Please enable JavaScript.
Coggle requires JavaScript to display documents.
🏛️ National Cybersecurity Authority (NCA) Enterprise Security Perspective…
🏛️ National Cybersecurity Authority (NCA) Enterprise Security Perspective
🏛️ National Cybersecurity Authority (NCA) Enterprise Security Perspective
1️⃣ Cybersecurity Governance Foundation
📘 What is Governance
Governance defines how an organization manages cybersecurity decisions, responsibilities, policies, and controls.
Ensures security aligns with business objectives and national regulations.
🏢 Enterprise Security Structure
Board Level
Security strategy approval
Risk acceptance decisions
Executive Level
Chief Information Security Officer (CISO)
Responsible for cybersecurity program
Security Operations Level
Security Operations Center (SOC)
Detects, investigates, responds to threats
Infrastructure Team
Linux Administrators
Network Engineers
Cloud Engineers
Audit and Compliance Team
Ensures regulatory compliance
2️⃣ National Cybersecurity Authority (NCA) Framework Understanding
🇸🇦 National Cybersecurity Authority
Saudi government authority responsible for cybersecurity governance.
NCA Essential Cybersecurity Controls (ECC)
A cybersecurity control framework defining mandatory security requirements.
Purpose
Protect government and critical infrastructure systems
Security Domains
Cybersecurity Governance
Cybersecurity Defense
Third Party Security
Cloud Security
Industrial Control Security
Data Security
3️⃣ Enterprise Linux Infrastructure Architecture
🖥️ Linux Server Environment
Production Servers
Web Servers
Database Servers
Application Servers
Authentication Servers
File Servers
Development Environment
Testing Servers
Staging Servers
Disaster Recovery Environment
Backup Systems
Recovery Servers
4️⃣ Linux Operating System Fundamentals
🐧 Linux Distribution Understanding
Red Hat Enterprise Linux (RHEL)
Enterprise Linux operating system
Used in banking, government, critical infrastructure
Ubuntu Server
Debian based enterprise Linux distribution
SUSE Linux Enterprise Server (SLES)
Enterprise Linux used in large organizations
Linux Architecture
Kernel
Core component managing hardware and system resources
Shell
Command interface between user and operating system
File System
Structure used to store files and configurations
Services
Background processes providing functionality
5️⃣ Enterprise Linux Identity and Access Management
🔐 Identity Management
User Management
Local Users
Created directly on Linux server
Centralized Users
Managed by enterprise identity systems
Directory Services
Lightweight Directory Access Protocol (LDAP)
Protocol used to access centralized user directories
Active Directory (AD)
Microsoft identity management platform
Authentication
Password Authentication
Multi Factor Authentication (MFA)
Multiple verification methods
Example:
Password
Hardware token
Mobile authentication
Authorization
Defines what users can access
Privilege Management
sudo
Super User Do
Allows controlled administrative access
sudoers
/etc/sudoers
Controls:
Users
Groups
Commands
Permissions
Principle of Least Privilege
Users receive minimum required permissions
6️⃣ Enterprise Linux User and Group Security
👥 User Management
User Account Lifecycle
Creation
Modification
Disable
Removal
Groups
Purpose
Manage permissions for multiple users
Shared Directory Security
Set Group ID (SGID)
Ensures new files inherit directory group ownership
Access Control Lists (ACL)
Advanced permission management
Allows specific user permissions
7️⃣ Linux File System Security
📂 Linux File Permissions
Owner Permission
Group Permission
Others Permission
Permission Types
Read (r)
Write (w)
Execute (x)
Special Permissions
Set User ID (SUID)
Runs program with file owner's privileges
Set Group ID (SGID)
Maintains group inheritance
Sticky Bit
Prevents users deleting other users files
8️⃣ Linux Security Hardening
🔒 Server Hardening
Remove unnecessary software
Disable unused services
Apply security updates
Configure firewall
Secure authentication
Security Configuration
Password Policy
Account Lockout
Session Timeout
SSH Security
9️⃣ Secure Shell SSH Enterprise Security
