π‘οΈ Cybersecurity Defense Architecture β Hierarki Pertahanan Sistem Digital
Cybersecurity bukan satu produk β ia adalah 9 lapis pertahanan yang harus diterapkan simultan. Catatan ini memetakan seluruh attack surface ke dalam Defense-in-Depth hierarchy, dari ancaman fisik sampai reputasi, dengan NIST CSF 2.0 alignment, OSI layer mapping, timeline evolusi (1960-2026), dan trade-off matrix per layer. Setiap layer punya kontrol, tool, framework, dan failure mode sendiri.
Daftar Isi
- 1. Premise β Mengapa βSatu Layer = Amanβ Itu Mitos
- 2. Nine-Layer Defense-in-Depth Model
- 3. Layer L9 β Brand & Reputation
- 4. Layer L8 β Compliance & Legal
- 5. Layer L7 β Identity & Access (IAM)
- 6. Layer L6 β Application Security
- 7. Layer L5 β Endpoint Security (EDR/XDR)
- 8. Layer L4 β Network Security
- 9. Layer L3 β Data Security & Cryptography
- 10. Layer L2 β Cloud & Infrastructure
- 11. Layer L1 β Physical & Hardware
- 12. Layer L0 β Threat Intelligence & Governance
- 13. OSI Layer Mapping
- 14. NIST CSF 2.0 Alignment
- 15. Timeline 1960-2026 β Evolusi Ancaman
- 16. Cross-Reference ke Vault
- References
1. Premise β Mengapa βSatu Layer = Amanβ Itu Mitos
Kesalahan paling fatal dalam cybersecurity adalah mempercayai satu kontrol memberikan keamanan total:
- βPakai antivirus saja cukupβ β ransomware tetep masuk (1990-an)
- βPakai firewall saja cukupβ β insider threat bocor (2000-an)
- βPakai enkripsi saja cukupβ β side-channel attack bocor (2010-an)
- βPakai cloud security group saja cukupβ β misconfiguration bocor (2020-an)
Defense-in-Depth menyadari: setiap kontrol bisa gagal. Karena itu, kita stack 9 layer pertahanan β jika satu jebol, layer di belakangnya menahan.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β L9: Brand & Reputation β
β L8: Compliance & Legal β
β L7: Identity & Access β
β L6: Application Security β
β L5: Endpoint / EDR / XDR β
β L4: Network / NDR β
β L3: Data Security & Cryptography β
β L2: Cloud & Infrastructure β
β L1: Physical & Hardware β
β L0: Threat Intelligence & Governance β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β INCREASING ATTACKER REWARD β
DECREASING ATTACKER SKILL (zero-day exploits)
Prinsip Castle-and-Moat yang usang: perimeter saja tidak cukup β attacker masuk lewat berbagai vektor (phishing, supply chain, insider).
Prinsip Zero Trust modern: verifikasi setiap akses, dari setiap arah, dari setiap entitas β trust nothing.
2. Nine-Layer Defense-in-Depth Model
2.1 Definisi Setiap Layer
| Layer | Fungsi | Failure Mode Tipikal | Owner |
|---|---|---|---|
| L9 | Brand reputasi, crisis comms | Key product tak relevan setelah breach | PR, marketing |
| L8 | Compliance framework | Denda GDPR 4% revenue, PCI banned | Legal, GRC |
| L7 | Authentication, authorization | Akun compromised, privilege escalation | IAM team |
| L6 | App-level vulnerabilities | SQLi, XSS, RCE, supply chain | DevSecOps |
| L5 | Host-level detection & response | Ransomware lolos, lateral movement | SOC + EDR team |
| L4 | Network segmentation, IDS/IPS | East-west traffic tidak terlihat, DDoS | NetSec team |
| L3 | Encryption, key management, DLP | Data exfiltration, breach disclosure | DataSec |
| L2 | Cloud misconfig, IAM, secrets | S3 public bucket, IAM privilege excess | CloudSec |
| L1 | Data center access, hardware tampering | Boot-level implant, hardware backdoor | IT ops |
| L0 | Threat intel, governance, risk | Unknown unknown exploit | CISO, GRC |
2.2 Layer Dependency & Failover
[L0: intel feeds]ββββ feeds to βββββ [L4, L5, L6]
β
Detect threat signature
β
[L4: NDR]ββββ blocks βββββ if bypassed β [L5: EDR]ββββ blocks βββββ if bypassed β [L6: AppSec]
β
[L7: MFA catches]
β
[L3: encryption at rest]
β
[L1: physical security]
Jika L0-L6 gagal total, L7-L9 adalah last line of defense:
- L7: zero-trust dengan MFA tahan phising
- L3: data encrypted β theft tidak langsung berguna
- L9: brand reputation dijaga lewat respon krisis
3. Layer L9 β Brand & Reputation
Pertahanan tertinggi: memastikan bahwa bahkan setelah breach, brand tetap relevan.
3.1 Komponen
| Komponen | Fungsi |
|---|---|
| Incident response plan | Koordinasi respon saat breach terjadi |
| Crisis communications | Pernyataan publik, customer notification |
| Cyber insurance | Finansial cover untuk breach |
| Reputation monitoring | Dark web mentions, social sentiment |
| Customer trust restoration | Compensation, transparency |
3.2 Failure Mode
| Failure | Dampak | Contoh |
|---|---|---|
| Delay disclosure 6 bulan | GDPR fine β¬50M, brand drop 30% Yahoo (2017) | |
| Berbohong tentang cakupan breach | Multi-class lawsuit, executive ouster | Uber 2017 |
| Slow customer notification | 50% churn dalam 30 hari | Equifax (2017) |
| Tidak punya crisis comm team | Runaway story = market cap -20% | Target (2013) |
4. Layer L8 β Compliance & Legal
Memastikan organisasi mengikuti regulasi yang berlaku di industri + yurisdiksi.
4.1 Framework Compliance per Industri
| Industri | Wajib | Opsional |
|---|---|---|
| Healthcare (US) | HIPAA, HITECH | HITRUST, SOC 2 |
| Finance (US) | SOX, PCI DSS, GLBA | ISO 27001 |
| Finance (EU) | PSD2, Basel III, MiFID II | DORA |
| EU general | GDPR, NIS2, DSA | ISO 27001, 27017 |
| Cloud (US Fed) | FedRAMP, FISMA | CMMC |
| Energy/Utilities | NERC CIP | IEC 62443 |
| Privacy (US State) | CCPA, NYDFS | SOC 2 |
| Defense | CMMC, ITAR | FedRAMP High |
4.2 Dampak Compliance Failure
| Regulasi | Denda Tipikal |
|---|---|
| GDPR | 4% annual revenue OR β¬20M (mana yang lebih tinggi) |
| HIPAA | 50,000 per record + criminal |
| PCI DSS | 100K/month + kehilangan merchant |
| SOX | Criminal prosecution untuk officer |
| CCPA | $750 per record + class action |
| NIS2 | β¬10M atau 2% revenue |
5. Layer L7 β Identity & Access (IAM)
Siapa yang boleh melakukan apa, dan dari mana.
5.1 Komponen
| Komponen | Fungsi | Contoh |
|---|---|---|
| SSO | Single sign-on multi-app | Okta, Azure AD, Auth0 |
| MFA | Second factor from password | TOTP, FIDO2, push |
| PIM/PAM | Just-in-time admin | CyberArk, BeyondTrust |
| RBAC | Role-based access | AWS IAM, K8s RBAC |
| ABAC | Attribute-based access | Open Policy Agent |
| ZTA | Zero Trust Architecture | BeyondCorp, Zscaler |
| User behavior analytics | Anomaly detection on access | Splunk UBA, Exabeam |
5.2 Frameworks
- NIST SP 800-63 β Digital identity levels (IAL1-3, AAL1-3, FAL1-3)
- NIST SP 800-207 β Zero Trust Architecture
- OAuth 2.1 + OIDC β Modern delegated auth
- SAML 2.0 β Enterprise SSO
- SPIFFE/SPIRE β Workload identity
5.3 Failure Mode
| Attack | Mitigation |
|---|---|
| Phising | FIDO2 (WebAuthn) β tahan phising |
| Credential stuffing | MFA + breach detection |
| Session hijack | Short-lived JWT + refresh |
| Privilege escalation | Least privilege + JIT admin |
| Insider threat | UEBA + audit logs |
Koneksi ke Vault:
- hierarchy-cryptography β Public key infrastructure
- hierarchy-endpoint-security β EDR melihat user activity
6. Layer L6 β Application Security
Aplikasi itu sendiri β yang menerima input dari user dan memproses data.
6.1 OWASP Top 10 (2021) β Surface of Attack
| Rank | Vulnerability | Frequency |
|---|---|---|
| 1 | Broken Access Control | 3.81% |
| 2 | Cryptographic Failures | 4.49% |
| 3 | Injection | 4.74% |
| 4 | Insecure Design | 3.0% |
| 5 | Security Misconfiguration | 4.4% |
| 6 | Vulnerable & Outdated Components | 8.78% |
| 7 | Identification & Auth Failures | <1% |
| 8 | Software & Data Integrity Failures | 2.06% |
| 9 | Security Logging & Monitoring Failures | 6.51% |
| 10 | Server-Side Request Forgery | 1.43% |
6.2 SDLC Security Integration
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Requirements (Abuse cases) β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Design (Threat modeling STRIDE, attack trees) β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Coding (Secure code review, SAST) β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Testing (DAST, IAST, fuzzing, pentest) β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Build (SCA, SBOM, signed artifacts) β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Deploy (IaC scanning, secrets detection) β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Operate (RASP, WAF, observability) β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
6.3 Supply Chain Security (SBOM Era)
- SLSA (Supply-chain Levels for Software Artifacts) β Google framework
- Sigstore β Cosign signing
- in-toto β Attestation generation
- CycloneDX/SPDX β SBOM standards
- Sigstore Fulcio + Rekor β certificate transparency
Koneksi ke Vault:
7. Layer L5 β Endpoint Security (EDR/XDR)
Setiap device β laptop, server, IoT, container β adalah target.
7.1 Evolusi Endpoint Security
| Era | Teknologi | Deteksi | Response |
|---|---|---|---|
| 1990-2005 | Antivirus signature | Database signature | Quarantine file |
| 2005-2015 | Anti-malware heuristik | Rule-based | Block process |
| 2015-2020 | EDR (Endpoint Detection & Response) | Behavioral analytics | Isolate host, kill process |
| 2020-2024 | XDR (Extended Detection & Response) | Cross-domain correlation | Orchestrated response |
| 2024-2026 | AI-Native EDR | ML pattern + LLM analyst | Autonomous response |
7.2 EDR vs XDR vs NDR
| Aspek | EDR | XDR | NDR |
|---|---|---|---|
| Scope | Endpoint only | Endpoint + email + cloud + network | Network traffic only |
| Data source | Syscalls, file, registry | Multi-source unified | NetFlow, packet, pcap |
| Response | Kill process, isolate host | Cross-tier orchestrated | Block traffic, sinkhole |
7.3 MITRE ATT&CK Framework
ATT&CK = Adversarial Tactics, Techniques, and Common Knowledge β database taktik+teknik attacker:
- 14 Tactics β Recon, Initial Access, Execution, Persistence, Privilege Esc, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Exfiltration, Impact
- 200+ Techniques β spesifik behavior attacker
- 600+ Sub-techniques
Setiap kontrol EDR/XDR dipetakan ke ATT&CK technique yang bisa ia detect.
Koneksi ke Vault:
- hierarchy-endpoint-security β Dedicated endpoint security hierarchy
8. Layer L4 β Network Security
Arus lalu lintas di dalam dan antar jaringan.
