Tags:
This is Part 4 of 4 of our Rekt Casino Operational Leadership series, which itself is a sequel to our Transformation Series dealing with the same case study. You can read the other parts of the Operational Leadership series here:
If you haven’t been following the Rekt Casino webcast series, let’s get you up to speed: Rekt Casino suffered a breach due to a ransomware attack. The Casino did not have an operational security capability in place to help it resist intrusions, maintain awareness of its weaknesses, or identify and respond to attacks.
In our fourth and final webcast of our series, we talked about how the three disciplines in the Operational Leadership Series – the Critical Security Controls, Vulnerability Management, and Security Operations- can come together to get Rekt on the path to a stronger, more proactive defense. These disciplines are part of the SANS Operational Leadership Triad:
- SEC566: Implementing and Auditing the Critical Security Controls with James Tarala
- MGT516: Managing Security Vulnerabilities: Enterprise and Cloud with David Hazar
- MGT551: Building and Leading Security Operations Centers with Mark Orlando and John Hubbard
As we’ll see in this post, each of these disciplines provides a key element of the kind of defense that Rekt must now build in the aftermath of a major breach. We will also see that while each discipline represents a potentially massive undertaking in terms of time and investment, there are things we can do to build out basic capabilities we can expand and improve as Rekt’s new security program matures.
Building a Strong Foundation
Having discussed how each of these disciplines could have positioned Rekt Casino to defend itself more effectively, we can now look at how implementing all three in concert forms a more robust foundation upon which we can build a proactive defense.
From a SEC566 perspective, implementing the Critical Security Controls would have:
- Provided Rekt with a library of prioritized defenses
- Given Rekt a roadmap to implement a baseline set of controls and a mechanism to measure defensive progress over time
- Enabled Rekt to perform control-oriented risk assessment, using vulnerability management to help them continuously measure gaps and opportunities for improvement
- Put Rekt on a path to event-oriented risk assessment, where security operations informs defensive planning based on attacks and other observed events
A strong defense starts with the right technical controls. The goal is to gain as much situational awareness as possible, prevent as many attacks as possible, and detect the things we cannot and did not prevent. The Critical Security Controls are an effective security framework because they are based on actual attacks launched regularly against networks. Priority is given to Controls that (1) mitigate known attacks (2) address a wide variety of attacks, and (3) identify and stop attackers early in the compromise cycle.
From a MGT516 perspective, enterprise vulnerability management would have:
- Provided an accurate picture of Rekt’s weaknesses and exposures to help drive control and monitoring priorities
- Established a common goal for many of the Critical Security Controls ultimately designed to support better vulnerability management
- Provided a cross-functional goal of identifying and reducing vulnerabilities, to which the security operations team and security engineering would contribute
By understanding common issues and how to solve them, Rekt Casino will be better prepared to meet the challenges ahead and guide its IT teams and the broader organization to successfully treat vulnerabilities. The approach taken in MGT516 aligns to other modernization efforts Rekt is likely to take in the near future as it evaluates expansion into the cloud or implementing new processes like DevOps.
From a MGT551 perspective, a security operations center would have:
- Helped Rekt shift from an outdated, prevention-oriented mindset to a more modern detection oriented mindset
- Provided an over-arching monitoring capability to track the status and efficacy of the critical security controls
- Applied the context and awareness generated by the critical security controls and vulnerability management programs to identify and respond to attacks
- Provided situational awareness for the vulnerability management program by identifying new vulnerabilities, systems outside of program coverage, and changes in asset status based on incidents and other events
Information technology is so tightly woven into the fabric of modern business that cyber risk has become business risk, and this has certainly proven true for Rekt Casino. A security operations team analyzing telemetry from across the environment that includes control data and vulnerability information can be the difference between a temporary disruption and a massive business loss.
Starting the Journey
Each of these disciplines represent significant investments Rekt Casino, or any other organization, must make to be more resistant to attack. But without some capability in each of these disciplines, our operational defense doesn’t have the whole picture. Strong operational leadership in each of these three key disciplines will provide a robust and flexible starting point for a more proactive defense. More importantly, that defense will be focused on Rekt’s unique business and risk profile with controls and monitoring that prioritizes the biggest gains first.
For critical security controls, there are many sources of inventory data and some of the basic capabilities within the control library. Use a spreadsheet or data warehouse, engage with your IT management teams, and maximize the data to which you already have access to make as much progress as possible before turning to more significant new investments.
In vulnerability management, getting as much coverage as possible is one of the earliest and most important goals, and the biggest challenge – using a combination of tools at the network and host layers, the right access, and the right technical analysis of the data, organizations like Rekt Casino can build complete inventories of both hardware and software. This effort isn’t wholly reliant on major commercial scanning tools and may be supplemented by configuration management and patch management efforts.
In security operations, use existing frameworks like MITRE’s ATT&CK matrix to define threats facing your organization in common terms and prioritize your preventative controls and monitoring accordingly. Revisit the profile you have built often to update it based on new controls, vulnerabilities, and attacks you have observed, and share those insights with the other security functions so that they too can adjust and improve. Look to the risk appetite of your organization to strike the right balance between preventative controls and more passive, detection-oriented controls. Strive for prevention but do not compromise on detection!
Once we deploy basic capabilities in each of these areas, we have a baseline on which to grow and improve. Security is a process, not a state of being, and as we have followed Rekt Casino on their journey from breach to recovery to improvement we can now look to our own organizations to undertake the same initiatives. The SANS Operational Leadership Triad provides three entry points for this journey, so pick the one that is right for you.
About the Author
Mark Orlando is a SANS Associate Instructor, co-author MGT551: Building and Leading Security Operations Centers, instructor for SEC450: Blue Team Fundamentals: Security Operations and Analysis,
and the Co-Founder and CEO of Bionic Cyber. Prior to Bionic, Mark
built, assessed, and managed security teams at the Pentagon, the White
House, the Department of Energy, and numerous Fortune 500 clients. Mark
has presented on security operations and assessment at DefCon's Blue
Team Village, the Institute for Applied Network Security (IANS) Forum,
BSidesDC, and the RSA Conference and has been quoted in the New York
Times, the Washington Post, Forbes, and many other publications. He
holds a Bachelor's Degree in Advanced Information Technology from George
Mason University and served in the US Marine Corps as an Artillery
Non-Commissioned Officer.