Bob One of our systems got compromised. We are seeing command-and-control traffic going out.
Laura I have a few questions. What do we know about the system? What is the business criticality of this system, and what application is it running? What type of data is stored, and who are the owners and business units responsible for the system?
Bob It is still early in our investigation. We are looking into it. We don’t have too many details about the asset at this time; we don’t even have access. We know it is hosted in the public cloud infrastructure. The team is working on getting the details.
Heard that conversation before? You are not the only one. Asset management is one of those foundational capabilities that often comes up as the capability to build and get right. Effective asset management is a prerequisite for capacity planning, operational planning and support, operational security, cost management — the list goes on. However, most organizations have difficulty building an effective and sustainable asset management capability. Often it deteriorates over time, leaving organizations scrambling for information in the middle of an incident or a planning exercise. This is a consistent story across many organizations.
The reason for failure is often that the capability tries to deliver too much. Asset management initiatives will have roadmap items that build complex relationships between assets and entities, create dependency trees between them, establish discovery methods that generate too much data, and introduce new processes for registering and deleting assets. All of this looks great on the project plan. However, it adds considerable overhead, and these new processes are easy to bypass for folks who just want to get their work done. Over time, all of it becomes a burden on engineering and operations teams. The problem is in some cases made worse by on-demand provisioning infrastructure like a public or private cloud. It is not uncommon for organizations to restart asset management initiatives every few years, rebuilding the capability and repeating the same mistakes as the previous initiative.
Asset management is not just a core information technology capability: pretty much all cybersecurity initiatives and capabilities rely on it. The cybersecurity organization often asks: how can we build effective cybersecurity capabilities if the underlying foundational capability is subpar? Of course, asset management is not the shiniest of the cybersecurity capabilities. The approach below intends to change that. It not only builds an effective asset management capability but also makes asset management a force multiplier for the rest of the cybersecurity capabilities.
JEAM
Just Enough Asset Management (JEAM) has been in the works for a few years. The core concept of JEAM is reducing asset information collection to the minimum required — a minimum set that can drive most of the cybersecurity and IT processes. The selection of attributes is critical, as they must be collected consistently and reliably through near-real-time automated processes. JEAM does not introduce human-driven processes; it is driven entirely through automation.
A follow-up post provides an overview and a reference architecture for JEAM, and shows how it can be used for vulnerability management, incident detection and response, footprint assessment, risk management, and other capabilities — and how such a system can become the core of an organization’s cybersecurity capabilities.