enterprisesecuritymagapac

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Neiman Marcus

Evolving Role of the CISO/CISO of the Future

Shamoun Siddiqui, Chief Information Security Officer and VP Infrastructure Engineering and Operations, Neiman Marcus

Information security came of age in the early 2000s, primarily in the wake of several regulatory compliance mandates. Foremost amongst them was the Health Information Portability and Accountability Act (HIPAA). Originally developed and enacted in 1996 as part of the Social Security Act, the law did not take form until 2001 when an office of HIPAA Compliance was established. It took another 2 to 3 years for compliance to the HIPAA rules to became mandatory. The HIPAA Privacy Rule went into effect in 2004 and the HIPAA Security Rule in 2005.

The Security Rule required the implementation of administrative, technical, and physical safeguards to protect electronic forms of health data, i.e. protected health information (ePHI). One of the elements of the administrative controls was the need to designate an official to oversee the development and implementation of security policies and procedures. Implicit in this requirement was the need to have a formal information security organization. This is around the time that the role of a Chief Information Security Officer (CISO) came of age.

Around the same time frame, Sarbanes-Oxley was enacted for publicly traded companies and reinforced the need to provide oversight over certain elements of the IT infrastructure – such as logical and physical access controls, change management, and disaster recovery etc. SOX-404’s IT General Controls (ITGCs) were somewhat subjective in their nature and companies varied in their implementations. However, in general, the controls emphasized the need for a formal organization overseeing the IT processes, headed by a leader.

SOX-404 was followed soon by the Payment Card Industry (PCI), Data Security Standard (DSS) which was led by a consortium of credit card providers like Visa, Mastercard, and Discover etc. The DSS comprised of twelve “requirements” containing over 200 very prescriptive controls outlining the administrative, technical, and physical requirements for an effective program to protect cardholder data. Requirement 12 of the DSS specifically called out “The formal assignment of information security to a Chief Security Officer or other security-knowledgeable member of management”.

These early compliance mandates solidified the need for organizations to designate a Chief Information Security Officer and to maintain a formal information security function. CISOs were, initially, more likely to be found in either healthcare, financial services, or retail organizations as these were subject to somewhat more rigorous compliance programs. Since the need was driven by compliance, primarily, the CISO’s role was initially focused on building security organizations, developing and implementing core policies and standards, establishing processes for periodic reviews of various types and implementing a limited set of technologies to support the compliance programs.

"As enterprises rapidly move towards the cloud, with Gartner predicting that by 2025, 80% of companies will have shut down their traditional data centers, the CISO of the future will be faced with an entirely different landscape."

To take up on the last item, the fact was that the CISO’s budget was typically driven entirely by compliance and the technologies that were acquired and implemented were almost always in support of specific compliance requirements. As just a few examples:

• HIPAA required encryption of protected health information (PHI) as it traversed the public networks. Therefore, SSL encryption became a priority

• SOX placed an inordinate amount of focus on logical access to systems and applications. So, Identity and Access Management Systems (IDAM) suddenly became a focus for CISOs

• PCI mandated that any cardholder data at rest be encrypted and critical system files be monitored for change. So, the conversation shifted to encryption and key management technologies as well as File Integrity Monitoring (FIM)

These, “First Generation CISOs” tactically focused on technologies that supported the compliance and certification obligations of their companies. For them, “compliance brought security”.

In the late 2010s and early 2011s, as eCommerce started to take root and flourish, the concept of “digital transformation” become a priority. While the term was subjective and meant different things to different companies, the focus was on virtualization technologies and the move away from physical servers. Virtualization allowed the density of servers in a data center to increase dramatically. Any challenges that may have existed due to horizontal scalability of applications suddenly became less of a concern.

The use of virtualization spawned new challenges and concerns for the CISO. Example, if one VM on an ESX host was subject to compliance, should the scope include the entire chassis? What security controls should be implemented at the hypervisor level? How does one handle workloads on a hypervisor with differing trust levels? Along with these, many other issues like network configurations, firewalling and VM sprawl etc, became central to the conversations.

With digital transformation riding on the wave of virtualization, the CISO suddenly needed to expand their skillset beyond some of the more discrete and traditional technologies and start understanding some of the security challenges related to virtualization. These were the “Second Generation of CISOs” –moving from a compliance centric mindset to a more tech centric approach.

In parallel with the rise of virtualization there was another technology revolution taking hold. While cloud computing had been around for a couple of decades, it was in the mid-2000s, that cloud computing became a commercially viable computing alternative. Amazon’s EC3 and S3 blazed the trail for pay-as-you-go computing. Infrastructure as a Service (IaaS) became the new buzzword followed soon by a variety of “ – as a Service” offerings: SaaS, PaaS, DaaS etc.

As companies rushed to leverage elastic computing to address their seasonal needs, the second gen CISOs became a stumbling block. These CISOs were leery of the protections offered by cloud providers, and rightfully so. A lot of the controls that are inherent to a brick-and-mortar data center, were often missing by default from cloud environments and needed to be consciously included in the design and implementation, often at significant impact to the timing and operating costs. Data encryption and key management technologies, while available, were generally expensive to acquire and challenging to deploy and maintain. Finally, there was ambiguity around auditing and evidence collection.

