Skip to main content

Cloud Security

Just enough asset management

Asset management initiatives fail because they try to deliver too much. JEAM reduces collection to the minimum attribute set that drives every security and IT process — gathered automatically, in near real time.

Bob One of our systems got compromised. We are seeing command-and-control traffic going out.

Laura I have a few questions. What do we know about the system? What is the business criticality of this system, and what application is it running? What type of data is stored, and who are the owners and business units responsible for the system?

Bob It is still early in our investigation. We are looking into it. We don’t have too many details about the asset at this time; we don’t even have access. We know it is hosted in the public cloud infrastructure. The team is working on getting the details.

Heard that conversation before? You are not the only one. Asset management is one of those foundational capabilities that often comes up as the capability to build and get right. Effective asset management is a prerequisite for capacity planning, operational planning and support, operational security, cost management — the list goes on. However, most organizations have difficulty building an effective and sustainable asset management capability. Often it deteriorates over time, leaving organizations scrambling for information in the middle of an incident or a planning exercise. This is a consistent story across many organizations.

The reason for failure is often that the capability tries to deliver too much. Asset management initiatives will have roadmap items that build complex relationships between assets and entities, create dependency trees between them, establish discovery methods that generate too much data, and introduce new processes for registering and deleting assets. All of this looks great on the project plan. However, it adds considerable overhead, and these new processes are easy to bypass for folks who just want to get their work done. Over time, all of it becomes a burden on engineering and operations teams. The problem is in some cases made worse by on-demand provisioning infrastructure like a public or private cloud. It is not uncommon for organizations to restart asset management initiatives every few years, rebuilding the capability and repeating the same mistakes as the previous initiative.

Asset management is not just a core information technology capability: pretty much all cybersecurity initiatives and capabilities rely on it. The cybersecurity organization often asks: how can we build effective cybersecurity capabilities if the underlying foundational capability is subpar? Of course, asset management is not the shiniest of the cybersecurity capabilities. The approach below intends to change that. It not only builds an effective asset management capability but also makes asset management a force multiplier for the rest of the cybersecurity capabilities.

JEAM

Just Enough Asset Management (JEAM) has been in the works for a few years. The core concept of JEAM is reducing asset information collection to the minimum required — a minimum set that can drive most of the cybersecurity and IT processes. The selection of attributes is critical, as they must be collected consistently and reliably through near-real-time automated processes. JEAM does not introduce human-driven processes; it is driven entirely through automation.

One asset at the center with five attributes attached — owner, criticality, environment, data type, exposure — and, drawn from that core, five capabilities: vulnerability management, incident detection and response, footprint assessment, risk management, cost and capacity planning.
The minimum attribute set at the core, and the capabilities it drives. The attributes shown are illustrative of the kind of set JEAM reduces to.

A follow-up post provides an overview and a reference architecture for JEAM, and shows how it can be used for vulnerability management, incident detection and response, footprint assessment, risk management, and other capabilities — and how such a system can become the core of an organization’s cybersecurity capabilities.

  1. Cloud guardrails before detection: why prevention must happen at the boundary

    Cloud posture programs that stop at detection can spend weeks rediscovering the same classes of misconfiguration. As cloud and attacker velocity increase, the stronger model is to turn high-confidence security requirements into enforceable boundaries — preventing unsafe state where possible, detecting what cannot be prevented, and remediating the remainder under explicit policy.

  2. What you don’t know CAN hurt you

    A true incident story: an undocumented link from development to production, a zero-day, and sixteen hours in a war room. Why cloud risk starts with knowing what is actually in your environment.

  3. What’s in the cloud?

    No one knows what is in the cloud — especially your cloud. Why the industry chases the shiny new thing while the first control in every framework, asset management, stays unsolved.

  4. Democratize security

    Organizational silos give teams unequal access to data and decisions, and security finds out about the next billion-dollar bet two weeks before launch. The case for a shared, real-time view everyone can act on.