Learning Objective 2.1.A: Identify social engineering attacks.
- 2.1.A.1 Social engineers use psychological tactics to manipulate targets into taking a desired action.
- 2.1.A.2 Pretexting is when adversaries create a believable reason to contact a target.
- 2.1.A.3 Authority is when adversaries impersonate someone with power over a target or pretend to relay instructions from that person.
- 2.1.A.4 Intimidation is when adversaries state negative consequences if demands aren’t met.
- 2.1.A.5 Consensus is when adversaries create social pressure by making a target believe everyone else is doing a desired action.
- 2.1.A.6 Scarcity is when adversaries create a sense of limited availability.
- 2.1.A.7 Familiarity is when adversaries pretend to be or know someone close to a target to establish trust.
- 2.1.A.8 Urgency is when adversaries create a deadline that requires quick action by a target to avert negative consequences.
Learning Objective 2.1.B: Identify types of adversaries.
- 2.1.B.1 Script kiddies are low-skilled adversaries who use tools developed by others without understanding how the tools work. They are often motivated by greed or a desire for recognition.
- 2.1.B.2 Hacktivists are motivated by social, political, or personal causes. They compromise computers and networks to support their cause or stop perceived harm, believing their goals justify their illegal methods.
- 2.1.B.3 Insider adversaries are unique threats because they have legitimate credentials and access to systems and data. They can be recruited by malicious third parties and can be motivated by greed or revenge.
- 2.1.B.4 Cyberterrorists are motivated by politics or beliefs and seek to disrupt entire communities, regions, or nations through cyberattacks (e.g., attacking a power grid, water treatment plant, or other civil infrastructure). They can act independently or on behalf of governments or criminal organizations.
- 2.1.B.5 Transnational criminal organizations seek financial gain primarily by deploying ransomware and stealing corporate intellectual property (IP) to sell in illegal markets.
Learning Objective 2.1.C: Describe the phases of a cyberattack.
- 2.1.C.1 Cyberattacks aim to disrupt, harm, steal, or destroy devices, networks, or data. Adversaries work in phases, which may not all be used in every attack. The phases are:
- i. Reconnaissance
- ii. Initial access
- iii. Persistence
- iv. Lateral movement
- v. Taking action
- vi. Evading detection
- 2.1.C.2 In the reconnaissance phase of an attack, adversaries gather as much information as possible about their target, often using open source intelligence (OSINT), which is freely available information.
- 2.1.C.3 In the initial-access phase of an attack, adversaries establish a foothold on the target’s computer, often through social engineering or compromised or weak credentials.
- 2.1.C.4 After gaining access during an attack, adversaries establish persistence to maintain access without needing to regain it. They may use a command and control (C2) protocol to send commands to the device and receive output, often through malware like a remote access trojan (RAT) or rootkit.
- 2.1.C.5 In the lateral-movement phase of an attack, adversaries try to escalate their privileges by accessing computers and user accounts with elevated permissions to services and data.
- 2.1.C.6 In the taking-action phase of an attack, adversaries act on their objectives by collecting targeted data, exfiltrating it, and disrupting services or destroying data.
- 2.1.C.7 In the final phase of an attack, many adversaries try to evade detection by removing or editing log files and erasing other files they may have planted on devices (e.g., malware).
Learning Objective 2.1.D: Describe the risk assessment process.
- 2.1.D.1 Risk occurs when a threat can exploit a vulnerability to compromise an asset.
- 2.1.D.2 An asset is anything valuable. Assets include financial resources, intellectual property, data, digital infrastructure, physical property, and reputation.
- 2.1.D.3 Risk assessment considers two factors:
- The likelihood of an attack against a specific vulnerability
- The severity of the projected damage from an attack against a specific vulnerability
- 2.1.D.4 The likelihood of a vulnerability being exploited depends on many factors, including:
- The value of the target: Adversaries are more likely to attack targets they perceive as valuable.
- The level of skill required to exploit the vulnerability (i.e., the difficulty): Vulnerabilities with well-documented exploits often require less skill and can be carried out by more adversaries.
- The motivation and capabilities of likely adversaries: Highly motivated and skilled adversaries are more likely to be able to perform more complex exploits.
- 2.1.D.5 The severity of an attack is often measured by financial cost, which can also include reputational and operational impacts.
- Illustrative examples for 2.1.D.5:
- A hacktivist is passionate about illegal fishing practices supported by a local food production company. The main webpage of this food production company would be a high-value target for this hacktivist; defacing the webpage to expose the company’s support of illegal fishing would provide no financial gain to the adversary, but would allow them to raise awareness about an issue that motivates them.
- Illustrative examples for 2.1.D.5:
- 2.1.D.6 The result of a risk assessment can be quantitative or qualitative.
- Quantitative risk assessment assigns a numeric value to a vulnerability based on a numeric scale (e.g., 1–10) or quantifiable impact, which could be financial (e.g., a $10,000 annual risk).
- Illustrative examples for 2.1.D.6:
- Low, medium, high, severe
- Unlikely low impact, likely low impact, unlikely high impact, likely high impact
- 2.1.D.7 Risk assessment documentation should include:
- Vulnerable assets and their value
- Descriptions of likely threats to the assets
- Details of specific vulnerabilities for specific assets and how they would be exploited
- An explanation of the severity of damage (financial, operational, reputational, etc.) if a specific asset were compromised, and the likelihood of that compromise occurring
- A final rating, quantitative or qualitative, for each risk identified
- Illustrative examples for 2.1.D.7:
- Scaled score (e.g., 1–10)
- Monetary value (e.g., a $10,000 risk vs. a$100,000 risk)
Learning Objective 2.1.E: Identify strategies for managing risk.
- 2.1.E.1 Once a risk has been identified and assessed, an organization has four options for managing that risk:
- i. Avoid
- ii. Transfer
- iii. Mitigate
- iv. Accept
- 2.1.E.2 Risk avoidance stops the activity that is generating the risk. If the activity is a critical part of an organization’s mission or purpose, then avoidance is not possible.
- 2.1.E.3 Risk transference places the burden of the risk on another entity, such as an insurance company, a government, or consumers.
- 2.1.E.4 Risk mitigation implements security controls to reduce the likelihood or impact of a risk.
- 2.1.E.5 Residual risk is the risk that remains after an organization has gone through avoidance, transference, and mitigation. The residual risk is the level of risk that an organization is willing to accept. Risk acceptance acknowledges the fact that absolute security is unattainable.
- 2.1.E.6 To conserve financial resources and employee capacity, an organization will often favor solutions that are cost effective and easy to implement and maintain. Cost-effective solutions cost less to install and maintain than the expected loss from an attack.
Learning Objective 2.1.F: Identify types of security controls.
- 2.1.F.1 Security controls address at least one of the following principles:
- Confidentiality ensures that only authorized individuals, systems, or processes can access data. Systems lacking confidentiality are vulnerable to data theft or destruction.
- Integrity ensures data are accurate and trustworthy. Systems lacking integrity are vulnerable to data manipulation.
- Availability ensures data and services are accessible to authorized individuals when needed. Systems lacking availability may experience unexpected downtime.
- 2.1.F.2 Security controls can be classified by type.
- Physical controls provide security in the physical space and include locks, fences, and cameras, bollards, and security guards.
- Technical controls provide security in the digital space and include firewalls, anti-malware software, and encryption.
- Managerial controls provide rules, guidelines, policies, and procedures that specify what security should be in place and include password policies, regular access reviews, and incident response plans (IRPs).
- 2.1.F.3 Security controls can be classified by function.
- Preventative controls address potential vulnerabilities with the goal of stopping an adversary from attacking and include locks and encryption.
- Detective controls help identify attacks when they occur and include intrusion detection systems (IDSs), cameras, and security incident and event management (SIEM) systems.
- Corrective controls fix problems and help restore systems to an operational state and include vulnerability patching, repairing a broken card reader, and intrusion prevention systems (IPSs).
Learning Objective 2.1.G: Explain why a defense-in-depth security strategy is necessary to optimally protect an organization.
- 2.1.G.1 A defense-in-depth strategy, or layered defense, uses multiple types of security controls to protect sensitive data and systems.
- 2.1.G.2 A defense-in-depth strategy allows an organization to address different types of threats, each with a security control most suited to mitigate it.
- 2.1.G.3 A defense-in-depth strategy allows for resilience in data protection so when one security control is bypassed by an adversary, another security control may still prevent access to the data or system or limit the damage done to the data or system.
- 2.1.G.4 Layers in a defense-in-depth strategy can include human, physical, network, device, application, and data.
מטרות למידה 2.1.A: זיהוי התקפות הנדסה חברתית.
- 2.1.A.1 מהנדסים חברתיים משתמשים בטקטיקות פסיכולוגיות כדי לעורר בקרב היעד נטיות לקבלת פעולה רצויה.
- 2.1.A.2 יצירת תרחיש (Pretexting) היא מצב שבו מתקיפים יוצרים סיבה סבירה ליצירת קשר עם יעד.
