not directly related to assigning roles for incident management. However, it can help identify vulnerabilities that may lead to incidents, thus indirectly supporting the incident management process.
    • CISO as a ServiceCISO as a Service can assist in defining and assigning key roles and backup roles for incident management. This service ensures that clear responsibilities and oversight structures are in place, and also helps in coordinating with third-party services by providing internal oversight.
    • Incident ResponseIncident Response services are directly relevant, as they can handle incident management. However, it is crucial for an internal person to oversee the third-party service to ensure compliance with the control, aligning with the requirement for internal oversight of third-party incident management activities.
  • .2Create and maintain a contact list of parties who should be informed in case a security incident occurs.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus provides early warning of exposures and threats, helping detect the conditions for an incident before it escalates.
    • Penetration TestingPenetration testing and attack simulation rehearse your response, testing the plan against realistic intrusions.
    • CISO as a ServiceCISO as a Service can assist in creating and maintaining a contact list by providing guidance on who should be included, based on industry best practices and regulatory requirements. This service ensures the contact list is comprehensive and regularly updated, aligning with compliance needs.
    • Incident ResponseIncident Response services can leverage an up-to-date contact list to effectively manage communication during a security incident. They ensure that all relevant parties are informed promptly, facilitating a coordinated response and adherence to compliance protocols.
  • .3Establish and maintain a process for all employees to report security incidents that includes a reporting timeframe, reporting personnel, processes, and information to report.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus provides early warning of exposures and threats, helping detect the conditions for an incident before it escalates.
    • Penetration TestingPenetration testing and attack simulation rehearse your response, testing the plan against realistic intrusions.
    • CISO as a ServiceCISO as a Service can help develop and implement a comprehensive incident reporting process by creating policies and procedures that define the reporting timeframe, the personnel responsible for reporting, and the specific information that needs to be reported. This service ensures that the organization's incident reporting process aligns with compliance requirements and industry best practices.
    • Incident ResponseIncident Response services can support the incident reporting process by providing expertise in identifying the types of incidents that should be reported and advising on the most efficient and effective ways to report them. Additionally, they can help in training personnel on the importance of timely and accurate incident reporting as part of a broader incident response strategy.
  • .4Establish and maintain an incident response policy detailing the roles, accountabilities, compliance requirements and accountability plan.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus provides early warning of exposures and threats, helping detect the conditions for an incident before it escalates.
    • Penetration TestingPenetration testing and attack simulation rehearse your response, testing the plan against realistic intrusions.
    • CISO as a ServiceCISO as a Service is instrumental in developing and maintaining an incident response policy. The service provides expertise in defining roles, responsibilities, and compliance requirements. It helps ensure that the policy is comprehensive and aligned with regulatory standards.
    • Incident ResponseIncident Response services are critical for implementing the incident response policy effectively. They provide practical insights and real-world experience to define roles and responsibilities accurately, ensuring the organization is prepared for potential incidents and can respond in accordance with the policy.
  • .5Assign key roles and responsibilities to respond to incidents from departments like legal, IT, information security, facilities, public relations, human resources, analysts, and others as applicable.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus provides early warning of exposures and threats, helping detect the conditions for an incident before it escalates.
    • Penetration TestingInternal Penetration Testing doesn't directly assign roles and responsibilities for incident response. However, it indirectly supports this by identifying vulnerabilities and risks within the organization, which can guide the preparation of incident response roles by highlighting areas needing attention.
    • CISO as a ServiceCISO as a Service is crucial in establishing a clear incident response framework by defining and assigning roles and responsibilities across various departments. The service provides expert guidance in formulating and documenting incident response plans, ensuring all relevant departments are prepared and aligned with compliance requirements.
