In 2010, the Australian Defence Signals Directorate (DSD) published a list of strategies to mitigate ‘targeted cyber intrusions’ based on its own operational IT security experience in defence and other government agencies.
The 2011 update – which won the SANS Institute’s 2011 U.S. National Cybersecurity Innovation Award - stressed that all Australian organisations (not just government) holding valuable information are targets, but they may not detect successful intrusions for some time after the attack.
This Mapping Guide summarises the main points from the 2011 update including that:
• Users have become attack vectors (executives, PAs and system administrators);
• Social engineering techniques are used to gather intelligence for the attack:
• The principal bait is a spear phishing email, apparently from a trusted source;
• The malware is planted in attachmentsor in embedded links to malicious websites.
and shows how Huntsman SIEM technology maps to the main strategies.
Key terms and concepts addressed in this mapping guide:
• IT security risk, IT security monitoring; threat mitigation;
• Event logging; log management, forensic replays, compliance monitoring;
• Data breach, policy breach, fraud, misuse, access controls, authentication;
• Real-time event monitoring, alerting & incident management, analysis, reporting;
• IT risk management, Security Information and Event Management;
Take the next step
Read our Short Whites
Browse all Resources
Contact Us
INDUSTRY INSIGHTS
“…now Huntsman analyses the priority and impact of the events as they occur, automatically. It then alerts our teams so they can focus on reducing the risks rather than ploughing through the trial and error process of problem solving.”
Chief Information Security Officer, International Communications Carrier
