Cyber JIF Framework Supporting Information
Cyber JIF Framework Supporting Information
Resources
We want to provide many resources and guides on many of the requirements in the NJ Cyber JIF Cybersecurity Framework, but your
technology expert should be your first resource. You will find most the resources we highlight below are governmental entities, most
notably MS-ISAC, US-CERT, CIS, NJCCIC and NIST. These organizations provide an extensive array of free resources to public entities,
so we encourage contacting them for services.
Backups
NJCCIC offers tips for data back-up setups: https://cyber.nj.gov/mitigation-guides/backups-the-cure-to-viral-cyber-infections.
Training
Consider using an outside vendor to provide the training. See the Cyber JIF’s Cyber Hygiene Training Vendor guide attached.
Cybersecurity Ventures, along with many other organizations, publishes an annual report of top vendors:
https://cybersecurityventures.com/security-awareness-training-companies/.
Passwords
Review NJCCIC’s and NIST’s password recommendations. NIST is the go-to source for cybersecurity standards and NJCCIC typically
follows and provides some additional commentary:
https://cyber.nj.gov/instructional-guides/passwords-passwords-passwords
https://pages.nist.gov/800-63-3/
There are many services available to run your organization’s email addresses against known breaches, which are typically provided by
your security software/SaaS provider, such as Norton, BitDefender, etc. A very popular provider is “Have I Been Pwned?”:
https://haveibeenpwned.com/.
Banking Controls
See NJ DCA’s electronic payroll guide for assistance in this area of banking controls:
https://www.state.nj.us/dca/divisions/dlgs/resources/pdf/payroll%20_agency_%20handbook.pdf
Segmentation
NJCCIC guide to Network Segmentation: https://www.cyber.nj.gov/this-is-security/network-segmentation
Employee Policies
Remote Working: AXA XL’s partner InformationShield has provided a template Remote Working policy to use with your employees.
See attached.
Mobile Device Access & Waiver: AXA XL’s partner NetDiligence has provided a template policy for your employee’s use of personal
devices for work, giving authorization for you to access and wipe the device.