Why invest in a Security Assurance Capability?

Security Assurance is a term that is used commonly in conversations with organisations who want confidence that they have the measures in place to handle potential security threats. 

What is security Assurance?

CSP see Security Assurance as being the evidenced based, professional opinion on the security posture of a product, service or capability that is provided or used by an organisation as part of its business or operational activities. It is an intrinsic element of the day-to-day activities of the organisation. It is Not Information Technology or Cyber Centric but in the modern data driven world security of IT systems, networks and data (Information Security Assurance) is a significant component.

This view aligns (probably a bit loosely in some use cases) with the definition in ISO/IEC 15443 (Information technology – Security techniques – Security assurance framework)

Assurance

Grounds for justified confidence that a claim has been or will be achieved, or grounds for justified confidence that a TOE (Target of Evaluation) meets the SFRs (Security Functional Requirements).

When helping organisations perform security assurance reviews, CSP favour the second definition – where the TOE is the Product, Capability or Service that is under review.

The assurance status can be informed by comparing the desired security characteristics against the real-life security outcomes, delivered by the specific product, capability or service.

To help construct an effective Security assurance approach, there are a number of frameworks and models that can be used to help provide organisation with a structure to follow, when creating the security assurance functions. CSP recommend that when considering the appropriate framework to be used, organisations should be flexible and if necessary, apply organisational specific elements to the framework to make it most relevant to the organisation.

Organisations that have the structures and processes in place, to have a robust approach to security assurance are well informed. They are able to make business decisions with a clear understanding of the level of security risk associated with them. A security assurance programme can help identify key areas of investment for security budgets and provide mechanisms to clearly assess the benefit of the spend.

The example below reflects a common scenario:

When organisations are purchasing Cloud Services, they need to be confident that the service provider presents them with a secure platform and that the organisations use of the platform also meets the security requirements. This is not always as easy as it sounds and as modern development methods and misunderstandings regarding the responsibilities of the Cloud Consumer and Cloud provider, are quite common.

NIST Cyber Security Framework (CSF)

A framework such as the  NIST Cyber Security Framework (CSF) could be used in the above example, as this focuses on the features that secure the Networks and Services which underpin business capabilities. The CSF also provides a model for organisations to decide “how” secure they need to be across functional areas and prioritise activities to achieve the desired outcomes.

CSF would help an organisation to assess the security aspects being provided by the supplier and those that are being provided by the organisation. This is all under the Cloud Services joint responsibility paradigm and articulates the level of assurance in the security outcomes being met.

However, COBIT and the ISO 27000 series also provide governance and security outcomes that can be a tested and reviewed to give a view of security posture.

Our Recommendations

CSP do not recommend a specific framework or control set, but encourage organisations to establish an assurance programme that is appropriate to the organisation.

The organisation is your “train set “only you really know what elements you need confidence in. Internal and External consultants can help advise and structure programmes of work and give the benefit of their experience but it’s the leaders in the organisation that make decisions based upon the results of security assurance activities.

We do recognise that many organisations collect data and generate Management Information reports based on that data. We also recognise that much of the data does not help leaders within organisations make decisions. A good security assurance programme, be it Information security assurance or wider can help turn the data collected into meaningful information that informs and supports the business.

Leave a Reply

Your email address will not be published. Required fields are marked *