{"id":936,"date":"2024-04-06T09:00:00","date_gmt":"2024-04-06T08:00:00","guid":{"rendered":"https:\/\/www.itminister.co.uk\/blog\/?p=936"},"modified":"2024-04-03T18:47:28","modified_gmt":"2024-04-03T17:47:28","slug":"cyber-security-documentation","status":"publish","type":"post","link":"https:\/\/www.itminister.co.uk\/blog\/cyber-security-documentation\/","title":{"rendered":"Cyber Security Documentation"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Ignoring This Could Cost Organizations Everything!<\/h2>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"1024\" data-id=\"937\" src=\"https:\/\/www.itminister.co.uk\/blog\/wp-content\/uploads\/2024\/04\/Cyber-Security-Documentation.jpg\" alt=\"\" class=\"wp-image-937\" srcset=\"https:\/\/www.itminister.co.uk\/blog\/wp-content\/uploads\/2024\/04\/Cyber-Security-Documentation.jpg 1024w, https:\/\/www.itminister.co.uk\/blog\/wp-content\/uploads\/2024\/04\/Cyber-Security-Documentation-300x300.jpg 300w, https:\/\/www.itminister.co.uk\/blog\/wp-content\/uploads\/2024\/04\/Cyber-Security-Documentation-150x150.jpg 150w, https:\/\/www.itminister.co.uk\/blog\/wp-content\/uploads\/2024\/04\/Cyber-Security-Documentation-768x768.jpg 768w, https:\/\/www.itminister.co.uk\/blog\/wp-content\/uploads\/2024\/04\/Cyber-Security-Documentation-100x100.jpg 100w\" sizes=\"auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" \/><\/figure>\n<\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Intro<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The term &#8220;documentation&#8221; describes the organized keeping and filing of numerous types of documents. When referring to Cyber Security, it includes a broad range of documents that act as a fundamental pillar that creates a framework for comprehending the security posture of an organization, promoting efficient stakeholder communication, and guaranteeing adherence to industry standards and laws.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why Cyber Security Documentation Matters?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Documentation is necessary for understanding the significance of security Governance, Risk and Compliance, and their implications for protecting digital assets and data. It offers various guidance, knowledge, and resources that serves as a reference manual for security professionals, empowering them to apply and uphold security measures consistently throughout an organization.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Essential Types Cyber Security Documents<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Cyber Security professionals should be knowledgeable of the ten primary categories of documents, including their contents and purposes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Policies:<\/strong> represent high-level directives from leadership that guide decisions and goals. They establish clear requirements through standards and procedures, fulfilling external obligations like laws and contracts.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><em>Example: Acceptable Use Policy (AUP)<\/em><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Control Objectives:<\/strong> are defined targets that organizations aim to achieve through Cyber Security and data privacy practices. They ensure alignment with laws, regulations, and industry standards to demonstrate due diligence<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><em>Example: Maintain integrity of critical systems and data<\/em><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Standards:<\/strong> are compulsory specifications that establish minimum security requirements to ensure cyber security and data privacy protections are incorporated into systems, applications, and processes.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><em>Example: Microsoft Cloud Security Benchmark<\/em><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Guidelines:<\/strong> suggested practices that complement standards, offering flexibility where discretion is allowed. They are derived from secure methodologies, not mandated requirements<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><em>Example: Secure Software Development Guidelines<\/em><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Controls:<\/strong> are Technical, Administrative, or Physical safeguards that manage risks by preventing, detecting, or mitigating threats. Assessment Objectives (AOs), being a subset of this document, will outline desired outcomes for evaluating if controls meet requirements.