Protecting and securing the OS

https://www.pcisecuritystandards.org/documents/PCI_DSS_V1.0_Best_Practices_for_Implementing_Security_Awareness_Program.pdf
https://www.threatstack.com/blog/how-to-implement-a-security-awareness-program-at-your-organization
https://security.berkeley.edu/incident-response-planning-guideline
https://www.manageengine.com/patch-management/what-is-patch-management.html

1. For this week, we are going to dive into the fourteenth and seventeenth controls of CIS.
Discuss the following:
Why is Security Awareness and Skills training so essential? Why would CIS require almost every subcontrol for this control?
Are there any free security awareness training services out there? Would they meet all of the requirements detailed in sub controls 14.2-14.8?
What should be considered when developing a security awareness program?
In a small business with no dedicated cybersecurity team, who should be designated to handle cybersecurity incidents? What kinds of contact information should be included?
When developing an incident handling process and program, what considerations must be made?

2. Patch Management plan for Raven, He has requested the following information:

What methods, if any, exist to centralize patching of Windows devices? Does it make sense for Raven to invest time and money into centralizing Windows updates?
What methods, if any, exist to centralize patching of macOS devices? Does it make sense for Raven to invest time and money into centralizing macOS updates?
What methods, if any, exist to centralize patching of Linux devices? Does it make sense for Raven to invest time and money into centralizing Linux updates?
Is there a single solution that can be used to patch all three operating systems with the same tool? If so, what is it and how can it do this?
What considerations must be in a Patch Management policy?

3. For this week, your submission must be your final round of recommendations for the Raven Corporation.

For this assignment, you must submit the following:

A summary of all deficiencies that you identified according to the CIS 18 IG1
Final Recommendations should be developed and submitted in a “tiered” approach – Most Important (Tier 1), Highly Important (Tier 2), and Important (Tier 3). These should be detailed enough to allow the organization to implement your recommendation, but generic enough that allows them to put their own spin on it.
This does not need to be in any particular format. Just make it clear which control/subcontrol your recommendations go to. Justify your recommendations.

Last Completed Projects

topic title academic level Writer delivered