- The IT asset exists.
- Where the IT asset is.
- Who uses the IT asset (e.g., receptionist, marketing, legal, HR, executive).
"Step No. 1: Scope for cybersecurity exposure, first for external and SaaS threats"
- To understand the exposure, you must first understand what can be exposed. In other words, what IT assets do you have?
- You must also know where the asset is located.
- The SaaS asset may not be easily discovered, and the security exposure must include the SaaS provider, thus the requirement for Cloud Asset Management.
- The I/PaaS asset type was not mentioned but has similar yet more complicated issues than SaaS and is also managed by Cloud Asset Management.
"Step No. 2: Develop a discovery process for assets and their risk profiles"
- ITAM lives and dies by discovery and typically not just one discovery tool. Furthermore, the discovery tool is only effective for discoverable assets.
- The ITAM staff reconciles what was discovered against the current inventory.
- Discovery is an ongoing effort aided by ITAM processes that capture the request, approval, procurement, receiving, configuration, deployment, in-use, recovery, and disposal of IT assets.
"Step No. 3: Prioritize the threats most likely to be exploited"
- To properly prioritize threats, you must know what assets are in use, where the assets are located, for what purpose, and by whom. ITAM lifecycle processes capture all of this information.
"Step No. 4: Validate how attacks might work and how systems might react"
- The data curated by ITAM provides an accurate picture of the attack surface. An accurate attack surface allows IT security to create valid attack scenarios.
- An accurate attack surface makes the blue and red team's exercises efficient.
"Step No. 5: Mobilize people and processes"
- An effective ITAM program establishes channels for communication and education horizontally and vertically across the organization.
- The CTEM program can leverage these channels to promote its program.
- ITAM can benefit from the CTEM program if the communication channels are incomplete.
Why Reinvent the Wheel?
Implement CTEM and Get a Bigger ROI with ITAM
Cyber Security Frameworks
ITAM IQ identifies 37 ITAM components representing the IT asset lifecycle, standards, and initiatives.
CIS has 161 controls, and when mapped to ITAM, the result is over 400 points where ITAM components enable and support the CIS framework.
NIST has 23 functions and 108 categories, and when mapped to ITAM, the result is over 300 points where ITAM components enable and support the NIST framework.
ITAM / Cyber Security Workshop
Remember, an organization's IT security is only as good as its ITAM program!
Citations
Panetta, K. (2023, August 21). How to manage cybersecurity threats, not episodes. Gartner. https://www.gartner.com/en/articles/how-to-manage-cybersecurity-threats-not-episodes
Pezeta, L. (2019). Black Telescope Under Blue and Blacksky. Pexels. Retrieved January 12, 2024, from https://www.pexels.com/photo/black-telescope-under-blue-and-blacksky-2034892/.