Skip to content

Opsec Domain: proposed categories #226

@shallem

Description

@shallem

Following the new taxonomy proposed by @mattaereal here, I would like to suggest the following categories for the OpSec domain. Feedback would be greatly appreciated, along with any help in taking each category forward into sub-categories, items, benchmarks, etc.

Categories in OpSec that I can think of (with some sub-categories) are:

  1. Identity and Access Management
    Subs: Authentication, Federation, RBAC, MFA
  2. Endpoint protection
    Subs: end-user, mobile, server
  3. Communications Security
    Subs: phishing, smishing, data exfiltration, URL protection
  4. Data Security
    Subs: PoLP, data classification, information rights management
  5. Wallet security
  6. Digital risk protection
    Subs: brand protection, fraud prevention, pretexting, data leak detection, baiting, impersonation, compromised credentials, dark web monitoring
  7. Cloud security
    Subs: cloud architecture, BoM, segmentation, firewalls, log monitoring
  8. Vendor / Third-Party security
  9. Physical security
  10. Incident response
  11. Travel security

I am sure that I am missing quite a lot, and my knowledge in certain areas is limited. Enhancements and contributions would be very helpful.

Metadata

Metadata

Labels

content:updateThis issue or PR updates content or suggests toquestionFurther information is requested

Projects

Status

No status

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions