MAY 2024ENTERPRISE SECURITY| | 19THE COMMON VULNERABILITY SCORING SYSTEM, OR CVSS, IS THE INDUSTRY BENCHMARK FOR SEVERITY SCORING, AND WHILE THE CVSS SHOULD BE USED AS A GUIDERAIL, IT CANNOT PROVIDE ORGANISATION-SPECIFIC CONTEXT TO DRIVE REMEDIATION EFFORTSorganisational exposure. This delay ultimately provides adversaries with a window of opportunity that on average, according to InfoSec Institute, sits between 60 to 150 days, to exploit a given weakness in a target environment, long before it can be mitigated. Vulnerability Management systems have also primarily focused on the identification of purely technical vulnerabilities, called "Common Vulnerabilities and Exposures" or CVEs for short. The Common Vulnerability Scoring System, or CVSS, is the industry benchmark for severity scoring, and while the CVSS should be used as a guiderail, it cannot provide organisation-specific context to drive remediation efforts. This CVE and CVSS-centric view has blinded organisations to the presence and prioritisation of critical risk factors such as misconfigurations, human-induced errors, identity related exposure, even supply chain related risks. This narrow approach has ultimately left organisations more vulnerable and exposed. Next came systems that integrated Threat Intelligence (TI) and other criteria to provide a more well-rounded view of your vulnerability footprint. While these systems provide an improved snapshot for prioritisation, actual threat information, ease of exploitability, and recommended remediations; such tools are still complex and time consuming in nature, requiring significant administrative overhead to manage. They still lack the organisation specific context to enable truly effective risk-based decision making and prioritisation. With the proliferation of hybrid and multi-cloud-based services, increased mobility, remote teleworking practices, accessibility and integration of AI, and the pervasive use of social media, technology adoption and innovation has become ubiquitous. As such, Vulnerability Management norms have intrinsically changed; where Vulnerability Management systems and processes previously didn't extend beyond the realms of keeping Operating Systems patched and up to date, today this is but a link in a much broader chain. Recognising these past limitations has driven the emergence of a more proactive and holistic approach to safeguarding our systems. Underpinned by the rapid development, convergence, and adoption of two separate yet interrelated domains: Attack Path, and Attack Surface Management. Attack Path Management involves analysing the interconnected pathways that potential attackers could exploit to move laterally through a network. By understanding these potential paths of attack, organisations gain heightened visibility into the critical relationships and dependencies that exist between their infrastructures. This enables contextual prioritisation of vulnerabilities based on their potential impacts, facilitating a far more proactive approach to managing uncertainty. Attack Path Management goes beyond simply identifying individual vulnerabilities and focuses on understanding how such vulnerabilities can be chained together to create a pathway for attackers to exploit. This allows organisations to assess risks from a systemic perspective, identifying the most effective ways to mitigate threats and prioritise resources accordingly. Attack Surface Management on the other hand considers the broader attack surface of the organisation, which includes not only vulnerabilities within the network but also external factors that may expose the organisation to exploitation. This approach considers factors such as cloud hosted systems and data, IoT / OT devices, third party integrations (API's), supply chain, and even human-related risk factors. By adopting a holistic Attack Surface Management approach, organisations gain a comprehensive view of their entire digital landscape. Enabling the identification of potential weakness that could otherwise be leveraged by an attacker, even if they're not immediately apparent through traditional vulnerability scanning mechanisms. By addressing vulnerabilities across the entire attack surface, organisations can more effectively reduce their overall risk, whilst enhancing their cyber resilience.We as an industry must be responsive to these advancements, shifting away from legacy Vulnerability Management practices towards more holistic Attack Surface and Attack Path Management. Through these proactive capabilities Security Operations teams can be further empowered to identify and mitigate vulnerabilities more effectively. By understanding the interconnected nature of our IT environments and considering factors beyond the technical realm, we can better protect our digital assets from the evolving cyber threat landscape. Embracing new and pre-emptive approaches will be crucial for organisations looking to stay ahead of the threat curve, whilst ensuring the sustained resilience of our systems and operations. ES
<
Page 9 |
Page 11 >