{"id":133,"date":"2024-09-25T16:24:07","date_gmt":"2024-09-25T16:24:07","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/cyberimpact1\/?page_id=133"},"modified":"2024-12-04T02:04:37","modified_gmt":"2024-12-04T02:04:37","slug":"it-cyse-200t-2","status":"publish","type":"page","link":"https:\/\/sites.wp.odu.edu\/dylanstearns\/it-cyse-200t-2\/","title":{"rendered":"CYSE 200T"},"content":{"rendered":"<h1 class=\"p1\" style=\"text-align: center\">Cybersecurity, Technology, and Society<\/h1>\n<p>Assignment Showcase: Write Up &#8211; The Human Factor in Cybersecurity<\/p>\n<div class=\"Page-container\">\n<div id=\"page-0\" class=\"Page PageComponent\">\n<div class=\"Draw Draw--not-drawing Draw--selection\">\n<div class=\"TextLayer-container\">\n<div class=\"textLayer\"><strong><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">THE HUMAN FACTOR IN CYBERSECURITY<\/span><\/strong><\/div>\n<div class=\"textLayer\"><br class=\"textLayer--absolute\" role=\"presentation\" \/><strong><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">Balancing Limited funds as a CISO<\/span><\/strong><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">As a CISO the most important thing to keep up with is arguably funding,<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">without<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">funding<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">a company<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">isn&#8217;t<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">able to<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">run at all.<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">Another thing is figuring out what to use the<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">funding for<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">;<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">some things to consider what you should use funding on is train<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">ing staff and technological<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">advancements.<\/span><\/div>\n<div class=\"textLayer\"><br class=\"textLayer--absolute\" role=\"presentation\" \/><strong><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">Training<\/span><\/strong><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">When it comes to training in cybersecurity,<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">many employees<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">are<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">undertrained and lack<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">awareness on cybersecurity pr<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">o<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">cedures<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">and what to look out for when in a workplace<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">environment. According to the Harvard Business Review,<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">\u201c<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">cybercriminals scammed $26<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">billion between October 2013 and July 2019 with the \u201cBusiness Email Compromise\u201d scam<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">that, using deceptive and manipulative social engineering techniques, lured employees<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">and individuals into divulging their credentials and event<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">ually making unauthorized<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">transfers or funds.<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">\u201d If every employee in a company was trained<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">in<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">cyb<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">ersecurity and how<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">to be secure in the workplace,<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">then<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">the<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">chance<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">of an internal attack goes down by<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">a<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">copious amount.<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">Not only do the chances go down but employees collectively get a<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">general understanding of cybersecurity<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">.<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">This creates<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">a more<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">knowledgeable environment if<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">an employee were to spot something they could immediately send it over to the<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">cyber<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">security<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">department to inspect it.<\/span><\/div>\n<div class=\"textLayer\"><br class=\"textLayer--absolute\" role=\"presentation\" \/><strong><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">Technolog<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">y<\/span><\/strong><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">When it comes to technolog<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">y in cybersecurity, you<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">can&#8217;t<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">go without it. If a<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">company&#8217;s<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">database is running without strong<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">security,<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">it likely<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">won&#8217;t<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">survive very long. Many things<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">that are good to have as a company ar<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">e<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">Role<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">Based Access Control<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">(RBAC)<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">which limits<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">users only to what they are assigned to, Firewalls that act as a<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">barrier between trusted and<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">untrusted networks, and two factor authentication (2FA) whic<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">h is a form of multi factor<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">authentication that makes sure the user is the correct user before allowing access to a<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">database. There are many more forms of technology that a CISO should<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">spark interest in<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">but those three are really the<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">foundation<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">to ensure the co<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">mpany is secure.<\/span><\/div>\n<div class=\"textLayer\"><br class=\"textLayer--absolute\" role=\"presentation\" \/><strong><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">Conclusion<\/span><\/strong><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">Ultimately,<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">as a CISO you have to balance limited funds between training employees of<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">the company and technology to strengthen the company.<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">T<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">raining<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">employees<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">can<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">significantly reduce the risk of human error which is a major<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">part<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">of<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">cybersecurity<\/span><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"Page-container\">\n<div id=\"page-1\" class=\"Page PageComponent\">\n<div class=\"Draw Draw--not-drawing Draw--selection\">\n<div class=\"TextLayer-container\">\n<div class=\"textLayer\"><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">breaches.<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">By educating employees on<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">what to look out for<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">companies can create a<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">secure<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">workplace environment where cybersecurity is a<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">normal<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">practice<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">.<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">On the other side of<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">things<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">,<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">investing in<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">technologies<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">like<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">Role<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">Based Access Control<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">(RBAC),<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">firewalls, and two<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">factor authentication<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">(2FA) is<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">important to overall protect the<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">company&#8217;s<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">databases<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">.<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">Overall, the best way to<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">balance funds and<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">keep you<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">r<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">company secure as a CISO<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">is<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">by<\/span><br class=\"textLayer--absolute\" role=\"presentation\" \/><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">combining<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">training and technology as it creates<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">strong security<\/span> <span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">against cyber threats<\/span><span class=\"textLayer--absolute\" dir=\"ltr\" role=\"presentation\">.<\/span><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity, Technology, and Society Assignment Showcase: Write Up &#8211; The Human Factor in Cybersecurity THE HUMAN FACTOR IN CYBERSECURITY Balancing Limited funds as a CISOAs a CISO the most important thing to keep up with is arguably funding, without fundinga company isn&#8217;t able to run at all. Another thing is figuring out what to use&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/dylanstearns\/it-cyse-200t-2\/\">Read More<\/a><\/div>\n","protected":false},"author":29867,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/dylanstearns\/wp-json\/wp\/v2\/pages\/133"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/dylanstearns\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/dylanstearns\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/dylanstearns\/wp-json\/wp\/v2\/users\/29867"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/dylanstearns\/wp-json\/wp\/v2\/comments?post=133"}],"version-history":[{"count":5,"href":"https:\/\/sites.wp.odu.edu\/dylanstearns\/wp-json\/wp\/v2\/pages\/133\/revisions"}],"predecessor-version":[{"id":322,"href":"https:\/\/sites.wp.odu.edu\/dylanstearns\/wp-json\/wp\/v2\/pages\/133\/revisions\/322"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/dylanstearns\/wp-json\/wp\/v2\/media?parent=133"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}