Skip to main content
Guidance

How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI

Act now to be ready to withstand and recover from severe cyber attacks.

Page 4 of 26

1.2 Know what you’re protecting and understand your attack surface

You should maintain a definitive record of your systems since you can’t defend an asset if you don’t know about it. This should be a continually updated, accurate and up-to-date view of your system (or element of a system). The definitive record will change over time as all system changes are recorded to maintain its accuracy and authority. It captures the system architecture as a holistic design that not only encompasses the components of a system (including technology, security controls, people and process), but how these elements integrate into larger business functions and objectives. This helps you understand your attack surface.

For operational technology (OT) and ICS create a separate inventory that maps critical assets and their relationship to business processes. Start by mapping your most critical systems, then expand coverage to all assets. Focus on assets that, if compromised, would cause the most damage to your operations or public safety. 

How to know what you're protectingHow it helps
Ensure you have a definitive record of all your systems, devices, software, and data assets, and that these are visible to your security systems.
  • Revisiting your definitive record is essential in a period of severe threat. 
  • The definitive record, coupled with knowledge about the emerging severe threat, enables you to take proportionate actions to manage down your risk.
Remove assets you no longer need.
  • Reduces your attack surface.

Published

Reviewed

Version

1.0