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><em>Example: Identity and Access Management Controls for Privilege Accounts<\/em><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Procedures<\/strong>: often referred to as &#8220;control activities&#8221; are documented steps to execute tasks in accordance with policies, standards, or controls, where the outcome aims to demonstrate a specific control requirement are met.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><em>Example: Patch Management Procedures<\/em><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Risks: <\/strong>are situations where something valuable is exposed to danger or loss. Risk is assessed by multiplying the likelihood of occurrence by the potential impact to get the risk severity. Managing risks also involves strategies such as avoidance, reduction, transfer, or acceptance, based on the organization risk appetite.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><em>Example: Risk Register<\/em><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Threats<\/strong>: denote individuals, elements, or events with the actions to cause harm or danger. If a threat materializes, it can impact the effectiveness of controls intended to mitigate that threat.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><em>Example: Threat Intelligence Reports\/ Threat Catalogue<\/em><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Metrics<\/strong>: provides snapshot of precise individual security measurements at a moment in time, where metrics effectiveness follow the SMART criteria (Specific, Measurable, Attainable, Repeatable, and Time-dependent).<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><em>Example: Number of Security Incidents per Month, per System Type<\/em><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Plans<\/strong>: outline strategies for mitigating risks and improving security posture along with how an organization will respond to and recover from security incidents or disruptions.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><em>Example: Incident Response Plan<\/em><\/pre>\n\n\n\n<blockquote class=\"wp-block-quote has-text-align-center is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Strict documentation guidelines preserve security policies, processes, and best practices, serving as institutional memory of the organization security maturity. Promoting, uniformity, mitigating risks, enabling timely response to threats, and reduces human error\u2014a major contributing element to security breaches.<\/strong><\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Best Practices for Documentation<\/h2>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"1024\" data-id=\"938\" src=\"https:\/\/www.itminister.co.uk\/blog\/wp-content\/uploads\/2024\/04\/Why-Cyber-Security-Documentation-Matters.jpeg\" alt=\"\" class=\"wp-image-938\" srcset=\"https:\/\/www.itminister.co.uk\/blog\/wp-content\/uploads\/2024\/04\/Why-Cyber-Security-Documentation-Matters.jpeg 1024w, https:\/\/www.itminister.co.uk\/blog\/wp-content\/uploads\/2024\/04\/Why-Cyber-Security-Documentation-Matters-300x300.jpeg 300w, https:\/\/www.itminister.co.uk\/blog\/wp-content\/uploads\/2024\/04\/Why-Cyber-Security-Documentation-Matters-150x150.jpeg 150w, https:\/\/www.itminister.co.uk\/blog\/wp-content\/uploads\/2024\/04\/Why-Cyber-Security-Documentation-Matters-768x768.jpeg 768w, https:\/\/www.itminister.co.uk\/blog\/wp-content\/uploads\/2024\/04\/Why-Cyber-Security-Documentation-Matters-100x100.jpeg 100w\" sizes=\"auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" \/><\/figure>\n<\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Cyber Security documents are a must-have, hence why these recommended practices for creating and maintaining them should be followed.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Creating Effective Documentation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Alignment with Business Needs:<\/strong> needs to be carefully tailored to the organization&#8217;s unique security needs, considering its resources, weaknesses, and risk tolerance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Clarity and Briefness<\/strong>: avoid overusing technical jargon and to explain complicated concepts in a way that is understandable to a broad audience within the organization, even those without a technical experience.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Accessibility and Usability<\/strong>: should be easily available to all authorized staff, ideally housed in a centralized repository.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Maintaining Documentation Efficacy<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Version Control:<\/strong>&nbsp; by guaranteeing that everyone is using the most recent version, a version control system keeps track of and document revisions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Assigning Ownership:<\/strong>&nbsp; Clearly identify who is responsible for each document&#8217;s accuracy and establish accountability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>User Engagement:<\/strong> determine areas for improvement and assess the effectiveness of the documentation through input from user\u2019s feedback on a regular basis.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Regular Review and Updates<\/strong>: Since the field of cyber security is always changing, determine areas for improvement and assess the effectiveness of the documentation through input from user\u2019s feedback on a regular basis.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Benefits of Effective Documentation<\/h2>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-3 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"1024\" data-id=\"939\" src=\"https:\/\/www.itminister.co.uk\/blog\/wp-content\/uploads\/2024\/04\/Essentials-Cyber-Security-Documents.jpeg\" alt=\"\" class=\"wp-image-939\" srcset=\"https:\/\/www.itminister.co.uk\/blog\/wp-content\/uploads\/2024\/04\/Essentials-Cyber-Security-Documents.jpeg 1024w, https:\/\/www.itminister.co.uk\/blog\/wp-content\/uploads\/2024\/04\/Essentials-Cyber-Security-Documents-300x300.jpeg 300w, https:\/\/www.itminister.co.uk\/blog\/wp-content\/uploads\/2024\/04\/Essentials-Cyber-Security-Documents-150x150.jpeg 150w, https:\/\/www.itminister.co.uk\/blog\/wp-content\/uploads\/2024\/04\/Essentials-Cyber-Security-Documents-768x768.jpeg 768w, https:\/\/www.itminister.co.uk\/blog\/wp-content\/uploads\/2024\/04\/Essentials-Cyber-Security-Documents-100x100.jpeg 100w\" sizes=\"auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" \/><\/figure>\n<\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Here are a few tangible examples of how documentation in action assisted organizations in mitigating cyberattacks.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Phishing Madness<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A healthcare provider, implemented a security awareness program that included documented <strong>guidelines<\/strong> for email authenticity. When targeted with a phishing campaign, the documented <strong>procedures<\/strong> helped staff to identify and report suspicious emails, which were already identified in <strong>control objectives<\/strong> and <strong>Risk catalogues<\/strong>. This equipped employees to distinguish legitimate emails from fraudulent phishing attempts.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Ransomware Disturbance<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A financial services firm, put into place a thorough incident response <strong>plan<\/strong> for isolating compromised systems. When a ransomware attack struck, the documented <strong>plan<\/strong> guaranteed a coordinated and efficient response, thereby preventing ransomware from propagation throughout the network. The <strong>procedures<\/strong> for data recovery made it possible to quickly restore financial data, reducing financial losses and minimizing business disruption<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Privileged Access Menace<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A retail chain created <strong>standards<\/strong> for the documented least privilege principle, allowing users to have access to only the information required to perform their jobs. When a cybercriminal gained unauthorized access to a low-level employee account, the principle of least privilege prevented them from escalating privileges and accessing sensitive data. The <strong>procedures<\/strong> for managing privileged accounts ensured their timely detection and remediation<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Cloud Mystery<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A global organization outlined its <strong>policies<\/strong> and <strong>procedures<\/strong> for cloud security. These provided <strong>guidelines<\/strong> for data encryption, access controls, and cloud resource security. When a misconfigured cloud storage was being created that would have exposed sensitive data, the documented security policies and preventive <strong>controls<\/strong> implemented denied the creation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Cyber Security documents serve as an organization defence plan road map, directing communication, strategy, and legal needs. They provide information on risks, policies, and best practices for reducing and\/or preventing cyberattacks such as phishing and ransomware.