Chapter 7. Every Information Security Problem Boils Down to One Thing
Ben Smith
It’s the dirty little secret of our industry: just about every challenge that we face in trying to secure our infrastructure from threats ultimately comes down to an asset management problem.
In many organizations, asset management is viewed as pure drudgery and a never-ending stretch to accomplish. Assets residing on your network, not just those dedicated to your employees but perhaps your supporting third parties as well, are not static entities. Today’s asset inventory is almost guaranteed to look a little different than yesterday’s. Much like Sisyphus pushing the boulder almost to the top of the mountain every day, your asset management goal posts can and will change daily.
Yet if you don’t know what is plugged into your network, if you don’t know who is plugged into your network, your visibility will be dangerously limited, along with the ability to do your job in securing your organization.
Further complicating this task: defining exactly what an “asset” is may not be a totally straightforward exercise. In some cases, assets to be protected by you and your team may not be limited to traditional server, endpoint, or network gear. Are we talking about everything with an IP address? Is a digital signing certificate an asset that should be cataloged and protected like a physical device? Should identities ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access