Article Excerpts
- "For a cyber security system to be effective it must know what it is meant to protect"
- "S&P Global Ratings considers robust ITAM to be vital to an entity's ability to proactively manage vulnerabilities, respond to incidents efficiently, and minimize the financial impact of cyber attacks."
- "In our view, ITAM should be directed by explicit policy that provides the authority for the system to be effective and assigns clear roles and responsibilities."
- "The absence of ITAM can create gaps and blind spots in organizations' cyber risk management"
- "The FTC's complaint against Equifax, for example, cited an inability "to maintain an accurate inventory of public facing technology assets" that contributed to poor patching among the "basic security failures" at the company."
- "U.K. government's National Cyber Security Centre. "Many organisations have significant gaps in what they understand about their environment."
- NIST's cybersecurity framework states the requirement for ITAM, although weakly.
- CIS's cybersecurity framework states the requirement for ITAM, although weakly.
- And the famous saying "you can't secure what you don't know you have!" is ubiquitous.
- Artificial Intelligence – offering hope for a more profitable future!
- FinOps – the latest vendor-generated hype promising to deliver IT for everyone, cheaper and faster, but puts cybersecurity in the back seat.
- Cloud – outsource everything for a cheaper and faster future!
Let's look at a diagram that appeared in the S&P article. The "brain icon" was added to identify ITAM IQ comments.
Security Monitoring
Any security framework of value states an accurate IT asset inventory is the foundation for the security program. The problem with this is the absence of any description of how difficult it is to achieve an accurate inventory. IT Asset Managers are well aware of the perception that all we do is "count things." Which leads to the subsequent great misunderstanding.
Lifecycle Management
While what is stated is true about lifecycle management, it is only one of the many benefits ITAM lifecycle management brings to security. The first benefit is an accurate inventory! That's right! You must manage the entire lifecycle of assets to maintain an accurate inventory. And what is the lifecycle? It starts when someone thinks they need an IT asset and goes beyond the end of the asset's life for some asset types.
Incident Response
Incident response depends on an accurate inventory and asset histories to determine the extent of any damage. Again, the reference to an "accurate inventory" is as if it were something that could be purchased at a convenience store.
Vulnerability Management
With every asset type comes vulnerabilities. Understanding those vulnerabilities is best done before a new asset type is purchased and then managing and tracking the asset through its life. Once again, an accurate asset inventory is required, and ITAM is the gatekeeper for all assets that connect to the organization's network.
Cyber Risk Management
Four words: accurate IT asset inventory.
The Bottom Line
ITAM delivers value for many functional areas, not just IT security, making it the organization's best investment in any business program. However, implementing an ITAM program is not easy. Starting with the PC era, organizations have become lazy, undisciplined, sporadic, and, let's face it, irresponsible when managing IT assets. From the PC to the laptop, the internet, then the smartphone, and to date, the cloud, we have been neglecting IT asset management for years. The expectation that an ITAM Program can be implemented within a year is, nicely put, unrealistic.
Simply put, your cyber security program is only as mature as your ITAM program.
[1] https://www.spglobal.com/ratings/en/research/articles/230815-cyber-risk-insights-it-asset-management-is-central-to-cyber-security-12819307
Hero photo credit: Leeloo Thefirst