CISOOnline

CISA unveils a six-step blueprint for isolating critical infrastructure during cyberattacks

It’s also important to identify connections that might lower trust or increase network vulnerability, such as those to carrier-provided networks, or Wi-Fi, satellite, radio point-to-point, or mobile connections. Operators should identify any protection mechanisms, like encryption, that may be in place in these areas, according to the agencies.

Further, operators should understand the business context of each connection, including the type of information that flows through it and how critical it is to operations and to the system owner or third-party provider. Technical information around these interconnections should also be documented, for instance, internet gateway information, architectural diagrams, firewall, router, and virtual private network (VPN) configurations, as well as emergency contact details.

“This critical technical information will be necessary for building isolation controls,” the guide notes.



Source link