🔑 Secure Shell (SSH)
Remote administration protocol
SSH Hardening
Disable root login
Use SSH keys
Disable password authentication
Change default configurations
SSH Security Monitoring
Failed login detection
Brute force detection
Unauthorized access detection
🔟 Linux Firewall Enterprise Security
🧱 Firewall
Controls network traffic entering and leaving systems
Linux Firewall Technologies
firewalld
iptables
nftables
Firewall Concepts
Zones
Rules
Ports
Services
Network Segmentation
1️⃣1️⃣ SELinux Enterprise Mandatory Access Control
🛡️ Security Enhanced Linux (SELinux)
Security framework developed by National Security Agency (NSA)
Security Models
Mandatory Access Control (MAC)
System controls permissions based on security policies
Discretionary Access Control (DAC)
Users control their own files
SELinux Components
Context Labels
Policies
Enforcement Modes
Modes
Enforcing
Permissive
Disabled
1️⃣2️⃣ Linux Patch and Vulnerability Management
🔍 Vulnerability Management
Identify
Analyze
Prioritize
Remediate
Vulnerability Tools
Nessus
OpenVAS
Qualys
Patch Management
Security updates
Kernel updates
Package updates
1️⃣3️⃣ Enterprise Linux Logging and Monitoring
📊 Logging Architecture
Linux Logs
Authentication Logs
System Logs
Application Logs
Important Files
/var/log/messages
/var/log/secure
/var/log/auth.log
Log Management
Centralized Logging
Log Retention
Log Analysis
1️⃣4️⃣ Security Information and Event Management (SIEM)
🛰️ SIEM
Security Information and Event Management
Platform that collects, analyzes, and detects security events
Enterprise SIEM Platforms
Elastic Security
Splunk
Microsoft Sentinel
SIEM Functions
Log Collection
Correlation
Detection Rules
Alerting
Investigation
1️⃣5️⃣ Endpoint Detection and Response (EDR)
🛡️ EDR
Endpoint Detection and Response
Security technology monitoring servers and endpoints
Functions
Process Monitoring
Malware Detection
Behavior Analysis
Response Actions
1️⃣6️⃣ Linux Intrusion Detection
🚨 Host Intrusion Detection System (HIDS)
OSSEC
Open Source Security
Wazuh
Enterprise security monitoring platform
Detection Areas
File Integrity Monitoring
Rootkit Detection
Authentication Monitoring
Policy Violations
1️⃣7️⃣ Linux File Integrity Monitoring
📁 FIM
File Integrity Monitoring
Detects unauthorized changes
Tools
AIDE
Advanced Intrusion Detection Environment
Tripwire
Enterprise file integrity monitoring solution
Monitoring
System binaries
Configuration files
Security files
1️⃣8️⃣ Enterprise Incident Response
🚨 Incident Response Lifecycle
Preparation
Identification
Containment
Eradication
Recovery
Lessons Learned
Investigation Tools
Linux Logs
Memory Analysis
Disk Analysis
Network Evidence
1️⃣9️⃣ Linux Threat Detection
MITRE ATT&CK Framework
Adversarial Tactics Techniques and Common Knowledge
Used to map attacker behavior
Detection Examples
Brute Force Attack
Privilege Escalation
Malware Execution
Persistence
2️⃣0️⃣ Enterprise Backup and Disaster Recovery
💾 Backup Strategy
Full Backup
Incremental Backup
Differential Backup
Disaster Recovery
Recovery Point Objective (RPO)
Maximum acceptable data loss
Recovery Time Objective (RTO)
Maximum acceptable downtime
2️⃣1️⃣ Compliance and Auditing
📋 Security Compliance
NCA ECC
ISO 27001
NIST Cybersecurity Framework
CIS Controls
Linux Auditing
auditd
Linux Audit System
Audit Rules
User Activity Monitoring
2️⃣2️⃣ Enterprise Linux Security Operations Center (SOC)
🏢 SOC Architecture
Tier 1 Analyst
Alert Monitoring
Tier 2 Analyst
Investigation
Tier 3 Analyst
Threat Hunting
Incident Response Team
Attack Containment
2️⃣3️⃣ Advanced Enterprise Linux Security Skills
Cloud Linux Security
Amazon Web Services (AWS)
Microsoft Azure
Google Cloud Platform
Container Security
Docker Security
Kubernetes Security
DevSecOps
Development Security Operations
Security integrated into software lifecycle
Automation
Ansible
Python
Shell scripting
2️⃣4️⃣ Enterprise Linux Security Mastery Path
Level 1
Linux Administration
Level 2
Linux Hardening
Level 3
Identity Security
Level 4
Monitoring and Detection
Level 5
SIEM Engineering
Level 6
Incident Response
Level 7
Threat Hunting
Level 8
Enterprise Security Architecture