Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

9/13/2019
10:00 AM
Joshua Goldfarb
Joshua Goldfarb
Commentary
Connect Directly
Twitter
RSS
E-Mail vvv
100%
0%

Taking a Fresh Look at Security Ops: 10 Tips

Maybe you love your executive team, your security processes, tools, or strategy. Maybe you hate them. Whatever the situation, it's likely at some point that things will have changed.

A few months back, someone asked me to help him take apart a bed frame. He had a problem stemming from a stripped screw that could not be removed. When I came over, I noticed another screw on the other arm of the bracket. The second screw was not stripped, and so I loosened it. This freed the bracket, which allowed me to easily take apart the bed frame.

I'm relaying this incident not to brag about my talent as a brilliant problem solver or because I am exceptionally handy. In fact, the person who asked me for help is a particularly brilliant problem solver — a far better one than I. The reason I was able to solve the bed frame problem is because I looked at it with fresh eyes, a state of mind that is also useful in the realm of cybersecurity, as these 10 examples demonstrate:

  1. Executive support: Struggling to get the attention of executives and the board? Not able to make security a priority for the business and advance items important to security? Try looking at the problem through new eyes — namely theirs. How do executives view the business? What risks and threats to the business are they concerned with? If you can view issues from the perspective of the C-suite, you might have better luck communicating why security is important in a language they'll understand far better.
  2. Security strategy: Sure, you may have a formal security strategy that was written a few years back. But have you looked at it with your present-day eyes? The environment in which the security team operates changes constantly. It might be time to take a fresh look at the overall direction of the program.
  3. Risk: Do you understand the risks that the business faces? Are you sure? Risks evolve continuously and understanding what they are and how they affect the business today is paramount to successfully securing the business.
  4. Threats: Are you familiar with the information security threat landscape that you face? Are you certain that your knowledge is up to date? It might be time to take a new look at the threat landscape as it pertains to your enterprise.
  5. Goals: When was the last time you set goals for the security team? Was it at a time when you may have looked at the information security world differently? If the last time you examined goals was not so recently, you will likely see the topic differently now. Give goals a glance through your present-day eyes.
  6. Priorities: The security team's priorities are likely shifting constantly. New challenges arise continuously, as do old challenges. So why is it that you set priorities only once per year, or even less frequently than that? Of course, priorities cannot be reset daily, but there is a balance here. Try looking at priorities more frequently than annually.
  7. People: You're likely quite fond of and proud of the security team you've built. You've probably assembled a group of skilled and talented contributors. But there is more to the equation than just the quality of the team you've put together. There is also consideration of the alignment of the team and their skill sets to your strategic objectives. Has it been a while since you took a look at your team from that perspective? It might be worth a new look.
  8. Process: I've seen my share of bad processes over the course of my career. Even the good processes I've come across were written for a given purpose under a specific set of circumstances. What if the purpose and/or the circumstances change? Over a period of time, this is almost always the case. Given that, doesn't it make sense to reevaluate whether or not different processes make sense in the current environment? Casting a fresh look upon processes often produces more effective and efficient ones.
  9. Technology: Maybe you love your security tooling. Maybe you hate it. Maybe you painstakingly architected your security stack with an eye for detail. Maybe you inherited some or all of it. Whatever the situation, it's likely that things have changed quite a bit since the tooling in place was procured and deployed. Isn't it time to ensure that the technology in place still fits the bill? My guess is that you'll find several pieces that are no longer appropriate.
  10. External organizations: You probably have a membership in a few different external organizations. Perhaps you are a part of mailing lists, attend conference calls, or participate in meetings with these organizations on a fairly regular basis. When was the last time you stopped to think about what you're actually getting out of these organizations versus what you're putting into them? What once made sense may no longer be the case. Definitely worth a glance with fresh eyes.

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "Escaping Email: Unlocking Message Security for SMS, WhatsApp"

Josh (Twitter: @ananalytical) is an experienced information security leader who works with enterprises to mature and improve their enterprise security programs.  Previously, Josh served as VP, CTO - Emerging Technologies at FireEye and as Chief Security Officer for ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Data Privacy Protections for the Most Vulnerable -- Children
Dimitri Sirota, Founder & CEO of BigID,  10/17/2019
Sodinokibi Ransomware: Where Attackers' Money Goes
Kelly Sheridan, Staff Editor, Dark Reading,  10/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18214
PUBLISHED: 2019-10-19
The Video_Converter app 0.1.0 for Nextcloud allows denial of service (CPU and memory consumption) via multiple concurrent conversions because many FFmpeg processes may be running at once. (The workload is not queued for serial execution.)
CVE-2019-18202
PUBLISHED: 2019-10-19
Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via crafted HTTP requests.
CVE-2019-18209
PUBLISHED: 2019-10-19
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
CVE-2019-18198
PUBLISHED: 2019-10-18
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.
CVE-2019-18197
PUBLISHED: 2019-10-18
In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclo...