enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Virginia Tech

Putting Enterprise Risk Management into Practice

Randy Marchany, CISO, Virginia Tech

A chief information security officer's (CISO) main function is to devise and implement strategies to protect mission-critical data used by their organization from unauthorized access, examination, or modification. Enterprise risk management (ERM) is an enterprise-wide strategy designed to identify potential events that may affect the entity, manage and accept tolerable risk and support the enterprise's business objectives.

An example of mapping risk to various levels is shown here.

Figure 1. Clarifying Risk Terms(courtesy S.F.Midkiff)

Information technology (IT) may play a key role, but it is not always the primary role. CISOs should always remember the business process trumps the security process in most cases.

We identify risks, rate the probability of these events happening and prioritize which ones the enterprise needs to address and be willing to accept the risk of inaction. Velocity is the rate at which the enterprise feels the impact. See Figure 2 for risk examples.

“The key to a successful ERM implementation is to have a comprehensive asset inventory and classification process in place.”

Figure 2. Risk Examples(courtesy S.F.Midkiff)

The Center for Internet Security (CIS) Controls and helps organizations map out steps to defend themselves from common cyberattacks. They map to a wide variety of international control frameworks/standards such as ISO, NIST, PCI, ATT&CK, and HIPAA.

CIS Control 1 – Inventory and Control of Enterprise Assets

You can’t protect something if you don't know the who, what, why, when, and where properties of the asset. Hardware assets are truly mobile in today's remote work environment.

Work-from-home assets are connected to an ISP's network, not directly to the corporate network. This complicates incident response since we can’t disconnect the asset from the net. This process is critical because if there is an incident, you need to know what the asset is (endpoint, server, Windows, Linux, Mac, proprietary), where it is (corporate network or ISP), and who is responsible for its care and feeding.

CIS Control 3 – Data Protection

The Mitre ATT&CK model describes the methods attackers use to attack a target. I believe attackers have any or all of these three goals:

1. Steal your data – use it for monetary purposes, disclose it to put you at a disadvantage.

2. Destroy your data – cripple your business processes

3. Compromise machines and use them for steps 1, 2, and 3.

We should be designing our security and ERM strategies to address these three goals. CIS Control three lists 14 safeguards to help you address data protection. We need to identify, classify (low, moderate, high), protect, retain, and securely dispose of the data. We define high-risk data as any data covered by law and/or regulation, and we are required to notify external parties of unauthorized access.

These efforts help answer.

1. The ‘why’ question – Why is high-risk data where it is? Why does person X have access to it?

2. The ‘when’ question – When did an asset become a high-risk asset? When was high-risk data accessed? When was the high-risk data destroyed or deleted?

High-Risk Data Types

We combine the information collected for CIS Control 1 with the data collected in this phase to understand how these data types are distributed across the assets. Let’s assume the enterprise has 50000 assets and 5000 high-risk assets.

Figure 3. High-risk data distribution example

Figure 3 shows an example of high-risk data stored on those 5000 assets. Let’s use the following color chart:

1. Green – bank/debit account numbers

2. Red – SSN

3. Pink – CCN

4. Orange – DMV numbers

5. Dark blue – critical to the organization

Given this information and the chart shown in Figure 3, we can ask the following questions:

1. Why do we have so many high-risk systems?

2. Do they need to be high-risk?

3. Why are bank/debit account numbers stored on so many assets?

4. Why are SSN, CCN, and DMV stored on so many assets?

5. What type of assets are these? Endpoints? Servers? Applications (on-prem, cloud)?

6. Should we or can we concentrate our high-risk data in the cloud?

7. Is the high-risk data encrypted at rest? Who has the keys?

8. Are the users properly trained in the use and protection of high-risk data?

The impact of these risks on the enterprise's PII data is significant and can cause major disruptions in operations. The likelihood of such an attack can be classified as medium, assuming data protection policies are followed. However, the velocity of a ransomware attack is high (seconds to hours). Velocity dictates the priority of controls to be applied. How? Lower velocity values mean your detection times are faster. This can justify purchasing controls that can take advantage of shorter detection times.

Since the velocity is high, your detection time increases, so controls such as data encryption, better detection, and recovery (backup) processes need to be enhanced and tested frequently.

Finally, we should reduce the high-risk data footprint by centralizing where high-risk data is stored.

We simplified this example, but the key to a successful ERM implementation is to have a comprehensive asset inventory and classification process. This helps us centralize where sensitive data is stored. Challenges to this effort include a) finding that has the data you need, b) going through the bureaucratic processes to gain access to that data c) finding a tool to help you analyze your data results. Of course, executive management buy-in is essential. Once you have this data, you need to express the results in financial terms.

You can use this information to help you prioritize the class of controls you need to effectively defend your organization’s critical data assets.

I encourage you to look at the CIS Controls and how they map to common international standards.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief