7.7 Detection & Preventive Security Controls
7.7 Detection & Preventive Security Controls
Security controls are valuable only when they continue to work in the environment they are protecting.
Firewalls need appropriate rules. Intrusion-detection systems need useful signatures and tuning. Anti-malware engines need current intelligence. Sandboxes need to recognise suspicious behaviour. Security services need monitoring and oversight.
CISSP 7.7 therefore focuses not simply on installing security technology, but on operating, maintaining, tuning and validating controls that detect or prevent malicious activity.
Prevent
Stop unwanted activity before it reaches or affects the protected asset.
STOP ITDetect
Identify suspicious or malicious behaviour that still occurs.
SEE ITMaintain
Keep controls healthy, current, appropriately configured and tuned.
KEEP IT EFFECTIVEOperate and Maintain Detection and Preventative Measures
The current CISSP Exam Outline explicitly includes:
Including next-generation, web application and network firewalls.
Intrusion Detection Systems and Intrusion Prevention Systems.
Permit known or approved entities and block known unwanted entities.
Detection or preventive capabilities delivered by external providers.
Execute suspicious or untrusted content within a restricted environment.
Deceptive resources designed to attract or reveal suspicious activity.
Detect, prevent, quarantine or otherwise control malicious software.
Use data-driven models to identify, classify or prioritise suspicious behaviour.
7.7 Official Topics
The Big Idea
Detection and prevention are complementary.
Defensive Model
Preventive vs Detective
Attempts to stop an unwanted action from succeeding.
STOP IT
Identifies potentially unwanted activity so it can be investigated or acted upon.
FIND IT
An anti-malware product may detect malware and then prevent execution. An IPS can detect an attack and automatically block it.
๐ 7.2 vs 7.7 Why does IDS/IPS appear in both?
Focuses on monitoring activities and the information used to detect security events.
Focuses on operating and maintaining the protective and detective technologies themselves.
Defence in Depth
No single detection or preventive mechanism should be expected to stop every attack.
Firewalls
A firewall controls network communication according to security policy.
It can permit required traffic while rejecting communications that should not cross a security boundary.
Firewall
Firewall Types
Makes decisions using information such as source, destination, protocol and port.
Maintains awareness of connection state when evaluating traffic.
Can inspect and mediate communications at higher protocol layers.
Commonly combines traditional firewall functions with deeper traffic, application and threat inspection capabilities.
Protects web applications by inspecting HTTP/HTTPS application traffic.
Controls traffic entering or leaving an individual host.
๐ Network Firewall vs WAF Different layers and different questions
Typically asks:
Should this network communication be permitted?
Typically asks:
Does this HTTP request appear appropriate for the web application?
Network firewall permits: TCP 443.
WAF then identifies: a malicious request inside the permitted HTTPS service.
๐ฅ Next-Generation Firewall Firewall functionality combined with richer inspection and threat controls
NGFW implementations may combine capabilities such as:
Advanced features provide little benefit if rules are overly broad, unused or poorly maintained.
Default Deny
A strong firewall policy commonly permits traffic that is explicitly required and denies traffic that is not authorised.
Application servers:
may connect to database servers on the required database port.
Application network:
ANY โ ANY โ ANY.
Ingress & Egress Filtering
Controls traffic entering a network or security zone.
WHAT MAY COME IN?
Controls traffic leaving a network or security zone.
WHAT MAY GO OUT?
Malware attempts to connect to: an attacker-controlled command-and-control server.
Appropriate egress filtering may: block or reveal the connection.
Traffic Direction
Firewall Rule Lifecycle
Firewall security is not finished when a rule is created.
๐งน Firewall Rule Problems Rules accumulate over time
Allows more systems, protocols or destinations than required.
Created for troubleshooting and never removed.
Supports a system or service that no longer exists.
Another earlier rule causes the intended rule never to be reached.
Multiple rules perform the same function unnecessarily.
Rule order causes unexpected policy behaviour.
IDS vs IPS
Monitors activity and identifies signs of potentially malicious behaviour.
Typically: alerts.
DETECTIVE
Includes detection capability and can also attempt to stop identified malicious activity.
Typically: alerts + blocks.
DETECTIVE + PREVENTIVE
IDS vs IPS
๐ฆ Passive vs Inline Where the control sits changes what it can do
Receives or observes a copy of traffic.
Common IDS approach.
Detection can occur without being directly in the traffic path.
Traffic passes through the security control.
Common IPS approach.
The device can directly allow, drop or modify traffic.
Network-Based vs Host-Based Detection
Monitors network communication.
Operates on or closely monitors an individual host.
Signature vs Anomaly / Behaviour Detection
Looks for patterns associated with known malicious activity.
Strong for: known threats.
Identifies activity that differs from expected behaviour or learned patterns.
Can help identify: previously unseen or unusual activity.
Detection Method
True / False Positives & Negatives
| Reality | Control Says | Result |
|---|---|---|
| Attack | Attack | True Positive |
| Normal | Attack | False Positive |
| Attack | Normal | False Negative |
| Normal | Normal | True Negative |
Detection Errors
โ๏ธ False Positive vs False Negative Both matter, but in different ways
Analysts investigate harmless activity.
Real malicious activity passes undetected.
Detection Tuning
Whitelisting / Blacklisting
The CISSP Exam Outline currently uses the terms whitelisting and blacklisting.
In modern technical documentation you will also commonly see:
allowlisting and blocklisting / denylisting.
Define what is authorised.
Everything else may be rejected.
KNOWN / APPROVED GOOD
Define what is prohibited.
Everything else may remain permitted unless another control blocks it.
KNOWN BAD
Lists
โ Application Allowlisting Permit approved software instead of trying to identify every bad program
Not on approved list.
Result: execution blocked.
โ Blocklisting Stop known unwanted entities
Blocklists may contain:
Known ransomware command-and-control domain:
added to security blocklist.
An attacker can use infrastructure that is not yet known to be malicious.
Allowlisting vs Blocklisting
Default: not allowed.
Permit: approved entities.
Stronger control where the permitted set is manageable.
Default: generally allowed.
Deny: known unwanted entities.
Easier where legitimate possibilities are extremely broad.
โ๏ธ Allowlisting Must Be Maintained A static approved list can become an operational problem
Approved application: Version 12.
Organisation deploys: Version 13.
Allowlist still recognises only: Version 12.
The control may now:
block legitimate business software.
Third-Party Provided Security Services
Organisations may outsource parts of their detection or prevention capability to specialist providers.
Managed Security Service Provider supplying ongoing security technology or monitoring services.
Managed Detection and Response provider focused on detection, investigation and response support.
Provider filters hostile web or volumetric traffic before it reaches organisational systems.
Third party filters malicious email, attachments and links.
External service blocks or detects access to malicious domains.
Provider supplies information about malicious infrastructure, campaigns or indicators.
๐ค Questions for a Security Provider Who does what when something happens?
Service Levels Matter
Provider will: monitor security alerts.
Provider monitors: 24 hours a day.
Critical alert: reviewed within 10 minutes.
Confirmed critical incident: customer notified through specified escalation path.
Sandboxing
A sandbox provides a restricted environment in which untrusted or suspicious code can run with limited access to real system resources.
Sandbox
What Might a Sandbox Observe?
Does the program create, encrypt or delete files?
Does it launch suspicious child processes?
Does it contact suspicious external infrastructure?
Does it modify system settings?
Does it try to survive system restart?
Does it attempt elevation or access protected resources?
๐ญ Sandbox Evasion Malware may try to recognise that it is being analysed
Sophisticated malware can attempt to identify indicators of a sandbox and change its behaviour.
Malware checks for:
If analysis is suspected, malware:
does nothing malicious.
๐ช Sandbox Escape The isolation mechanism itself can have weaknesses
A sandbox must itself be securely designed and maintained.
If malicious code exploits the isolation technology, it may be able to:
Honeypots & Honeynets
A deceptive system or resource designed to appear attractive to an attacker.
ONE DECOY RESOURCE
A larger environment or collection of deceptive systems designed to appear like a real network.
NETWORK OF DECOYS
Deception
Why Use Deception?
Legitimate users should have little reason to interact with the decoy.
Security teams may observe techniques used against the environment.
Interaction can reveal tools, infrastructure and attacker behaviour.
Access to a deceptive resource can provide a high-value investigation signal.
An internal server named:
PAYROLL-LEGACY-DB
exists only as a deception system.
A workstation begins authenticating to it unexpectedly.
๐ฏ Related Concept: Honeytokens The decoy does not have to be an entire computer
Deception can also involve fake information or credentials designed to generate an alert if used.
A fake credential is placed where: no legitimate process should ever use it.
Authentication occurs using that credential.
Result: high-value security signal.
โ ๏ธ Honeypots Need Isolation A compromised decoy should not become an attack platform
A honeypot intentionally attracts malicious activity.
If poorly isolated, an attacker could potentially use the compromised decoy to:
Anti-Malware
Anti-malware technologies identify and control malicious software such as viruses, worms, trojans, spyware, ransomware and other hostile code.
Recognises known malicious patterns.
Looks for characteristics associated with malicious programs.
Watches what software actually does.
Uses information about files, URLs, certificates or publishers.
Inspects activity as files or processes are accessed or executed.
Isolates suspicious content to prevent normal use.
๐ป Traditional Anti-Virus vs Modern Endpoint Detection Modern endpoint protection commonly combines several techniques
Historically focused strongly on identifying known malware through signatures and scanning.
May combine:
Anti-Malware Must Stay Current
โค๏ธ Monitor Security Agent Health "Installed" is not the same as "protecting"
Is the security agent present?
Is the service operational?
Are engine and detection updates current?
Is the agent communicating with management systems?
Are expected prevention features actually enabled?
Has protection been disabled or modified?
Security Controls Become Targets
Attackers may attempt to disable or bypass the very technologies designed to detect them.
Endpoint security agent: unexpectedly stops on a production server.
Machine Learning & AI-Based Security Tools
Machine-learning and AI capabilities can analyse large volumes of security information and identify patterns that would be difficult to manage manually.
Identify behaviour that differs from expected patterns.
Analyse characteristics or behaviour of suspicious files.
Identify unusual identity or access activity.
Detect unusual traffic patterns.
Help rank large numbers of alerts according to predicted risk.
Identify relationships across multiple signals.
Help summarise or enrich security information.
Recommend or initiate actions when appropriate controls and confidence thresholds are met.
Signature vs ML / Behaviour Detection
"Does this match something we already recognise as malicious?"
KNOWN PATTERN
"Does this activity resemble malicious or unusual behaviour?"
PATTERN / ANOMALY
User normally downloads: 20 MB per day.
Today: 480 GB downloaded at 02:00.
๐ค AI Security Tools Are Still Security Controls They need validation, monitoring and governance
Normal behaviour may be classified as malicious.
Malicious behaviour may not be recognised.
Real-world behaviour changes over time and the model may become less representative.
Weak or incomplete data can reduce detection quality.
Attackers may deliberately alter behaviour to evade detection.
Analysts may need enough information to understand why a high-impact decision was made.
Incorrect high-confidence decisions can cause operational impact if automatically enforced.
Important decisions may still require analyst judgement and contextual validation.
๐ Model Drift The environment the model learned may change
Employees normally work: 09:00 - 17:00 from office networks.
Employees work: globally and remotely around the clock.
A behavioural model based entirely on the original pattern may suddenly generate:
large numbers of false positives.
Detection Confidence & Automated Action
Operate AND Maintain
The ISC2 objective is not simply:
"know what these technologies are."
It says:
operate and maintain.
Is the control functioning?
Is it protecting the systems it should protect?
Is the policy appropriate?
Are engines, signatures, intelligence and software current?
Is detection producing useful results?
Are important events reaching monitoring systems?
Does the control detect or block what it should?
Does the control still match current threats and business needs?
Operate & Maintain
๐งช Do Not Assume the Control Works Security technology should be validated
IPS blocks: a known exploit.
Relevant IPS signature: disabled.
Detection Coverage
Security teams should understand which parts of the environment are actually covered by controls.
"All endpoints have EDR."
Coverage: 92%.
Missing:
Sensor Placement Matters
Detection effectiveness depends partly on where monitoring controls are positioned.
Observe external inbound and outbound traffic.
