Want to get your CISO on board with your identity access management (IAM) strategy? Here's some advice:
- Get a baseline.
- Educate your team
- Translate from technical risk to business risk
- Begin with the basics
- Deliver quick wins.
These are Nicole Landry’s tips for success, as the director of IAM at Equitable (EQ) Bank outlined in a virtual session at Sonrai Security’s ACCESS ‘23 summit this week.
Across the board, keeping everyone in the loop is critical, she said: “If we don't get IAM for the cloud right, we leave ourselves open to breaches — it’s really communicating that upwards.” Here are her five tips for IAM success.
1. Take a lay of the land, determine riskUpon joining EQ, Landry’s top priority was understanding the financial institution’s current state and where it was on its cloud journey, she explained.
“It was really understanding where we're at, where we're going, what our plans are, where our objectives are,” she said.
At that point, the company had already selected its cloud providers and had on-boarded or migrated 70% of its applications, she said.. Now, the bank is working with Microsoft and other key partners to determine the next generation of its cloud.
In her role, it has also been critical to understand the issues the company has experienced around identity and security issues and identify the teams integral to the cloud process — that is, cloud operations, engineering and help desk professionals.
In terms of the IAM piece, her team is continually identifying the types of accounts in use and the credentials and permissions of each of those. For instance, is a certain account the appropriate one to use for a given activity?
“The primary piece is evaluating risk,” Landry said.
Critical to the IAM process is explaining what, exactly, cloud identities are and what they have the permission to do. For example, in Azure, it might be widely assumed that the help desk would be the appropriate department to be the user administrator, Landry said.
“But that couldn't be further from the truth,” she said, “based on the condition and the functionality of that role. So it’s really being able to understand those roles and what they mean and being able to communicate that outward.”
2. Explain security-based on roleDifferent roles and departments have different priorities and interests: That’s a given. For instance, one C-suite member’s goal will vary widely from another’s.
“The CFO is not really too interested in the specifics that enable the security in the cloud,” said Landry. “They’re focused on ensuring that your organization remains a trusted provider to its clients.”
Therefore, it is key to identify what different stakeholders see as important and align those to security and identity.
“You have to make those kinds of key correlations,” said LaIndry. “It’s really not overcomplicating it; you don't get that understanding when it's too complicated or it's not at that high level.”
Similarly, she said, show forward movement, positive outcomes and attack smaller problems first. “Start with the obvious,” said Landry. “Don’t overthink it.”
3. Make education criticalFrom a team perspective — and this applies to departments across the board — Landry emphasizes the importance of blocking off time in the day to build proficiency and knowledge.
This can include researching new and evolving threats and methods and attending seminars and trainings.
“We need to ensure that our teams — and also ourselves — block off that time for that education and build it into our day-to-day,” Landry said. “Sometimes that's challenging, but it's important to encourage that.”
4. Identify problems to communicating measurable outcomesChris Kirschke, head of cloud security at grocery store chain Albertsons, offered similar practical advice..
New security leaders should commit their first 90 days to understanding problems and their impacts. “Ask a lot of questions, do a lot of listening,” Kirschke said.
Look at how stakeholders — infrastructure, DevOps, IAM teams and others — do their jobs, what processes they’re leveraging and where the pain points are, he advised. Have one-on-ones, understand team members’ backgrounds and determine where their skills are (and if there are deficiencies, do they need to do training or hire additional talent?).
Just as importantly, “at the end of the day you have to talk to business leaders: ‘How can I help you?’” he said.
Yes, that conversation can often be the hardest because they might provide a laundry list of concerns without diving in, he acknowledged, or they may simply be content in staying hands-off.
“You really have to dig in, ask harder questions, get them to answer those questions,” said Kirschke.
5. Move from strategy to executionFrom there, security leaders can create roadmaps, dig into measurable outcomes, increase remediation efficiencies and automate capabilities, Kirschke said.
But start small, he advised. “Probably the number one mistake I see is boiling the ocean,” he said. “You end up with a huge waterfall project that does nothing but tire people out.”
Throughout the process, security leaders must be clear in what they’re delivering, commit to that, regularly reassess and provide real data on gains. Metrics and dashboards populated along the way can create feedback loops.
“You have to show the big picture,” said Kirschke, “this is what we are actually delivering to the business.”
Similarly, focus on the positive and the good gains and strides and “avoid the wall of shame.”
And, at the same time, security leaders should be firm and clear in their priorities. “Figure out how to draw the line in the sand with your stakeholders,” said Kirschke.
Finally, in partnering with vendors, it’s important to map and evaluate technical capabilities and products.
Most importantly, “I really want to see how focused they are on my problem: Are their answers clear, specific, factual, complete, respectful,” said Kirschke. “We’re looking for a vendor that we can be a partner with, that we know we can trust.”
Comments