Skip to content
NGTEdu Logo

NGTEdu

A PRODUCT OF NGTECH.CO.IN

NGTEdu Logo

NGTEdu

  • Home
  • Cyber Attacks
  • Malware
  • Vulnerabilities
  • Data Breach
  • Home
  • Cyber Attacks
  • CIS Control 09: Email and Web Browser Protections
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

CIS Control 09: Email and Web Browser Protections

4 years ago Andrew Swoboda
CIS Control 09: Email and Web Browser Protections

Web browsers and email clients are used to interact with external and internal assets. Both applications can be used as a point of entry within an organization. Users of these applications can be manipulated using social engineering attacks. A successful social engineering attack needs to convince users to interact with malicious content. A successful attack could give an attacker an entry point within an organization. CIS Control 9 provides several safeguards to ensure safety of external information.

Key Takeaways for Control 9

Web Browsers

Web browsers can be protected by the following: updating the browser, enabling pop-up blockers, enabling DNS filtering, and managing plugins. Always update web browsers to the latest version to fix known issues. Enable pop-up blockers to block malicious pop-up messages from being displayed to users. DNS filtering blocks access to malicious domains and protects users from navigating to them. Managing plugins can protect users from potentially installing malicious plugins.

Email

Email security can be increased by proper social engineering training, spam-filtering/malware scanning, domain-based message authentication, encryption, and file type filtering. Increasing the frequency of social engineering training allows users to successfully spot phishing and business email compromise (BEC). Spam-filtering and malware scanning can be used to reduce malicious emails. Another way to reduce malicious emails is to use domain-based message authentication, reporting, and conformance (DMARC). DMARC filters email based on the alignment of policies and removes any that do not conform. Encryption can be used to ensure that the contents remain private. File type filtering can be enabled to protect users from receiving malicious content.

Safeguards for Control 9

1. Ensure Use of Only Fully Supported Browsers and Email Clients

Description: Ensure only fully supported browsers and email clients are allowed to execute in the enterprise. Use only the latest version of browsers and email clients.

Notes: The security function associated with this safeguard is Protect. Success with this control provides users with supported browser and email clients. Using the latest browser and email clients provides protection against patch vulnerabilities.

2. Use DNS Filtering Services

Description: Use DNS filtering services on all enterprise assets to block access to known malicious domains.

Notes: The security function associated with this safeguard is Protect. Success with this control provides users with protection against known malicious domains.

3. Maintain and Enforce Network-Based URL Filters

Description: Enforce and update network-based URL filters to limit an enterprise asset from connecting to potentially malicious or unapproved websites. Example implementations include category-based filtering, reputation-based filtering, or block lists filtering. Enforce filters for all enterprise assets.

Notes: The security function associated with this safeguard is Protect. Success with this control provides the benefit of blocking malicious or unapproved websites. This restricts users from accessing malicious or unapproved URLs on enterprise systems.

4. Restrict Unnecessary or Unauthorized Browser and Email Client Extensions

Description: Restrict any unauthorized or unnecessary browser or email client plugins, extensions, and add-on applications either through uninstalling or disabling them.

Notes: The security function associated with this safeguard is Protect. Success with this control means that no plugins can be installed without approval. This stops potential malicious plugins from running on a system.

5. Implement DMARC Network

Description: Implement DMARC polices to lower the chance of receiving spoofed or modified emails from valid domains. Begin by implementing the Sender Policy Framework (SPF) and the DomainKey Identified Mail (DKIM) standards.

Notes: The security function associated with this safeguard is Protect. Success with this control provides users with less spam and phishing emails. However, training is necessary to ensure users do not to click on malicious emails that make it through the filter.

6. Block Unnecessary File Types

Description: Block unnecessary file types from entering the enterprise’s email gateway.

Notes: The security function associated with this safeguard is Protect. Success with this control blocks all file types that are not necessary for the organization to function. This protects the organization from malicious files entering the enterprise’s email gateway.

7. Deploy and Maintain Email Server Anti-Malware Protections

Description: Deploy and maintain email server anti-malware protections, such as attachment scanning and/or sandboxing.

Notes: The security function associated with this safeguard is Protect. Success with this control protects users from detected malicious attachments. Ensure that the anti-malware protection is updated with the latest definitions.

See how simple and effective security controls can create a framework that helps you protect your organization and data from known cyber-attack vectors by downloading the CIS Controls guide here.

Read more about the 18 CIS Controls here:

CIS Control 1: Inventory and Control of Enterprise Assets

CIS Control 2: Inventory and Control of Software Assets

CIS Control 3: Data Protection

CIS Control 4: Secure Configuration of Enterprise Assets and Software

CIS Control 5: Account Management

CIS Control 6: Access Control Management

CIS Control 7: Continuous Vulnerability Management

CIS Control 08: Audit Log Management

CIS Control 09: Email and Web Browser Protections

The post ” CIS Control 09: Email and Web Browser Protections” appeared first on TripWire

Source:TripWire – Andrew Swoboda

Tags: Phishing, TripWire

Continue Reading

Previous Critical National Infrastructure (CNI) Attacks on the Rise: Are We Ready?
Next Two Eastern Europeans Sentenced for Providing Bulletproof Hosting to Cyber Criminals

More Stories

  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 Likely via Trivy CI/CD Compromise

6 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR

8 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner

8 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

13 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

5 Learnings from the First-Ever Gartner Market Guide for Guardian Agents

13 hours ago [email protected] (The Hacker News)
  • Data Breach
  • Vulnerabilities

The Hidden Cost of Cybersecurity Specialization: Losing Foundational Skills

15 hours ago [email protected] (The Hacker News)

Recent Posts

  • TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 Likely via Trivy CI/CD Compromise
  • Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR
  • Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner
  • Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials
  • 5 Learnings from the First-Ever Gartner Market Guide for Guardian Agents

Tags

Android APT Bug CERT Cloud Compliance Coronavirus COVID-19 Critical Severity Encryption Exploit Facebook Finance Google Google Chrome Goverment Hacker Hacker News High Severity Instagram iPhone Java Linux Low Severity Malware Medium Severity Microsoft Moderate Severity Mozzila Firefox Oracle Patch Tuesday Phishing Privacy QuickHeal Ransomware RAT Sim The Hacker News Threatpost TikTok TripWire VMWARE Vulnerability Whatsapp Zoom
Copyright © 2020 All rights reserved | NGTEdu.com
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More here.Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT