How can compliance frameworks blind companies from understanding their own accepted risks?
But does it truly translate to understanding that you are accepting risks and what those are? As opposed to being surprised when the bad thing happens even though it links back to this risk that we told you about in accordance with the framework—which you all nodded your head about at the time. Now the bad thing that we said could happen has actually happened and everyone’s shocked.
I'm a big believer in the Mitre ATT&CK framework, but it’s also limiting in that it doesn't cover certain things. I do advisory work for a company that does stuff at the firmware security level, but Mitre won't recognize that in the Mitre ATT&CK framework because they don’t believe there have been enough attacks and evidence for it to be expanded—which means even that framework is driving behind the risk curve. That's why you have to look at the frameworks and identify where it’s limiting you.
As much as it's useful for focus, that focus means we're losing peripheral sight of some things and potentially foresight on other things further ahead. It's only up to us as to whether or not the framework will do that; it’s how we use it.
Content you might like
Strongly agree5%
Agree67%
Neutral24%
Disagree2%
Strongly disagree0%
Slow recovery response times33%
Data availability is limited49%
Too expensive to scale effectively52%
Difficult to manage for widespread use38%
Prone to misconfiguration12%
No - There are no drawbacks6%
While they give us efficiency, effectiveness, they provide us some level of liability protection and some consistency for management to have a structured discussion—that they understand once we train them on those boundaries—if we are not doing the discussion around the bias that they create and the things that we may miss, then we're probably not doing our jobs.
Use them for their efficiency and effectiveness, but also question them periodically and set up a monthly or quarterly review to ask, what is this not telling us? What are we missing because we're so focused on using this set of parameters as the mitigation for that?