The One About Controls

RSA Conference 2024 · Track Session

Overview

In "The One About Controls," Sri (Sriram), Deputy CISO at Genpact, presents a refreshing perspective on managing cybersecurity controls, moving beyond a checkbox mentality to a dynamic, business-aligned lifecycle approach. Drawing inspiration from Abraham Maslow's hierarchy of needs, Sri argues that the vast array of available security controls must be prioritized and adapted to an organization's specific circumstances, needs, and aspirations rather than uniformly applied. The talk emphasizes that effective control management is not a static state but an ongoing, cyclical process of identification, selection, implementation, validation, and refinement, heavily influenced by an organization's capabilities, capacity, and cost constraints.

Watch on YouTube

Visual summary for The One About Controls
Visual summary for The One About Controls

Key moments

  1. 0:00 Introduction and talk title explanation
  2. 1:00 Maslow's hierarchy applied to security controls
  3. 2:00 Reinterpreting Maslow's pyramid as a control tree
  4. 2:40 Ana's story: established entity's control needs
  5. 4:00 Rama's story: startup's evolving control requirements
  6. 5:27 Ana and Rama's stories merge: contrasting control needs
  7. 5:40 Defining controls and their lifecycle stages
  8. 6:50 Classifying controls by domains and industry standards

The One About Controls

Speakers: Sri (Sriram), Deputy CISO, Genpact

Conference: RSAC 2024

YouTube: https://www.youtube.com/watch?v=yxQ7Kdfyvg8

Overview

In "The One About Controls," Sri (Sriram), Deputy CISO at Genpact, presents a refreshing perspective on managing cybersecurity controls, moving beyond a checkbox mentality to a dynamic, business-aligned lifecycle approach. Drawing inspiration from Abraham Maslow's hierarchy of needs, Sri argues that the vast array of available security controls must be prioritized and adapted to an organization's specific circumstances, needs, and aspirations rather than uniformly applied. The talk emphasizes that effective control management is not a static state but an ongoing, cyclical process of identification, selection, implementation, validation, and refinement, heavily influenced by an organization's capabilities, capacity, and cost constraints.

This presentation is highly relevant for security leaders, practitioners, and business stakeholders grappling with the complexity of modern cybersecurity. It offers a structured yet flexible framework for making strategic decisions about control investments, ensuring that security efforts directly support business objectives. Sri's approach helps organizations avoid the common pitfalls of over-engineering or under-securing by advocating for a nuanced understanding of what controls are truly "needed" versus merely "aspirational" at any given time, thereby optimizing security posture and resource allocation.

Background

▶ Watch: Introduction and talk title explanation (0:00)

The foundational premise of Sri's talk is an analogy to Abraham Maslow's 1943 hierarchy of needs, which posits that human motivation progresses from basic physiological and safety needs to higher-level needs like self-actualization. Sri adapts this concept to cybersecurity, suggesting that organizations, much like individuals, have varying "needs" for controls. There's a vast landscape of potential security controls, but not all are equally critical or feasible for every organization at every stage. Some controls address fundamental "safety needs" of the business, while others might be "aspirational," desirable but not immediately essential or financially viable. The challenge lies in distinguishing these and building a control environment that is both robust and practical.

To illustrate this, Sri introduces two contrasting characters: Ana, born into an affluent London family who eventually seeks self-actualization through pro bono legal work, and Rama, an entrepreneur from Bangalore building a cloud-based accounts payable startup. Ana represents an established entity with mature security considerations, possibly driven by compliance and reputation. Rama, on the other hand, embodies a startup with constrained resources, focused on rapid growth and essential functionality, where control choices must be pragmatic and directly support market entry and customer trust. Their stories eventually merge as Rama's global expansion necessitates Ana's legal expertise, symbolizing how evolving business contexts demand adaptive control strategies. This narrative highlights that control selection is not a one-size-fits-all solution but a dynamic process driven by specific business goals, operational realities, and resource availability, which Sri encapsulates as Capability, Capacity, and Cost (the "3 Cs").

Key Findings

▶ Watch: Reinterpreting Maslow's pyramid as a control tree (2:00)

The central finding of Sri's talk is the articulation of a Control Lifecycle as the most effective paradigm for managing cybersecurity controls. This lifecycle comprises five distinct, yet interconnected, phases: Identification, Selection, Implementation, Validation, and Refinement. This cyclical model ensures that controls remain relevant, effective, and aligned with evolving business needs and threat landscapes.

Another key insight is the emphasis on differentiating between "real needs" and "aspirational needs" when it comes to controls. Organizations often face an overwhelming array of control options dictated by various standards (NIST, ISO, PCI DSS) and threat intelligence. The ability to prioritize and consciously decide which controls to adopt, and more importantly, which to defer or not implement at all, is crucial. This prioritization is heavily influenced by the "3 Cs": Capability (the expertise and tools available), Capacity (the resources, both human and financial), and Cost (the monetary investment required). Sri argues that these three factors are almost always the primary determinants of an organization's control choices, regardless of external mandates or best practices.

Finally, the talk underscores the critical importance of metrics and effective communication throughout the control lifecycle. Without clear, consistent, and concise metrics tied to business objectives, the success or failure of controls cannot be adequately assessed or reported. Moreover, these metrics must be tailored to different organizational layers—strategic (CXO), tactical (mid-management), and operational (practitioner)—to ensure that the right information is presented to the right audience, enabling informed decision-making and continuous improvement.

Technical Deep Dive

▶ Watch: Rama's story: startup's evolving control requirements (4:00)

Sri's technical deep dive into control management is structured around his proposed Control Lifecycle, emphasizing a systematic approach to building and maintaining a robust security posture.

The lifecycle begins with Identification, where organizations survey the landscape of potential controls. This phase is influenced by various external and internal drivers. Regulations such as ISO series, NIST standards, and industry-specific mandates like PCI DSS dictate a baseline. Threat intelligence frameworks like MITRE ATT&CK or best practice guides like CIS Controls provide additional guidance. The speaker highlights that there is significant overlap among these standards, suggesting that a single control can often satisfy multiple requirements. Once identified, controls need to be classified. Sri proposes structuring controls by common cybersecurity domains such as Identity and Access Management (IAM), perimeter security, cloud security, physical security, and crucially, the human element and process controls. Alternatively, organizations can align with frameworks like NIST Cybersecurity Framework (CSF) Version 2. A hierarchical structure is recommended: domains contain subdomains, which house one or more control objectives, each with one or more control statements, further broken down into specific requirements or configuration elements.

The Selection phase is where the "3 Cs" become paramount. Using Rama's startup as an example, Sri illustrates how an organization with limited resources must make conscious choices. For IAM, Rama might prioritize authentication and authorization. For authentication, objectives could include ensuring individual access, securing accounts, and meeting complex password requirements. For authorization, Multi-Factor Authentication (MFA) might be a chosen control objective. External factors like customer needs, company objectives (e.g., global expansion, revenue), and cultural elements (e.g., outbound email screening) also influence selection. Rama, for instance, might initially choose to implement MFA based on ISO standards and focus on relevant application input controls from the MITRE framework, but due to capacity and cost, might defer implementing digital rights management based on threat intelligence. This conscious decision-making, including what not to implement, is a critical aspect of effective control selection.

Implementation translates selected controls into actionable configurations and processes. For Rama, this could mean ensuring process reports are secure, implementing MFA for specific high-risk groups (e.g., IT staff) but not necessarily all business users, and screening outbound emails to reflect a desired company culture. A significant technical detail for his payment application is robust input validation to prevent common attack vectors like SQL injection and to handle exceptions gracefully, avoiding user-facing errors like "404 Page Not Found." This phase emphasizes that implementation details must be tailored, recognizing that a "one-size-fits-all" approach to even a single control (like MFA) may not be optimal or feasible across an entire organization.

Validation is the testing phase, akin to a driving test. It assesses whether the stated control objectives are being met. Key considerations include defining what to test, understanding the real exposure, identifying impacted certifications, and acknowledging capacity constraints (e.g., it's impractical to test thousands of controls from CIS or NIST at a high frequency). Automation, potentially leveraging tools or frameworks like NIST OSCAL (Open Security Controls Assessment Language) that use JSON for control assessment, is highlighted as a way to make validation faster and more reliable. The results of validation, whether control success or failure, must be appropriately reported and consumed by other teams (IT, threat intelligence, defense) to ensure a holistic security posture. This aligns with the PDCA (Plan-Do-Check-Act) cycle for continuous improvement.

Finally, Refinement closes the loop, adjusting controls based on validation results and changing circumstances. Influencing factors include current metrics, security incidents, external breaches, insights from conferences, historical issues, evolving technology (e.g., AI's impact), and updated threat intelligence feeds. Refinement doesn't always mean adding more controls; it can also involve optimizing existing ones. Sri provides a compelling example: increasing password complexity (e.g., from 10 to 14 characters) might, based on historical trends and threat intelligence, allow for a reduction in password expiry frequency (e.g., from 90 days to 180 or 365 days). This demonstrates how a strengthened control in one area can compensate, allowing for a reduction in burden or a change in configuration in another, without compromising efficacy. This cyclical process ensures that the control repository remains dynamic and adaptive.

Demo / Proof of Concept

▶ Watch: Ana and Rama's stories merge: contrasting control needs (5:27)

The talk "The One About Controls" did not feature a live technical demonstration or a software-based proof of concept. Instead, Sri utilized a narrative-driven approach, employing the fictional startup of "Rama" to illustrate the practical application of the control lifecycle and decision-making processes in a real-world business context. This storytelling method served as an extended case study, detailing how control identification, selection, implementation, validation, and refinement would unfold for a growing cloud-based application, considering factors like regulations, cost, and capacity.

Defensive Implications

▶ Watch: Classifying controls by domains and industry standards (6:50)

The insights shared in "The One About Controls" carry significant implications for cybersecurity defenders, offering a strategic blueprint for building and maintaining an effective security program.

First and foremost, defenders should adopt a structured, lifecycle-based approach to control management. Moving away from static control lists, the continuous cycle of identification, selection, implementation, validation, and refinement ensures that security measures remain relevant and effective against evolving threats and business needs. This proactive stance helps avoid the accumulation of outdated or inefficient controls.

Secondly, the emphasis on Capability, Capacity, and Cost (the "3 Cs") provides a pragmatic framework for prioritization. Defenders must realistically assess their organization's resources and expertise when selecting controls. It's crucial to distinguish between "real" and "aspirational" controls, making conscious decisions about what to implement now, what to defer, and what to consciously not implement based on a clear understanding of risk tolerance and business objectives. This prevents resource drain on controls that may not offer the most significant impact for a given organization.

Third, defenders must tailor their control implementation to specific organizational contexts. As demonstrated by Rama's startup, MFA might be mandatory for IT staff but not for all business users, reflecting a nuanced risk assessment and cost consideration. Similarly, foundational controls like robust input validation for web applications are critical and should be prioritized over more advanced, but less impactful, measures if basics are weak.

Fourth, the talk underscores the paramount importance of effective metrics and communication. Security teams should develop clear, consistent, and concise metrics that are relevant to different audiences (CXO, mid-management, operational teams). These metrics must directly connect to business objectives, demonstrating the value and performance of security controls. Visual aids like spider graphs or bar graphs, tailored to the level of detail required by each audience, can significantly improve understanding and buy-in.

Fifth, defenders are encouraged to leverage established frameworks and automation. Standards like NIST, ISO, PCI DSS, MITRE ATT&CK, and CIS Controls provide a strong foundation for control identification. Tools and frameworks like NIST OSCAL (Open Security Controls Assessment Language), which uses JSON for control assessment, can significantly automate and streamline the validation process, making it more reliable and efficient by reducing manual effort.

Finally, Sri's closing thought is a critical reminder for all defenders: "Don't forget the foundation." Many security incidents stem from basic failures like weak configurations or weak passwords. Before investing in advanced security solutions, organizations must ensure that their fundamental security hygiene is impeccable. This includes regularly patching systems, enforcing strong password policies, and securing basic network and application configurations. Neglecting these basics renders more sophisticated controls largely ineffective.

Key Takeaways

  • Adopt a Dynamic Control Lifecycle: Implement a continuous process of control identification, selection, implementation, validation, and refinement to ensure security measures remain relevant and effective.
  • Prioritize with the "3 Cs": All control decisions should be pragmatically evaluated against the organization's Capability, Capacity, and Cost to align security investments with business realities.
  • Tailor Controls and Metrics to Business Objectives: Security controls and their performance metrics must directly support specific business goals and be communicated effectively to different organizational layers (strategic, tactical, operational).
  • Never Neglect the Foundational Basics: Weak configurations and passwords remain primary attack vectors. A strong security posture is built upon robust fundamental controls before layering on advanced solutions.
  • Leverage Frameworks and Automation: Utilize established standards like NIST, ISO, MITRE, and CIS for control guidance, and explore automation tools like NIST OSCAL to enhance the efficiency and reliability of control validation.
  • Embrace Continuous Refinement: Control adjustments aren't always about adding more; they can involve optimizing or even reducing the depth of certain controls based on threat intelligence, incidents, and evolving technology (e.g., balancing password complexity with expiry frequency).

About the Speaker(s)

Sri (Sriram) is the Deputy CISO at Genpact. In his presentation, he shared his personal opinions and insights on cybersecurity controls, emphasizing that his views should not be attributed to his employer, past, present, or future. He is an engaging speaker, using analogies and narrative examples to convey complex ideas about security management.

All talks from RSA Conference 2024