In today's issue, I'm diving into a key yet often neglected area of cybersecurity:
Transitioning from a fragmented to a structured approach in cyber asset management.
If you're in cybersecurity, you know managing assets is vital, but often it's not done well.
The Common Misstep
Organizations can't agree on what counts as an asset. It could be anything from hardware, software, to services – basically, anything dealing with data.
This confusion often leads to a messy asset list with mistakes in important details like who owns it, where it is, and what its weaknesses are. While it's a customized approach, it results in disorder and inefficiency.
Before you know it, your asset list is a labyrinth of outdated or missing info. Add in fast-changing tech like cloud services and IoT, and it's even harder to keep up.
A Better Approach: Structured Asset Management
Here are my tips for a more organized system:
1. Redefine cyber assets. Be clear and simple about what counts as an asset for your organization.
2. Use various tools. Different asset types need different tools – like scanners for vulnerabilities and processes for tracking ownership.
3. Embrace the complexity. Accept that modern assets, including cloud and IoT devices, are complex (not event talking about OT). Keep your asset list updated regularly.
4. Use tools properly. Don't misuse tools – like using a vulnerability scanner for asset discovery.
Example: Streamlining Asset Management in a Complex Environment
Say you're managing a network with cloud services, endpoints, and IoT devices. Here's how to apply these steps:
Redefine Cyber Assets
- Start by simplifying what you count as a cyber asset. Maybe it's anything that handles sensitive data.
- Customize this definition for your organization's specific data and security needs. For example, in healthcare, any device dealing with patient info is critical and considered as an asset.
- Regularly update this definition to stay updated with new technologies, business changes and data processing methods.