8.1 Komponen Jaringan
| Komponen | Fungsi |
|---|---|
| Firewall (stateful) | Filter paket berdasarkan state |
| WAF (Web Application Firewall) | Filter HTTP/HTTPS sesuai rule |
| IDS/IPS | Intrusion Detection/Prevention |
| NDR | Network Detection & Response |
| NAC | Network Access Control |
| Microsegmentation | East-west isolation |
| VPN / ZTNA | Encrypted remote access |
| BGP RPKI | Route hijacking prevention |
| DDoS protection | Mitigation volumetric attacks |
8.2 OSI Layer Mapping
| OSI Layer | Ancaman | Kontrol |
|---|---|---|
| 1 (Physical) | Wiretap, EMP | Faraday cage, fiber tap detection |
| 2 (Data Link) | ARP spoof, MAC flood | Port security, 802.1X |
| 3 (Network) | IP spoof, route hijack | RPKI, BCP38 |
| 4 (Transport) | SYN flood, port scan | TCP RST, rate limit |
| 5 (Session) | Session hijack | Encrypted sessions, short JWT |
| 6 (Presentation) | SSL stripping | HSTS, certificate pinning |
| 7 (Application) | SQLi, XSS, mitm | WAF, input validation |
8.3 East-West vs North-South Traffic
North-South (in/out)
ββββββββββββββββββββββββ
β β
βββββββ βββββββ East-west βββββββ
β App βββββββ App β βββββββββββββ β App β
β 1 β β 2 β intra-DC β 3 β
βββββββ βββββββ βββββββ
β βββββββ β
ββββββββ DB ββββββββββ
βββββββ
- North-south traffic = traffic masuk/keluar DC (perimeter defense handles)
- East-west traffic = traffic antar-service dalam DC (microsegmentation handles)
- 80%+ modern traffic = east-west, tapi tool tradisional fokus north-south
Koneksi ke Vault:
- hierarchy-network-security
- hierarchy-wireless β Wireless subset
- hierarchy-kernel-bypass-networking β Kernel-level mitigasi
- hierarchy-offensive β Red team perspective
9. Layer L3 β Data Security & Cryptography
Data at rest, in transit, in use β diproteksi dengan kriptografi.
9.1 The Three States of Data
Data at Rest β Encryption at storage layer (LUKS, KMS, dm-crypt)
β Backup encryption
β Tokenization / anonymization
Data in Transit β TLS 1.3, WireGuard, IPsec, mTLS
β Certificate management (cert-manager)
β PFS (Perfect Forward Secrecy)
Data in Use β Confidential Compute (SEV-SNP, TDX, SGX)
β Memory encryption (AMD SME)
β Homomorphic encryption (research)
9.2 Key Management Lifecycle
Generate β Store β Distribute β Use β Rotate β Destroy
β β β β β β
β β β β β ββ Crypto-shred / zeroize
β β β β ββ Per Q3 / annual rotation
β β β ββ Access control (KMS+IAM)
β β ββ HSM, KMS, sealed secret
β ββ HSM (FIPS 140-3 L3)
ββ entropy source
9.3 Algoritma yang Direkomendasikan (2026)
| Use Case | Algoritma | Key Size |
|---|---|---|
| Symmetric encryption | AES-256-GCM | 256 bit |
| Asymmetric | Ed25519, X25519, ML-KEM-768 | - |
| Hashing (general) | SHA-3-256, BLAKE3 | 256-512 bit |
| Password hashing | Argon2id | 64-128 MB mem |
| TLS 1.3 | AES-256-GCM + Ed25519 | - |
| Backup | AES-256-GCM + Argon2id passphrase | - |
Koneksi ke Vault:
- hierarchy-cryptography
- hierarchy-quantum-cryptography-stack β PQC migration
- hierarchy-digital-plumbing β TLS/OpenSSL
10. Layer L2 β Cloud & Infrastructure
Konfigurasi cloud yang aman, IAM, secrets management, runtime security.
10.1 Cloud Security Failure Modes
| Failure | Contoh |
|---|---|
| Public S3 bucket | 100M+ records bocor (2017-2024 trends) |
| Excessive IAM permissions | Service account dengan admin |
| Secrets in source code | API keys di public repo |
| Unpatched container images | CVE ratusan di registry |
| Insecure API gateway | No auth, no rate limit |
| Misconfigured K8s | Privileged pod, hostPath mount |
10.2 CSPM, CIEM, CNAPP
| Tool Kategori | Fungsi | Vendor |
|---|---|---|
| CSPM (Cloud Security Posture Mgmt) | Multi-cloud config audit | Wiz, Prisma Cloud, Lacework |
| CIEM (Cloud Infrastructure Entitlement Mgmt) | IAM rightsizing | Sonrai, Ermetic |
| CNAPP (Cloud-Native App Protection Platform) | K8s runtime + observability | Wiz, Aqua, Snyk |
| Secrets Mgmt | Vault, KMS | HashiCorp Vault, AWS KMS, SOPS |
| IaC Scan | Terraform/Kubernetes audit | Checkov, tfsec, Trivy |
10.3 K8s-Specific Stack
βββββββββββββββββββββββββββββββββββββββββββββββββββ
β Cluster (managed: EKS/GKE/AKS) β
β ββ Control Plane encryption at rest β
β ββ etcd encryption β
β ββ Network Policy (Calico/Cilium) β
βββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Workload β
β ββ Pod Security Standards β
β ββ Runtime (Falco, Tetragon) β
β ββ Image scanning (Trivy, Grype) β
β ββ Supply chain (Sigstore, Kyverno) β
β ββ mTLS service mesh (Istio, Linkerd) β
βββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Pipeline β
β ββ Static analysis (kubescape, kube-bench) β
β ββ Admission control (OPA, Kyverno) β
β ββ Secret rotation (External Secrets, SOPS) β
βββββββββββββββββββββββββββββββββββββββββββββββββββ
Koneksi ke Vault:
- hierarchy-infrastructure-evolution β On-prem to cloud evolution
- container-kubernetes-security-deepdive
- kubernetes-security-roadmap
- cloud-infrastructure
11. Layer L1 β Physical & Hardware
Akses fisik ke hardware, secure boot, hardware backdoors.
11.1 Komponen
| Kontrol | Fungsi |
|---|---|
| Data center access controls | Biometric, mantrap, visitor log |
| Surveillance | CCTV, motion sensor, IR curtain |
| Hardware tamper-evident | Seal, intrusion sensor |
| Secure boot | BIOS/UEFI signature chain |
| TPM | Hardware root of trust, measured boot |
| HSM | Cryptographic key storage FIPS 140-3 |
| Faraday cage | EMP / TEMPEST shielding |
| Hardware attestation | TEE attestation remote |
11.2 Trusted Execution Environments (TEE)
| TEE | Vendor | Use Case |
|---|---|---|
| Intel SGX | Intel | Enclave computation (deprecated dari desktop) |
| Intel TDX | Intel | VM-level confidential computing |
| AMD SEV-SNP | AMD | VM-level + memory encryption |
| ARM TrustZone | ARM | Mobile, IoT normal mode |
| Apple SE | Apple | Secure enclave di iOS/Mac |
| AWS Nitro | AWS | Custom cloud hardware |
| Nvidia H100 CC | Nvidia | GPU confidential computing |
Koneksi ke Vault:
12. Layer L0 β Threat Intelligence & Governance
Paling bawah β fondasi intelijen + keputusan yang menggerakkan semua layer di atas.
12.1 Komponen Governance
| Komponen | Fungsi |
|---|---|
| CISO | Executive accountability untuk security |
| SOC | 24/7 monitoring, triage, response |
| GRC | Governance Risk Compliance |
| CTI | Cyber Threat Intelligence team |
| Red Team | Authorized adversary simulation |
| Bug Bounty | External researcher engagement |
| Penetration test | Scheduled adversarial testing |
12.2 Frameworks Inti
| Framework | Owner | Fungsi |
|---|---|---|
| NIST CSF 2.0 | NIST | Generic security framework (6 functions: Govern, Identify, Protect, Detect, Respond, Recover) |
| NIST SP 800-53 | NIST | Control catalog (1000+ controls) |
| ISO 27001/27002 | ISO | ISMS implementation |
| MITRE ATT&CK | MITRE | Adversary behavior catalog |
| CIS Controls | CIS | 18 prioritized actions |
| OWASP ASVS | OWASP | Application security verification |
12.3 Threat Intelligence Sources
| Tier | Sumber |
|---|---|
| Strategic | Vendor reports (Mandiant, CrowdStrike, Microsoft) |
| Operational | ISACs, threat sharing communities (MISP, STIX/TAXII) |
| Tactical | IoC feeds (abuse.ch, AlienVault OTX, VirusTotal) |
| Technical | YARA rules, Snort/Suricata signatures |
| OSINT | Twitter, Reddit, dark web forums, paste sites |
13. OSI Layer Mapping
Singkat β setiap cybersecurity layerε―ΉεΊ OSI:
| Cybersecurity Layer | OSI Layer | Tools Khas |
|---|---|---|
| L1 Physical | OSI 1 | Faraday, biometrics, security cameras |
| L4 Network (firewall/IDS) | OSI 2-4 | Cisco ASA, Palo Alto, Suricata |
| L4 Network (NDR) | OSI 3-4 | ExtraHop, Corelight |
| L3 Data (TLS encrypt) | OSI 6 | OpenSSL, cert-manager |
| L3 Data (storage encryption) | OSI 1 | LUKS, dm-crypt |
| L2 Cloud | OSI 7 | Wiz, Prisma Cloud |
| L6 Application (WAF) | OSI 7 | ModSecurity, Cloudflare WAF, Coraza |
| L6 Application (RASP) | OSI 7 | Datadog ASM, Sqreen |
| L5 Endpoint (EDR) | Host layer | CrowdStrike, SentinelOne, Wazuh |
| L7 Identity | OSI 7 | Okta, Auth0, Azure AD |
14. NIST CSF 2.0 Alignment
NIST CSF 2.0 punya 6 Functions. Setiap cybersecurity layer punya representative controls:
| Function | Deskripsi | Cybersecurity Layer yang Dominan |
|---|---|---|
| GOVERN | Kebijakan, risk, supplier | L8 + L0 |
| IDENTIFY | Asset, risk | L0 + L9 |
| PROTECT | Kontrol preventif | L1, L2, L3, L6, L7 |
| DETECT | Deteksi anomaly | L4, L5, L6 |
| RESPOND | Containment, eradication | L0, L5 |
| RECOVER | Restoration | L9 + L1 |
15. Timeline 1960-2026 β Evolusi Ancaman
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Era β Decade β Major Shift β
ββββββββββΌβββββββββΌβββββββββββββββββββββββββββββββββββββββββββ€
β ARPANETβ 1960s β Physical access = total access β
β Unix β 1970s β Password files, user permission β
β β 1980s β Worms (Morris 1988), first antivirus β
β Web β 1990s β Network worms, firewall tsunami, Nessus β
β E-com β 2000s β SQL injection, XSS, APT, Storm Worm β
β Cloud β 2010s β Supply chain, ransomware, IoT botnets β
β β 2015s β Cryptoware, BEC, deepfake voice β
β AI-era β 2020s β LLM prompt injection, deepfake vishing β
β β 2025 β Autonomous agents attacking each other β
β β 2026+ β Self-evolving malware, AI-powered APT β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Trend besar tiap dekade:
- Surface: makin meluas (device, cloud, container, AI agent)
- Speed: makin cepat (zero-day dalam hitungan jam)
- Sophistication: makin advanced (AI-generated phishing)
- Target: bergeser dari random β high-value (ransomware, BEC)
16. Cross-Reference ke Vault
| Layer | Catatan Vault |
|---|---|
| L9 | (tidak ada dedicated) β komunikasi krisis via SOPs |
| L8 | (audit di vault SOPs), hierarchy-it-domain untuk governance |
| L7 | hierarchy-cryptography (PKI), hierarchy-programming-language (OAuth libs) |
| L6 | waf-ml-anomaly-detection, software-supply-chain-security-deepdive |
| L5 | hierarchy-endpoint-security (dedicated) |
| L4 | hierarchy-network-security (dedicated), hierarchy-wireless |
| L3 | hierarchy-cryptography (dedicated), hierarchy-quantum-cryptography-stack |
| L2 | hierarchy-infrastructure-evolution, container-kubernetes-security-deepdive, kubernetes-security-roadmap, ansible-hardening-rocky-linux-9 |
| L1 | hierarchy-operating-systems, embedded-systems |
| L0 | hierarchy-osint-rf (intel source), hierarchy-offensive (red team) |
References
- NIST. βCybersecurity Framework 2.0.β (2024).
- NIST SP 800-207. βZero Trust Architecture.β (2020).
- OWASP. βOWASP Top 10 2021.β https://owasp.org/Top10/
- MITRE. βATT&CK Matrix.β https://attack.mitre.org/
- CIS. βCIS Critical Security Controls v8.β (2021).
- ISO/IEC 27001:2022. βInformation security management systems.β
- SANS Institute. βDefense in Depth.β (2018).
- Verizon. β2024 Data Breach Investigations Report.β
- Mandiant. βM-Trends 2024 Annual Report.β
- NSA. βNSA Cybersecurity Advisories.β 2020-2024.
- Cloud Security Alliance. βTop Threats to Cloud Computing.β (2024).
- PCI Security Standards Council. βPCI DSS v4.0.β (2022).
- ENISA. βThreat Landscape Report 2024.β
- Google. βBeyondProd, BeyondCorp.β (2019-2024).
- R. Ross. βRisk Frameworks: NIST and ISO.β NIST Publication, 2023.