The general discomfort around appropriate controls in public cloud environments led the second gen CISOs to resist any attempts by IT and business teams to move critical business applications and data to public cloud.

However, the cloud train, was one that could not be stopped and forward looking CISO’s, realizing the eventuality, embraced the cloud and actively started working with the technology and development teams within their companies to help establish secure cloud environment. These were the “Third Generation CISOs”.

The cloud represented an altogether new frontier for these CISOs and they raced to understand the fast evolving technologies being used in the cloud eco systems. Their initial approach was to extend the traditional data center controls over to the cloud. Therefore, IDS/IPS, WAF, AV, and vulnerability scanning etc found their way into cloud implementations.

However, these heavy weight technologies, designed to operate within brick-and-mortar data centers, were soon found to be somewhat cumbersome and expensive to utilize in cloud implementations. Cloud providers, also recognizing these challenges, started offering more agile and cost-effective services within their ecosystems. The rise of infrastructure as code also demanded lightweight technologies that could be easily consumed by the developers to build secure machine instances in the cloud. All of this necessitated that the CISOs become intimately familiar with what was available in those environments and how the different pieces plugged into the CI/CD pipelines and automation processes seamlessly.

These third gen CISOs found themselves relinquishing control over these security elements to developers and to cloud centers of excellence (CCoE). The rise of DevSecOps meant that developers now needed to ensure that security elements were built into their development process and deliverables. The CISOs then maintained governance and oversight mechanisms. In ideal circumstances, CISOs would have security resources embedded with the developers or within the CCoE.

By this time, the CISO is evolving from being a compliance expert to being someone who must deeply understand technology.We are now seeing the evolution of the “Fourth Generation CISO”.

As enterprises rapidly move towards the cloud, with Gartner predicting that by 2025, 80% of companies will have shut down their traditional data centers, the CISO of the future will be faced with an entirely different landscape.

With the dissolution of the brick-and-mortar data centers, all of the heavy weight technologies like appliance or VM based firewalls, IDS/IPS, WAFs, load balancers, proxy filters, logging and monitoring systems, etc must now be rearchitected or redesigned for use in cloud environments. Cloud native replacements for these technologies, and much more, have taken hold and are now part of the ecosystem of every major cloud provider.

Whereas in the data center environment, the infrastructure teams and often, cybersecurity teams, were responsible for the selection, implementation, and maintenance of these technologies, in public clouds, they are now squarely in the domain of the developers. DevOps teams now routinely select appropriate technologies from the cloud marketplaces and integrate them in their CI/CD pipelines and automation platforms.

The fourth gen CISO now needs to thoroughly understand cloud infrastructures and more importantly, understand the products and services that are available in the cloud marketplaces. Furthermore, the CISO and his/her teams need to be able to provide appropriate guidance to the developers for integration of all required security technologies into the development lifecycle.

And this is just part of the new challenge. Just as cloud adoption has spurred the growth of ecommerce and advanced data analytics etc, it has also resulted in an explosion of new cloud native security technologies. A decade ago, a security practitioner could easily list out security vendors and the critical security platform or technologies. Now it is a virtual impossibility. There are hundreds of products and services that promise to secure, protect, defend, and monitor your data and your environment. Acronyms abound: EDR, MDR, XDR, SOAR, PAM, SDWAN, ZTNA, TI, SASE, CASB, SDP, SWG,CSPM, UEBA, and on and on. A CISO must be familiar with all these and more and be able to craft a suitable strategy for his/her team and company to adopt and to execute.

Cloud computing is also evolving at a breakneck pace. From virtual machines to containers to orchestration of containers to serverless computing; from centralized computing to edge computing; from simple analytics to advanced machine learning and artificial intelligence; from standalone databases to data lakes and unfathomable amounts of data; the landscape is continuously evolving. The CISOs must understand this ever-expanding universe and must be able to secure it against a plethora of increasingly sophisticated threats emanating from organized threat actors who appears to be technologically savvy themselves.

This is only possible if the CISO is himself a technologist. The CISO of the future, per force, must understand all aspects of infrastructure technologies, must be intimately familiar with cloud ecosystems and the security products and services available within, must be able to understand the technical challenges presented by an increasingly distributed workforce, must be able to create a technical and an architectural roadmap for his company’s security platforms and must be able to understand the evolving threat landscape.

The technology tsunami is going to wash all over us, in our personal lives and in the workplace. Every passing day, we witness some evolution or new development that momentarily wows us and then becomes a routine part of our daily lives. Hiding in between the waves of the tsunami are unprecedented threats to our safety and security and to the safety and security of sensitive information. A traditional CISO is out of place in this new world. We need security leaders, who are forward looking and highly agile and who have a bird’s eye view of all of the elements of technology within their enterprise and outside, and who can bring a coherent strategy to bear in order to protect their company.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.