Readiness Assessment | ASD's Essential Eight Strategies Addressed by Check Point
Evaluate your organization's alignment with the Australian Cyber Security Centre (ACSC) Essential Eight mitigation strategies. Assess cyber security maturity, identify protection gaps, and strengthen security across endpoints, email, networks, data centers, and cloud environments.

1ASD’S ESSENTIAL EIGHT STRATEGIES ADDRESSED BY CHECK POINT
Australian Signals Directorate (ASD) ESSENTIAL EIGHT STRATEGIES TO MITIGATE CYBER SECURITY INCIDENTS
& A CUSTOMER MATURITY ASSESSMENT
2ASD’S ESSENTIAL EIGHT STRATEGIES ADDRESSED BY CHECK POINT
Introduction The Essential 8 mitigation strategies are a recommendation by the Australian Cyber Security Centre (ACSC) as a baseline practice towards cyber maturity for Australians organisations. Organisations will do well to implement the Essential 8 mitigation strategies as a starting point in their cyber security roadmap.
Whilst the Essential Eight are designed to primarily protect Microsoft Windows-based internet-connected networks, a mature cyber security strategy should take a wholistic approach to all of your digital footprint including endpoints (Windows, MAC, Linux, mobile phones and tablets), email, network, data centres and public and private cloud.
This document was created to help organisations understand how Check Point address security across your entire digital footprint. It can also act as a reference document to help you understand your current cyber maturity levels against the Essential Eight mitigation strategies.
3ASD’S ESSENTIAL EIGHT STRATEGIES ADDRESSED BY CHECK POINT
CUSTOMER MATURIT Y ASSESSMENT ON ASD’S ESSENTIAL EIGHT
4ASD’S ESSENTIAL EIGHT STRATEGIES ADDRESSED BY CHECK POINT
ESSENTIAL EIGHT CONTROL
CUSTOMER E8 MATURITY
LEVEL (CURRENT
STATE)
CUSTOMER E8 MATURITY
LEVEL (TARGET STATE)
REQUIREMENTS TO MEET MATURITY LEVEL THREE
What is Application Control? Application control restricts the use of unauthorised software from being present or running on an ICT system. Application control prevents or restricts the malicious programs that attackers can utilise to breach your network and achieve their objectives within the environment. Application whitelisting technologies stop malware and other unauthorised software from operating and disrupting ICT services. Unlike security technologies such as antivirus software which block identified bad activity and permit all other activity, application whitelisting technologies are designed to only permit known good files and block all others. To be effective, application control should include network endpoints (e.g. workstations) and servers.
• Application control is implemented on workstations and servers to restrict the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications, control panel applets and drivers to an organisation-approved set.
• Microsoft’s ‘recommended block rules’ are implemented.
• Microsoft’s ‘recommended driver block rules’ are implemented.
• Application control rulesets are validated on an annual or more frequent basis. Allowed and blocked executions on workstations and servers are centrally logged and protected from unauthorised modification and deletion, monitored for signs of compromise, and actioned when cyber security events are detected.
What is Patching Applications? Patch management is the process for identifying, acquiring, installing, and verifying patches for products and systems. ‘Patching applications’ is the systematic implementation of software updates to ensure functionality and security updates/fixes are applied to applications within your ICT environment. Patching applications prevents attackers from using known security vulnerabilities to breach your network and achieve their objectives.
• Patches, updates or vendor mitigations for security vulnerabilities in internet-facing services are applied within two weeks of release, or within 48 hours if an exploit exists.
• Patches, updates or vendor mitigations for security vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release, or within 48 hours if an exploit exists.
• Patches, updates or vendor mitigations for security vulnerabilities in other applications are applied within one month.
• A vulnerability scanner is used at least daily to identify missing patches or updates for security vulnerabilities in internet-facing services.
• A vulnerability scanner is used at least weekly to identify missing patches or updates for security vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products.
• A vulnerability scanner is used at least fortnightly to identify missing patches or updates for security vulnerabilities in other applications.
• Applications that are no longer supported by vendors are removed.
5ASD’S ESSENTIAL EIGHT STRATEGIES ADDRESSED BY CHECK POINT
ESSENTIAL EIGHT CONTROL
CUSTOMER E8 MATURITY
LEVEL (CURRENT
STATE)
CUSTOMER E8 MATURITY
LEVEL (TARGET STATE)
REQUIREMENTS TO MEET MATURITY LEVEL THREE
What is Configuring Microsoft Office macro settings? Commonly used Microsoft Office applications can execute macros to automate routine tasks. Macros are popular applications, which can enable highly efficient repetitive processes. However, macros can contain malicious code resulting in unauthorised access to sensitive information as part of a targeted cyber intrusion, including being used to download other malicious software. Microsoft Office environments can be configured to prevent macros that have come from the internet or have not been identified as trusted.
• Microsoft Office macros are disabled for users that do not have a demonstrated business requirement.
• Only Microsoft Office macros running from within a sandboxed environment, a Trusted Location or that are digitally signed by a trusted publisher are allowed to execute.
• Only privileged users responsible for validating that Microsoft Office macros are free of malicious code can write to and modify content within Trusted Locations.
• Microsoft Office macros digitally signed by an untrusted publisher cannot be enabled via the Message Bar or Backstage View.
• Microsoft Office’s list of trusted publishers is validated on an annual or more frequent basis.
• Microsoft Office macros in files originating from the internet are blocked.
• Microsoft Office macro antivirus scanning is enabled.
• Microsoft Office macros are blocked from making Win32 API calls.
• Microsoft Office macro security settings cannot be changed by users.
• Allowed and blocked Microsoft Office macro executions are centrally logged and protected from unauthorised modification and deletion, monitored for signs of compromise, and actioned when cyber security events are detected.
What is User Application Hardening? User application hardening reduces the ‘attack surface’ malicious cyber actors can use to deploy malicious software onto user systems (e.g. workstations). Blocking or removing common software used to download or run malicious software prevents malicious software from running on organisation networks and disrupting ICT services.
• Web browsers do not process Java from the internet.
• Web browsers do not process web advertisements from the internet.
• Internet Explorer 11 is disabled or removed.
• Microsoft Office is blocked from creating child processes.
• Microsoft Office is blocked from creating executable content.
• Microsoft Office is blocked from injecting code into other processes.
• Microsoft Office is configured to prevent activation of OLE packages.
• PDF software is blocked from creating child processes.
• ACSC or vendor hardening guidance for web browsers, Microsoft Office and PDF software is implemented.
• Web browser, Microsoft Office and PDF software security settings cannot be changed by users.
• .NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed.
• Windows PowerShell 2.0 is disabled or removed.
• PowerShell is configured to use Constrained Language Mode.
• Blocked PowerShell script executions are centrally logged and protected from unauthorised modification and deletion, monitored for signs of compromise, and actioned when cyber security events are detected.
6ASD’S ESSENTIAL EIGHT STRATEGIES ADDRESSED BY CHECK POINT
ESSENTIAL EIGHT CONTROL
CUSTOMER E8 MATURITY
LEVEL (CURRENT
STATE)
CUSTOMER E8 MATURITY
LEVEL (TARGET STATE)
REQUIREMENTS TO MEET MATURITY LEVEL THREE
What is Restrictive Administrative Privileges? User accounts with administrative privileges for operations systems and applications can make significant changes to workstations and network configurations, bypass security settings and access, modify or delete sensitive information. Higher level administrators, such as domain administrators, have similar ability on entire networks. When attackers have access to accounts with administrator privileges, they can access more computer and system resources than regular users. This can occur when an administrator’s account is breached or a regular user account’s privileges are escalated to those of an administrator. Restricting administrator privileges does not seek to prevent legitimate administrator activity but introduce safeguards to prevent account misuse. Restricting administrator privileges can also prevent unintentional changes to network environment.
• Requests for privileged access to systems and applications are validated when first requested.
• Privileged access to systems and applications is automatically disabled after 12 months unless revalidated.
• Privileged access to systems and applications is automatically disabled after 45 days of inactivity.
• Privileged access to systems and applications is limited to only what is required for users and services to undertake their duties.
• Privileged accounts are prevented from accessing the internet, email and web services.
• Privileged users use separate privileged and unprivileged operating environments.
• Privileged operating environments are not virtualised within unprivileged operating environments.
• Unprivileged accounts cannot logon to privileged operating environments.
• Privileged accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.
• Just-in-time administration is used for administering systems and applications.
• Administrative activities are conducted through jump servers.
• Credentials for local administrator accounts and service accounts are unique, unpredictable and managed.
• Windows Defender Credential Guard and Windows Defender Remote Credential Guard are enabled.
• Use of privileged access is centrally logged and protected from unauthorised modification and deletion, monitored for signs of compromise, and actioned when cyber security events are detected.
• Changes to privileged accounts and groups are centrally logged and protected from unauthorised modification and deletion, monitored for signs of compromise, and actioned when cyber security events are detected.
