---
title: How CSC can help build your InfoSec framework
description: How CSC can help build your InfoSec framework
---

[![TowerWall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/head-logo-2.svg "TowerWall")](https://towerwall.com/)

[![TowerWall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/towerwall-logo-white-test.svg "TowerWall")](https://towerwall.com/)

- [Our Partners](https://towerwall.com/how-we-protect-you/our-technology-partners/)
- Our Solutions 
    - - Our Cybersecurity Solutions 
                  - We operationalize infosec,  
                     building security solutions that  
                     safeguard your most critical assets.
          - - [Solutions Overview](https://towerwall.com/cybersecurity-solutions/)
                  - [Risk Assessments & Security Reviews](https://towerwall.com/cybersecurity-solutions/risk-assessments-security-reviews/)
                  - [Program & Policy Development](https://towerwall.com/cybersecurity-solutions/program-policy-development/)
                  - [Incident Response & Remediation](https://towerwall.com/cybersecurity-solutions/incident-response-remediation/)
                  - [Managed Detection & Response](https://towerwall.com/cybersecurity-solutions/managed-detection-response/)
          - - [Compliance & Privacy](https://towerwall.com/cybersecurity-solutions/compliance-privacy/)
                  - [Comprehensive Security Training](https://towerwall.com/cybersecurity-solutions/comprehensive-security-training/)
                  - [Vulnerability Protection](https://towerwall.com/cybersecurity-solutions/vulnerability-protection/)
                  - [Penetration Testing](https://towerwall.com/cybersecurity-solutions/penetration-testing/)
- Virtual Security Officers 
    - - Virtual Security Officer 
                  - Leverage the experience and  
                     security acumen of Towerwall’s  
                     on-demand security experts.
          - - [Virtual Chief Information Security Officer (VCISO)](https://towerwall.com/virtual-security-officers/virtual-chief-information-security-officer-vciso/)
                  - [Virtual Data Protection Officer (vDPO)](https://towerwall.com/virtual-security-officers/virtual-data-protection-officer-vdpo/)
                  - [Virtual Chief Privacy Officer (vCPO)](https://towerwall.com/virtual-security-officers/virtual-chief-privacy-officer-vcpo/)
- We Advise 
    - - We Advise 
                  - One-size security solutions only  
                     lead to failure.
          - Industries 
                  - [Higher Education](https://towerwall.com/industries/higher-education/)
                  - [Financial Services & Banking](https://towerwall.com/industries/financial-services-banking/)
                  - [Healthcare](https://towerwall.com/industries/healthcare/)
                  - [BioPharma & Bio-Therapeutics](https://towerwall.com/industries/biopharma-bio-therapeutics/)
                  - [Retail](https://towerwall.com/industries/retail/)
                  - [Government](https://towerwall.com/industries/government/)
                  - [Catholic Diocese](https://towerwall.com/industries/catholic-diocese-cybersecurity/)
                  - [Cannabis](https://towerwall.com/industries/cannabis/)
                  - [Small Business](https://towerwall.com/industries/small-business/)
                  - [Enterprise](https://towerwall.com/industries/enterprise/)
          - Trends & Threats 
                  - [Remote Workforce](https://towerwall.com/trends-threats/remote-workforce/)
                  - [Vendor Questionnaire](https://towerwall.com/trends-threats/vendor-questionnaire/)
                  - [HIPAA](https://towerwall.com/trends-threats/hipaa/)
                  - [Ransomware](https://towerwall.com/trends-threats/ransomware/)
                  - [GDPR](https://towerwall.com/trends-threats/gdpr/)
                  - [Cloud Security](https://towerwall.com/trends-threats/cloud-security/)
                  - [Phishing](https://towerwall.com/trends-threats/phishing/)
                  - [Cybersecurity Insurance](https://towerwall.com/trends-threats/cybersecurity-insurance/)
- [Resources](https://towerwall.com/resources/) 
    - - Resources 
                  - Our latest insights, events,  
                     and tools to keep you safe.
          - - [Insights](https://towerwall.com/resources/?resources_category=MTU%3D&focusarea=0&industries=0&search=)
                  - [Webinars](https://towerwall.com/resources/?resources_category=MTg%3D&focusarea=0&industries=0&search=)
                  - [Whitepapers](https://towerwall.com/resources/?resources_category=MTY%3D&focusarea=0&industries=0&search=)
                  - [View All](https://towerwall.com/resources/)
- [Company](https://towerwall.com/company/) 
    - - Our Company 
                  - We are the industry’s leading cybersecurity preparedness partner.
          - - [Who We Are](https://towerwall.com/company/)
                  - [Our Team](https://towerwall.com/company/our-team/)
                  - [Our Approach](https://towerwall.com/our-approach/)
                  - [Our Values](https://towerwall.com/company/our-values/)
          - - [Awards & Recognition](https://towerwall.com/company/awards-recognition/)
                  - [Certifications & Affiliations](https://towerwall.com/company/certifications-affiliations/)
                  - [Community Involvement](https://towerwall.com/company/community-involvement/)
                  - [Careers](https://towerwall.com/company/careers/)
                  - [Contact Us](https://towerwall.com/company/contact-us/)

