7 Protecting your assets
This chapter presents a layered, data-driven approach to protecting organizational assets, uniting policy, people, and technology to preserve confidentiality, integrity, and availability. It centers on identity and access management as the gatekeeper: establishing lifecycle-driven identities, strong authentication (including MFA, biometrics, and context-aware proofing), and granular authorization through models like RBAC and ABAC under the principle of least privilege. SSO and federation extend trusted access across domains, while service and hardware authentication further harden inter-service communications and device trust. Technical safeguards are complemented by physical controls, and all protections are organized as preventive, detective, and corrective measures, with metrics embedded throughout to guide risk decisions and balance false positives and negatives.
The chapter then traces data security across its lifecycle—at rest, in transit, and in use—emphasizing modern encryption practices (symmetric/asymmetric), current TLS versions, and robust hashing (e.g., SHA‑256 and above) while retiring obsolete methods. It highlights backup and recovery as critical defenses against ransomware and extortion, requiring encrypted, tested backups tied to clear RPO and RTO objectives. Equally vital is the human layer: role-relevant cybersecurity training and frequent awareness touchpoints that build a security-minded culture. Access permission governance, regular audits, and aligned policies keep privileges right-sized as roles and business needs evolve.
Operational resilience is built through disciplined configuration management, timely patching, secure hardware lifecycle practices, comprehensive logging, and a secure SDLC that integrates threat modeling, secure coding, SAST/DAST, penetration testing, code signing, hardening, and continuous monitoring/SOAR. Network resilience combines layered defenses, segmentation, and encryption with environmental protections, redundancy, failover, load balancing, and capacity planning—often leveraging elastic cloud resources—while accounting for hybrid cloud and third‑party risks through testing and tabletop exercises. Throughout, the chapter stresses metrics and continuous improvement: tracking IAM efficiency, training outcomes, encryption and backup coverage, baseline drift, and remediation speed to sustain a measurable, adaptive security posture.
An example of a Single Sign-On (SSO) process.
Federated identities require a user to be authenticated at their home organization, after which separate security domains use SAML to verify that they can trust and accept user identities from one another.
Security controls can be categorized by their type as well as their function.
The left shows Acme Corp’s identity and access management metrics before IAM improvements. On the right are the identity and access management metrics after IAM improvements.
The left side shows the review of training and awareness metrics before implementing a comprehensive training program. The right side shows the improvements after implementing the training program.
On the left shows the Secure Tech data security dashboard before implementing data protection practices. On the right is the data security dashboard after implementing data protection practices.
An overview of how security is integrated into each phase of the SDLC, highlighting critical security tasks associated with planning, development, testing, deployment, and maintenance stages.
The left side shows the SecureNet Inc. platform security dashboard before implementing the new security monitoring strategy. After implementing the new platform security monitoring strategy, the platform security dashboard is on the right.
Exercise: Match the testing method with the SDLC phase.
Answers to exercise 7.4.
Summary
- Identity and access metrics measure how well users are managed and authenticated.
- Authentication success and failure rates highlight security and user access reliability.
- Training metrics track the scope and effectiveness of cybersecurity education programs.
- Data security is evaluated by tracking encryption use and incident response success.
- Metrics for platform security assess the maintenance and response to software vulnerabilities.
- Resilience in infrastructure is measured by incident responses and system availability.
Data-Driven Cybersecurity ebook for free