7ASD’S ESSENTIAL EIGHT STRATEGIES ADDRESSED BY CHECK POINT
ESSENTIAL EIGHT CONTROL
CUSTOMER E8 MATURITY
LEVEL (CURRENT
STATE)
CUSTOMER E8 MATURITY
LEVEL (TARGET STATE)
REQUIREMENTS TO MEET MATURITY LEVEL THREE
What is Patching Operating Systems? Patching operating systems is the process of keeping our workstations and servers up to date with the latest technologies to improve security, functionality, reliability and user experience. Updating operating systems, like patching applications, is the systematic implementation of software updates to ensure functionality and security updates/fixes are applied to your ICT environment. Patching operating systems prevents attackers from using known security vulnerabilities to attack your network devices and achieve their objectives.
• Patches, updates or vendor mitigations for security vulnerabilities in operating systems of internet-facing services are applied within two weeks of release, or within 48 hours if an exploit exists.
• Patches, updates or vendor mitigations for security vulnerabilities in operating systems of workstations, servers and network devices are applied within two weeks of release, or within 48 hours if an exploit exists.
• A vulnerability scanner is used at least daily to identify missing patches for security vulnerabilities in operating systems of internet-facing services.
• A vulnerability scanner is used at least weekly to identify missing patches for security vulnerabilities in operating systems of workstations, servers and network devices.
• The latest release, or the previous release, of operating systems are used for workstations, servers and network devices.
• Operating systems that are no longer supported by vendors are replaced.
What is Multi-factor authentication? Multi-factor authentication is one of the most effective security measures organisations can implement to prevent attackers from gaining access to networks and devices. Often known as twofactor authentication, multi-factor authentication requires users to present two or more separate pieces of evidence when signing into their account. For example, two or more of the following: • username and password—something you know • authorisation through an MFA (multifactor
authentication) application—something you have
• your fingerprint—something you are.
Multi-factor authentication prevents attackers from gaining access to accounts if they guess the password or know the username and password.
Multi-factor authentication should be implemented for all remote access, high privileged accounts (e.g. administrators) and when users require access to important data.
• Multi-factor authentication is used by an organisation's users if they authenticate to their organisation’s internet-facing services.
• Multi-factor authentication is used by an organisation’s users if they authenticate to thirdparty internet-facing services that process, store or communicate their organisation's sensitive data.
• Multi-factor authentication (where available) is used by an organisation’s users if they authenticate to third-party internet-facing services that process, store or communicate their organisation's non-sensitive data.
• Multi-factor authentication is enabled by default for non-organisational users (but users can choose to opt out) if they authenticate to an organisation’s internet-facing services. Multi-factor authentication is used to authenticate privileged users of systems.
• Multi-factor authentication is used to authenticate users accessing important data repositories.
• Multi-factor authentication is verifier impersonation resistant and uses either: something users have and something users know, or something users have that is unlocked by something users know or are.
• Successful and unsuccessful multi-factor authentications are centrally logged and protected from unauthorised modification and deletion, monitored for signs of compromise, and actioned when cyber security events are detected.
8ASD’S ESSENTIAL EIGHT STRATEGIES ADDRESSED BY CHECK POINT
ESSENTIAL EIGHT CONTROL
CUSTOMER E8 MATURITY
LEVEL (CURRENT
STATE)
CUSTOMER E8 MATURITY
LEVEL (TARGET STATE)
REQUIREMENTS TO MEET MATURITY LEVEL THREE
What are daily backups? Backups of important or new information and software are a means to restore operating systems quickly following a service disruption. Critically, backups must be tested to make sure they’re functioning correctly, and organisations have processes to effectively recover the data they need. Attackers commonly target backups, so storing backup data ‘offline’, where backups can’t be accessed or written over is increasingly important. As more government services move online, daily backups are becoming increasingly important, as critical data needs to be retained so that if a cyber incident does occur, service disruption is minimal. As a result, organisations may require hourly or continuous backups.
• Backups of important data, software and configuration settings are performed and retained in a coordinated and resilient manner in accordance with business continuity requirements.
• Restoration of systems, software and important data from backups is tested in a coordinated manner as part of disaster recovery exercises.
• Unprivileged accounts, and privileged accounts (excluding backup administrators), cannot access backups.
• Unprivileged accounts, and privileged accounts (excluding backup break glass accounts), are prevented from modifying or deleting backups.
9ASD’S ESSENTIAL EIGHT STRATEGIES ADDRESSED BY CHECK POINT
Australian Signals Directorate (ASD) ESSENTIAL EIGHT STRATEGIES TO MITIGATE
CYBER SECURIT Y INCIDENTS
10ASD’S ESSENTIAL EIGHT STRATEGIES ADDRESSED BY CHECK POINT
RATING MITIGATION STRATEGY RELATIVE SECURITY
EFFECTIVENESS RATING
END POINT SECURITY CAPABILITY
(HARMONY ENDPOINT)
NETWORK SECURITY CAPABILITY
(CHECK POINT SECURITY GATEWAYS)
CLOUD SECURITY CAPABILITY (CHECK POINT CLOUD GUARD PORTFOLIO)
MOBILE THREAT DEFENCE CAPABILITY
(HARMONY MOBILE)
MITIGATION STRATEGIES TO PREVENT MALWARE DELIVERY AND EXECUTION
1 Application control to prevent execution of unapproved/ malicious programs including .exe, DLL, scripts (e.g. Windows Script Host, PowerShell and HTA) and installers.