Detect lateral movement between zones.
Monitor traffic involving high-value assets.
Observe cloud-native traffic and workloads.
Once an attacker is inside the network, east-west visibility may become especially important.
๐ Encrypted Traffic Creates Visibility Questions Security controls may see metadata but not necessarily application contents
Sees: TLS connection.
Payload: encrypted.
Depending on architecture, detection may rely on:
Fail Open vs Fail Closed
If the security control fails, traffic or access continues.
Benefit: availability.
Risk: security inspection may be bypassed.
If the security control fails, traffic or access is denied.
Benefit: security enforcement.
Risk: service disruption.
โป๏ธ Security Controls Can Become Single Points of Failure Inline controls need resilience
Every customer transaction passes through: one IPS appliance.
Appliance fails.
Depending on design:
Detection Controls Need Change Management
Modifying security controls can affect production traffic and detection capability.
New prevention signature incorrectly identifies normal banking application traffic as malicious.
Result: customer transactions blocked.
Useful Detection & Prevention Metrics
What percentage of required assets are protected?
How many sensors or agents are functioning?
How useful are generated alerts?
How often does the control incorrectly identify benign activity?
Which known threats or techniques lack coverage?
Are signatures, engines and threat intelligence current?
Are old firewall or prevention rules still required?
Do controlled tests demonstrate that intended attacks are detected or blocked?
Malicious Email Attachment
The Forgotten Temporary Rule
An engineer creates a temporary rule:
Internet โ Production Database โ Database Port
It is required for: 30 minutes.
The Noisy Signature
IDS generates: 40,000 alerts every day.
Analysts discover: 39,800 are legitimate application behaviour.
The Silent Attack
An attacker exploits a web server.
IDS: does not alert.
The attack is later discovered through endpoint telemetry.
Determine why the detection failed and use the incident to improve coverage.
The Fake Domain Administrator Credential
Security places a monitored fake credential in a location that should never be accessed by legitimate users.
The MDR Alert
An external MDR provider identifies suspicious administrator activity at:
02:15.
The provider's contract allows it to:
alert the company
but not:
disable accounts or isolate servers.
Unusual Administrator Behaviour
A behavioural model identifies:
Each signal individually might be legitimate.
Together they create:
a high-risk behavioural anomaly.
๐ CISSP Scenarios Recognise the detection or preventive measure being tested
A control blocks network traffic that is not explicitly authorised.
Which control?
Firewall.
A network device allows only explicitly required communications.
Which principle?
Default deny / least privilege.
A control permits TCP 443 but does not understand the malicious HTTP request inside it.
Which additional control may help?
Web Application Firewall.
Security needs to inspect HTTP parameters for attacks against a web application.
Which control?
WAF.
A firewall combines application identification, threat intelligence and intrusion prevention.
Which firewall type?
Next-Generation Firewall.
A firewall controls communications on an individual laptop.
Which type?
Host-based firewall.
Security controls traffic entering the corporate environment.
Which direction?
Ingress.
Security blocks a compromised server from contacting an attacker externally.
Which direction is being controlled?
Egress.
A temporary firewall rule remains years after the project closed.
Which operational weakness?
Poor firewall rule lifecycle management.
An IDS identifies malicious network traffic and generates an alert.
Which control function?
Detective.
An IPS detects the same traffic and drops it.
Which functions?
Detective and preventive.
A security sensor receives a copy of network traffic but does not sit directly in the path.
Which deployment style?
Passive monitoring.
Traffic must pass directly through a security device that can drop packets.
Which deployment style?
Inline.
Detection looks for a byte pattern associated with known malware.
Which method?
Signature-based detection.
Detection identifies a user downloading 500 times their normal data volume.
Which general method?
Anomaly / behaviour detection.
Normal business activity triggers a malware alert.
Which result?
False positive.
Real malicious activity occurs but the IDS produces no alert.
Which result?
False negative.
Thousands of harmless alerts consume analyst time.
What may be required?
Detection tuning.
A real attack was missed.
What should occur afterwards?
Detection coverage should be reviewed and improved.
Only approved applications are permitted to execute.
Which concept?
Application allowlisting / whitelisting.
Known malicious domains are prohibited.
Which concept?
Blocklisting / blacklisting.
Security wants to control what is permitted rather than continuously identify every possible malicious program.
Which approach?
Allowlisting.
A new malicious domain has not yet appeared on any denylist.
Can blocklisting alone stop it?
Not necessarily.
A legitimate software update is blocked because the allowlist was not updated.
Which lesson?
Allowlisting requires operational maintenance.
An external organisation monitors endpoint alerts around the clock.
Which 7.7 topic?
Third-party provided security services.
An MDR provider detects an attack but does not have authority to isolate the endpoint.
What must be clear?
Escalation and response responsibilities.
An organisation outsources security monitoring.
Does it outsource accountability for security risk?
No.
Unknown executable is run inside an isolated analysis environment.
Which technique?
Sandboxing.
Malware behaves harmlessly because it detects a virtual analysis environment.
Which technique?
Sandbox evasion.
A sandbox reports no malicious activity.
Does this prove the file is benign?
No.
A deliberately attractive fake server is deployed to identify attackers.
Which control?
Honeypot.
An entire fake network environment is deployed.
Which control?
Honeynet.
A fake API key generates an alert when attackers attempt to use it.
Which related concept?
Honeytoken.
A compromised honeypot can reach production servers.
Primary concern?
Insufficient isolation.
A security product compares a file with known malicious patterns.
Which anti-malware method?
Signature detection.
Security software observes a process encrypting thousands of files and blocks it.
Which method?
Behaviour-based anti-malware detection.
Endpoint agent is installed but has not received updates for six months.
Primary concern?
Control maintenance / outdated protection.
Endpoint protection unexpectedly stops on one production server.
Why investigate?
Attackers may attempt to disable security controls.
A machine-learning system identifies abnormal user behaviour.
Is unusual behaviour automatically malicious?
No. Context and validation are required.
Remote work changes normal user behaviour and the AI system begins producing many false alarms.
Possible issue?
Model or behavioural drift.
AI automatically disables a critical production account based on a low-confidence alert.
Primary concern?
Inappropriate automation without sufficient confidence or guardrails.
Security wants to know whether all required endpoints actually have active EDR.
Which metric?
Control coverage and health.
An organisation has excellent internet-edge IDS visibility but none between internal network segments.
Which gap?
Internal / east-west detection coverage.
Network IDS sees encrypted TLS sessions but cannot inspect the application payload.
Which issue?
Encrypted-traffic visibility.
An IPS fails and all network traffic stops.
Which behaviour?
Fail closed.
The same IPS fails and traffic bypasses security inspection.
Which behaviour?
Fail open.
One inline firewall failure can stop every customer transaction.
Which architecture concern?
Single point of failure / resilience.
A new IPS signature is deployed and starts blocking legitimate traffic.
Which operational controls matter?
Testing, tuning, change management and rollback.
Security purchased an expensive detection product but never checks whether it identifies the attacks it was intended to detect.
Primary weakness?
Control effectiveness has not been validated.
Management asks for the central principle of CISSP 7.7.
Best answer?
Operate layered preventive and detective controls, keep them healthy and current, tune them to the environment and verify that they actually provide the intended protection.
Recognise the Clue Words
Permit / Deny Network Traffic
Boundary control.
FirewallHTTP Attack
Application traffic.
WAFApplication-Aware Firewall
Advanced inspection.
NGFWTraffic Coming In
Direction.
IngressTraffic Going Out
Direction.
EgressDetect Only
Alert.
IDSDetect + Block
Prevention.
IPSTraffic Copy
Observe.
Passive IDSTraffic Passes Through
Enforce.
Inline IPSKnown Attack Pattern
Pattern match.
SignatureUnusual Behaviour
Deviation.
Anomaly DetectionAlarm ยท No Attack
Wrong alarm.
False PositiveAttack ยท No Alarm
Miss.
False NegativeToo Many Alerts
Improve quality.
TuningOnly Approved Software
Known good.
AllowlistingKnown Malicious Domain
Known bad.
BlocklistingMDR / MSSP
External security capability.
Third-Party ServiceRun Suspicious File Safely
Isolation.
SandboxMalware Knows It Is Analysed
Hide behaviour.
