HomeSecurityCISA: Ransomware security self-assessment tool released

CISA: Ransomware security self-assessment tool released

The U.S. Cybersecurity Agency (CISA) has released the Ransomware Readiness Assessment (RRA), a new module for the Cyber ​​Security Evaluation Tool (CSET).

CISA ransomware

See also: REVIL ransomware: New Linux cryptor targets ESXi VMs

RRA is a security audit self-assessment tool for organizations that want to better understand how well they are equipped to defend against and recover from ransomware attacks targeting information technology (IT), operational technology (OT), or industrial control system (ICS) assets.

This CSET module was tailored to the RRA to assess various levels of ransomware threat readiness so that it is useful to all organizations regardless of their cybersecurity maturity.

See also: Golang: New ransomware shows hackers are increasingly using it

CISA says RRA can be used in the following ways to defend against this growing threat:

  • It helps organizations assess their cybersecurity, in relation to ransomware, based on recognized standards and best practice recommendations in a systematic, disciplined and repeatable manner.
  • Guides asset owners and operators through a systematic process for assessing operational technology (OT) and information technology (IT) security practices against the ransomware threat
  • It provides an analysis dashboard with graphs and tables that present the assessment results in a concise and detailed format.

How to use the RRA security audit tool

To use the self-assessment tool, you must first install CSET and then:

  1. Log in or launch the CSET app
  2. Start a new assessment
  3. Select Maturity Model on the Assessment Configuration screen (this is the first screen you are presented with after selecting “New Assessment”)
  4. Select Ransomware Readiness Assessment from the Maturity model screen
  5. You are now ready to complete the RRA assessment. Refer to the tutorial for additional instructions or the RRA guide located in the Help menu.

CISA previously released Aviary, a tool for reviewing post-breach activity in Microsoft Azure Active Directory (AD), Office 365 (O365), and Microsoft 365 (M365) environments.

See also: Lorenz: Researchers developed decryptor for ransomware

Aviary works by analyzing data outputs generated using Sparrow, a PowerShell-based tool for identifying potentially compromised applications and accounts in Azure and Microsoft 365.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS