DECEMBER 2023ENTERPRISE SECURITY| | 9A COMMON INDUSTRY EXAMPLE OF INNOVATION RISK IS TAKING SHORTCUTS IN THE CLOUD DUE TO TIME PRESSURES OR KNOWLEDGE GAPS, LEADING TO CLOUD MISCONFIGURATIONS AND EXPOSURE OF SENSITIVE DATAor 90 days. This imposes burdens on the user, and costs are associated with recovering accounts for the Service Desk. Regular password changes do not improve security so use SSO with MFA to reduce user friction and maintain security simultaneously.LEVERAGE ZERO-TRUST TO MOBILISE THE WORKFORCE- In today's world, business users must work from any location, including occasional risky public wi-fi hotspots. Good segmentation between end-users and critical assets in the data centre, plus the ability to respond to end- user threats immediately when they arise, will provide flexibility for the workforce to work from any location. Many businesses still use traditional client VPNs, which have caused ransomware to propagate from end-user devices to critical assets in the data centre.Replacing these with zero trust private access will reduce the attack surface to just the web applications the user needs for their role, eliminating the exposure of risky ports and protocols.WEEKLY SECURITY ARCHITECTURE TRIAGE SURGERIES: There is nothing worse for a security team than shadow IT, a new solution going live without any security engagement. Formal governance, including design review boards, has its place but needs to be more convenient for product owners to present their solutions. In an agile workplace, we have informal surgeries for product owners to walk through their proposals to the Information Security team, ensuring we get insight and provide feedback into new initiatives early. Tight engagement between product owners and security architecture is essential in our organisation.BREAK GLASS SOLUTION FOR PRODUCTION SUPPORT- The utopia is for everything to be fixed through a deployment pipeline. Occasionally, Developers need access to production data to fix an incident. Use automation, such as an access broker, to grant privileged access for a limited period to resolve an incident. This prevents large numbers of accounts with standing access to production data, making detecting and responding to suspicious activity much easier.DROP-IN APPOINTMENTS FOR NEW STARTERS- A Developer can have many years of experience but are uncomfortable admitting they are less skilled in secure development practices.Examples of insecure practices include pushing sensitive code to public repos, including secrets in source code, passwords in slack channels and a lack of awareness of web applications' most critical security risks. Have each new Developer spend an hour with a DevSecOps lead to show them how to use the deployment tools and set their expectations regarding security practices. Developers appreciate being shown how to get up and running quickly, and it's a great way to find out if any new starters need more education than others.In summary, Information Security can enable the business through a digital transformation by being proactive and having solutions to manage innovation risks before security incidents materialise. Having tight engagement and proactive solutions reduces friction for most users and third parties, freeing the business to explore its goals. If Information Security defaults to a reactive stance, this will result in more risk, more incidents, or a slow pace of the transformation. ESRichard Frost
<
Page 8 |
Page 10 >