Sandbox EvasionFake Server
Deception.
HoneypotFake Network
Deception environment.
HoneynetFake Credential
Tripwire.
HoneytokenKnown Malware Pattern
Endpoint scan.
Anti-Malware SignatureRansomware-Like Behaviour
Behaviour.
Anti-Malware / EDRSecurity Agent Stopped
Control tampering?
InvestigateML Behaviour Changed
Environment changed.
Model DriftAI Says Suspicious
Not proof.
Validate ContextIs Control Running?
Operational state.
Control HealthAre All Assets Protected?
Reach.
CoverageDoes It Actually Detect?
Assurance.
Effectiveness TestingFailure Permits Traffic
Availability favoured.
Fail OpenFailure Blocks Traffic
Security enforcement.
Fail Closedโ ๏ธ Common CISSP Mistakes Know what the control actually does
Prevention attempts to stop activity. Detection identifies activity.
An IPS can detect and prevent.
Permitted traffic can still contain attacks.
They inspect and protect different aspects of communication.
Configuration still matters.
One controls inbound traffic, the other outbound.
Rules require review and retirement.
IDS primarily detects. IPS can attempt to prevent.
Passive sensors observe; inline controls can directly enforce traffic decisions.
Signatures are strongest when malicious patterns are already known.
Legitimate behaviour can also be unusual.
Detection needs useful signal rather than unlimited noise.
False positive = harmless activity alerted.
False negative = attack missed.
Allowlisting defines what may operate. Blocklisting defines what may not.
Unknown malicious entities may not yet appear on the list.
Legitimate software changes must be accommodated.
Provider and customer responsibilities must be defined.
Accountability remains with the organisation.
Malware can alter behaviour or evade analysis.
Isolation technology can also have weaknesses.
Its primary purpose is deception and observation.
A compromised decoy should not provide access to real assets.
Health, updates, configuration and coverage matter.
Modern protection may include heuristics, behaviour and reputation.
Attackers may intentionally disable security controls.
Model output requires appropriate interpretation.
Machine-learning tools still make classification errors.
Environment and model behaviour should be monitored for drift.
High-impact preventive actions may need appropriate guardrails.
Alternative telemetry and inspection points may still provide useful detection.
Internal and cloud environments may require additional visibility.
Blocking traffic during control failure may affect critical service availability.
Traffic may continue without required inspection.
Inline controls may require resilience and redundancy.
Detection and prevention should be validated through appropriate testing.
Quick Reference
| If you see... | Think... |
|---|---|
| Control network communication | Firewall |
| Protect HTTP application traffic | WAF |
| Application-aware firewall + threat inspection | NGFW |
| Traffic entering | Ingress |
| Traffic leaving | Egress |
| Detect intrusion | IDS |
| Detect and stop intrusion | IPS |
| Known malicious pattern | Signature |
| Unusual behaviour | Anomaly Detection |
| Benign activity generates alert | False Positive |
| Attack generates no alert | False Negative |
| Too much detection noise | Tuning |
| Only approved entities allowed | Allowlisting |
| Known malicious entities denied | Blocklisting |
| External detection provider | MDR / MSSP |
| Restricted execution environment | Sandbox |
| Malware hides from analysis | Sandbox Evasion |
| Decoy server | Honeypot |
| Decoy network | Honeynet |
| Decoy credential or record | Honeytoken |
| Detect malicious software | Anti-Malware |
| Endpoint telemetry + response | EDR |
| Security agent unexpectedly stopped | Possible Defence Evasion |
| ML identifies unusual pattern | AI / Behaviour Detection |
| Normal behaviour changes over time | Model Drift |
| Does control cover all assets? | Coverage |
| Is sensor functioning? | Control Health |
| Does control detect the attack? | Effectiveness Testing |
| Failure permits traffic | Fail Open |
| Failure denies traffic | Fail Closed |
Firewall Memory Aid
IDS / IPS Memory Aid
Allow / Block Memory Aid
Allowlist = Known Good ยท Blocklist = Known Bad
Isolation & Deception Memory Aid
7.7 Master Memory Aid
Prevent โ Detect โ Tune โ Test โ Improve
The Security Operations Questions
Key Takeaways
CISSP 7.7 focuses on operating and maintaining detection and preventative security measures.
The current CISSP outline explicitly includes firewalls, IDS/IPS, whitelisting/blacklisting, third-party security services, sandboxing, honeypots/honeynets, anti-malware and machine-learning/AI-based tools.
Prevention and detection are different security-control functions.
Preventive controls attempt to stop unwanted activity from succeeding.
Detective controls identify potentially malicious activity so it can be investigated or acted upon.
Some controls perform both functions.
Prevention = stop it. Detection = find it.
Defence in depth means relying on several complementary controls rather than expecting one product to stop every attack.
A firewall controls network communication according to security policy.
Firewall decisions may consider addresses, protocols, ports, connection state, applications, users and other contextual information depending on the technology.
Network firewalls and Web Application Firewalls operate at different levels.
A network firewall can permit HTTPS while a WAF separately identifies a malicious HTTP request carried inside that permitted service.
Network firewall = should this network communication occur? WAF = is this web request appropriate?
Next-generation firewalls can combine traditional firewall capabilities with deeper application and threat inspection.
Advanced technology does not compensate for poor configuration.
Firewall policy should follow business requirements and least privilege.
Default-deny approaches allow explicitly required communications and deny other traffic.
Ingress controls traffic entering a network or security zone.
Egress controls traffic leaving it.
Egress filtering can help prevent or identify compromised systems communicating with attacker infrastructure.
Firewall rules require lifecycle management.
Rules should be requested, justified, approved, implemented, tested, monitored, reviewed and removed when no longer required.
Temporary rules are particularly dangerous when temporary quietly becomes permanent.
Intrusion Detection Systems identify potentially malicious activity.
Intrusion Prevention Systems can detect malicious activity and also attempt to stop it.
IDS = detect and alert. IPS = detect and attempt to prevent.
Passive sensors can observe copies of network traffic.
Inline controls sit in the enforcement path and can directly influence traffic.
Network-based detection focuses on communications.
Host-based detection provides visibility into activity occurring on individual systems.
Signature-based detection identifies known malicious patterns.
Anomaly or behaviour-based detection identifies activity that differs from expected patterns.
Signature = have I seen this malicious pattern? Anomaly = does this behaviour look unusual?
Unusual does not automatically mean malicious.
A false positive occurs when harmless activity is incorrectly identified as malicious.
A false negative occurs when malicious activity is incorrectly treated as benign or remains undetected.
False positive = alarm without attack. False negative = attack without alarm.
Excessive false positives create alert fatigue and consume analyst resources.
Detection tuning attempts to improve useful signal while preserving important coverage.
Detection should evolve as applications, users, networks and threats change.
The CISSP outline still uses the terms whitelisting and blacklisting.
Modern documentation also commonly uses allowlisting and blocklisting or denylisting.
Allowlisting defines what is permitted.
Blocklisting defines what is prohibited.
Allowlist = known or approved good. Blocklist = known bad.
Application allowlisting can prevent execution of software that is not explicitly authorised.
This can be very powerful where the authorised software set is reasonably controlled.
It also requires good change management because legitimate applications and versions change.
Blocklists are useful for known malicious domains, addresses, hashes, applications and other indicators.
However, a blocklist cannot automatically recognise malicious infrastructure that has never been identified before.
Third-party security providers can deliver detection and preventive capabilities.
Examples include managed security monitoring, managed detection and response, DDoS protection, cloud WAF, email filtering and DNS security.
Provider responsibilities should be clearly defined.
Organisations should understand what is monitored, when monitoring occurs, how alerts are escalated, what actions the provider may perform and what information remains available to the customer.
Outsourcing the security service does not outsource accountability for organisational risk.
Sandboxing provides a restricted environment for executing untrusted or suspicious code.
Security systems can observe file, process, network and persistence behaviour before deciding whether the content should be permitted.
Sandbox results are not absolute proof that software is safe.
Malware can attempt to identify analysis environments and hide its malicious behaviour.
This is commonly known as sandbox evasion.
The sandbox itself must also be securely isolated because vulnerabilities in the isolation mechanism can create sandbox-escape risk.
