- Melissa
- Chief Information Security Officer
- Noah
- Security Engineer
- Amber
- Head of Assurance and Compliance
Melissa How can we get a list of all cloud-deployed applications?
Noah We don’t have any capability. Everything changes so fast. CI/CD and infrastructure as code make it rather hard to track deployments across the environment.
Melissa We have 50 vendors, and we cannot answer that question.
Noah We can build it. It would be helpful for the application security teams, the incident response team, and the compliance team. DevOps and architecture teams might find it useful too.
Amber Would I be able to get details about applications and compliance obligations without going to 20 different teams? Coordination is so hard. It is so frustrating.
Noah We can build that too. That would be easy. Four engineers, a technical program manager, and a business analyst, and we can do it in eight months — and of course we have to maintain it afterward. But we can build it.
Melissa (In her head) That would be a million dollars in resource cost alone. There has to be a better way.
“No one knows what’s in the cloud, especially your cloud.”
As an industry, we have focused on shiny new things, the best of breed, and whatever is in the news, while neglecting the fundamentals. Fundamentals, basic hygiene: asset management and tracking, program management. The cloud has aggravated this situation. Deployments and the need to generate value quickly are so high that there is constant churn in most cloud environments. Against that backdrop, most organizations struggle to answer basic questions:
- How many cloud applications and workloads do we have in the cloud?
- What are their business severity and risk? What data is processed by each?
- Where are they deployed? When were they last updated?
- What is the deployed architecture? Does it match the designed architecture? What was changed?
- What is the relationship between deployed applications and the underlying infrastructure?
- If I see a URL, can I track it back to my infrastructure and code?
All teams need these answers. Incident response teams need them during investigations; the application security team performs threat modeling, prioritizes vulnerabilities and approvals; DevOps monitors changes in the application; assurance tracks evidence and readiness assessments. The use cases for this fundamental capability are endless. Yet most organizations struggle with these questions. Pick any cybersecurity or information technology framework: the first control is often asset management. We all struggle to run a cybersecurity program without real-time, automated asset management. We have all heard about the exposed S3 bucket that no one knew about, the EC2 instance exposed to the public, the RDS database in a public subnet holding personally identifiable information, and the deployed application that looks like a completely different beast in production.
Asset management is often delegated as IT’s responsibility. Sometimes that works, but more often than not it does not. A lack of good asset management often translates into a lack of suitable program performance measurement — that Peter Drucker quote: “If you cannot measure it, you cannot improve it.”
To get better at cybersecurity, it is time we got better at fundamentals. Instead of running after the latest FUD, we focus on getting the basics right — not as a standalone capability, but as an integrated capability that enriches every other capability. It becomes a force multiplier. Once the fundamentals are correct, we have a better chance of building something sustainable and right-sized. Perhaps we might not even need 50 vendors.