We have several sayings in our company that I like to repeat publicly.The first is "Security is a process not a product," meaning security is something you do rather than something you buy or even something that you are.It is people and systems doing something normally all day, every day-that is security and not just in the sense that what they do keeps us secure.Of course, the process of doing security is what keeps us secure by definition, but it is the process that keeps us secure, not the products that are used in the process (nor even the people who are not always part of every process).My second saying is "Security is more like accounting than it is like firefighting."Both are processes, but accounting is something you do every day when you process transactions or analyze data, whereas firefighting is something you do on occasion and in response to something causing harm.Notably firefighting is reactive, whereas accounting is proactive.Yes, there is something very much like firefighting in cybersecurity in the form of incident response, and that too is a security function.But day in day out, and even statistically speaking, firefighting is practically absent.Security events occur every day, and many can be called "incidents."However, the necessary response does not resemble firefighting.A day in the life of a security analyst or even a security engineer involves categorizing events identified by security systems, finding ways to tune those systems, configuring systems to address gaps in visibility, and measuring and reporting status and progress.That is a lot more like bookkeeping, audits, and reports.My favorite saying is "because security gives us freedom" in the sense of the freedom to focus on other things with confidence.But this is more than offloading a burden.It is about operational excellence.Any cybersecurity or even information technology (IT) professional will tell you how valuable it is to simply design and run systems well.Keep backups.Take inventory.Document your processes.Validate important actions like onboarding and offboarding employees.Log everything.Develop metrics.Plan and test and test again.The financial world understands this, and the initial operational standards used in IT stem from those.This operational excellence enables us to scale, do more, and identify pain points, bottlenecks, and opportunities.It gives us freedom.Like any field, cybersecurity has its standards and established methods, but despite how much is documented and readily available, the practice is highly fragmented and surprisingly nonprescriptive.Standards, common practices, frameworks, convergence via external pressures, and resources like MITER CVE, ATT&CK, VirusTotal, professional organizations and training, conferences, and community, are heavily leveraged, but it is left to the organization to use them.It is highly valuable to use a framework in your cybersecurity plans as it will give you some alignment with the industry and maybe even some cover when compliance applies.But compliance does not equal security.That takes maturity.The National Institute of Standards and Technology (NIST), Department of Defense (DoD), Cybersecurity and Infrastructure Security Agency, and many other organizations and private entities have developed their own concepts of maturity levels.The Cybersecurity Maturity Model Certification from the DoD even describes its certification levels in terms of maturity, although they refer to granularity of controls rather than overall methods and practices.
Read more