Monitoring and Measurement
Selecting, installing, and making good operational use out of all security controls - including those focused on safety, privacy, and all other aspects of information security - are part of fulfilling the organization's due care responsibilities.
3 slides · 2 min read · Domain 1
Due diligence is answered in part by a program of assessments, which should include ad hoc, informal, event-driven or other special purpose security assessments, as well as the periodic formal audit assessments that compliance regimes may require.
Traditional security systems architectures allowed and encouraged) each step in the risk management, mitigation, and effectiveness set of lifecycles or processes to be its own separate set of tools and capabilities, which would be used on their own separate schedules. Risk events deemed critical enough would be assessed and reported in real time; others might wait for overnight analytics processing, or end of month key performance metrics production and reporting. The threat actors found this most convenient. It gave them time to hide.
BEROSI
The operational sophistication of many of today's APTs has forced the security community to step up its defensive game, especially by cutting its cycle time from detection to response. More and more organizations are finding the need to move to a continuous flow model for security systems operation and use, primarily because this provides a continuous | measurement, analysis, assessment, reporting, and alarm capability.
Many systems we've examined - SOAR, SIEMs, JIT Identity, next-generation firewalls as a service, and managed security services, to name just a few - can be used singly or in appropriate combination to provide the right amount of real-time or near-real-time data-driven reporting.
In much the same way as antivirus and anti-malware systems almost seamlessly blend detection, containment, and eradication activities into one, so too do modern security systems blur the lines between using controls, measuring their performance, gathering those measurements, analyzing and assessing them for meaning (especially for indicators of compromise), and issuing alarms and reports. One way to measure that is to look at a typical production security operations center dashboard tool which gathers endpoint, server, link, and user behavior signals from across a large enterprise.
This may result in tens of thousands of data records every second coming into the monitoring system. These systems are helping infrastructure systems and other enterprises detect and respond to distributed denial of service attacks in less than a minute. That's purposeful, intentional monitoring and measurement, leading to action.
