September - 2020ENTERPRISE SECURITY| | 9Customer and Provider Cloud Security ResponsibilitiesOn-PremiseInfrastructure as a Service (IaaS)Platform as a Service (PaaS)Software as a Service (SaaS)Enterprise ApplicationsEnterprise ApplicationsEnterprise ApplicationsEnterprise ApplicationsData*Data*Data*Data*RuntimeRuntimeRuntimeRuntimeMiddlewareMiddlewareMiddlewareMiddlewareOperating SystemsOperating SystemsOperating SystemsOperating SystemsVirtualizationVirtualizationVirtualizationVirtualizationServersServersServersServersStorageStorageStorageStorageNetworkingNetworkingNetworkingNetworkingTools of the TradeContinuous monitoring of the enterprise-ensuring that previously discovered vulnerabilities are appropriately mitigated and new vulnerabilities are removed in a timely manner based on risk -are critical activities to ensure a safe and resilient operating environment. Vulnerability and patch compliance tools must be implemented by the organization to address the diverse technologies deployed throughout the enterprise. These tools can provide automated analysis for server and workstation operating systems, server software applications (ex: database and email server software), desktop applications (ex: office productivity suites), network devices (ex: switches, routers and firewalls), and applications and databases (ex: dynamic and static code analysis). Automated Metrics and ReportingDue to the complex nature of the modern enterprise, automation must be implemented wherever possible to discover, triage and report on the vulnerabilities across the organization. Vulnerabilities are an expected part of the life cycle for digital assets as organizations are growing their use of technology. As such, it should be expected that vulnerability data will grow in tandem with an organization's technological footprint, and the volume of data will become greater than a manual process can handle. Organizations should implement tools that allow for automated discovery in accordance with enterprise-defined security policies and risk posture. These systems should allow for automated reporting and metrics development. Best Practices Implement automation wherever possible to support vulnerability identification, mitigation and reporting regardless of the location or type of technology deployed by the organization. Ensure that effective lines of communication are established between Cybersecurity and IT Operations teams. Focus on customer service by establishing effective and repeatable processes related to patch and vulnerability management. When a potential vulnerability has been identified through automated tools, the vulnerability must be analyzed to determine its validity (false-positive or false-negative). Triage identified vulnerabilities, ensuring that high-risk vulnerabilities are quickly identified, prioritized,assigned a mitigation recommendation and mitigated in a timely fashion according to established organizational or industry standard vulnerability mitigation timelines. Tie identified vulnerabilities back to the organizational risk assessment and discuss how vulnerabilities can influence mission performance and objectives. Identify, capture and manage any deviations to vulnerability mitigation timelines using repeatable processes at the enterprise level. ES Customer ManagedProvider ManagedData*Data protection is foundational to risk treatment and vulnerability triaging regardless of who manages technical security controlsCustomerVulnerability management is the process of identifying and mitigating vulnerabilities that exist within an organization and is an integral part of digital systems lifecycle management
<
Page 8 |
Page 10 >