- 2.1.A.3 סמכות היא מצב שבו מתקיפים מחקים מישהו בעל כוח על היעד או מדמים העברת הוראות ממנו.
- 2.1.A.4 אינטimidation (הרתעה) היא מצב שבו מתקיפים מודעים למ consequences שליליות אם הדרישות לא יתקבלו.
- 2.1.A.5 קונסנסוס הוא מצב שבו מתקיפים יוצרים לחץ חברתי על ידי כך שהיעד יאמין שכל האחרים עושים את הפעולה הרצויה.
- 2.1.A.6 חוסר זמינות הוא מצב שבו מתקיפים יוצרים תחושה של זמינות מוגבלת.
- 2.1.A.7 היכרות היא מצב שבו מתקיפים מדמים להיות מישהו הקרוב ליעד או מכירים אותו כדי ליצור אמון.
- 2.1.A.8 דחיפות היא מצב שבו מתקיפים יוצרים מועד אחרון הדורש פעולה מהירה מהיעד כדי למנוע consequences שליליות.
מטרות למידה 2.1.B: זיהוי סוגי מתקיפים.
- 2.1.B.1 "Script kiddies" הם מתקיפים בעלי מיומנויות נמוכות המשתמשים בכלים שפותחו על ידי אחרים מבלי להבין כיצד הכלים עובדים. הם לעיתים קרובות מופעלים על ידי תאובה או רצון להכרה.
- 2.1.B.2 Hacktivists מופעלים על ידי causes חברתיים, פוליטיים או אישיים. הם מקלקלים מחשבים ורשתות כדי לתמוך ב-cause שלהם או לעצור harm נראית, באמונה שהatches שלהם מצדיקים את שיטותיהם הבלתי חוקיות.
- 2.1.B.3 מתקיפי insider (פנים) הם איומים ייחודיים מכיוון שיש להם תעודות הסמכה חוקיות וגישה למערכות ולמידע. הם יכולים להתגייס על ידי צד שלישי רע, ויכולים להיות מופעלים על ידי תאובה או נקמה.
- 2.1.B.4 Cyberterrorists מופעלים על ידי פוליטיקה או אמונות ושואפים להפרע בקהילות, אזורים או מדינות שלמות באמצעות התקפות سایبر (למשל, תקיפת רשת חשמל, מפעל טיפול במים או תשתיות אזרחיות אחרות). הם יכולים לפעול באופן עצמאי או בשם ממשלות או ארגוני פשע.
- 2.1.B.5 ארגוני פשע טרנס-לאומיים שואפים לרווח פיננסי בעיקר על ידי השקעת ransomware וגניבת IP (קניין רוחני) עסקי למכירה בשווקים בלתי חוקיים.
מטרות למידה 2.1.C: תיאור שלב ההתקפה הסיברית.
- 2.1.C.1 התקפות سایבר שואפות להפרע, לפגוע, לגנוב או להשמיד מכשירים, רשתות או מידע. המתקיפים עובדים בשלבים, שאינם בהכרח מופעלים בכל התקפה. השלבים הם:
- i. סיור
- ii. גישה ראשונית
- iii. הישרדות
- iv. תנועה אופקית
- v. ביצוע פעולות
- vi. הימנעות מהזיהוי
- 2.1.C.2 בשלב הסיור המודיעינתי של התקפה, אויבים איספו ככל האפשר מידע על יעדם, לעיתים קרובות באמצעות מודיעין ממקורות פתוחים (OSINT), שהוא מידע זמין בחינם.
- 2.1.C.3 בשלב הגישה הראשונית של התקפה, אויבים מקימים נקודת עגינה במחשב המיועד, לעיתים קרובות דרך הנדסה חברתית או דרכי סמכות משוחדות או חלשות.
- 2.1.C.4 לאחר שרכשו גישה במהלך התקפה, אויבים מקימים קיומיות כדי לשמור על הגישה ללא צורך בהשבתה מחדש. הם עשויים להשתמש בפרוטוקול פיקוד ושליטה (C2) לשליחת פקודות למכשיר ולקבלת תפוצה, לעיתים קרובות דרך תוכנת זיהום כמו טרוजन לגישה מרחוק (RAT) או רוטקיט.
- 2.1.C.5 בשלב התנועה האופקית של התקפה, אויבים מנסים להגביר את הרשאותיהם על ידי גישה למחשבים ולחسابי משתמשים עם רישיונות מוגברים לשירותים ולמידע.
- 2.1.C.6 בשלב ביצוע הפעולות של התקפה, אויבים פועלים לפי המטרות שלהם על ידי איסוף מידע ממוקד, שליפתו החוצה מהמערכת והפרעת שירותים או השמדת מידע.
- 2.1.C.7 בשלב הסופי של התקפה, רבים מאויביים מנסים להימנע מגילוי על ידי מחיקה או עריכת קובצי יומן ומחיקת קבצים אחרים שייתכן שהטילו במכשירים (למשל, תוכנת זיהום).
מטרות למידע 2.1.D: לתאר את תהליך הערכת הסיכון.
- 2.1.D.1 סיכון מתרחש כאשר איום יכול לנצל פגיעות כדי לפגוע בנכס.
- 2.1.D.2 נכס הוא כל דבר בעל ערך. נכסים כוללים משאבים פיננסיים, רכוש רוחני, מידע, תשתית דיגיטלית, נכסי קרקע ושמע.
- 2.1.D.3 הערכת הסיכון לוקחת בחשבון שני גורמים:
- הסיכוי להתקפה על פגיעות ספציפית
- חומרת הנזק המשוער מהתקפה על פגיעות ספציפית
- 2.1.D.4 הסיכוי לפגיעות מסוימת יהיה מנוצל תלוי בגורמים רבים, כולל:
- הערך של היעד: אויבים נוטים יותר לתקוף יעדים שהם תופסים כבעלי ערך.
- רמת המיומנות הנדרשת לניצול התקלה (כלומר, הקושי): תקלות עם ניצולים מוסברים היטב דורשות לעיתים פחות מיומנות ועלולות להיות מוצלחות על ידי מספר רב יותר של מתקיפים.
- המotivation והיכולות של מתקיפים סבירים: מתקיפים בעלי מotivation גבוהה ומיומנות היא רבה נוטים יותר לצלוח בביצוע ניצולים מורכבים יותר.
- 2.1.D.5 חומרת התקפה נמדדת לעיתים קרובות על פי העלות הכספית, שיכולה לכלול גם השפעות על המוניטין ועל הפעילות.
- דוגמאות הדגמה עבור 2.1.D.5:
- פעיל דיגיטלי (האקטיביסט) נלהב לגבי מעשי ציד בלתי חוקיים התומכים בחברת ייצור מזון מקומית. הדף הראשי של חברת ייצור המזון הזו יהיה מטרה בעלת ערך גבוה עבור ההאקטיביסט הזה; שחיקת הדף כדי לחשוף את תמיכת החברה בציד הבלתי חוקי לא תספק התועלת כספית למתקוף, אך תאפשר לו להעלות מודעות לנושא שמניע אותו.
- דוגמאות הדגמה עבור 2.1.D.5:
- 2.1.D.6 תוצאות הערכת הסיכון יכולות להיות כמותיות או איכותיות.
- הערכת סיכון כמותית מייחסת ערך מספרי לחולשה על בסיס סולם מספרי (למשל, 1–10) או השפעה כמותית, שעשויים להיות כספיים (למשל, סיכון שנתי של 10,000$).
- דוגמאות הדגמה עבור 2.1.D.6:
- נמוך, בינוני, גבוה, חמור
- לא סביר עם השפעה נמוכה, סביר עם השפעה נמוכה, לא סביר עם השפעה גבוהה, סביר עם השפעה גבוהה
- 2.1.D.7 מסמכי הערכת הסיכון אמורים לכלול:
- נכסים רגישים וערכם
- תיאורים של איומים סבירים לנכסים
- פרטים על חולשות ספציפיות עבור נכסים ספציפיים וכיצד הן ינוצלו
- הסבר על חומרת הנזק (כספי, תפעולי, מוניטין, וכו') אם נכס ספציפי יתחרש, וכן על סבירות התרחשות תחרוש זה
- דירוג סופי, כמותי או איכותי, עבור כל סיכון שזוהה
- דוגמאות הדגמה עבור 2.1.D.7:
- ציון בקנה מידה (למשל, 1–10)
- ערך כספי (למשל, סיכון של $10,000 risk vs. a$100,000)
מטרות לימוד 2.1.E: זיהוי אסטרטגיות לניהול סיכונים.
- 2.1.E.1 לאחר זיהוי ושיקול סיכון, לארגון יש ארבע אפשרויות לניהול הסיכון:
- i. הימנעות
- ii. העברה
- iii. הקטנה
- iv. קבלה
- 2.1.E.2 הימנעות מסיכון מונעת את הפעילות המייצרת את הסיכון. אם הפעילות היא חלק קריטי ממשימת הארגון או מטרתו, אזי הימנעות אינה אפשרית.
- 2.1.E.3 העברת סיכון מעמיסה את נטל הסיכון על צד שלי, כגון חברת ביטוח, ממשלה או צרכנים.
- 2.1.E.4 הקטנת סיכון מגייסת בקרות אבטחה כדי להפחית את הסבירות או ההשפעה של הסיכון.
- 2.1.E.5 סיכון שאר הוא הסיכון שנותר לאחר שהארגון עבר תהליכי הימנעות, העברה והקטנה. רמת הסיכון השארית היא הרמה שבה הארגון מוכן לקבל את הסיכון. קבלת סיכון מכירה בעובדה שאבטחה מוחלטת בלתי ניתנת להשגה.
- 2.1.E.6 כדי לשמר משאבים פיננסיים וקיבוע עובדים, ארגון יעדיף לעיתים קרובות פתרונות שיחוסיים וקלים ליישום ולתחזוקה. פתרונות שיחוסיים עולים פחות להתקנה ולתחזוקה מאשר ההפסד הצפוי מהתקפה.
מטרות למידה 2.1.F: זיהוי סוגי הבקרות האבטחה.
- 2.1.F.1 בקרות אבטחה טומנות בתוכן לפחות אחד מהעקרונות הבאים:
- סודיות מבטיחה כי רק אנשים, מערכות או תהליכים מורשים יכולים לגשת לנתונים. מערכות שאין בהן סודיות חשופות לגניבת נתונים או להשמדתם.
- שלמות מבטיחה שהנתונים מדויקים ואמינים. מערכות שאין בהן שלמות חשופות לעריכת נתונים.
- זמינות מבטיחה שהנתונים והשירותים יהיו נגישים לאנשים מורשים כאשר נדרש. מערכות שאין בהן זמינות עלולות לחוות הפסקות פעולה בלתי צפויות.
- 2.1.F.2 בקרות אבטחה ניתן למיין לפי סוג.
- בקרות פיזיקליות מספקות אבטחה במרחב הפיזיקלי וכוללות נעילה, גדרות, מצלמות, עמודי הגנה ושומרים.
- בקרות טכניות מספקות אבטחה במרחב הדיגיטלי וכוללים חומות אש, תוכנת אנטי-מאלוויר ואנצ'יפרציה.
- בקרות מנהליות מספקות כללים, הנחיות, מדיניות ותהליכים המפרטים מה אמור להיות ממוקם באבטחה וכוללים מדיניות סיסמאות, בדיקות גישה תקופתיות ותוכניות תגובה לאירועים (IRPs).
- 2.1.F.3 בקרות אבטחה ניתן למיין לפי פונקציה.
- בקרים מונעים מטרתם להתמודד עם תקלות אפשריות במטרה למנוע מתקיף לתקוף, וכוללים נעילות והצפנה.
- בקרים מאירועים מסייעים לזהות התקפות בעת התרחשותן וכוללים מערכות זיהוי התחדשות (IDSs), מצלמות ומערכות ניהול אירועים ואובייקטי אבטחה (SIEM).
- בקרים מתקנים מתקנים בעיות וסייעים לשחזר מערכות למצב תפעולי, וכוללים תיקוני תקלות, תיקון קורא כרטיסים שבור, ומערכות מניעת התחדשות (IPSs).
מטרות לימוד 2.1.G: הסבר מדוע אסטרטגיית הגנה בעומק היא הכרחית להגנה מיטבית על ארגון.
- 2.1.G.1 אסטרטגיית הגנה בעומק, או הגנה שכבתית, משתמשת בסוגים שונים של בקרות אבטחה כדי להגן על נתונים ומערכות רגישים.
- 2.1.G.2 אסטרטגיית הגנה בעומק מאפשרת לארגון להתמודד עם סוגים שונים של איומים, כל אחד עם בקרת אבטחה המתאימה ביותר להפחתתו.
- 2.1.G.3 אסטרטגיית הגנה בעומק מאפשרת עמידות בהגנת נתונים כך שכאשר בקרת אבטחה אחת עוברת על ידי אתגר, בקרת אבטחה אחרת עשויה עדיין למנוע גישה לנתונים או למערכת או להגביל את הנזק שנגרם לנתונים או למערכת.
- 2.1.G.4 השכבות באסטרטגיית הגנה בעומק יכולות לכלול אנשים, פיזיות, רשת, מכשירים, יישומים ונתונים.

