enterprisesecuritymag

June - 2020ENTERPRISE SECURITY| | 9must make an assessment of what resources they have available and know the avenues of approach bad actors will use to attack the systems and data they safeguard. Translating Henry's actions into cybersecurity terms means gaining an understanding of the people, processes, and technologies already in place.For the past several years, the private and public sectors alike have been somewhat reactionary in the strategies employed to protect systems and data; external factors have been driving procurement and policy more than an internal focus on risk analysis and risk-based decision making. Being forward looking is a luxury most CIOs and CISOs don't have. Many organizations are in a cycle of playing catch up by patching and protecting against last week's threat. How does a CISO get ahead? Taking a moment to assess where the state of the enterprise is from a people, process, and technology standpoint is a good place to start and this is where a lesson from the U.S. Army on OAKOC can be handy for the CISO. Observation: This means developing an understanding of the infrastructure that houses the organization's data and systems. This assessment should encompass all devices and solutions connected to and from the enterprise. After assessing the environment, map the business requirements as an overlay to any technical topological representations. Avenues of Approach: This is simply taking a moment to understand the attack vectors used by bad actors. A current picture of popular attack vectors can be easily obtained through open sources such as CIO Review or subscribing to a cyber threat intelligence service provider. This analysis should also include how the Security Information and Event Monitoring (SIEM) and Governance, Risk and Compliance (GRC) platforms are used to incorporate risk and intelligence information. For example, patching for WannaCry may still be a known problem. A cyber threat intelligence service provider can provide information on the likelihood this vulnerability will be exploited and feeding vulnerability scanning results into a SIEM or GRC could provide a clearer understanding to the extent vulnerabilities exist on the enterprise. Key and Decisive Terrain: Take time to study topology diagrams and understand how existing security technologies are employed with reference to Avenues of Approach and look for opportunities to utilize existing technologies in more defensible locations on the Enterprise. Obstacles: These are typically lack of personnel, employees lacking cybersecurity skillsets, or budgetary constraints. They could also be internal business processes that hamper security efforts. There may even be internal politics such as friction between network operations and security teams. Obstacles are not going to go away; accepting the organization's challenges are essential for the CISO's vision to be transformed into a strategy.Cover: It is definitely in the best interest of a CISO to have cover from the CIO, CEO and the Board. What is meant by cover is support for, and adoption of, cybersecurity policies and budgets which translates to development in people, processes, and technologies. In order to obtain cover from leadership, the CISO must translate existing security concerns into language that conveys the impact on the business including financial, reputational and legal consequences of not mitigating cyber-risks. King Henry was able to use the concepts behind OAKOC to translate vision into action resulting in a decisive victory. Like Henry V, a CISO can create equally dramatic results by merging vision with these principles to organize existing security efforts into a cohesive strategic plan. ESJake MargolisObstacles are not going to go away; accepting the organization's challenges are essential for the CISO's vision to be transformed into a strategy
< Page 8 | Page 10 >