How to Build Cross-Functional InfoSec Alliances

101 views
•
November 4, 2016
by
RSAC Cybersecurity
YouTube video player
How to Build Cross-Functional InfoSec Alliances

TL;DR

Information security succeeds when defenders expand their sphere of influence and recruit teammates whose existing priorities align with security outcomes. By mapping adversaries from actor and motivation through targets and methods, then matching them with allies across leadership, operations, legal, finance, sales, audit, procurement, government affairs, and open source communities, organizations can focus limited resources on their most relevant risks.

Transcript

Hello. Welcome to our quick look at our s- upcoming session at the RSA Conference 2016 in Abu Dhabi, Building Bridges: Surprising Strategies and Teammates for InfoSec Success. This is David Edgew and I'm here with Josh Corman, and we're excited to share with you, uh, a quick look at the content we'll be presenting. Hi, I'm Joshua Corman. Uh, this i... Read More

Key Insights

  • A CISO operates amid several turbulent forces: evolving threats, regulatory requirements, disruptive technology, changing business needs, and shifting economics and culture. Any one of these forces can increase the cost, complexity, and risk involved in running an effective security program.
  • Compliance can eclipse the threat landscape as the main driver of security programs and spending. When regulatory frameworks drift away from actual threats, organizations may prioritize satisfying auditors even though compliance was intended to serve as a proxy for managing security risk.
  • Technology trends can undermine established security controls while creating new attack surfaces and operational complexity. The examples presented include x86 virtualization, cloud computing, consumer BYOD, the Internet of Everything, containers, and DevOps, all of which can disrupt existing combinations of people, processes, and technology.
  • The adversary model maps a who to a why, a what, and a how. It connects actor classes with motivations, targeted assets, and operating capabilities, helping defenders avoid the unreliable practice of attributing an incident solely from malware or a particular tactic, technique, or procedure.
  • Defensible infrastructure and operational excellence form the foundation of security effectiveness. Asset inventory, change control, coordinated operations, and sound technology choices often sit outside the security team's direct authority, even though weaknesses in these areas can determine whether countermeasures succeed.
  • Situational awareness provides the eyes and ears needed for earlier detection and more targeted response. Broad visibility helps defenders notice weak signals, but achieving it can depend on teams and systems beyond the security function's direct sphere of control.
  • A security team's sphere of influence is larger than its sphere of control. Relationships with colleagues can extend security into decisions owned by IT operations, technology leadership, finance, legal, sales, audit, procurement, government affairs, and open source communities.
  • Effective teammate selection depends on matching allies to the problem. Each teammate has a role, motivations, preferred assets, capabilities, and spheres of control and influence. Security failures can result from bringing the wrong teammates, or too few teammates, to a particular adversarial challenge.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can security teams expand their influence across an organization?

Security teams can expand their influence by identifying colleagues whose existing responsibilities and motivations align with security goals. General counsel may care about legal risk, finance may prioritize financial controls, and sales may value customer trust. Building relationships around these shared interests allows security professionals to affect infrastructure, operations, governance, and business decisions that sit outside their direct sphere of control.

Q: What is the who, why, what, and how adversary model?

The model connects four parts of an attack: who the actor is, why that actor is motivated, what assets the actor targets, and how the actor operates. Actor classes can include nation-state competitors, organized crime, and activists, while motivations can be financial, industrial, or ideological. Connecting the full chain gives defenders more useful context for prioritization and response than examining one technical indicator alone.

Q: Why is attributing an attacker from malware or tactics unreliable?

Attributing an attacker from malware or a tactic, technique, or procedure is unreliable because different actors can reuse recognizable methods or intentionally imitate another group. The presenters used their broader adversary model to identify false flags. Examining actor class, motivation, targeted assets, and capabilities together provides a more coherent basis for analysis than assuming one observed technique proves a particular identity.

Q: Why can compliance become disconnected from security threats?

Compliance frameworks are introduced less frequently than new threats, yet they can be disruptive and costly to maintain. Although compliance can theoretically serve as a proxy for the threat landscape, the two may drift apart. When that happens, programs and spending can become driven more by fear of auditors than by the attackers and attack paths that create the organization's most relevant security risks.

Q: What organizational capabilities create a strong security foundation?

A strong security foundation begins with defensible infrastructure and IT, followed by operational excellence. Important capabilities include asset inventory management, change control, coordinated action, and the ability to maintain composure during incidents. These foundations are often controlled by CIOs, CTOs, or IT operations rather than security professionals, so their effectiveness depends heavily on cross-functional cooperation and influence.

Q: How does situational awareness improve information security?

Situational awareness gives defenders broad and persistent visibility into what is happening across the environment. It helps teams detect whispers and echoes of malicious activity earlier and respond more precisely. Security groups often fight without sufficient visibility, and the required data or systems may belong to other organizational functions, making partnerships essential to developing effective detection and response capabilities.

Q: Who can become a useful teammate for an information security program?

Useful teammates include executive leaders such as the CIO and CFO, general counsel, and sales leadership, as well as a wider supporting cast. Internal audit, procurement, government affairs, and open source communities can also help drive meaningful security change. Their value comes from their responsibilities, motivations, capabilities, and influence over assets or decisions that matter to the security program.

Q: How should organizations match security teammates to adversaries?

Organizations should first identify the subset of adversary classes they are most likely to face in their industry or business, potentially through a periodic tabletop exercise. They can then examine attacker motivations, targeted portions of their asset environment, and likely attack strength. Finally, they should select teammates whose authority, influence, priorities, and capabilities best address those specific adversaries and exposed assets.

Summary & Key Takeaways

  • Security leaders face simultaneous pressure from changing attackers, compliance frameworks, disruptive technologies, business priorities, economic conditions, and cultural shifts. These forces increase cost, complexity, and risk, while security teams may lack direct control over the infrastructure, operations, and organizational decisions that determine whether defensive programs work effectively.

  • The adversary model connects who is attacking, why they are motivated, what assets they target, and how they operate. This chain discourages attribution based only on malware or tactics, techniques, and procedures. It can reveal false flags and help organizations prioritize the adversary classes, assets, and attack strengths most relevant to them.

  • Security teams can achieve more by treating colleagues as teammates with distinct motivations, assets, capabilities, and spheres of influence. Executives and supporting functions may already value legal risk, financial controls, customer trust, operational reliability, or governance. Aligning security work with those interests can unlock broader organizational support and produce stronger defensive outcomes.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