{"id":44008,"date":"2019-12-09T08:17:27","date_gmt":"2019-12-09T08:17:27","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=44008"},"modified":"2019-12-09T08:17:33","modified_gmt":"2019-12-09T08:17:33","slug":"gartner-leveraging-automation-for-modern-security","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2019\/12\/09\/gartner-leveraging-automation-for-modern-security\/","title":{"rendered":"Gartner: Leveraging automation for modern security"},"content":{"rendered":"\n<p><em>Modern security teams are facing more threats than ever, as well as more pressure to provide business value. Katell Thielemann, VP Analyst at Gartner, tells us why it\u2019s so important that CISOs consider automation tools to balance security with efficiencies. <\/em><\/p>\n\n\n\n<p>Security and risk leaders must\nexplore automation to provide increased business value and maintain security\nstandards.<\/p>\n\n\n\n<p>When\nAmy, the CISO of a healthcare provider, looked at cloud security across the\nenterprise, she realised the default access control models were creating a\nvariety of access issues. BeWell\u2019s Infrastructure-as-a-Service (IaaS) providers\ndefaulted to a secure state, allowing only the owner access.<\/p>\n\n\n\n<p>On\nthe flip side, Software-as-a-Service (SaaS) providers defaulted to totally open\naccess. With multiple clouds in use, it would be impossible for Amy to manually\nrelax permissions for IaaS and ensure adequate controls for SaaS. The solution?\nAutomation.<\/p>\n\n\n\n<p>No longer are we\nasked a singular question, \u2018how are you providing security and managing risk?\u2019.\nWe are now asked a more complex question, \u2018how are you helping the enterprise realise\nmore value while assessing and managing risk, security and even safety?\u2019. The\nbest way to bring value to your organisation today is to leverage automation.<\/p>\n\n\n\n<p><strong>The impact of automation<\/strong><strong><\/strong><\/p>\n\n\n\n<p>Automation is already impacting the world in two\nways, first, as an enabler to the security and risk function and second, as new\nsecurity frontiers that need to be acknowledged and understood.<\/p>\n\n\n\n<p>As pieces of the business begin to adopt emerging\ntechnologies ranging from the cloud to Blockchain to digital twins and\nimmersive technologies, CISOs like Amy will find themselves overwhelmed with\npriorities.<\/p>\n\n\n\n<p>According to Beth Schumaecker, Director, Advisory,\nGartner, \u201cOther business units are likely building solutions without consulting\nthose of us in security. This means they are making technology-related choices\nevery day, often without realising the risk implications of what they are doing.<\/p>\n\n\n\n<p>\u201cThe consequences of these business choices \u2013 choices\nover which we have no control and do not always see \u2013 can be huge, especially\nas the potential for digital business continues to grow.\u201d<\/p>\n\n\n\n<p>As\nDigital Transformation alters security needs and necessary skill sets and\ncompetencies, it creates new talent gaps that are difficult (if not impossible)\nto fill.<\/p>\n\n\n\n<p><strong>Automation in the business<\/strong><strong><\/strong><\/p>\n\n\n\n<p>Many automation tools are ad hoc; others formally\nautomate key parts of a process. Some tools use one technique, while other\ntypes of automation utilise a handful of techniques. For example, robotic\nprocess automation is best suited to task-centric environments and predictive\nanalysis that uses predictive modelling, regression analysis, forecasting and\npattern matching to answer the \u2018what is likely to occur\u2019 question.<\/p>\n\n\n\n<p>Some companies will use automation to reduce costs,\nstandardise or increase productivity. Others will use it to improve the quality\nand consistency of risk controls, while reducing error caused by humans. Organisations\nwill also use automation to increase speed or agility.<\/p>\n\n\n\n<p><strong>CARTA is a key enabler<\/strong><strong><\/strong><\/p>\n\n\n\n<p>Regardless\nof how automation is being used, security and risk leaders can no longer depend\non traditional security approaches. Continuous adaptive risk and trust\nassessment (CARTA) is a strategic approach to security that acknowledges there\nis no perfect protection and security needs to be adaptive, everywhere, all the\ntime.<\/p>\n\n\n\n<p>\u201cWe need to consciously take an adaptive approach to\nautomation that minimises the risks to our organisation while helping it reap\nthe rewards,\u201d according to David Mahdi, Senior Director Analyst, Gartner. \u201cWe must balance risk and trust adaptively to\nnavigate our place on the automation continuum in order to deliver value.\u201d<\/p>\n\n\n\n<p>Automation does add risk. For example, algorithms can\ninclude implicit and explicit bias by a creator, or algorithms on untrusted\noperating systems could be unknowingly controlled by outside parties.<\/p>\n\n\n\n<p>Any automation choice must be conscious and adapted\nto the current situation, as well as adaptable to the future.<\/p>\n\n\n\n<p>But, if done correctly, automation can also be hugely\nbeneficial to the security team and business.<\/p>\n\n\n\n<p><strong>Deliver value with automation<\/strong><strong><\/strong><\/p>\n\n\n\n<p>Security and risk professionals must deliver value\nusing automation in three areas: Identity, data and new product or service\ndevelopment.<\/p>\n\n\n\n<p><strong>Identity is the foundation for all other\nsecurity controls<\/strong><strong><\/strong><\/p>\n\n\n\n<p>Decisions regarding\nidentity should always remain within the control of security and risk teams.\nThis becomes even more important as businesses increasingly move to cloud\nenvironments. As systems and companies become more complex, relying solely on\nmultiple passwords for identity confirmation becomes difficult and risky.<\/p>\n\n\n\n<p>Consider using an intelligent risk engine to automate\ncertain parts of the process. A CARTA approach to identity will be key to\nensuring that the risk engine isn\u2019t too relaxed or restrictive, but also works\nfor the user.&nbsp; <\/p>\n\n\n\n<p><strong>Data is where much of enterprise value\nresides<\/strong><strong><\/strong><\/p>\n\n\n\n<p>Businesses are data generation powerhouses. Failing\nto protect and watch data can be costly \u2013 and can, in fact, harm an organisation\u2019s\nvalue.<\/p>\n\n\n\n<p>Review the access control models for any Infrastructure-as-a-Service\nand SaaS applications and consider using a cloud access security broker (CASB)\nto identify and classify data and files. Use a CASB in combination with\nenterprise digital rights management to extend controls over the entire\nenterprise, regardless of where the data lives.<\/p>\n\n\n\n<p><strong>New products or services development is a\nfocus for companies<\/strong><strong><\/strong><\/p>\n\n\n\n<p>Companies are developing new products and services to\ngain competitive edge and are leveraging emerging technologies, which are\nhighlighting new business opportunities. With an increasing need to go to\nmarket faster, DevOps processes can run afoul of security protocols. Automation can help achieve the ultimate goal of\nDevSecOps, where security is built into the beginning of the process with no\nnegative impacts.<\/p>\n\n\n\n<p>Consider automation options such as interactive\napplication security testing, a machine-based solution that enables you to\nobserve the behaviour of an application from the inside. Your team can then\npiggyback security testing onto the quality assurance testing and avoid using a\nsingle security test case.<\/p>\n\n\n\n<p>Within\nthese mission-critical priorities, security and risk management leaders must prioritise\nwhat they want to handle, what other teams can reasonably do and what doesn\u2019t\nwarrant time or attention. Security teams must also consider how automation can\nbe integrated into systems and how it can reasonably be used within a CARTA\napproach to security.<\/p>\n\n\n\n<p>\u201cTo\norchestrate and champion value protection and empower value creation, our job\nis to recognise and manage the tension, and find our place on the automation\ncontinuum,\u201d Mahdi added.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Modern security teams are facing more threats than ever, as well as more pressure to provide business value. Katell Thielemann, VP Analyst at Gartner, tells us why it\u2019s so important that CISOs consider automation tools to balance security with efficiencies. Security and risk leaders must explore automation to provide increased business value and maintain security [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":44011,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[6787,5,6,9961,13],"tags":[637,10793,5205],"class_list":["post-44008","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-transformation","category-enterprise-security","category-insights","category-thought-leadership","category-top-stories","tag-automation","tag-katell-thielemann","tag-security"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/44008","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=44008"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/44008\/revisions"}],"predecessor-version":[{"id":44010,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/44008\/revisions\/44010"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/44011"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=44008"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=44008"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=44008"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}