Essential In addition to Endpoint Detection & Response (EDR) capabilities, Check Point’s Endpoint Security offering includes Application Control components that restricts network access for specified applications. Security administrators simply define policies and rules that allow, block or terminate applications and processes.
The Application Control feature available in this solution allows whitelisting of applications to create a list of approved applications.
It can also detect and prevent malicious / unapproved applications from executing via threat prevention capabilities such as Anti-Malware, Anti-Ransomware, Anti- Bot, Threat Emulation (Sandboxing) and Threat Extraction / Content Disarm and Reconstruction (CDR)
Further to this, the Anti-Malware feature available in Check Point’s solution protects and organisation’s end users and network from all kinds of malware threats regardless of where the end users are located. Organisations can centrally manage the detection and remediation of malware on endpoints.
In addition to Application Control on the Endpoint, Check Point also provides Network based application control capabilities allowing whitelisting of applications to create a list of approved applications.
Check Point can detect, prevent and inform users about non-whitelisted/ malicious applications detected at the network layer. This is achieve through security controls available on the Check Point Security Gateways such as Application Control and URL Filtering.
Check Point can detect, prevent and inform users about non-whitelisted/ malicious applications detected at the network layer in the Cloud (through security gateways deployed in public / private cloud for application control of cloud traffic).
Further to this, Check Point can also detect non- approved SaaS applications in use by employees by scanning corporate e-mails in O365 / Gmail accounts.
Current Cloud attack trends shows an increase in Application Programming Interface (API) based attacks. Cyber criminals attack web applications and APIs using methods such as SQL injection and cross-site scripting, as well as automatic scripts, known as “bots”. As such, in order to mitigate this evolving attack trend, organisations must update their mitigation strategy. Check Point Cloud Security protects web applications and prevents OWASP Top 10 attacks.
Check Point Mobile Threat Defense (MTD) enforces application control, including whitelisting of applications. The solution can detect and prevent malicious apps via built-in zero-day threat prevention features. Check Point’s cloud based algorithms (Behavioral Risk Engine-BRE) analyzes the true behavior of the mobile applications, alerting on their maliciousness and preventing them from calling home to a Command and Control (C&C) server.
The solution provides application black listing as well as location white/black listing— enforcing policy based on the location of the mobile device.
Further to this, Check Point Mobile Threat Defense uses a unique Patent feature by Check Point called On-device Network Protection (ONP), which prevents attacks by blocking malicious web pages, downloading of malicious files that pose a risk to the device and anti-phishing protection including zero- phishing (credential theft).
The solution also prevents access to websites based on categories inappropriate for an organization’s corporate policies.
11ASD’S ESSENTIAL EIGHT STRATEGIES ADDRESSED BY CHECK POINT
RATING MITIGATION STRATEGY RELATIVE SECURITY
EFFECTIVENESS RATING
END POINT SECURITY CAPABILITY
(HARMONY ENDPOINT)
NETWORK SECURITY CAPABILITY
(CHECK POINT SECURITY GATEWAYS)
CLOUD SECURITY CAPABILITY (CHECK POINT CLOUD GUARD PORTFOLIO)
MOBILE THREAT DEFENCE CAPABILITY
(HARMONY MOBILE)
2 Patch applications (e.g., Flash, web browsers, Microsoft Office, Java and PDF viewers). Patch/ mitigate computers with ‘extreme risk’ security vulnerabilities within 48 hours. Use the latest version of applications.
Essential Check Point recommends organisations patch applications regularly and with a sense of urgency. This is because application vulnerability is a major attack vector used by threat actors to gain a foothold in their victim’s environment.
Check Point's Endpoint Protection capability allows monitoring and detection of specific file properties / registry keys to ensure that patched / latest versions of applications are running on an endpoint.
Further to this, Check Point's Anti-Exploit provides protection against common vulnerable attack vectors/ applications (browser and Office exploit based attacks are some examples).
By detecting the exploit attempt, Anti-Exploit prevents downloading or execution of a malicious payload. On detection Anti-Exploit will shut down the process being exploited and then will generate a forensics report.
Check Point Intrusion Prevention System (IPS) provides comprehensive protection against malicious and unwanted network traffic, which focuses on application and server vulnerabilities, as well as 'in-the-wild' attacks by exploit kits and malicious attackers.
