NOVEMBER 2023ENTERPRISE SECURITY| | 19CXO INSIGHTSCustomers, regulators, business partners employees and your Board of Directors all expect that you have deployed the right technology to protect their data and systems. Unidentified gaps in your security posture may lead to missed performance guarantees, audit findings, and in the worst case a security incident. Traditional assurance mechanisms, such as inquiry and sampling, only give confidence that a portion of your environment is protected at a point in time. Being resource intensive, these methodsare typically executed infrequently. On the other hand, automation can provide frequent, comprehensive assessments, enabling closed-loop remediation.To automate assurance for security technology, clear definitions of "good" are required. The definition must allow you to precisely define a test for "good," to identify the data required for testing, and to interpret the output of the test.We chose effectiveness as our litmus test, defined asthe measure of four attributes: coverage, availability, configuration and currency. Coverage is a measure of the percentage of your technical environment to which a security technologyhas been deployed. Our challengewas identifying theasset population. For endpoints, through extensive collaboration between security and infrastructure teams, we were ableto correlate our asset management system withour security management consoles andestablish our own source of truth for population.Asset population forms the denominator of the coverage measure. Our next challenge was to identify what had been deployed. For security software deployed to endpoints, we correlated data from our software distribution systems and from our security management consoles to provide the numerator. The next measure, availability,tells you if the security technology is "on." Continuing with the endpoint example, we considered an agent to be available if it had reported back to its management console. Tuning the threshold for alerting took work. There are valid reasons for an agent not to report in. For example, a laptop that is shut down for the weekendwill not be sending a heartbeat to the console.Configurationmeasuresdeviations to configuration standards. For example, do anti-malware agents have the requiredblocking policies? Key to this measure was working closely with our security engineering teams to exactly specify the expected configurations.Once a baseline was agreed to, it was straightforward to download configurations from the management console and compare them to it.The final measure, currencytests whether all components of the security technology are up to date. Versioning can be inconsistent across vendors, so we establisheda procedure to regularly update an internal table of vendor specific version names and numbers. In collaboration with our security and infrastructure REST ASSURED IN THE EFFECTIVENESS OF YOUR SECURITY TECHNOLOGYBy Matt Stiak, Director, Cyber Risk Management, Delta Dental of CaliforniaMatt Stiak
<
Page 9 |
Page 11 >