← Back to Blog

GRC

GRC – Embedding Security into Operations

Policies are devised for a reason: to ensure compliance, effectiveness and efficiencies. The same applies with cybersecurity policies. They are devised to ensure that protection is enforced naturally and seamlessly. To that end, security policies ensure that operations can proceed normally while resting assured they are well protected, and without second thought. This is the essence behind Governance, Risk and Compliance (GRC) protocols. They are operational enablers, not inhibitors.

Designing and enforcing GRC entails some core principles and best practices. Here are some of the core ones.

Shift Compliance to the Left

Prevention is always better than cure. It is common that security policies are created to become a reference for conducting audits. This is definitely a good thing, but it is not enough and not the ideal. The ideal is to shift compliance left, meaning that compliance is enforced at the beginning of processes and operations such that, ideally, audit would not be necessary. Granted, auditing is always necessary as a means to ensure compliance and provide assurances to different stakeholders. However, if processes are guaranteed to enforce and comply in their execution, auditing can theoretically be unnecessary, and any time (randomly and surprisingly) it is conducted it is guaranteed to realize a positive result.

Take your DevSecOps Pipeline Seriously

The DevSecOps pipeline is a very powerful and effective means to ensure security measures are embedded in the final product/implementation without active or deliberate efforts. The pipeline can automatically perform very powerful tasks (code reviews, asset tagging, enforcing IAM roles, etc...) to ensure all code/customization is secure from inception to production.

Evidence Collection Automation

It is very common that security or operations teams be required to fill large and often complicated Excel sheets to describe compliance, report incidents, present logs, etc.. This very fact can make the reporting slow and in some cases (where time is of the essence) outdated. It is advisable where possible that evidence is collected automatically as part of normal operations execution, that way the data is auto-collected and sometimes even auto-analyzed. This naturally requires a deliberate decision on what variables need to be extracted (priority and frequency) which is a natural part of the GRC exercise.

Give the GRC Protocols Context

Teams function best when they understand context, and are not as effective if no context is provided. Provide such context as much as possible, so that teams use it to do the right thing without necessarily requiring supervised guidance. E.g. explain that multi-factor authentication at this point is necessary because our contract states a breach would cost us this much money. Taking this step at this point ensures we are not liable and reduces the chances of such breach.

Embed KPIs into the GRC

If security-based KPIs are added to teams, or if their KPIs are calculated based in security metrics, teams will naturally uphold the security measures that will secure these KPIs. In fact, where there could be loopholes in the GRC the teams will figure out how to close them. Teams want their KPIs to look good, and managers who place these KPIs much have the conviction of their necessity. This is one way of weaving security into operations.

Tools that Reflect Single Source of Truth

If your operations team uses an advanced tool to manage the infrastructure, while your security team is using spreadsheets, you have created an undesirable “pace-gap.” Practically, you have put your security team at a disadvantage because operations will be naturally at a faster pace than the security team, which renders the security team useless. The right thing is to have all teams refer to one set of tools as the single-source-of-truth and hence ensure they are all on the same pace. Those tools also need to be properly integrated so as not to create dysfunctional silos.

GRC practices must move from the I-just-want-the-certificate mindset to a serious proactive embedded security mindset. It is not easy, it is a journey that requires patience and evolution. But with small, but certain steps, GRC protocols will take your business a very long way.