This is part of vulnerability management and Check Point IPS is often used to enforce preventive measures against both known and unknown software exploits, even before vendor patches are deployed by IT administrators within the organisation.
This approach is often referred to as virtual patching and can be used to protect applications and operating systems on both clients and servers. Virtual patching prevents attacks from exploiting vulnerable systems by scanning for threats at the network level.
Check Point’s virtual security gateways within public and private cloud infrastructure provide full threat prevention capability including Intrusion Prevention System (IPS) and provides comprehensive protection against malicious and unwanted network traffic, which focuses on application, operating systems and server vulnerabilities, as well as in-the-wild attacks by exploit kits and malicious attackers.
As part of a vulnerability management process, Check Point IPS should be used to enforce preventive measures against both known and unknown software exploits, even before vendor patches are deployed by IT administrators within the organisation.
This approach is often referred to as virtual patching and can be used to protect applications and operating systems on both clients and servers. Virtual patching prevents attacks from exploiting vulnerable systems by scanning for threats at the network level.
Check Point Mobile Threat Defense alerts on vulnerable apps or apps that need to be upgraded/ patched. When the solution is integrated with an MDM/UEM solution, the MDM/UEM would be able to enforce patching on applications.
In addition, the solution also alerts on unpatched vulnerable mobile devices based on OS version or the device hardware (hardware-based vulnerabilities).
12ASD’S ESSENTIAL EIGHT STRATEGIES ADDRESSED BY CHECK POINT
RATING MITIGATION STRATEGY RELATIVE SECURITY
EFFECTIVENESS RATING
END POINT SECURITY CAPABILITY
(HARMONY ENDPOINT)
NETWORK SECURITY CAPABILITY
(CHECK POINT SECURITY GATEWAYS)
CLOUD SECURITY CAPABILITY (CHECK POINT CLOUD GUARD PORTFOLIO)
MOBILE THREAT DEFENCE CAPABILITY
(HARMONY MOBILE)
3 Configure Microsoft Office macro settings to block macros from the internet, and only allow vetted macros either in ‘trusted locations’ with limited write access or digitally signed with a trusted certificate.
Essential Check Point's Endpoint Protection capability removes exploitable or active content such as macros (threat extraction / content disarming), reconstructs files to eliminate potential threats, and delivers sanitized content to users in a few seconds to maintain business flow.
In addition, Check Point also monitors the actual behavior of the applications, macros and scripts—using ‘Behavioural Guard’. It will look for malicious behavior and prevent when identified.
Check Point's Security Gateways remove exploitable or active content such as macros (threat extraction/ content disarming), reconstructs files to eliminate potential threats, and delivers sanitized content to users in a few seconds to maintain business flow.
Check Point’s multi-layer threat prevention security gateways for Cloud ecosystems eliminates the vulnerability gap that is created due to unknown threats.
This is achieved by removing exploitable or active content such as macros from files that are being sent through to an organisation’s Cloud infrastructure. This capability reconstructs files to eliminate potential threats, and delivers sanitized content to users in a few seconds to maintain business flow.
This is achieved by security gateways deployed in public / private cloud for CDR sanitisation of Cloud traffic.
N/A for mobile devices
13ASD’S ESSENTIAL EIGHT STRATEGIES ADDRESSED BY CHECK POINT
RATING MITIGATION STRATEGY RELATIVE SECURITY
EFFECTIVENESS RATING
END POINT SECURITY CAPABILITY
(HARMONY ENDPOINT)
NETWORK SECURITY CAPABILITY
(CHECK POINT SECURITY GATEWAYS)
CLOUD SECURITY CAPABILITY (CHECK POINT CLOUD GUARD PORTFOLIO)
MOBILE THREAT DEFENCE CAPABILITY
(HARMONY MOBILE)
4 User application hardening. Configure web browsers to block Flash (ideally uninstall it), ads and Java on the internet. Disable unneeded features in Microsoft Office (e.g. OLE), web browsers and PDF viewers.
Essential Check Point’s Endpoint Security provides protection across a wide range of file types, including MS Office, Adobe PDF, Java, Flash, executables and archives, on various Windows OS environments.
In addition, the capability can prevent the download of malicious files through the browser (through sandboxing and CDR).
Check Point recommend additional security controls above and beyond this control, such as phishing protection for corporate users and administrators from Zero day phishing sites and password / identity theft.
Check Point’s Endpoint Security solution can enforce application hardening based on registry key requirements. This can be monitored and enforced by Check Point’s Endpoint compliance capability, which is inbuilt into the Endpoint Security solution.
In addition to security controls on the endpoint, Check Point Security Gateways can also prevent the downloading of applications and widgets including specific file types.
This includes MS Office, Adobe PDF, Java, Flash, executables, and archives, as well as multiple Windows OS environments.
Network security gateways could also be used to address URL Filtering, Application control and CDR.
In addition to security controls on the endpoint, Check Point Security Gateways (security gateways deployed in public / private cloud) can also control the downloading of applications and widgets including specific file types.
This capability provides protection across the widest range of file types. This includes MS Office, Adobe PDF, Java, Flash, executables and archives, as well as multiple Windows OS environments.
For SaaS based apps such as O365 and G-Suite, Check Point offers Sandboxing (for unknown files and URLs) and CDR controls.
Further to this, it is imperative that organisations secure their cloud native applications by ensuring that security is built into their CI/CD pipeline to scan, both build time and run time source code (SAST/DAST). Check Point’s Cloud security capabilities enable organisation to continuously analyse cloud applications before and after deployment, ensuring organisations can achieve a continuous severless secure posture—automating application hardening, minimizing the attack surface and simplifying governance.
Check Point Mobile Threat Defense prevents attacks as the user browses or clicks different links or apps on the device to reach sites and download content.
The solution also enforces safe browsing, anti-phishing including credential theft (zero-phishing), anti-bot, URL Filtering and prevents the download of risky files such as side loaded apps or network profiles that will put the device in a risky state.
14ASD’S ESSENTIAL EIGHT STRATEGIES ADDRESSED BY CHECK POINT
RATING MITIGATION STRATEGY RELATIVE SECURITY
EFFECTIVENESS RATING
END POINT SECURITY CAPABILITY
(HARMONY ENDPOINT)
NETWORK SECURITY CAPABILITY
(CHECK POINT SECURITY GATEWAYS)
CLOUD SECURITY CAPABILITY (CHECK POINT CLOUD GUARD PORTFOLIO)
MOBILE THREAT DEFENCE CAPABILITY
(HARMONY MOBILE)
MITIGATION STRATEGIES TO LIMIT THE EXTENT OF CYBER SECURITY INCIDENTS
18 Restrict administrative privileges to operating systems and applications based on user duties. Regularly revalidate the need for privileges. Don’t use privileged accounts for reading email and web browsing.
Essential Restricting Admin privileges should be implemented by Active Directory and 3rd party Privileged Access Management controls within the organisation.
In addition, Check Point Endpoint Security will prevent any privileged escalation on the endpoint in the event of any malicious activity.
Further to this, Check Point’s all-in one Endpoint Security Management platform uses granular role-based access control (RBAC) to allow administrators to either read or write access to only those features their job description allows.
Check Point Network Security Controls uses granular RBAC to allow security administrators either read or write access to only those features there job description allows.
Check Point's Cloud security management platform uses granular RBAC to allow cloud security administrators either read or write access to only those features their job description allows.
In addition, Check Points Cloud Security provides privileged identity protection via IAM (Identity and Access Management) Safety, which offers an additional layer of defense on top of native identity and access management protection where it is needed.
IAM Safety gives security teams granular control over users, roles and actions, with privilege elevation on an as-needed basis (just-in-time security) for protected actions with second-level out-of-band authorization from a mobile device for critical updates. IAM Safety also provides audited tamper protection from suspicious activity.
Check Point’s Mobile Threat Defense platform detects privilege escalation such as jailbroken or rooted devices. This automatically limits the access to and processing of corporate resources (Conditional Access) on risky devices to protect the organisation’s internal resources from being breached.
Check Point Mobile Threat Defense utilizes a cloud management portal in which security administrator roles and privileges are configurable to provide granular access.
This platform can be integrated with all major MDM/UEM solutions in the industry to provide additional access restrictions to corporate resources from the mobile device, once a risk is detected.
The solution automatically mitigates any risk posed through applications, the network and the OS (by informing the MDM/UEM, alerting the user and alerting the admin) until the threat is eliminated. Based on the level of risk, the solution will prevent the mobile device from accessing specific resources, applications etc.
In addition, integration with an MDM/UEM platform allows the solution to restrict secure container access, or make real-time, risk-based policy adjustments on compromised devices.
15ASD’S ESSENTIAL EIGHT STRATEGIES ADDRESSED BY CHECK POINT
RATING MITIGATION STRATEGY RELATIVE SECURITY
EFFECTIVENESS RATING
END POINT SECURITY CAPABILITY
(HARMONY ENDPOINT)
NETWORK SECURITY CAPABILITY
(CHECK POINT SECURITY GATEWAYS)
CLOUD SECURITY CAPABILITY (CHECK POINT CLOUD GUARD PORTFOLIO)
MOBILE THREAT DEFENCE CAPABILITY
(HARMONY MOBILE)
19 Patch operating systems. Patch/ mitigate computers (including network devices) with ‘extreme risk’ security vulnerabilities within 48 hours. Use the latest operating system version. Don’t use unsupported versions.