    • Incident ResponseIncident Response services are directly aligned with this control as they provide expertise and support in defining key roles and responsibilities for responding to incidents. IR services ensure that all departments understand their roles in the event of a security incident, facilitating a coordinated and effective response.
  • .6Determine the primary and secondary measures to communicate and report security incidents.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus provides early warning of exposures and threats, helping detect the conditions for an incident before it escalates.
    • Penetration TestingInternal Penetration Testing can indirectly support this control by identifying weaknesses in internal communication channels that may affect the reporting of security incidents. By understanding these vulnerabilities, the organization can ensure that their incident communication measures are secure and reliable.
    • CISO as a ServiceCISO as a Service is instrumental in establishing and defining the primary and secondary measures for communicating and reporting security incidents. This service provides expert guidance in developing incident response plans, including communication protocols, ensuring that all relevant parties are informed and that the organization remains compliant with regulations.
    • Incident ResponseIncident Response services are directly relevant to this control as they provide the expertise and resources to effectively communicate and report security incidents. These services help in establishing clear communication channels and procedures to ensure timely and accurate reporting of incidents to stakeholders, which is essential for compliance.
  • .7Conduct incident response exercises based on real scenarios to prepare key roles to process and respond to incidents.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus provides early warning of exposures and threats, helping detect the conditions for an incident before it escalates.
    • Penetration TestingInternal Penetration Testing can contribute to incident response exercises by identifying potential vulnerabilities and attack vectors within the internal network. This information can be used to create realistic scenarios for the exercises, thereby improving the organization's readiness to respond to incidents.
    • CISO as a ServiceCISO as a Service can help design and facilitate incident response exercises by developing appropriate policies, procedures, and scenarios based on real-world threats. This service ensures that key roles are prepared to process and respond to incidents effectively, aligning with compliance requirements.
    • Incident ResponseIncident Response services are directly applicable as they can lead and conduct incident response exercises, providing expertise and guidance. These exercises can simulate real scenarios to test and enhance the organization's response capabilities, ensuring preparedness for actual incidents.
  • .8Conduct post incident reviews to avoid repeat occurrences.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus provides early warning of exposures and threats, helping detect the conditions for an incident before it escalates.
    • Penetration TestingInternal Penetration Testing can support post-incident reviews by identifying vulnerabilities that may have contributed to the incident. The insights gained from testing can be used to strengthen defenses and prevent repeat occurrences.
    • CISO as a ServiceCISO as a Service can help in conducting thorough post-incident reviews by providing expert guidance on analyzing incidents, identifying root causes, and developing strategies to prevent recurrence. This service ensures that lessons learned are documented and integrated into the organization's security policies and procedures.
    • Incident ResponseIncident Response services are crucial for conducting post-incident reviews. They can provide detailed analysis and reporting on the incident, including how it occurred and what can be done to prevent similar incidents in the future. Their expertise is vital for understanding the incident's impact and for developing corrective actions.
  • .9Establish and maintain incident thresholds to differentiate between incidents and events.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus provides early warning of exposures and threats, helping detect the conditions for an incident before it escalates.
    • Penetration TestingInternal Penetration Testing can indirectly contribute to defining incident thresholds by uncovering vulnerabilities and providing insight into potential impacts. This helps in understanding what constitutes a significant security event or incident within the organization's internal environment.
    • CISO as a ServiceCISO as a Service is crucial for establishing and maintaining incident thresholds. It provides expert guidance in developing comprehensive incident management policies and procedures, including the differentiation between incidents and events. This service ensures that thresholds align with the organization's risk management strategies and compliance requirements.
    • Incident ResponseIncident Response services play a direct role in defining and utilizing incident thresholds. They provide expertise in identifying and categorizing incidents and events, ensuring that the organization can effectively differentiate between them and respond appropriately. This ensures that incident thresholds are practical and operationally effective.
18Penetration TestingASMPentestCISO-aaS

This one's literally us. We run the penetration tests — external and internal — that prove where your defences actually break, and help you act on the results.

  • .1Establish and maintain a pen testing program based on the enterprise’s size, complexity, and maturity. Address scope, limitations, retrospective requirements, and remediation.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM provides continuous monitoring and external penetration testing capabilities to identify and manage vulnerabilities on the external attack surface. This ensures that potential external threats are preemptively identified and mitigated, which is a critical component of a comprehensive penetration testing strategy.
    • Penetration TestingInternal Penetration Testing is directly applicable as it involves testing the organization's internal network for vulnerabilities and risks. This service helps ensure compliance by identifying and mitigating internal security threats, which is a fundamental aspect of penetration testing requirements.
    • CISO as a ServiceCISO as a Service supports penetration testing compliance by developing and maintaining security policies and procedures that include regular testing schedules, scope definitions, and remediation strategies. This service ensures that penetration testing is integrated into the organization's overall security posture and compliance framework.
  • .2Conduct external pen tests – clear box or opaque box at least once annually. Include enterprise and environmental reconnaissance in the pen test.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementEASM complements the requirement for external penetration tests by continuously monitoring and assessing the external attack surface. It identifies new vulnerabilities and assets as they appear, providing ongoing reconnaissance and helping to ensure that annual penetration tests are comprehensive and up-to-date.
    • Penetration TestingInternal Penetration Testing is not directly applicable to external penetration test requirements, but it can provide additional insights into the organization's security posture by uncovering internal vulnerabilities that may also be exploitable by external threats.
    • CISO as a ServiceCISO as a Service scopes the testing programme and turns findings into a prioritised remediation plan.
  • .3Remediate the vulnerabilities identified in the pen test based on enterprise scope and prioritization.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously maps the external attack surface that penetration testing then probes in depth.
    • Penetration TestingPenetration testing is the control itself: expert external and internal testing that proves where defences actually break.
    • CISO as a ServiceCISO as a Service can help ensure compliance by developing a structured vulnerability remediation process. This includes prioritizing vulnerabilities based on risk and enterprise scope, ensuring that identified vulnerabilities from pen tests are effectively addressed and resolved according to compliance requirements.
  • .4Validate secure measures after a pen test and make the necessary modifications and in configurations and detection capabilities.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously maps the external attack surface that penetration testing then probes in depth.
    • Penetration TestingInternal Penetration Testing is directly relevant to this control. It helps validate that the secure measures implemented are effective by simulating attacks on the internal network. After the test, it provides insights into necessary modifications in configurations and detection capabilities to enhance security.
    • CISO as a ServiceCISO as a Service can provide guidance on how to interpret penetration testing results and ensure that the necessary modifications in configurations and detection capabilities align with compliance and security standards. However, the actual validation is not performed by this service.
  • .5Conduct internal pen tests: clear box or opaque box at least once annually, based on requirements.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus continuously maps the external attack surface that penetration testing then probes in depth.
    • Penetration TestingInternal Penetration Testing directly addresses this control by providing the required clear box or opaque box tests at least annually. This service helps identify vulnerabilities and risks within the organization's internal network, ensuring compliance with the requirement for regular internal testing.
    • CISO as a ServiceCISO as a Service can provide guidance and ensure that the organization includes internal penetration testing in its security policy and compliance framework, but it does not conduct the tests itself.

Governance

NSM Grunnprinsipper

NSM Grunnprinsipper is a set of fundamental cybersecurity principles developed by the Norwegian National Security Authority (NSM). Which is why they are only provided in Norwegian. It provides practical guidance for protecting information systems, focusing on key areas like risk management, access control, incident handling, and secure configuration. These principles are designed to help organizations improve their cybersecurity posture and meet regulatory requirements. The framework aligns with international standards like ISO 27001 and regional regulations such as NIS2, offering a structured approach to implementing robust security measures across different sectors.

95 of 138 controls directly addressed by a River Security service, plus 43 supported partially.

Service coverage

Penetration Testing
3%4 +134~/138
CISO as a Service
60%83 +55~/138
Incident Response
11%15 +107~/138

Strengths

  • Practical Guidance: Offers clear, actionable principles for improving cybersecurity.
  • Risk Management Focus: Emphasizes risk management as a core element, enhancing resilience.
  • Regulatory Alignment: Helps organizations meet local and international compliance standards, such as NIS2 and ISO 27001.
  • Adaptability: Can be applied across various sectors and organization sizes.
  • Structured Approach: Provides a well-organized framework for implementing security measures.

Trade-offs

  • Generalization: May not address highly specialized security needs for certain industries.
  • Implementation Effort: Applying all principles can require significant resources and time.
  • Limited Global Recognition: While effective in Norway, it may not be as widely recognized internationally as other frameworks.
  • Baseline Assumptions: Assumes a certain level of existing cybersecurity maturity, which may not suit all organizations.
Controls & how we help
DirectPartialNot mapped
1Identifisere og kartleggeASMPentestCISO-aaS

Du kan ikke sikre det du ikke vet at du har. Active Focus kartlegger kontinuerlig alt dere eksponerer mot internett, slik at oversikten gjenspeiler virkeligheten – ikke et regneark fra i fjor.

  • .1Kartlegg styringsstrukturer, leveranser og understøttende systemer
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus oppdager og overvåker kontinuerlig virksomhetens internettvendte verdier, slik at kartleggingen alltid er oppdatert.
    • Penetration TestingPenetrasjonstesting avdekker ukjente eller glemte verdier underveis i et oppdrag, og bidrar dermed indirekte til en mer komplett oversikt.
    • CISO as a ServiceCISO as a Service etablerer policy, eierskap og prosesser for verdikartlegging, slik at oversikten holdes korrekt og autorisert.
  • .1.1Identifiser virksomhetens strategi og prioriterte mål
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus oppdager og overvåker kontinuerlig virksomhetens internettvendte verdier, slik at kartleggingen alltid er oppdatert.
    • Penetration TestingPenetrasjonstesting avdekker ukjente eller glemte verdier underveis i et oppdrag, og bidrar dermed indirekte til en mer komplett oversikt.
    • CISO as a ServiceCISO as a Service etablerer policy, eierskap og prosesser for verdikartlegging, slik at oversikten holdes korrekt og autorisert.
  • .1.2Identifiser virksomhetens strukturer og prosesser for sikkerhetsstyring.
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus oppdager og overvåker kontinuerlig virksomhetens internettvendte verdier, slik at kartleggingen alltid er oppdatert.
    • Penetration TestingPenetrasjonstesting avdekker ukjente eller glemte verdier underveis i et oppdrag, og bidrar dermed indirekte til en mer komplett oversikt.
    • CISO as a ServiceCISO as a Service etablerer policy, eierskap og prosesser for verdikartlegging, slik at oversikten holdes korrekt og autorisert.
  • .1.3Identifiser virksomhetens prosesser for risikostyring knyttet til IKT
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus oppdager og overvåker kontinuerlig virksomhetens internettvendte verdier, slik at kartleggingen alltid er oppdatert.
    • Penetration TestingPenetrasjonstesting avdekker ukjente eller glemte verdier underveis i et oppdrag, og bidrar dermed indirekte til en mer komplett oversikt.
    • CISO as a ServiceCISO as a Service etablerer policy, eierskap og prosesser for verdikartlegging, slik at oversikten holdes korrekt og autorisert.
  • .1.4Identifiser virksomhetens toleransegrenser for risiko knyttet til IKT
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus oppdager og overvåker kontinuerlig virksomhetens internettvendte verdier, slik at kartleggingen alltid er oppdatert.
    • Penetration TestingPenetrasjonstesting avdekker ukjente eller glemte verdier underveis i et oppdrag, og bidrar dermed indirekte til en mer komplett oversikt.
    • CISO as a ServiceCISO as a Service etablerer policy, eierskap og prosesser for verdikartlegging, slik at oversikten holdes korrekt og autorisert.
  • .1.5Kartlegg virksomhetens leveranser, informasjonssystemer og understøttende IKT-funksjoner
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus oppdager og overvåker kontinuerlig virksomhetens internettvendte verdier, slik at kartleggingen alltid er oppdatert.
    • Penetration TestingPenetrasjonstesting avdekker ukjente eller glemte verdier underveis i et oppdrag, og bidrar dermed indirekte til en mer komplett oversikt.
    • CISO as a ServiceCISO as a Service etablerer policy, eierskap og prosesser for verdikartlegging, slik at oversikten holdes korrekt og autorisert.
  • .1.6Kartlegg informasjonsbehandling og dataflyt i virksomheten
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus oppdager og overvåker kontinuerlig virksomhetens internettvendte verdier, slik at kartleggingen alltid er oppdatert.
    • Penetration TestingPenetrasjonstesting avdekker ukjente eller glemte verdier underveis i et oppdrag, og bidrar dermed indirekte til en mer komplett oversikt.
    • CISO as a ServiceCISO as a Service etablerer policy, eierskap og prosesser for verdikartlegging, slik at oversikten holdes korrekt og autorisert.
  • .2Kartlegg enheter og programvare
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus oppdager og overvåker kontinuerlig virksomhetens internettvendte verdier, slik at kartleggingen alltid er oppdatert.
    • Penetration TestingPenetrasjonstesting avdekker ukjente eller glemte verdier underveis i et oppdrag, og bidrar dermed indirekte til en mer komplett oversikt.
    • CISO as a ServiceCISO as a Service etablerer policy, eierskap og prosesser for verdikartlegging, slik at oversikten holdes korrekt og autorisert.
  • .2.1Etabler en prosess for å kartlegge enheter og programvare som er i bruk i virksomheten
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus oppdager og overvåker kontinuerlig virksomhetens internettvendte verdier, slik at kartleggingen alltid er oppdatert.
    • Penetration TestingPenetrasjonstesting avdekker ukjente eller glemte verdier underveis i et oppdrag, og bidrar dermed indirekte til en mer komplett oversikt.
    • CISO as a ServiceCISO as a Service etablerer policy, eierskap og prosesser for verdikartlegging, slik at oversikten holdes korrekt og autorisert.
  • .2.2Fastsett retningslinjer for godkjente enheter og programvare i virksomheten
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus oppdager og overvåker kontinuerlig virksomhetens internettvendte verdier, slik at kartleggingen alltid er oppdatert.
    • Penetration TestingPenetrasjonstesting avdekker ukjente eller glemte verdier underveis i et oppdrag, og bidrar dermed indirekte til en mer komplett oversikt.
    • CISO as a ServiceCISO as a Service etablerer policy, eierskap og prosesser for verdikartlegging, slik at oversikten holdes korrekt og autorisert.
  • .2.3Kartlegg enheter i bruk i virksomheten
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus oppdager og overvåker kontinuerlig virksomhetens internettvendte verdier, slik at kartleggingen alltid er oppdatert.
    • Penetration TestingPenetrasjonstesting avdekker ukjente eller glemte verdier underveis i et oppdrag, og bidrar dermed indirekte til en mer komplett oversikt.
    • CISO as a ServiceCISO as a Service etablerer policy, eierskap og prosesser for verdikartlegging, slik at oversikten holdes korrekt og autorisert.
  • .2.4Kartlegg programvare i bruk i virksomheten
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus oppdager og overvåker kontinuerlig virksomhetens internettvendte verdier, slik at kartleggingen alltid er oppdatert.
    • Penetration TestingPenetrasjonstesting avdekker ukjente eller glemte verdier underveis i et oppdrag, og bidrar dermed indirekte til en mer komplett oversikt.
    • CISO as a ServiceCISO as a Service etablerer policy, eierskap og prosesser for verdikartlegging, slik at oversikten holdes korrekt og autorisert.
  • .3Kartlegg brukere og behov for tilgang
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus oppdager og overvåker kontinuerlig virksomhetens internettvendte verdier, slik at kartleggingen alltid er oppdatert.
    • Penetration TestingPenetrasjonstesting avdekker ukjente eller glemte verdier underveis i et oppdrag, og bidrar dermed indirekte til en mer komplett oversikt.
    • CISO as a ServiceCISO as a Service etablerer policy, eierskap og prosesser for verdikartlegging, slik at oversikten holdes korrekt og autorisert.
  • .3.1Kartlegg brukere i informasjonssystemene
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus oppdager og overvåker kontinuerlig virksomhetens internettvendte verdier, slik at kartleggingen alltid er oppdatert.
    • Penetration TestingPenetrasjonstesting avdekker ukjente eller glemte verdier underveis i et oppdrag, og bidrar dermed indirekte til en mer komplett oversikt.
    • CISO as a ServiceCISO as a Service etablerer policy, eierskap og prosesser for verdikartlegging, slik at oversikten holdes korrekt og autorisert.
  • .3.2Kartlegg og definer de ulike brukerkategoriene
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus oppdager og overvåker kontinuerlig virksomhetens internettvendte verdier, slik at kartleggingen alltid er oppdatert.
    • Penetration TestingPenetrasjonstesting avdekker ukjente eller glemte verdier underveis i et oppdrag, og bidrar dermed indirekte til en mer komplett oversikt.
    • CISO as a ServiceCISO as a Service etablerer policy, eierskap og prosesser for verdikartlegging, slik at oversikten holdes korrekt og autorisert.
  • .3.3Kartlegg ansvar og roller spesielt knyttet til IKT-sikkerhet
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus oppdager og overvåker kontinuerlig virksomhetens internettvendte verdier, slik at kartleggingen alltid er oppdatert.
    • Penetration TestingPenetrasjonstesting avdekker ukjente eller glemte verdier underveis i et oppdrag, og bidrar dermed indirekte til en mer komplett oversikt.
    • CISO as a ServiceCISO as a Service etablerer policy, eierskap og prosesser for verdikartlegging, slik at oversikten holdes korrekt og autorisert.
2Beskytte og opprettholdeASMPentestCISO-aaSIR

Beskyttelse må vedlikeholdes, ikke bare etableres. Vi setter sikkerhetskravene og herdingsstandardene, overvåker angrepsflaten kontinuerlig, og tester at beskyttelsen faktisk holder over tid.

  • .1Ivareta sikkerhet i anskaffelses- og utviklingsprosesser
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .1.1Integrer sikkerhet i virksomhetens prosess for anskaffelser
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .1.2Kjøp moderne og oppdatert maskin- og programvare
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .1.3Foretrekk IKT-produkter som er sertifiserte og evaluert av en tiltrodd tredjepart
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .1.4Reduser risiko for målrettet manipulasjon av IKT-produkter i leverandørkjeden
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .1.5Benytt en metode for sikker utvikling av programvare
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .1.6Benytt separate miljøer for utvikling, test og produksjon
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .1.7Gjennomfør tilstrekkelig med testing gjennom hele utviklingsprosessen
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .1.8Vedlikehold programvarekode som utvikles/benyttes i virksomheten
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .1.9Ta ansvar for virksomhetens sikkerhet også ved tjenesteutsetting
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .1.10Undersøk sikkerheten hos tjenesteleverandør ved tjenesteutsetting
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .2Etabler en sikker IKT-arkitektur
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .2.1Etabler og vedlikehold en helhetlig sikkerhetsarkitektur
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .2.2Bygg IKT-systemet med IKT-produkter som fungerer godt sammen sikkerhetsmessig
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .2.3Del opp virksomhetens nettverk etter virksomhetens risikoprofil
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .2.4Skill fysisk de mest kritiske del-nettverkene
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .2.5Del opp domenearkitekturen iht. virksomhetens behov
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .2.6Reguler tilgang til tjenester basert på kjennskap til både brukere og enhet
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .2.7Etabler en robust og motstandsdyktig IKT-arkitektur
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .3Ivareta en sikker konfigurasjon
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .3.1Etabler et sentralt styrt regime for sikkerhetsoppdatering
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .3.2Konfigurer klienter slik at kun kjent programvare kjører på dem
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .3.3Deaktiver unødvendig funksjonalitet
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .3.4Etabler og vedlikehold standard sikkerhetskonfigurasjoner
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .3.5Verifiser at aktivert sikkerhetskonfigurasjon er i henhold til virksomhetens godkjente sikkerhetskonfigurasjon
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .3.6Utfør all konfigurasjon, installasjon, og drift for øvrig på en trygg måte
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .3.7Endre alle standardpassord på IKT-produktene før produksjonssetting
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .3.8Ikke deaktiver kodebeskyttelsesfunksjoner
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .3.9Etabler sikker tid i virksomheten
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .3.10Reduser risiko med IoT-enheter
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .4Beskytt virksomhetens nettverk
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .4.1Etabler tilgangskontroll på flest mulige nettverksporter
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .4.2Krypter alle trådløse og kablede forbindelser
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .4.3Kartlegg fysisk tilgjengelighet for svitsjer og kabler
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .4.4Aktiver brannmur på alle klienter og servere
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .5Kontroller dataflyt
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .5.1Styr dataflyt mellom nettverks-soner
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .5.2Begrens tilgangen til interne tjenester fra eksterne lokasjoner
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .5.3Sperr all direkte-trafikk mellom klienter
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .5.4Isoler utstyr som er sårbart og har lav tillitt
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .5.5Styr dataflyten til spesielt eksponerte tjenester
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .5.6Beskytt spesielt kritiske tjenester med egen dataflyt
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .5.7Ha kontroll på trafikk mellom virksomheten og samarbeidspartnere/ tjenesteleverandører
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .5.8Styr all trafikk (ikke bare interne tjenester) til og fra forvaltede mobile klienter via virksomhetens nett
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .6Ha kontroll på identiteter og tilganger
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .6.1Etabler retningslinjer for tilgangskontroll
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .6.2Etabler en formell prosess for administrasjon av kontoer, tilganger og rettigheter
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .6.3Benytt et sentralisert og automatiserbart verktøy for å styre kontoer, tilganger og rettigheter
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .6.4Minimer rettigheter til sluttbrukere og spesialbrukere
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .6.5Minimer rettigheter på drifts-kontoer
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .6.6Styr tilganger til enheter
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .7Beskytt data i ro og i transitt
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .7.1Etabler en strategi for håndtering av kryptografi i virksomheten
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .7.2Aktiver kryptering i de tjenestene som tilbyr slik funksjonalitet
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .7.3Krypter lagringsmedier som holder konfidensiell data og som lett kan mistes eller kompromitteres
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .7.4Benytt kryptering når konfidensiell informasjon overføres eller når tilliten til informasjonskanalen er lav
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .7.5Definer krav til sikringsnivå for ulike typer informasjon
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .8Beskytt e-post og nettleser
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .8.1Verifiser at innkommende e-post er fra en legitim avsender-adresse
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .8.2Aktiver STARTTLS på virksomhetens e-postserver
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .8.3Bruk kun støttede e-postklienter, nettlesere og programtillegg
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .8.4Tillat kun virksomhetsgodkjente programtillegg
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .9Etabler evne til gjenoppretting av data
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .9.1Legg en plan for regelmessig sikkerhetskopiering av alle virksomhetsdata
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .9.2Inkluder sikkerhetskopier av programvare
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .9.3Test sikkerhetskopier regelmessig
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .9.4Beskytt sikkerhetskopier mot tilsiktet og utilsiktet sletting, manipulering og avlesning
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .10Integrer sikkerhet i prosess for endringshåndtering
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .10.1Integrer sikkerhet i virksomhetens prosess for endringshåndtering
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .10.2Involver nødvendig IKT-sikkerhetspersonell i forbindelse med endringer
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .10.3Gjennomfør nødvendig endring, konfigurering og testing av påvirkede sikkerhetsfunksjoner
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
  • .10.4Integrer sikkerhet i virksomhetens prosess for hasteendringer
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus overvåker angrepsflaten kontinuerlig og fanger opp svak konfigurasjon, eksponerte tjenester og endringer som svekker beskyttelsen.
    • Penetration TestingPenetrasjonstesting verifiserer at beskyttelsestiltakene faktisk holder, ved å prøve å utnytte dem slik en angriper ville gjort.
    • CISO as a ServiceCISO as a Service setter sikkerhetskrav, herdingsstandarder og rutiner for å etablere og vedlikeholde beskyttelsen.
    • Incident ResponseIncident Response bidrar til å opprettholde beredskapen, slik at virksomheten er klar til å håndtere hendelser når beskyttelsen svikter.
3OppdageASMPentestCISO-aaSIR

Angripere regner med å ikke bli oppdaget. Vi overvåker angrepsflaten deres utenfra, tester om innbrudd faktisk blir oppdaget, og setter strategien for deteksjon.

  • .1Oppdag og fjern kjente sårbarheter og trusler
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .1.1Gjennomfør jevnlig sårbarhetskartlegging
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .1.2Abonner på tjenester relatert til sårbarhetsetterretning
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .1.3Benytt automatisert og sentralisert verktøy for å håndtere kjente trusler (som skadevare)
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .2Etabler sikkerhetsovervåkning
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .2.1Fastsett virksomhetens strategi og retningslinjer for sikkerhetsovervåkning
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .2.2Følg lover, reguleringer og virksomhetens retningslinjer for sikkerhetsovervåkning
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .2.3Avgjør hvilke deler av IKT-systemet som skal overvåkes
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .2.4Beslutt hvilke data som er sikkerhetsrelevant og bør samles inn
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .2.5Verifiser at innsamling fungerer etter hensikt
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .2.6Påse at innsamlet data ikke kan manipuleres
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .2.7Gjennomgå og konfigurer innhenting av sikkerhetsrelevant data og den sentrale loggdatabasen jevnlig
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .3Analyser data fra sikkerhetsovervåkning
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .3.1Lage en plan for analyse av data fra sikkerhetsovervåkning
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .3.2Etabler og vedlikehold kompetanse om normaltilstanden i virksomhetens informasjonssystemer
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .3.3Ta i bruk verktøy som muliggjør manuelle og automatiske søk, samt alarmering basert på kriterier
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .3.4Innhent og bearbeid trusselinformasjon fra relevante kilder
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .3.5Vurder fortløpende om innhentet data er tilstrekkelig relevant og detaljert
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .3.6Etabler rutine for eskalering av alarmer
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .3.7Benytt analyseverktøy, teknologi og algoritmer
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .4Gjennomfør inntrengningstester
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .4.1Planlegg inntrengingstester med tydelig mål og omfang
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .4.2Involver relevante interesseparter i forkant
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .4.3Benytt verktøy for sårbarhetskartlegging og angrepsverktøy
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .4.4Gjennomfør jevnlige inntrengingstester (minst årlige) for å identifisere sårbarheter
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .4.5Test rutiner for deteksjon og beredskap
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
  • .4.6Kommuniser resultater fra inntrengingstester til relevante interesseparter
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir kontinuerlig overvåking av angrepsflaten utenfra – en tidlig varsling som utfyller intern deteksjon.
    • Penetration TestingPenetrasjonstesting sjekker om angrep faktisk blir oppdaget, og avdekker blindsoner i overvåking og deteksjon.
    • CISO as a ServiceCISO as a Service setter strategien for deteksjon – fra dekningsgrad og logging til varsling og oppfølging.
    • Incident ResponseIncident Response følger opp det deteksjonen avdekker, og undersøker og håndterer når noe blir oppdaget.
4Håndtere og gjenoppretteASMPentestCISO-aaSIR

Når noe går galt, teller tempo. Vi håndterer hendelsen – begrenser, fjerner og gjenoppretter – og hjelper dere å bygge og øve planen før dere trenger den.

  • .1Forbered virksomheten på håndtering av hendelser
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .1.1Etabler et planverk for hendelseshåndtering
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .1.2Gjennomfør en analyse av virksomhetskritiske effekter
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .1.3Utarbeid rolle- og ansvarsbeskrivelse for personell som skal involveres i hendelseshåndtering
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .1.4Utarbeid avtaler med relevante tredjeparter
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .1.5Fastsett hvilke kommunikasjonskanaler som skal benyttes i forbindelse med hendelser
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .1.6Test og øv på planer jevnlig slik at disse er godt innøvd
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .2Vurder og klassifiser hendelser
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .2.1Gjennomgå loggdata og samle relevante data om hendelsen for å oppnå et godt beslutningsgrunnlag
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .2.2Avgjør alvorlighetsgrad for hendelsen
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .2.3Informer relevante interesseparter
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .3Kontroller og håndter hendelser
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .3.1Kartlegg omfang og påvirkning på forretningsprosesser
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .3.2Undersøk om hendelsen er under kontroll og gjennomfør nødvendige reaktive tiltak
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .3.3Loggfør alle aktiviteter, resultater og relevante avgjørelser
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .3.4Iverksett gjenopprettingsplan i løpet av, eller i etterkant av hendelsen
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .3.5Koordiner og kommuniser med interne og eksterne interessenter underveis i hendelseshåndteringen
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .3.6Gjennomfør nødvendige aktiviteter i etterkant av hendelsen
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .4Evaluer og lær av hendelser
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .4.1Identifiser erfaringer og læringspunkter («lessons learned») fra hendelser
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .4.2Kartlegg og gjennomgå identifiserte, kompromitterte sikkerhetstiltak
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .4.3Vurdere effektiviteten av prosesser, prosedyrer, rapporteringsformater og organisatoriske strukturer med tanke på å respondere på hendelser
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.
  • .4.4Kommuniser og del erfaringsresultatene med (relevante) interessenter
    ASMPentestCISO-aaSIR
    Why & how we help
    • Attack Surface ManagementActive Focus gir tidlig varsling om eksponeringer og trusler, slik at forholdene for en hendelse kan fanges opp før den eskalerer.
    • Penetration TestingPenetrasjonstesting og angrepssimulering øver håndteringen og tester planen mot realistiske innbrudd.
    • CISO as a ServiceCISO as a Service bygger og vedlikeholder beredskapsplanen, roller og rutiner for hendelseshåndtering.
    • Incident ResponseIncident Response leverer den praktiske håndteringen – begrensning, fjerning, gjenoppretting og læring – når en hendelse inntreffer.

Not sure which framework applies to you?

We help organizations translate compliance obligations into a concrete, testable security program. Let's map your requirements together.

Schedule a meeting