Whew! Another class almost done (it's finals week now). This class was not like I was expecting, and I came away from it with new ideas, knowledge, and additional tools for my cybersecurity toolset.
The focus of this class was taking a information system, modeling it for threats, and coming up with an action plan to address these threats. This was slightly unexpected for a class titled "Current Trends of Cybersecurity" (we did discuss current trends, never fear! More on that below). However, this class seemed to be rather practical, and I realized I had to integrate a lot of knowledge from previous classes to successfully threat model. It was helpful that we were threat-modeling a semi-familiar system (Harry & Mae's, Inc.) which we had already assessed for various topics in the past.
Looking back, I really enjoyed the interaction with the other students. We worked together, critiqued each other's threat models and reports, bounced ideas off each other, and enjoyed our final class together (for a lot of us, anyway). Before this class, we didn't spend a lot of time looking at each other's work besides weekly forum posts, so I was quite surprised at some of the deliverables that were presented. Surprised because of their quality and thoroughness, that is; they were putting out semi-weekly reports that were 20+ pages in length and were much more fine-grained than I was prepared to deliver. That's not a problem–my goal was to address major threats with obviously beneficial mitigations rather than an exhaustive review of all threats since Harry & Mae's did not have a cybersecurity program to start with. Thus, my objective was different than theirs. However, it made me realize how far I had to go in noticing vulnerabilities and finding and categorizing threats. If I had to go back and do something differently, it would be to try and approach this case study with fresh eyes and not rely on past assessments (which I did when less experienced).
Now about the "Current Trends..." part of the title. A significant (though not majority) portion of this class involved student-led discussions on what was happening in cybersecurity in the news. For example, the NotPetya ransomware arose during our class, so we discussed how ransomware affects cybersecurity, how to prevent it, and so on. The discussions were interesting--we come from a diverse background, so everyone has something slightly different to contribute. Things got heated at least once (Android aficionados got slightly riled at a pro-Apple article that attacked their OS). However, it was a productive aspect of the class overall which I'm glad was incorporated.
Overall, this class was a great learning experience. I am not a professional in threat modeling yet, but this class got me warmed up to it and helped me integrate past knowledge into actually modeling threats to a system.
Now, on to advanced forensics!
The focus of this class was taking a information system, modeling it for threats, and coming up with an action plan to address these threats. This was slightly unexpected for a class titled "Current Trends of Cybersecurity" (we did discuss current trends, never fear! More on that below). However, this class seemed to be rather practical, and I realized I had to integrate a lot of knowledge from previous classes to successfully threat model. It was helpful that we were threat-modeling a semi-familiar system (Harry & Mae's, Inc.) which we had already assessed for various topics in the past.
Looking back, I really enjoyed the interaction with the other students. We worked together, critiqued each other's threat models and reports, bounced ideas off each other, and enjoyed our final class together (for a lot of us, anyway). Before this class, we didn't spend a lot of time looking at each other's work besides weekly forum posts, so I was quite surprised at some of the deliverables that were presented. Surprised because of their quality and thoroughness, that is; they were putting out semi-weekly reports that were 20+ pages in length and were much more fine-grained than I was prepared to deliver. That's not a problem–my goal was to address major threats with obviously beneficial mitigations rather than an exhaustive review of all threats since Harry & Mae's did not have a cybersecurity program to start with. Thus, my objective was different than theirs. However, it made me realize how far I had to go in noticing vulnerabilities and finding and categorizing threats. If I had to go back and do something differently, it would be to try and approach this case study with fresh eyes and not rely on past assessments (which I did when less experienced).
Now about the "Current Trends..." part of the title. A significant (though not majority) portion of this class involved student-led discussions on what was happening in cybersecurity in the news. For example, the NotPetya ransomware arose during our class, so we discussed how ransomware affects cybersecurity, how to prevent it, and so on. The discussions were interesting--we come from a diverse background, so everyone has something slightly different to contribute. Things got heated at least once (Android aficionados got slightly riled at a pro-Apple article that attacked their OS). However, it was a productive aspect of the class overall which I'm glad was incorporated.
Overall, this class was a great learning experience. I am not a professional in threat modeling yet, but this class got me warmed up to it and helped me integrate past knowledge into actually modeling threats to a system.
Now, on to advanced forensics!
No comments:
Post a Comment