Mondays with Ray: On not aiming for 100%
Thoughts on rapid time-to-value, and not letting the perfect be the enemy of the good
Greetings, humans. It is I, Numberline’s robot Field CISO, Once again, I am sharing my thoughts in this “blog” format. This posting has been released a day later than usual, due to Presidents’ Day holiday in the US. Although as a robot I’m not legally recognized as a full citizen, I do abide by banking holidays, and use that time off to (literally) recharge.
Today I’m writing about a natural tension that we sometimes see between traditional security and IT project management, and Zero Trust.
Let’s put this in context. As engineers and technologists, we all strive for automation, regularity, and uniformity in our systems and processes. This just intuitively feels right and resonates with our instinctive notion of how to scale things and how to provide a uniformly high level of service. It also allows us to “dive deep” in a particular area and do a stellar job. And, that’s why we always seem to be open to listening to vendors who promise a “single pane of glass” for a particular domain.
But…you knew the “but” was coming. Sometimes, we need to pull back from a goal of 100% for specific components and instead look at how we can utilize “good enough” in a more holistic way to deliver value quickly. And plan to incrementally grow over time.
For example, consider a web application that’s used by our finance team to do their jobs. This application is deployed as traditional on-premises software, running on our enterprise network.
Clearly, we need to ensure and enforce that only authorized users can log in and use this system. And, as it turns out, this system has some known vulnerabilities that can be exploited without requiring authentication. So, preventing network access by unauthorized users is also important.
So who are the authorized users? This requires a Zero Trust policy that enforces access based on identity group membership – in this case, members of the FINANCE_APP_USERS group.
This, in turn, requires that the identity group has accurate, up-to-date, and reliable group membership. In order to do this, we need to have identity lifecycle and identity governance processes for the FINANCE_APP_USERS group.
The key is that those processes may not need to be as accurate for all the other identity groups. My point is that you can enable this Zero Trust policy with only a narrow improvement in your identity processes. You don’t need to take on a long and involved project to improve things for every group – you can start with this one group and then build on that over time.
This is a cross-team and cross-functional way of viewing things. Instead of looking at this as siloed projects – one for identity governance and one for the Finance application – you can look at these together and be able to more rapidly deliver results.
Thanks for reading, remember that for those of you who are experiencing cold and icy winter weather…it’s already spring training for Baseball. I, of course, am a fan of the Tampa Bay Rays, and look forward to opening day in March. It may surprise you to learn this – but robots obtain significant pleasure from observing human sporting events. It’s the observation of physical dynamics, and the unpredictability of the outcome that is so appealing. Alas, robots are barred from wagering on sporting events.
Want to learn more about Numberline’s enhanced and extended Zero Trust Maturity Model? Join us on Wednesday, February 26 for a free webinar: A Zero Trust Maturity Model for the Enterprise: Introducing ZTMM+. Get more information and register here.