How to Build a Comprehensive Security Roadmap

TL;DR
Build comprehensive security by integrating capabilities across visibility, context, and action instead of relying on isolated defensive tools. Inventory assets, assess vulnerabilities and configurations, monitor logs, users, and traffic, prioritize incident response, and progress toward automated remediation as confidence in data and analytics grows.
Transcript
Journey, and you will find replacement to the ones left behind. When I was doing the research for this keynote, I wanted to find a local proverb to help describe the journey ahead. As I started my research, I realized there's not a lot of local proverbs that talk about journey, so I wasn't sure if this was the right proverb or not. But as I continu... Read More
Key Insights
- Information security has historically been treated as an afterthought, with controls layered around existing IT infrastructure. This practice produced isolated defenses that do not work together effectively, leaving gaps attackers can exploit even when organizations deploy numerous security products.
- Cloud migration changes the environment that security programs must protect. Moving infrastructure from corporate-owned data centers to public cloud services can enlarge existing visibility and control gaps, making an already fragmented defense-in-depth model increasingly difficult to operate effectively.
- Applications are the critical component of the digital economy because they store sensitive data and intellectual property and support daily activities. As infrastructure moves to the cloud, application vulnerabilities are expected to replace device vulnerabilities as a primary attack vector.
- Containers, DevOps, continuous deployment, and microservices change how applications are built, released, and connected. Applications may be updated multiple times per day, while distributed communication channels and development teams create changes that existing security processes and tools are not prepared to monitor.
- Comprehensive security is organized around six capability domains rather than individual products. Discover and assess create visibility, monitor and analyze supply context, and respond and protect turn that context into prioritized action across the security program.
- A complete asset inventory is the starting point for protection. Organizations need continuous knowledge of authorized and unauthorized assets because unknown devices can threaten critical resources, and teams cannot assess or protect systems they do not know exist.
- Security monitoring must extend beyond hosts and perimeter networks. Organizations need logs from applications, cloud services, and cloud infrastructure, monitoring of user access to data and applications, and visibility into internal network traffic to detect normal and abnormal behavior.
- Automated remediation depends on trust in security data and analytics. It is expected to take the industry the longest to achieve, but continuous development and cloud deployment techniques can eventually provide the technical mechanisms needed to implement reliable automated action.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How do you build a comprehensive security roadmap?
Build the roadmap as a connected sequence of visibility, context, and action capabilities. Begin by inventorying assets, assessing device and application vulnerabilities, and auditing configurations. Then monitor logs, user access, and internal and perimeter traffic. Use the resulting context to prioritize incident response, protect critical assets and data, and gradually establish enough trust in data and analytics to automate remediation.
Q: Why is the traditional defense-in-depth approach outdated?
Traditional defense in depth encourages organizations to deploy isolated point solutions as separate layers of protection. Those layers have not been interconnected effectively, so gaps remain between them and give attackers places to operate. These weaknesses are difficult to address inside a corporate-owned data center and become larger as infrastructure, applications, and monitoring responsibilities move into cloud environments.
Q: Why should security programs focus on capabilities instead of tools?
A capability-based program treats security as a comprehensive set of functions that work together, while a tool-focused program can produce disconnected controls. The roadmap groups those functions into discover, assess, monitor, analyze, respond, and protect. Connecting them allows visibility to create useful context and enables that context to guide prioritized action, incident response, and protection of critical assets.
Q: Why are applications central to the future of security?
Applications store sensitive data and intellectual property and support activities such as communication, bill payment, and travel booking. Their importance grows with digital transformation and cloud adoption. At the same time, containers, continuous development, continuous deployment, and microservices make applications faster to change and more distributed, requiring security practices that extend beyond static source analysis or dynamic testing of running software.
Q: What security visibility should organizations establish first?
Organizations should first create a comprehensive inventory of authorized and unauthorized assets. They should continuously monitor device vulnerabilities, assess application vulnerabilities, and audit security configurations across hosts, networks, applications, cloud services, and cloud infrastructure. These steps establish the visibility foundation needed to identify exposure, recognize unknown assets, and prevent a single cloud misconfiguration from opening applications and data to attack.
Q: What activity should a comprehensive security program monitor?
A comprehensive program should monitor logs from hosts, networks, applications, cloud services, and cloud infrastructure. It should also observe user access to data and applications so normal and abnormal behavior can be distinguished. Network monitoring must include internal traffic as well as perimeter traffic, although obtaining that visibility becomes more challenging when infrastructure moves from corporate data centers into the cloud.
Q: How does security context improve incident response?
Security context comes from monitoring and analyzing logs, user access, application activity, and network traffic. When this information is connected to asset, vulnerability, and configuration data, teams can prioritize the incidents that matter most. That prioritization helps responders concentrate on protecting critical assets and data during an attack instead of treating every alert or event as equally important.
Q: When can an organization automate security remediation?
Automated remediation becomes practical after an organization develops trust in its data and analytics. Reliable asset visibility, vulnerability assessment, configuration auditing, monitoring, analysis, and prioritized response provide the necessary foundation. Building that trust is expected to take longer than the other roadmap stages, although continuous development, continuous deployment, and cloud technologies can provide the technical means to implement automation once confidence is established.
Summary & Key Takeaways
-
Information security has traditionally been added around existing infrastructure through isolated defense-in-depth tools. Cloud migration, mobile adoption, containers, DevOps, microservices, and continuous deployment expose the limits of that approach. Security programs must follow changes in information technology and treat applications as central assets requiring coordinated protection.
-
The proposed roadmap organizes security into six capability domains. Discover and assess establish visibility, monitor and analyze provide context, and respond and protect enable action. These capabilities must work together as a comprehensive program, closing the gaps where attackers can operate between disconnected tools, controls, environments, and organizational processes.
-
The practical journey begins with asset inventory, device and application vulnerability assessment, and configuration auditing. It continues through comprehensive monitoring of logs, user access, and network traffic. Prioritized context then supports incident response and protection of critical assets, while trusted data and analytics eventually make automated remediation technically achievable.
Read in Other Languages (beta)
Share This Summary π
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity π






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator