by Ryan Seguin
February 21, 2021
Massive events such as the FIFA 2022 World Cup™ present a significant attack surface and target rich environments for the criminally motivated. The State of Qatar is taking this seriously and setting cybersecurity and privacy at the top of the FIFA 2022 World Cup™ event agenda. The State of Qatar is requiring entities to adopt and implement The Qatar 2022 Cybersecurity Framework, and elevate endpoint security in preparation for the World Cup.
The Cybersecurity Frameworks Capability Description – Capability Description – Change and Patch Management section (Chapter 7) focuses on preventative measures that ensure any asset related changes are securely deployed. Tenable.sc enables entities to monitor and report on the implementation of the operational processes, security controls and other technologies required to build a sustainable change and patch management program. By understanding the active and mitigated risk over time, the Risk Manager can better align patch management efforts with the business objectives to support the World Cup services.
Modeled from the Cybersecurity Governance Capability within the framework, the components on the left offer an in-depth look the current state of risk, and identify opportunities for remediation. Organizations with a robust patching plan must be vigilant and ensure the threat vectors are considered when determining mitigation efforts. This dashboard provides Risk Managers with a consolidated view to better direct mitigation efforts.
The components on the right focuses on mitigated data, which communicates to leadership the results of patch management efforts. The Security Directors and IT Managers are able to track compliance with departmental SLAs. As IT organizations complete patch management procedures, the CISO is able to visualize and quantify mitigation tasks. These data points supply Key Performance Indicators (KPI) and track risk reduction progress.
The Qatar 2022 CSF clearly outlines the compliance and risk management requirements to ensure a secure environment for the 2022 World Cup. The tools within this dashboard offer managers a decisive way to confidently make decisions regarding the enterprise that they direct. Equipped with proper knowledge and tools, entities ensure that their organization’s needs are fully met.
This dashboard is available in the Tenable.sc Feed, a comprehensive collection of dashboards, reports, Assurance Report Cards, and assets. The dashboard can be easily located in the Tenable.sc Feed under the category Compliance & Configuration Assessments. The dashboard requirements are:
Tenable.sc 5.15.0
• Nessus 8.11.1
Tenable.sc Continuous View (CV) is the market-defining On-Prem Cyber Exposure Platform. Tenable.sc CV provides the ability to continuously Assess an organization’s adherence to best practice configuration baselines. Tenable.sc provides customers with a complete Cyber Exposure platform for completing effective cybersecurity practices.