Essential Check Point acknowledge that patching operating systems in general is a process driven activity and we recommend all customers patch to the latest versions of OS within all systems and where possible, automate the process.
Check Point regularly updates its Endpoint software and provides customers with alerts on all future updates.
The Check Point Endpoint security solution provides the ability to ensure that the endpoints are compliant with the relevant corporate requirements such as: • all assigned security
controls are installed and running on the endpoint;
• anti-malware is running and that engine and signature databases are up to date;
• Required operating system service packs and updates are installed on the endpoint computer.
If the Endpoint is not running the latest patches as required by the corporate security policy, access to corporate resources is restricted.
Check Point’s Endpoint security offering can be used to mitigate the compliance demand and kick start the automatic patch update process of other third party applications by running a dedicated script.
Check Point Intrusion Prevention System (IPS) provides comprehensive protection against malicious and unwanted network traffic, which focuses on application and server vulnerabilities, as well as 'in-the-wild' attacks by exploit kits and malicious attackers.
This is part of vulnerability management and Check Point IPS is often used to enforce preventive measures against both known and unknown software exploits, even before vendor patches are deployed by IT administrators within the organisation.
This approach is often referred to as virtual patching and can be used to protect applications and operating systems on both clients and servers. Virtual patching prevents attacks from exploiting vulnerable systems by scanning for threats at the network level.
Check Point’s virtual security gateways within public and private cloud infrastructure provide full threat prevention capability including Intrusion Prevention System (IPS) and provides comprehensive protection against malicious and unwanted network traffic, which focuses on application, operating systems and server vulnerabilities, as well as in-the-wild attacks by exploit kits and malicious attackers.
As part of a vulnerability management process, Check Point IPS should be used to enforce preventive measures against both known and unknown software exploits, even before vendor patches are deployed by IT administrators within the organisation.
This approach is often referred to as virtual patching and can be used to protect applications and operating systems on both clients and servers. Virtual patching prevents attacks from exploiting vulnerable systems by scanning for threats at the network level.
Check Point's Mobile Threat Defense offering centralizes visibility of the Operating System versions of all the devices within the enterprise.
The solution analyses the device and looks for vulnerabilities within the Operating System and the device hardware itself including vulnerabilities in the chipset of the mobile device (see for example the latest Achilles vulnerability found by Check Point- Research in 40% of mobile devices worldwide).
The solution can further alert the MDM/UEM solution to ensure the device is in compliance with the Agency’s regulations on OS Patching levels.
Check Point recommend this information be used to ensure all mobile devices are running supported Operating systems.
16ASD’S ESSENTIAL EIGHT STRATEGIES ADDRESSED BY CHECK POINT
RATING MITIGATION STRATEGY RELATIVE SECURITY
EFFECTIVENESS RATING
END POINT SECURITY CAPABILITY
(HARMONY ENDPOINT)
NETWORK SECURITY CAPABILITY
(CHECK POINT SECURITY GATEWAYS)
CLOUD SECURITY CAPABILITY (CHECK POINT CLOUD GUARD PORTFOLIO)
MOBILE THREAT DEFENCE CAPABILITY
(HARMONY MOBILE)
20 Multi-factor authentication including for VPNs, RDP, SSH and other remote access, and for all users when they perform a privileged action or access an important (sensitive/high- availability) data repository.
Essential Check Point offers a number of options for VPN authentication including: • User and machine
authentication— Authenticate with a machine certificate and a user authentication method. Digital Certificates are the most recommended and manageable method for authentication.
• Various other One Time Password cards and USB tokens including RSA SecurID are supported.
Check Point Mobile Remote Access VPN (SSL VPN) capability is a safe and easy solution to connect to corporate applications over the internet with a mobile device or desktop/laptop. The solution provides enterprise-grade remote access with both Layer-3 VPN and SSL VPN.
Check Point's DynamicID available through Check Point Mobile Remote Access VPN is one option for multi-factor authentication which provides the ability to use One Time Password (OTP) for remote access connectivity. The OTP is sent to user’s mobile communications device (such as a mobile phone) via SMS or directly to their email account.
Organisations are recommended to have a strategy around Mobile Security especially if it will be used to receive MFA tokens or OTP.
Check Point's VPN offerings, both SSL and IPSEC, provides enterprise-grade remote access to give users simple, safe and secure connectivity to email, calendar, contacts and corporate applications.
Check Point DynamicID, available through Check Point Mobile Remote Access VPN (SSL VPN), is one option for multi-factor authentication.
DynamicID is a One Time Password (OTP) offered via SMS or directly to the user's email account.
In addition to controlling access to sensitive resources using MFA, Check Point recommends enhancing the security controls with the Identity Awareness capability available within its security gateways. Identity Awareness offers authenticated web access to sensitive data repositories. Traditionally, firewalls use IP addresses to control traffic and are unaware of the user and machine identities behind those IP addresses. Identity Awareness removes this notion of anonymity by mapping users and/or machine identities. This lets an organisation enforce access and audit data based on identity.
Check Point highly recommends applying MFA to enhance access controls within all Cloud environments.
Check Point’s security for SaaS applications such as O365 can be configured with the following MFA options: • End-users can only sign
in from devices with an ID-Guard agent installed and registered (trusted device and user pairing).
• End-users must use a One-Time Passcode (OTP) to sign in from devices without an ID-Guard agent installed and registered. The OTP is sent at each sign-in request through push notification to all the user's registered devices.
• End-users must use an OTP to sign in from devices without an ID- Guard agent installed and registered. The OTP is sent at each sign in request through SMS to the user's mobile device.
All of Check Point’s SaaS based Cloud Security Management platforms leverage various Multi- Factor Authentication (MFA) providers for sign-in.
Check Point Mobile Threat Defense offers corporate Identity Protection when users logging in to corporate apps from anywhere—it enforces employee identity assurance across multi- corporate resources and allows access only when the mobile device is actually free of security risks
It is imperative to secure mobile devices if organisations are to leverage these assets to receive Multi Factor Authentication Tokens or One Time Passwords (OTP).
17ASD’S ESSENTIAL EIGHT STRATEGIES ADDRESSED BY CHECK POINT
RATING MITIGATION STRATEGY RELATIVE SECURITY
EFFECTIVENESS RATING
END POINT SECURITY CAPABILITY
(HARMONY ENDPOINT)
NETWORK SECURITY CAPABILITY
(CHECK POINT SECURITY GATEWAYS)
CLOUD SECURITY CAPABILITY (CHECK POINT CLOUD GUARD PORTFOLIO)
MOBILE THREAT DEFENCE CAPABILITY
(HARMONY MOBILE)
MITIGATION STRATEGIES TO RECOVER DATA AND SYSTEM AVAILABILITY
34 Daily backups of important new/ changed data, software and configuration settings, stored disconnected, retained for at least three months. Test restoration initially, annually and when IT infrastructure changes.
Essential Check Point highly recommend organisations have a data backup strategy —this must include both online (which should be automated) and offline backups.
Check Point encourage you to test your backup and restore process regularly.
In order to assist with the backup process of an organisation’s endpoint security configuration, the Check Point Endpoint Security Management Server allows backing up of all security data and configuration. This includes Configuration files, Client packages, Certificates for client packages, Endpoint Security Management server database.
This data can be collected daily and can be stored externally on-premise. Check Point’s cloud based Endpoint Security services are backed up by daily snapshots, which can be reverted to in case of a need for a disaster recovery.
Check Point highly recommend organisations automate their data backup process. Check Point also encourage you to test your backup and restore process regularly.
Check Point's on-premise Security Gateways and Management Server allow multiple options for backup, including: Snapshot Management, System Backup (and System Restore), Save/Show Configuration (and Load Configuration).
All methods can be used to backup your on-premise Security Gateways, on-premise Security Management and Multi- Domain Server. This data can be collected daily and can be stored as required.
Alternatively, Customers managing Check Point Cloud Security Gateways from our SaaS based Security Management Platform (Infinity Portal) benefit from 'Zero Maintenance' which offers monitoring and backing up operations of your security policies and configurations. Back ups of the environment are conducted every 12 hours.
Check Point highly recommend organisations automate their online data backup process and ensure an offline backup strategy is in place. Check Point also encourage you to test your backup and restore process regularly.
Check Point's Cloud based Security Gateways and Management Server, allow multiple options for backup including: Snapshot Management, System Backup (and System Restore), Save/Show Configuration (and Load Configuration).
All methods can be used to backup your Cloud Security Gateways and Security Management. This data can be collected daily and can be stored as required.
Alternatively, Customers managing Check Point Cloud Security Gateways from our SaaS based Security Management Platform (Infinity Portal) benefit from 'Zero Maintenance' which offers monitoring and backing up operations of your security policies and configurations. Back ups of the environment are conducted every 12 hours.
Check Point highly recommend organisations automate their data backup process. We also encourage you to test your backup and restore process regularly.
Check Point’s cloud-based mobile threat prevention management platform stores all audit logs for software changes, policy configuration as well as device changes in the Events and Alerts tab. These Events and Alerts can be exported via syslog to be stored as backups.
Organisations can benefit from 'Zero Maintenance' which offers monitoring and backing up operations in your security management system. Backups of the environment are conducted daily.