enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

STADA Group

Managing Vulnerabilities to Mitigate Risks

Aleksandar Radosavljevi, Global Chief Information Security Officer, STADA Group

We are all witnessing that the number of cyberattacks is increasing and this trend will unfortunately also continue in the future. In the past few decades, organizations have kept investing significantly in their cyber security programs, such as by introducing modern security technologies. However, most of those cyber security programs struggle to address one area, even though it is a very important pillar of basic cybersecurity hygiene: Vulnerability Management. Vulnerability Management is a continuous process of identifying, assessing, reporting on, managing, and remediating cyber vulnerabilities. All it takes is one vulnerability which could be exploited to cause a data breach. This emphasize how critical it is to handle vulnerabilities.

Some of today’s organization environments have millions of vulnerabilities. Trying to patch all of them is almost impossible, and this is where most organizations fail, as they have in the majority of cases limited resource capacity. Regardless, organizations will try to patch everything, as they believe that even a single vulnerability could have the potential to result in a major business impact for the organization.

Trying to treat all vulnerabilities is not constructive and does not achieve anything for organizations, as not every single vulnerability could be treated the same; it is simply overwhelming. Additionally, vulnerability management requires most organizations to use one or multiple tools to address the vulnerabilities. This involves introducing a lot of operational overheads and frustration to IT operational teams. And in most situations, Security and IT operational teams disagree over which vulnerabilities to tackle first.

In order to triage the risks, organizations mostly rely on the Common Vulnerability Scoring System (CVSS) for vulnerabilities listed in the National Vulnerability Database. But focusing purely on CVE scores does not reduce overheads. In reality, only somewhere between three and five percent CVE’s are exploitable. Some data scientists could even predict which vulnerabilities are most likely to be potentially exploited.

Therefore, we need to change the approach above and as a first step remediate the riskiest vulnerabilities first. This approach is called risk-based vulnerability and it is based on prioritization. The most important aspect of vulnerability management prioritization is the context surrounding each vulnerability and its unique position within an IT environment. This includes:

- How important is the asset? Is it a Crown Jewel? Is it publicly exposed or customer-facing?

- What is the state of security controls protecting the asset?

- Does the asset hold financial, personal identifiable, or other organizational sensitive information?

- Does the vulnerability exist within a regulated environment?

- How many users could be impacted by a successful exploitation?

- Are exploiters actively targeting your industry?

Most modern vulnerability management solutions support the above approach and help customers to prioritize the handling of vulnerabilities. The organization should develop a roadmap regarding which contextual information could work the best for their environments, and gradually implementing more steps to bring the maturity to the next level. Of course, CVSS must be also taken into consideration when configuring those vulnerability management solutions. The result of following a risk-based vulnerability management prioritization approach is to significantly reduce the number of vulnerabilities which should be addressed, achieving approximately 50 percent remediation coverage and still addressing every high-risk vulnerability.

The outcome is that a risk-based vulnerability management prioritization approach aligns Information Security and IT operational teams around common goals, reducing operational overheads and significantly reducing the risk exposure.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.