Honeypots are deceptive systems or resources designed to attract suspicious activity.
Honeynets extend the deception concept across multiple systems or an apparent network.
Honeytokens apply similar thinking to deceptive information such as fake credentials, keys or records.
Honeypot = fake system. Honeynet = fake network. Honeytoken = fake information.
Because legitimate users should have little reason to interact with properly designed deception resources, such activity can generate useful security signals.
Honeypots must be appropriately isolated so a compromised decoy cannot become an attack platform against production systems.
Anti-malware technology can use signatures, heuristics, behavioural analysis and reputation information to identify malicious software.
Prevention capabilities may block or quarantine malicious programs before they execute successfully.
Modern endpoint protection and EDR capabilities can extend beyond traditional antivirus by providing behaviour telemetry, investigation, threat hunting and response functions.
Anti-malware protection should be maintained and monitored.
Security teams should know whether the agent is installed, running, updated, correctly configured and communicating with its management service.
Installed โ healthy. Healthy โ current. Current โ effective.
Attackers can attempt to disable security controls, including endpoint agents, logs and firewall policies.
Unexpected loss of a security control can therefore itself be valuable security telemetry.
Machine-learning and AI-based tools can analyse large quantities of security information and identify patterns, anomalies and correlations.
Possible uses include malware classification, behaviour analytics, alert prioritisation, network anomaly detection and analyst assistance.
AI-based detection still produces false positives and false negatives.
Its output should therefore be interpreted according to context and risk.
Behavioural models can lose effectiveness when normal organisational behaviour changes.
This creates the need to consider model and behavioural drift.
Attackers may also deliberately modify their behaviour to evade detection.
Automated preventive action should consider both:
detection confidence and consequence of being wrong.
A low-confidence automated decision that shuts down a critical service can itself cause substantial business harm.
"Operate and maintain" is an important part of the 7.7 objective.
Controls should be monitored for health, coverage, configuration, updates, tuning and effectiveness.
Security teams should understand which assets are actually protected.
A control cannot protect an asset it does not cover.
Sensor placement influences visibility.
Internet-edge monitoring alone may not identify lateral movement between internal systems.
Encrypted traffic also changes what network controls can inspect.
Endpoint telemetry, application logs, flow information and appropriately designed inspection points can provide complementary visibility.
Inline security controls can create availability dependencies.
Fail-open behaviour prioritises continued communication when the control fails but may allow traffic to bypass inspection.
Fail-closed behaviour denies communication when the control fails but can affect availability.
Critical inline controls may therefore require resilient architectures.
Changes to firewalls, IPS rules and other preventive technologies should be controlled and tested.
An incorrectly configured security control can block legitimate business activity just as effectively as it blocks an attacker.
Security measures should therefore be tested rather than merely assumed to work.
Installed โ enabled. Enabled โ configured correctly. Configured correctly โ proven effective.
Detection and preventive controls work best as layers.
A firewall may miss an application attack that a WAF catches.
A WAF may miss malware that endpoint security catches.
Endpoint security may miss behaviour that identity analytics detects.
The central CISSP principle is: deploy layered preventive and detective measures, understand what each control can and cannot see, keep the controls healthy and current, tune them to the environment and verify regularly that they provide the protection you expect.
๐ Sources & Further Reading Detection, prevention and security-control references
- ISC2 - CISSP Certification Exam Outline
View the current CISSP Exam Outline - NIST SP 800-53 Rev. 5 - Security and Privacy Controls for Information Systems and Organizations
View NIST SP 800-53 - NIST SP 800-41 Rev. 1 - Guidelines on Firewalls and Firewall Policy
View NIST firewall guidance - NIST SP 800-94 - Guide to Intrusion Detection and Prevention Systems
View NIST IDS/IPS guidance - NIST SP 800-167 - Guide to Application Whitelisting
View NIST application-control guidance - NIST SP 800-83 Rev. 1 - Guide to Malware Incident Prevention and Handling for Desktops and Laptops
View NIST malware guidance - NIST - Sandbox Glossary
View NIST sandbox terminology - NIST - Honeypot Glossary
View NIST honeypot terminology - NIST AI Risk Management Framework
View the NIST AI RMF resources