Topics  cannabis, Enterprise

# How CSC can help build your InfoSec framework

[By Michelle Drolet](https://blog.towerwall.com/author/towerwall2020)

[Read More](https://blog.towerwall.com/author/towerwall2020)

 3 Minute Read

October 28, 2015

## Critical Security Controls is a set of best practices devised by the Center for Internet Security, a nonprofit dedicated to improving cybersecurity in the public and private sectors.

Cyberattacks are costing businesses between $400 billion and $500 billion per year, depending on which analysts you listen to. Cybersecurity has never been a hotter topic. The market is expected to grow from $106 billion this year to more than $170 billion by 2020, according to [Markets and Markets](http://www.marketsandmarkets.com/PressReleases/cyber-security.asp). The average cost of a data breach, by the time you factor in remediation, non-compliance fines, and brand damage, is tough to accurately calculate, but it's high, and it's rising.

The [Heartbleed vulnerability](http://www.networkworld.com/article/2176022/router/heartbleed-bug-hits-at-heart-of-many-cisco--juniper-products.html) was 2014's catastrophic security bug, and it had a wide-reaching impact. But even as companies pour more money into security services and platforms, the exploit still remains on many servers. As the IoT threatens new avenues of risk, the response in the enterprise is mixed, and good practices in some areas are being severely undermined by a casual approach in others.

### Building a solid foundation

Just as a house built on sand is not going to last, an InfoSec strategy that lacks a solid foundation is going to fail, no matter how much money you throw at it. We hear plenty about the [growth in software vulnerabilities](http://www.networkworld.com/article/2953304/security/software-vulnerabilities-on-the-rise-record-high-report.html), the rise of malware and [ransomware](http://www.networkworld.com/article/2944043/cloud-security/don-t-get-mad-at-ransomware-thugs-say-thank-you.html), and the [risk of ignoring threats](http://www.networkworld.com/article/2922196/security0/top-7-security-threats-too-often-ignored.html), but what should you be doing?  
 A great place to start creating your InfoSec framework is with the [CIS](http://www.cisecurity.org/critical-controls/) (Center for Internet Security) Critical Security Controls. This is a recommended set of best practices, put together by government and law enforcement agencies, that focuses on actionable ways to bolster your cyber defenses. You'll find a full explanation at the[SANS institute](https://www.sans.org/critical-security-controls/).

Taking any of the 20 actions on the list will have a positive impact on your security status, but the smart move is to work towards fulfilling the full range.

### A step in the right direction

These are simple common-sense rules, but you'd be amazed at how often they're overlooked. We don't have time to cover everything in this article, but if we just take a brief look at the first couple of entries on the list, you'll get an idea of the practical advice within.  
***Critical Control 1 – Inventory of Authorized and Unauthorized Devices***  
 Building a good security foundation is about asking the right questions and identifying gaps in your knowledge. This first control is absolutely fundamental to security, but many organizations will struggle to answer questions like:

- How many servers do you have in total?
- How many devices are connected to your network?
- What about firewalls, switches, and routers?
- Can you control what joins your network?

There's no way you can have a complete map, or flag potential vulnerabilities, without knowing exactly what hardware you have. An up-to-date, comprehensive hardware inventory is essential.  
***Critical Control 2 - Inventory of Authorized and Unauthorized Software***  
 You should take this together with the first control and devise a list of authorized software that covers every system and device you're using. You'll need to be able to monitor your software in real-time to validate versions and ensure that unapproved apps are blocked or, at least, flagged.

To ensure vulnerabilities and exploits are dealt with in a timely fashion, you also need to know what operating systems and versions of software are in use, and have a system to flag necessary updates based on new threats as they emerge.

### It takes time

As you can see, simply creating an accurate inventory of your hardware and software can be a big undertaking. Rome wasn't built in a day, and you'll find it takes time and resources to build a good InfoSec framework, too. What's important is to formulate a plan that takes a holistic view. Start working through the steps outlined in the Critical Security Controls, and your defense will be strengthened with every step you take.  
 Whether you're training up a team, hiring a new CISO, or engaging the services of a security consultancy, this list arms you with a solid framework to measure your efforts against. It's invaluable actionable guidance, and it has the potential, not just to improve individual security, but to boost our collective security online. Every business should consider making it a starting point for building that solid security foundation.  
*The opinions expressed in this Blog are those of Michelle Drolet and do not necessarily represent those of the IDG Communications, Inc., its parent, subsidiary or affiliated companies.*

This article was recently published in [Network World](http://www.networkworld.com/article/2997643/network-security/how-csc-can-help-build-your-infosec-framework.html).  
*Image courtesy ofVictor Cruz.*

#### How CSC can help build your InfoSec framework

Back to Top

## Related Insights

### [Applying more Critical Security Controls to your organization](https://blog.towerwall.com/applying-more-critical-security-controls-to-your-organization)

 cannabis, Enterprise

### [Hundreds of cloud apps still vulnerable to DROWN](https://blog.towerwall.com/hundreds-cloud-apps-still-vulnerable-drown)

 cannabis, Enterprise

[View All Insights](https://blog.towerwall.com)

×

## Talk with us now about:

#### Your security needs.

- ![Phone](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/phone-icon.svg "Phone")
  
  [Call 774.204.0700](tel:774.204.0700)
- ![Mail](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/mail-icon.svg "Mail")
  
  [Email Us](mailto:info@towerwall.com)

### The front line of cybersecurity.™

For over 23 years, Towerwall, a woman-owned business, has helped scores of companies safeguard their data and leverage their investment in IT with advanced information security technology solutions and services. Our experience in all facets of information security coupled with serving in the CIO/CISO/ISO roles provides a unique first-hand understanding of the security challenges organizations face daily.

### Connect

- <https://blog.towerwall.com/info@towerwall.com>
- <https://www.linkedin.com/company/towerwall-inc.?trk=pro_other_cmpy>
- <https://twitter.com/Towerwall>
- <https://www.facebook.com/Towerwall>

- [Career Opportunities](https://towerwall.com/company/careers/)
- [Contact Us](https://towerwall.com/company/contact-us/)

© Towerwall, Inc. and its licensees. All rights reserved [Privacy Policy](http://towerwall.com/privacy-policy/) Sitemap [Created by Howbridge](https://meethowbridge.com/)

[![Towerwall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/footer-logo.svg "Towerwall")](https://towerwall.com/)