enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

AMH

Building Effective Vulnerability Management

Dan Demetry, Information Security Manager, AMH

Vulnerability management is a demanding operation that never sleeps. It’s also an area of the information security program that the board will always have an interest in and if you’re responsible for its results, it could feel like you’re under a spotlight or a microscope. The good news is that the technology to detect vulnerabilities has improved. The bad news is that the technology to remediate those same vulnerabilities has not kept up. Too often critical and severe vulnerabilities are found on an unstable production server with an obsolete OS and the patching process can only be executed manually and with a delicate touch. Some business process owners and server admins are brave enough to move forward with the patch while others are not and simply accept the risk because one day that very vulnerable server or the business application it hosts is “going away” in the future. And of course, there’s that remote work force that never returned to the office after the pandemic subsided. If they could only logon to the VPN every once in a while, to receive those Windows patches but many of them discovered that they just need to access a collection of corporate web applications to do their jobs without being on the corporate network.

There are some practical considerations to make vulnerability management more effective in the face of these challenges. It’s essential that prioritization is embedded into any vulnerability management program due to the sheer volume of vulnerabilities that are detected daily. Critical exploitable vulnerabilities should be prioritized over critical or severe vulnerabilities just as business-critical production assets should be prioritized over test assets. If you can demonstrate meaningful progress in remediating the most critical vulnerabilities on the most valuable assets in a consistent manner, then your vulnerability management program is fully functional.

“Critical exploitable vulnerabilities should be prioritized over critical or severe vulnerabilities just as business-critical production assets should be prioritized over test assets.”

The day is always coming where a zero-day has been discovered in the wild that directly impacts your IT environment and shortly thereafter the emergency patch/configuration fire drill alarm sounds and it’s time to run to your battle stations! It may be a shock to you that you’re getting resistance from pushing out that out-of-band patch that will protect the business from being compromised or breached due to heavy workloads or competing priorities from IT operations. This is the time to let them know of the risks involved of not pushing out the emergency patch which should go a long way in getting those senior leadership emergency approvals.However, it’s important to establish and cultivate those partnerships with IT operations now before you need them in an emergency, so this fire drill runs as smoothly as possible when the time comes.

Improvements to remediation technology have already begun such as patching from the cloud those remote laptops that never talk to the corporate network which will likely be a must-have soon. Prioritization and partnerships can fill the gaps and reduce the challenges until remediation technology catches up to the scale of the vulnerabilities detected to enable the remediation process to be more automated and more effective.Vulnerability management can feel overwhelming but focusing on the most critical vulnerabilities while protecting the most valuable assets that have been prioritized in advance while building strong partnerships will support your vulnerability management program in delivering the best results.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.