Knowledge base

Short, tagged, searchable.

Terms, frameworks, and concepts used on an Australian defensive desk. No exploit steps.

27 entries

IR hardening

3-2-1 backups

Three copies, two media, one off-site. Immutable or offline beats a snapshot the ransomware also encrypted.

au-compliance frameworks

ACSC

The Australian Cyber Security Centre, part of ASD. Alerts, advice, assistance. cyber.gov.au and 1300 CYBER1.

au-compliance

ASD

Australian Signals Directorate. Foreign signals intelligence and, through the ACSC, national cyber security.

concepts

CIA triad

Confidentiality, integrity, availability. Lose one and the system is already failing, even if the dashboard is green.

vulnerability frameworks

CISA KEV

Known Exploited Vulnerabilities catalogue. If it is here, someone is using it. Treat exposure as urgent.

concepts vulnerability

CVE vs CVSS

CVE names a vulnerability. CVSS scores a model of severity. Neither tells you if you are exposed or if it is being used.

detection IR

EDR

Endpoint detection and response. Behaviour plus the ability to isolate. An agent without an owner is inventory.

frameworks au-compliance hardening

Essential Eight

ASD's baseline of eight mitigation strategies. Maturity 0 to 3. The work is picking a level you can actually hold.

frameworks

ISO/IEC 27001

A management system standard. The certificate is proof you run the system, not that you are unbreachable.

IR

Incident response

Prepare, detect, contain, recover, learn. The first hour is decisions and evidence, not a slide template.

frameworks au-compliance

Information Security Manual (ISM)

ASD's control catalogue for Australian government and anyone who wants the same language. Applicability is the work.

identity hardening

Least privilege

Only the access required, only for as long as required. Standing admin is standing blast radius.

logging detection IR

Logging

Collect what can answer a question. Retain it with integrity. If it never gets queried, it is storage spend.

detection frameworks

MITRE ATT&CK

A knowledge base of adversary tactics and techniques. Use it to find detection gaps, not to decorate a slide.

identity

Multi-factor authentication

Something you know, have, or are. Phishable MFA is still better than none. Phishing-resistant is the actual target.

frameworks

NIST Cybersecurity Framework

Identify, Protect, Detect, Respond, Recover — plus Govern in 2.0. A common language, not a certification.

identity concepts

Phishing

Identity abuse delivered as a message. Training helps. Phishing-resistant MFA and mail authentication help more.

au-compliance IR

Privacy Act and OAIC

Australian privacy law and the regulator. Eligible data breaches must be assessed and, if they meet the test, notified.

IR concepts

Ransomware

A business model: encrypt, steal, threaten. The defence is identity, EDR, segmentation, and backups you have restored.

detection logging

SIEM

Security information and event management: collect, normalise, correlate, alert. Useless if nobody owns the queue.

detection IR

SOAR

Orchestration and response. Automate the boring. Keep a person on steps that isolate a host or disable an account.

detection IR

Security operations centre

People, detections, and a queue. A room full of screens is optional. Ownership of after-hours is not.

detection concepts

Threat intelligence

Context that changes a decision. IoCs expire. TTPs last. A feed you never action is a newsletter.

vulnerability hardening

Vulnerability management

Discover, prioritise, fix, verify. KEV and exposure beat a 400-page scanner PDF.

network identity concepts

Zero trust

Never trust, always verify. A VPN badge is not a day pass. Identity, device, path, and data each get asked again.