enterprisesecuritymag

| | ENTERPRISE SECURITY6 MAY - 2022The Evolving World of Vulnerability ManagementEditorialCopyright © 2022 ValleyMedia, Inc. All rights reserved. Reproduction in whole or part of any text, photography or illustrations without written permission from the publisher is prohibited. The publisher assumes no responsibility for unsolicited manuscripts, photographs or illustrations. Views and opinions expressed in this publication are not necessarily those of the magazine and accordingly, no liability is assumed by the publisher thereof.Managing EditorRussell ThomasEditorial StaffAaron PierceAlex D'SouzaAva GarciaJustin S GonsalvesVisualizersRonald DonovanSalesAlena D'Souzaalena@enterprisesecuritymag.comEmail:sales@enterprisesecuritymag.comeditor@enterprisesecuritymag.commarketing@enterprisesecuritymag.comDisclaimer : Some of the Insights are based on our interviews with CIOs and CXOsThe increasing adoption of undefended new technologies like Internet of Things (IoT) and escalation in cybercrime activity have given rise to more damaging breaches. The ensuing regulatory and legal scrutiny has revealed the shortcomings of this traditional approach. This raises the question about the limitations of traditional vulnerability management and what steps can be taken to drive a new, risk-centric approach designed to expose imminent threats (for mitigation) and more effectively reduce risk across the expanding attack surface.Vulnerabilities are not a new phenomenon ­ they are as old as computers. And while vulnerability management tools and practices have evolved over the past few decades by adding new capabilities like authenticated or agent-based scans, at their core they still rely on the Common Vulnerability Scoring System (CVVS), which is maintained by the Forum of Incident Response and Security Teams (FIRST). It is easy to be misled by CVVS scores and play math games with them. However, these exercises typically only reduce risk on paper ­ not in reality. Traditional vulnerability management approaches practice gradual risk reduction. They either focus remediation actions on the most severe vulnerabilities based on a high CVSS score (so-called vulnerability-centric model) or the value and exposure of an asset (i.e., Internet-facing, third-party access, contains sensitive data, provides business critical functions; so-called asset-centric model). Unfortunately, both practices are often tied to reducing the most amount of risk with the least number of patches.Managed detection and response technology through BDR helps reduce risks associated with Shadow IT (users deploying technology solutions without the knowledge or approval of IT). Example: Grammarly announces a zero-day, but this is not an approved service at your organization, so you don't think you are affected. However, one of your employees has installed a Grammarly browser extension to proofread and correct emails. No IT knowledge or control means the software may remain unpatched or misconfigured. There is no such thing as being 100 percent protected from cyberattacks, so organizations need to have continuous monitoring and a comprehensive response plan. Take an "assume breach" mentality based on the principle that you will eventually be breached and need to have people, process, and technology in place to limit damage from a cyberattack and recover quickly.Let us know your thoughts.MAY - 23 - 2022, Volume 08 - 02 Published by ValleyMedia, Inc.(ISSN 2691-4034) To subscribe to ENTERPRISE SECURITYVisit www.enterprisesecuritymag.com Russell Thomas Managing Editor editor@enterprisesecuritymag.comJoshua Parker
< Page 5 | Page 7 >