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Related Articles<\/h2>\n\n\n\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-embed wp-block-embed-embed\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"wp-embedded-content\" data-secret=\"qKh2pJRDZt\"><a href=\"https:\/\/www.itminister.co.uk\/blog\/security-of-the-cloud-security-in-the-cloud\/\">Security of the Cloud &amp; Security in the Cloud<\/a><\/blockquote><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;Security of the Cloud &amp; Security in the Cloud&#8221; &#8212; \" src=\"https:\/\/www.itminister.co.uk\/blog\/security-of-the-cloud-security-in-the-cloud\/embed\/#?secret=P445uW1H5A#?secret=qKh2pJRDZt\" data-secret=\"qKh2pJRDZt\" width=\"525\" height=\"296\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe>\n<\/div><\/figure>\n\n\n\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-embed wp-block-embed-embed\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"wp-embedded-content\" data-secret=\"X5kjx2mYGN\"><a href=\"https:\/\/www.itminister.co.uk\/blog\/it-is-time-to-start-threat-modelling\/\">&#8220;It is Time to Start Threat Modelling&#8221;<\/a><\/blockquote><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;&#8220;It is Time to Start Threat Modelling&#8221;&#8221; &#8212; \" src=\"https:\/\/www.itminister.co.uk\/blog\/it-is-time-to-start-threat-modelling\/embed\/#?secret=nlclBupX6l#?secret=X5kjx2mYGN\" data-secret=\"X5kjx2mYGN\" width=\"525\" height=\"296\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe>\n<\/div><\/figure>\n\n\n\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-embed wp-block-embed-embed\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"wp-embedded-content\" data-secret=\"ifU0vR775T\"><a href=\"https:\/\/www.itminister.co.uk\/blog\/how-mature-is-your-cybersecurity-actually\/\">How Mature is Your Cybersecurity Actually?<\/a><\/blockquote><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;How Mature is Your Cybersecurity Actually?&#8221; &#8212; \" src=\"https:\/\/www.itminister.co.uk\/blog\/how-mature-is-your-cybersecurity-actually\/embed\/#?secret=bs4dnN1o7c#?secret=ifU0vR775T\" data-secret=\"ifU0vR775T\" width=\"525\" height=\"296\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe>\n<\/div><\/figure>\n\n\n\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-embed wp-block-embed-embed\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"wp-embedded-content\" data-secret=\"LwcpZVuDZ6\"><a href=\"https:\/\/www.itminister.co.uk\/blog\/crafting-a-resilient-cybersecurity-strategy\/\">Crafting a Resilient Cybersecurity Strategy<\/a><\/blockquote><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;Crafting a Resilient Cybersecurity Strategy&#8221; &#8212; \" src=\"https:\/\/www.itminister.co.uk\/blog\/crafting-a-resilient-cybersecurity-strategy\/embed\/#?secret=wIzPPWu2n7#?secret=LwcpZVuDZ6\" data-secret=\"LwcpZVuDZ6\" width=\"525\" height=\"296\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe>\n<\/div><\/figure>\n\n\n\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-embed wp-block-embed-embed\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"wp-embedded-content\" data-secret=\"qNVYmYY9pB\"><a href=\"https:\/\/www.itminister.co.uk\/blog\/mastering-privilege-account-security\/\">Mastering Privilege Account Security<\/a><\/blockquote><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;Mastering Privilege Account Security&#8221; &#8212; \" src=\"https:\/\/www.itminister.co.uk\/blog\/mastering-privilege-account-security\/embed\/#?secret=36sYvlUlnL#?secret=qNVYmYY9pB\" data-secret=\"qNVYmYY9pB\" width=\"525\" height=\"296\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe>\n<\/div><\/figure>\n\n\n\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-embed wp-block-embed-embed\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"wp-embedded-content\" data-secret=\"yEGwAJrVDb\"><a href=\"https:\/\/www.itminister.co.uk\/blog\/a-guide-to-security-organizational-structure-models\/\">A Guide to Security Organizational Structure Models<\/a><\/blockquote><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;A Guide to Security Organizational Structure Models&#8221; &#8212; \" src=\"https:\/\/www.itminister.co.uk\/blog\/a-guide-to-security-organizational-structure-models\/embed\/#?secret=8yunTTFZNr#?secret=yEGwAJrVDb\" data-secret=\"yEGwAJrVDb\" width=\"525\" height=\"296\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe>\n<\/div><\/figure>\n\n\n\n<h1 class=\"wp-block-heading\">How Can ITM Help You?<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ember717\">IT Minister covers&nbsp;all&nbsp;aspects&nbsp;of Cyber Security including but not limited to&nbsp;<a href=\"https:\/\/www.itminister.co.uk\/homecybermanagement.html\">Home cyber Security Managed Solutions<\/a>&nbsp;to automated,&nbsp;<a href=\"https:\/\/www.itminister.co.uk\/businesscybersecurityservices.html\">Manage Threat Intelligence<\/a>,&nbsp;<a href=\"https:\/\/www.itminister.co.uk\/digitalforensics.html\">Digital Forensic Investigations<\/a>,&nbsp;<a href=\"https:\/\/www.itminister.co.uk\/penetrationtesting.html\">Penetration Testing<\/a>,&nbsp;<a href=\"https:\/\/www.itminister.co.uk\/mobiledevicesecurityassessment.html\">Mobile Device Management<\/a>,&nbsp;<a href=\"https:\/\/www.itminister.co.uk\/publiccloudhardening.html\">Cloud Security Best Practice<\/a>&nbsp;&amp;&nbsp;<a href=\"https:\/\/www.itminister.co.uk\/businesscybersecurityservices.html\">Secure Architecture by Design<\/a>&nbsp;and&nbsp;<a href=\"https:\/\/www.itminister.co.uk\/cybersecuritytraining.html\">Cyber Security Training<\/a>. Our objective is to support organisations and consumers at every step of their cyber maturity journey.&nbsp;<a href=\"https:\/\/www.itminister.co.uk\/contact.html\">Contact Us<\/a>&nbsp;for more information.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ignoring This Could Cost Organizations Everything! Intro The term &#8220;documentation&#8221; describes the organized keeping and filing of numerous types of documents. When referring to Cyber Security, it includes a broad range of documents that act as a fundamental pillar that creates a framework for comprehending the security posture of an organization, promoting efficient stakeholder communication, &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.itminister.co.uk\/blog\/cyber-security-documentation\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Cyber Security Documentation&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","beyondwords_generate_audio":"1","beyondwords_integration_method":"","beyondwords_project_id":"","beyondwords_content_id":"","beyondwords_preview_token":"","beyondwords_player_content":"","beyondwords_player_style":"","beyondwords_language_code":"","beyondwords_language_id":"","beyondwords_title_voice_id":"","beyondwords_body_voice_id":"","beyondwords_summary_voice_id":"","beyondwords_error_message":"#401: Unauthorized","beyondwords_disabled":"","beyondwords_delete_content":"","beyondwords_podcast_id":"","beyondwords_hash":"","publish_post_to_speechkit":"","speechkit_hash":"","speechkit_generate_audio":"","speechkit_project_id":"","speechkit_podcast_id":"","speechkit_error_message":"","speechkit_disabled":"","speechkit_access_key":"","speechkit_error":"","speechkit_info":"","speechkit_response":"","speechkit_retries":"","speechkit_status":"","speechkit_updated_at":"","_speechkit_link":"","_speechkit_text":""},"categories":[18,23,63,50,51],"tags":[],"class_list":["post-936","post","type-post","status-publish","format-standard","hentry","category-cyber-security-best-practice","category-cyber-security-research","category-cybersecurity-maturity","category-cybersecurity-strategy","category-data-classification-labelling"],"_links":{"self":[{"href":"https:\/\/www.itminister.co.uk\/blog\/wp-json\/wp\/v2\/posts\/936","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.itminister.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.itminister.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.itminister.co.uk\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.itminister.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=936"}],"version-history":[{"count":1,"href":"https:\/\/www.itminister.co.uk\/blog\/wp-json\/wp\/v2\/posts\/936\/revisions"}],"predecessor-version":[{"id":940,"href":"https:\/\/www.itminister.co.uk\/blog\/wp-json\/wp\/v2\/posts\/936\/revisions\/940"}],"wp:attachment":[{"href":"https:\/\/www.itminister.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=936"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.itminister.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=936"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.itminister.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=936"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}