THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by our Healthcare Tech Outlook Advisory Board.


Customers, regulators, business partners, employees and your Board of Directors all expect that you have deployed the right technology to protect their data and systems. Unidentified gaps in your security posture may lead to missed performance guarantees, audit findings, and – in the worst case – a security incident. Traditional assurance mechanisms, such as inquiry and sampling, only give confidence that a portion of your environment is protected at a point in time. Being resource-intensive, these methods are typically executed infrequently. On the other hand, automation can provide frequent, comprehensive assessments, enabling closed-loop remediation.
To automate assurance for security technology, clear definitions of “good” are required. The definition must allow you to precisely define a test for “good,” to identify the data required for testing and to interpret the output of the test. We chose effectiveness as our litmus test, defined as the measure of four attributes: coverage, availability, configuration and currency.
Coverage is a measure of the percentage of your technical environment to which a security technology has been deployed. Our challenge was identifying the asset population. For endpoints, through extensive collaboration between security and infrastructure teams, we were able to correlate our asset management system with our security management consoles and establish our own source of truth for the population.
Asset population forms the denominator of the coverage measure. Our next challenge was to identify what had been deployed. For security software deployed to endpoints, we correlated data from our software distribution systems and from our security management consoles to provide the numerator.
“To automate assurance for security technology, clear definitions of “good” are required”
The next measure, availability, tells you if the security technology is “on.” Continuing with the endpoint example, we considered an agent to be available if it had reported back to its management console. Tuning the threshold for alerting took work. There are valid reasons for an agent not to report in. For example, a laptop that is shut down for the weekend will not be sending a heartbeat to the console.
Configuration measures deviations from configuration standards. For example, do anti-malware agents have the required blocking policies? Key to this measure was working closely with our security engineering teams to exactly specify the expected configurations. Once a baseline was agreed to, it was straightforward to download configurations from the management console and compare them to it.
The final measure, currency, tests whether all components of the security technology are up to date. Versioning can be inconsistent across vendors, so we established a procedure to regularly update an internal table of vendorspecific version names and numbers. In collaboration with our security and infrastructure teams, we then set relative thresholds for minimum acceptable versions, for example, N - 2. A direct comparison to reports from the management consoles completed the measurement.
Once we demonstrated the reliability and accuracy of the automated measures, we codified thresholds of “good” for each of the measures in the policy. This allowed us to use existing policy exception processes to disposition gaps that could not be remediated.
To communicate results to leadership, we developed an interactive dashboard. It allows them to quickly understand the current state of adherence to standards, broken down by the four measures and by security technology. It also allows leaders to filter by specific platforms (e.g., Windows or Linux), to review time series for each of the measures and to drill down to individual gaps in adherence.
Finally, we needed to action on gaps. We coupled asset data with roles and responsibilities to identify who or what team was responsible for resolving individual adherence gaps. We then were able to automatically create tickets via the API of our IT management system. Each ticket lists specific actions required to remediate gaps. Technology operations teams can leverage the output of our assessments with no change to their existing processes.
By including ticket generation in our solution, we achieved closed-loop remediation. We now have highly accurate and up-to-date visibility into the effectiveness of our key security technologies. Coupled with leadership oversight and regular disposition of gaps, we enjoy a high degree of assurance that those security technologies are operating in line with expectations, allowing us to convey that assurance to our customers, regulators, partners, employees and Board.