enterprisesecuritymag

| | APRIL - 2023ENTERPRISE SECURITY8SETTING THE RIGHT SECURITY CULTURE By Mackenzie Muir, Chief Information Security Officer, Allianz Australia Information security experts are accustomed to the evolving complexity of the threat environment and frequently witness alterations in the methods and practices of attackers. Over recent years we have seen a dramatic evolution of the data security landscape thanks to a rise in malware, phishing and zero-day exploits. This rapidly changing area should be addressed as a company priority owing to the increasing senior management expectations and stringent regulations. Effective cyber security is about knowing what is important to your business ­ that is, identifying the `Crown Jewels' and focusing security resources, such as people, time, money and attention, towards them. This needs to be done while maintaining a minimum level of `security hygiene' across the board, that being the security requirements your systems must meet and comply with, across all business units within the organisation. Managing the balance between these two areas and the objectives of other business functions is where information security teams find their challenges. The effort required to not just list every system ­ if you don't know them all, then you cannot be sure you know your Crown Jewels ­ but have senior management agree and endorse the list of those systems cannot be underestimated. It also cannot be a one-off activity; managing your systems and lists require regular reviews based on the pace of change in your business. Once you have identified the Crown Jewels of your business you need to define the level of security they require. It needs to be above the minimum level set for everything, but how far above? What additional controls need to be applied to these systems, such as micro-segmentation or more frequent User Access Revalidation ­ otherwise known as UAR ­ activities? Identity is central to this security; you need to know who can access your systems and whether they should. This can be controlled through a request and approval process, regular access revalidation and finally, removal on termination. There should be absolute minimums that apply to all your systems, and increased controls that apply to the Crown Jewels. Depending on your industry and business context, an annual binary revalidation may suffice. Simply put, should user Jamie Bloggs have access to the system or not? It's a binary ­ yes or no. Mackenzie MuirIN MY OPINIONIN MY OPINIONIN MY OPINIONIN MY OPINION
< Page 7 | Page 9 >