enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

North Carolina Department of Revenue

How CyberSecurity Role Automation Can Help Fill Some of the Void in a Skill Market Shortage: Process, Benefits, Compliance and Best Practices

Jerome Smith, Deputy Chief Information Security Officer, North Carolina Department of Revenue

The cybersecurity skill shortage is continuing to be a top issue for the public and private sectors. To this day, there are a very large number of vacant cybersecurity positions. Due to the nature of such a high number of vacant positions and a skill shortage, critical infrastructure is at risk.

Without the necessary trained skills, it is becoming more difficult for businesses and the government to execute their security strategy. This can make it easier for hackers’ or state sponsored organizations to infiltrate critical infrastructure. One way to alleviate this issue is through security automation. Organizations can automate as many roles as possible in the interim while continuing to fill key roles.

WHAT IS THE AUTOMATION OF CYBERSECURITY ROLES OR TASKS?

The automation of a cybersecurity role or/task is the non-human intervention of the execution of security actions, which is usually performed by security personnel. These actions when invoked; can perform most of tasks that a security analyst can do without human intervention. Some of the roles that can be automated include but not limited to: Detection, Triaging, Mitigation, and Remediation.

COMMON BENEFITS OF AUTOMATING CYBERSECURITY ROLES:

• Higher Degree of Threat Intelligence--most automation tools use databases of various real-time security Intel feeds. These tools will know a threat before the security staff. Which helps to automatically triage alerts and identify true positives.

• Faster Response Time--in a security stack where security tools have the ability to talk to each other, there are faster mitigation response times.

• Streamlined Operations--less impact from employee turnover and reduced training cost. Allows the security staff to focus on strategic tasks.

• Reduced Manual Processes & Increase Tolerance for Employee Turnover-- implementing security role automation helps streamline operations and offers resistance to employee turnover.

• Security Stack Integration--integrate tools have the ability to communicate with each other whether it is through APIs or a common third party Intel source. This makes triaging events faster.

• Reporting Capability--ability to automatically provide customized reports and metrics.

• Time Savings--allows security staff to focus on higher level duties and the strategy map. Can also reduce the number of FTEs( Full Time Employee) needed to perform a job role or function.

• Compliance Audits--facilitates the passing of compliance audits. Saves time from gathering artifacts for audits. Reduces the chance of having gaps in an audit. 

COMMON BENEFITS FROM A COMPLIANCE PERSPECTIVE:

The automation of Cybersecurity Roles can also be beneficial in a compliance environment where entities are govern by regulatory laws, rules and regulations. 

• Visibility and Accountability--provides a unobstructed view of different roles and processes. It can also help identify any gaps that may require human intervention.

• Reduces human errors--reduces the number of compliance errors which could in audit findings.

• Continuous Compliance Enforcement- -once a role is automated with all of the compliance checks in place, it becomes a process and doesn’t deviate without human intervention.

• Noise Reduction—reduces out of process implementations that may be outside of policy.

"Security And Privacy Concerns Will Hinder5g Adoption And Growth If Csps Don’t Implement Robust Security Operations To Alleviate These Apprehensions"

CYBERSECURITY ROLE AUTOMATION BEST PRACTICES:

There are some best practices to consider when introducing automation into your environment. If they aren’t considered, the cons can outweigh the benefits. 

Establish Boundaries

Without the proper boundaries, automation can make for a long day. For example, you wouldn’t want to automate the role of creating user IDs without some type of vetting process for bulk creation.

FedRamp Certified

Choose a toolset that is FedRamp certified. This helps to alleviate the compliance and regulatory pressure. If the product is not certified, work your way down to the most applicable solution for your business model.

 Perform Regular Checkups

Automation is not a set it and forget it deployment. There should always be a degree of human involvement and oversight whether that is through monitoring, manual intervention, or risk analysis of the toolset and third parties. 

IDENTIFY WHAT TO AUTOMATE AND GRADUALLY IMPLEMENT

Identity the tasks to automate. They should be tasks that occur the most often and that are difficult or time consuming. Once you identify the tasks, gradually automate. I always recommend to operate in monitor mode for a month or more to identify any abnormalities. 

Identify the security events that occur most often, and those that take the longest time to investigate and resolve. Then define use cases and create a list of how security automation can help, based on organizational goals.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.