EvidenceSheet

ASD Strategies to Mitigate Cyber Security Incidents: the evidence behind every control

37 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.

Preventing Malware Delivery and Execution

01Application control (Essential) easy02Patch applications (Essential) easy03Configure Microsoft Office macro settings (Essential) easy04User application hardening (Essential) easy05Automated dynamic analysis of email and web content (Excellent) easy06Email content filtering (Excellent) easy07Web content filtering (Excellent) easy08Deny direct internet connectivity (Excellent) easy09OS generic exploit mitigation (Excellent) easy10Server application hardening (Very Good) easy11Operating system hardening (Very Good) easy12Antivirus software with heuristics (Very Good) easy13Control removable storage media (Very Good) easy14Block spoofed emails (Very Good) easy15User education (Limited) easy16Antivirus software with signatures (Limited) easy17TLS encryption between email servers (Limited) easy

Limiting the Extent of Cyber Security Incidents

18Restrict administrative privileges (Essential) easy19Patch operating systems (Essential) easy20Multi-factor authentication (Essential) easy21Disable local administrator accounts (Excellent) easy22Network segmentation (Excellent) easy23Protect authentication credentials (Excellent) easy24Non-persistent virtualised sandboxed environment (Very Good) easy25Software firewall - inbound (Very Good) easy26Software firewall - outbound (Very Good) easy27Outbound data loss prevention (Very Good) easy

Detecting Cyber Security Incidents and Responding

28Continuous incident detection and response (Excellent) easy29Host-based IDS/IPS (Very Good) easy30Endpoint detection and response (Very Good) easy31Hunt to discover incidents (Very Good) easy32Network-based IDS/IPS (Limited) easy33Capture network traffic (Limited) easy

Recovering Data and System Availability

34Regular backups (Essential) easy35Business continuity and disaster recovery plans (Very Good) easy36System recovery capabilities (Very Good) easy

Preventing Malicious Insiders

37Personnel management (Very Good) easy