THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


When my daughter was four years old, my early morning riser and I agreed that on lazy Sunday mornings she could wake me up briefly to enter my password on my iPad, watch two cartoons, and then wake me up for good. One morning, I woke up to the sound of Caillou’s voice instead and asked her how she was able to access my iPad without my password. My daughter beamed with pride stating that she had put my thumb on the circle button while asleep, so she didn’t need to wake me up. I smiled at her, deeply amused that one of the best end-user security controls (fingerprint biometrics) from one of the best security companies (Apple) had been hacked by a screentime-motivated child, exposing a vulnerability on that device. Vulnerabilities are simply a weakness in a system and many vulnerability practitioners face the daily challenge of finding remediation solutions to improve their organization’s risk posture.
In the realm of vulnerability management, patching is still king. Patching and refresh initiatives ensure a company’s technology stack is composed of secure assets, software, and hardware. Patching is well understood and is typically done with the support of vendor guidance, established processes, and well-adopted best practices. Out of the limelight are misconfiguration vulnerabilities, not patchable by nature. There is little disagreement that it is important. Misconfigurations have risen to number five on the Open Worldwide Application Security Project’s Top 10 list of critical web application security risks. And, according to Verizon’s Data Breach Investigation Report, they are at the root of 10 percent of all breaches, and 39 percent of web application breaches. Despite this, misconfiguration management is often an afterthought.
Misconfigurations have the unfortunate reputation of being harder to understand and taking more time to mitigate, often requiring deep expertise in each operating system a company leverages. Despite the fear of remediation associated with their less defined remediation impact, proper handling of misconfigurations is often the only option to address some exploited risks, especially for firewalls. According to Garner, Misconfiguration will cause 99 percent of firewall breaches through 2023.
“Leveraging system hardening and methodically raising the bar on security configurations is a great approach to reducing misconfigurations over time because it recognizes the balance that is needed between operational functionality and security.”
Part of the challenge lies in the prefix ‘mis,’ of the word misconfiguration. This presents the illusion that configuration settings are either safe or unsafe when the reality is that the true vulnerability of security configurations or a grouping of configurations, exists on a scale. They are sub-optimal configurations that are created when security settings are either not implemented or implemented poorly. An unknown security gap may be exposed when what was once considered safe settings, are shown to have security risks when tested in depth by ethical and unethical hackers. Leveraging system hardening and methodically raising the bar on security configurations is a great approach to reducing misconfigurations over time because it recognizes the balance that is needed between operational functionality and security.
Thankfully, managing security configuration does not have to stay shrouded in mystery. There are several standardized and established frameworks to offer clear and updated guidance on configuration settings. The NIST SP 800-12 outlines the recommendations around SecCM, (Security-Focused Configuration Management), for organizations with federal data. The most popular configuration standards framework used across many vulnerability assessment tools to identify misconfigurations is the CIS Benchmark. It provides detailed standards for over 25 vendor products and covers cloud, endpoint, network, hosting, and operating system recommendations.
Lesser known, but well-respected, security configuration guidance can also be found through the Defense Information Systems Agency (DISA) and their Security Technical Implementation (STIGS) guidelines. Finally, the National Checklist Program contains a variety of security configuration checklists for the purpose of system hardening and lockdowns.
Technology has also evolved rapidly to meet the growing needs of misconfiguration management. There is a growing list of tools that have augmented their existing capability with misconfiguration identification and remediation, even in the build pipeline. There are many newer products in the market that primarily focus on misconfiguration management. These new solutions are allowing for rich defense-in-depth defense capabilities, and some mitigations that were once solely in the space of patching can now be addressed by security configuration management.
One example of the many tools now available to us is Gytpol Validator, which looked at remediating the Log4j library as misconfigurations and provided a solution that decomposed their jar file down to lines of code and created scripts to comment out risky classes such as JNDI. Other powerful tools have risen to the top including BigFix Compliance, which compliments their BigFix Patch suite, solving for challenging remediation that involves both patching, configuration, and registry changes. Wiz, which focuses on vulnerability and misconfigurations in the cloud, successfully manages its continuous deployment across hybrid and multi-cloud implementations.
Security configuration management does not have to be hard, but it does take more patience. My daughter, now a screentime-motivated teenager, understands security configurations on our iPad better than anyone I know, especially all the options under the parental control section. There are hard negotiations these days on what privileges she should have (or rights according to her). What should not be negotiable is ensuring misconfigurations get the same priority as patching. The timing is great, especially with so many supporting frameworks and technology now available to make misconfiguration management more solvable than ever before.