
Adam Shnider
EVP, Assessment Services, Coalfire
Compliance


We've all been there. Drowning in spreadsheets, meticulously taking screenshots, and manually reviewing system configurations to ensure compliance. We have chalked this all up to a necessary evil, but it is more than just evil, it is wasting precious time from other initiatives to drive business growth and protect the organization. It is crazy we have spent the past 15 years moving everything to the cloud, automating everything else under the sun but compliance is still stuck in the manual assurance dark ages as if the only way to validate automated environments is with sampled system configuration and processes.
It is time to automate compliance and this means understanding how automated validation can work effectively to provide the continuous assurance we need for frameworks like FedRAMP, PCI, HITRUST and many other frameworks that require technical validation to reduce the burden of the assessment and leverage other operational security tools to demonstrate compliance. We're talking about moving beyond point-in-time checks to continuous assurance and proactive risk management while increasing assurance with broader visibility and less manual validation.
The buzz in compliance around automation grows daily with a lot of excitement over the promise that this offers to drive towards higher levels of assurance. It absolutely has the potential to lead to the outcomes everyone is hoping and it is important that we examine the idea of reliance on the automation. One main question I get after many years in the assessment space, as Coalfire discusses our own platform, Compliance Essentials and the automation capabilities is “What is required to rely on automated testing?” With everyone so excited about the promise and so much focus on the technology and tooling, I wanted to take a few minutes to ensure this question was addressed. Here are the key questions that need to be answered and built into any compliance automation solution for them to be provide the reliance for continuous assurance.
The first critical question is scope. Automated controls are designed to validate configurations across a specific population of systems or users. But how do we know it actually did?
Think about it: Current manual audits try to sample to cover all configurations while cloud environments can have hundreds, if not thousands, of systems and many are dynamically created. With automation, validating secure configurations of what is running and how these systems are built from code can provide much higher levels of assurance by looking at the code and dynamic systems to provide much higher levels of reliability and assurance.
Automation is only as good as the rules it follows. If the logic is flawed or doesn't align with the compliance requirements, the results are meaningless.
Consider this: An automated rule might flag any password shorter than 8 characters. But if the compliance framework requires a minimum of 12 characters, this rule is insufficient for the specific compliance needs providing false assurance of the control status.
Security and compliance are not static. Configurations change, new vulnerabilities emerge, and user behavior evolves. Automated controls need to reflect this dynamic landscape.
Imagine this: Automated controls are usually touted as providing real-time visibility and provide continuous assurance of control status, however, resources, even compute resources, cost money. Ensuring an automation solution is optimized to run at the right time with the right scope and assessing the right rules to provide ongoing assurance of control effectiveness make the automation approach effective and sustainable.
Even the most robust automation will occasionally identify exceptions – deviations from the expected configurations. How these exceptions are handled is a critical part of the control's effectiveness.
Think about this: An automated control flags a critical security misconfiguration. If there's no clear process for notification and remediation, the issue might go unaddressed or no trackable method to understand how this issue was managed. Conversely, a repeatable approach, even automated, to address and document any corrective steps to exceptions builds trust and reliance that security issues are managed appropriately.
The vision of leveraging automation through machine-readable evidence collection and automated rules for evidence validation is incredibly empowering and promising. It offers the potential for greater efficiency, enhanced accuracy, and continuous assurance. However, to realize these benefits, building automation for assurance and aligning with an organization's risk tolerance requires important elements to demonstrate the effectiveness of the automation to continue to build trust.
By focusing on completeness, accuracy, timeliness, and exception handling, we can ensure that automated validations are not just running but are truly providing the assurance we need to maintain a secure and compliant environment. Let's embrace this evolution and build a more robust and efficient future for control assessments.
Join us at the PCI Community Meeting September 16-18, where Coalfire will be showcasing our latest advancements in cybersecurity and compliance.
Learn more