CDM: Don’t forget the human in the equation

By

Patrick Howard

Patrick Howard is Program Manager for CDM & CMaaS at Kratos SecureInfo, and is former Chief Information Security Officer at the Nuclear Regulatory Commission and the Department of Housing and Urban Development.

Patrick D. Howard, CISSP, CISM is the former chief information security officer (CISO) at the Nuclear Regulatory Commission and the Department of Housing and Urban Development. He currently is program manager for CDM and CMaaS for Kratos SecureInfo. He can be contacted at Patrick.howard@secureinfo.com.

What does shelfware have to do with CDM? You know, that software or technology that promised to be the best thing since sliced bread, but instead sits unused on the shelf? When it comes to rolling out Continuous Diagnostics and Mitigation (CDM), federal agencies could find themselves in a similar situation. This is a cautionary tale that an effective CDM strategy consists of more than just selecting and installing shiny new tools. Implementing technologies without figuring out the human in the equation – who owns it, who needs it and how they’re going to use it – can result in costly shelfware without improving security. In fact, one study, by Flexera Software and IDC Research, found 96 percent of enterprises wasting money on unused software.

Implementing technology can often be deceptively easy. It’s the soft, squishy, and often unpredictable matter of how people react and perform when new tools are introduced, disrupting entrenched processes that can lead to so many problems and technology disuse. Rather than deal with the unexpected or undesired outcomes after the fact, department and agency CIOs and CISOs can successfully design and implement their CDM strategy by carefully considering technology and people together from the outset.

When recognizing the importance of humans in the CDM equation, pay heed to these key areas that affect program success:

Who owns it? IT operations and information security both have a stake in CDM, but somebody has to own it. These historically separate teams tend toview the same problems differently; so without a clear delineation of who’s responsible for CDM, some components can slip between the cracks. To avoid that, there must be clear accountability. For example, if CDM falls under IT operations, the IT operations director would exercise overall responsibility, while the CISO would be a primary customer for the information generated in order to manage the agency’s information security risk, or vice versa. The owner should document in the project charter all roles and responsibilities for CDM, including supporting roles and the balance between the functions.

The right information for the right people: CDM must serve many customers. ISSOs, system administrators, system owners, and authorizing officials each require different types of information to support their respective roles. Without appropriate customization, CDM tools can overwhelm users by drowning them in data not germane to supporting their business needs. Rather than being force-fed information through a one-size-fits-all dashboard, the CDM solution should be tailored to deliver prioritized information so users can act on and fix security weaknesses right away. For example, a system owner has little need for the granularity of detailed vulnerability scans; instead, the system should present him or her with a prioritized list of vulnerabilities according to their impact and the sensitivity of the data affected. The user data needs should be addressed in the requirements definition for the project.

Right people taking the right action: Dashboards themselves are not the Holy Grail. Unless they directly support remediation they’re simply window dressing. Vulnerabilities must be channeled to the personnel who can best assess and implement the corrective actions. A system that merely spits out data on missing patches has limited value unless the information is directly actionable and tracks to those remediation processes. Consequently, agency planners should design the CDM solution so that the right people can evaluate the impact of the vulnerabilities and address the risks.

Creating the right behavior: Deeply rooted habits are hard to break. No matter how inefficient the static, paper-based security and compliance practices of the past, it would be unrealistic to expect behaviors established over years to change with a flip of the switch. CDM requires an approach that’s predicated on agility and resilience in responding to a dynamic, multifaceted threat landscape. Agency leaders can align their IT and information security teams by investing in training that reinforces the concepts and practice of near real time monitoring and remediation, and how the people, processes, and technologies of CDM should optimally work together. Jobs will change because of CDM, and users need to be educated and prepared in order to be efficient and effective with their new responsibilities. If old habits are hard to break, allowing new bad habits to form is no better.

Ultimately, the most powerful asset an agency has is its people. Unless the humans in the equation are given equal emphasis in the CDM planning and operations, then even the most promising technology can go underutilized, if not relegated to shelfware. If agencies don’t have the necessary design, programming, and training capabilities, they can obtain them through DHS’ CDM/CMaaS services BPA.