WEBVTT

00:00:03.660 --> 00:00:06.240
Welcome to the Azure Security Podcast, where

00:00:06.240 --> 00:00:08.759
we discuss topics relating to security, privacy,

00:00:09.039 --> 00:00:11.480
reliability, and compliance on the Microsoft

00:00:11.480 --> 00:00:16.760
Cloud Platform. Hey everybody, welcome to episode

00:00:16.760 --> 00:00:20.760
130. This week it's just myself, Michael, with

00:00:20.760 --> 00:00:24.600
Mark. Mark is here to talk to us about some important

00:00:24.600 --> 00:00:27.559
milestones in the Security Adoption Framework,

00:00:27.579 --> 00:00:31.239
or SAF. So welcome to the podcast, Mark. So glad

00:00:31.239 --> 00:00:34.859
to be here. Turnabout is fair play. So before

00:00:34.859 --> 00:00:37.899
we get to your topic of SAF, why don't we take

00:00:37.899 --> 00:00:39.100
a little lap around the news? Why don't you kick

00:00:39.100 --> 00:00:41.820
things off with your news? Awesome. Yeah, I got

00:00:41.820 --> 00:00:46.359
a couple of pieces of news. I did finally just

00:00:46.359 --> 00:00:49.140
launch a YouTube channel, so I'm attempting to

00:00:49.140 --> 00:00:51.539
enter the world of video. Please be kind and

00:00:51.539 --> 00:00:55.320
gentle. And I kicked it off with an episode kind

00:00:55.320 --> 00:00:57.700
of talking about all the free resources and all

00:00:57.700 --> 00:01:00.500
the stuff that I work on for folks. I think it's

00:01:00.500 --> 00:01:02.439
a short 15 or 17 -minute video, something like

00:01:02.439 --> 00:01:06.159
that, to get that started. We also did launch

00:01:06.159 --> 00:01:08.659
the ZeroTrustPlaybook .com website. It used to

00:01:08.659 --> 00:01:11.459
just point to the Amazon website where you can

00:01:11.459 --> 00:01:14.060
buy it. But we got some resources and some other

00:01:14.060 --> 00:01:15.799
stuff up there. We're going to start blogging

00:01:15.799 --> 00:01:17.640
and do some other things there to kind of help

00:01:17.640 --> 00:01:20.379
people sort of understand and build on the playbooks

00:01:20.379 --> 00:01:23.269
there. And of course, you know, this episode

00:01:23.269 --> 00:01:25.510
kind of covers the other big news for me, which

00:01:25.510 --> 00:01:27.870
is that security option framework. So I'll let

00:01:27.870 --> 00:01:30.290
you get to your news before we jump into that.

00:01:30.430 --> 00:01:33.549
So the first item is there is a secure boot update

00:01:33.549 --> 00:01:37.709
from the old 2011 to the 2023 certificates for

00:01:37.709 --> 00:01:40.409
trusted launch VMs and confidential VMs in Azure.

00:01:41.010 --> 00:01:43.230
Even if you don't update the certificates, you

00:01:43.230 --> 00:01:45.730
can still use the VMs, you know, still apply

00:01:45.730 --> 00:01:48.730
patches, the whole nine yards. But there's things

00:01:48.730 --> 00:01:52.769
that we can't do to secure the boot process.

00:01:53.269 --> 00:01:56.590
We can't take on any more enhancements to secure

00:01:56.590 --> 00:01:59.090
that boot process. So if that's something that's

00:01:59.090 --> 00:02:01.209
of interest to you, which it should be, you need

00:02:01.209 --> 00:02:04.739
to update to the 2023 root certificate. Just

00:02:04.739 --> 00:02:06.299
bear that in mind. Again, obviously, it's going

00:02:06.299 --> 00:02:09.659
to be in the show notes. The next one is there

00:02:09.659 --> 00:02:13.159
is now an end -to -end toolkit for Azure HSM

00:02:13.159 --> 00:02:16.419
scenarios. This is actually pretty cool. It's

00:02:16.419 --> 00:02:18.580
up on GitHub, and it's a whole bunch of deployment

00:02:18.580 --> 00:02:20.960
templates and migration scripts and validation

00:02:20.960 --> 00:02:25.639
tests for the various products that we have on

00:02:25.639 --> 00:02:30.590
Azure. that are sort of in the HSM camp. So for

00:02:30.590 --> 00:02:33.909
example, managed HSM, Azure Key Vault, and there

00:02:33.909 --> 00:02:35.689
are other ones as well. Payments HSM is another

00:02:35.689 --> 00:02:38.830
example. So a lot of people think that the hardware

00:02:38.830 --> 00:02:41.169
security module stuff that we have in Azure is

00:02:41.169 --> 00:02:43.289
just Azure Key Vault. It's actually not true.

00:02:44.250 --> 00:02:46.189
There are actually other products that are based

00:02:46.189 --> 00:02:47.889
on very specific industries or very specific

00:02:47.889 --> 00:02:50.169
scenarios. So it's really good to see that this

00:02:50.169 --> 00:02:52.289
is available because it certainly takes a lot

00:02:52.289 --> 00:02:54.289
of the mystery out of setting these things up.

00:02:55.180 --> 00:02:57.300
All right. Well, let's now turn our attention

00:02:57.300 --> 00:03:01.199
to our guest slash co -host, Mark Simons. So

00:03:01.199 --> 00:03:03.800
Mark, I know you've been on just about every

00:03:03.800 --> 00:03:06.599
single episode since the start, but perhaps some

00:03:06.599 --> 00:03:08.300
people have, I'm not going to say forgotten,

00:03:08.539 --> 00:03:10.800
but sort of lost track of what you actually do

00:03:10.800 --> 00:03:13.099
and what your role is at Microsoft. So why don't

00:03:13.099 --> 00:03:15.259
you take a couple of moments and explain that?

00:03:15.939 --> 00:03:17.900
I suddenly feel like I'm in the room with the

00:03:17.900 --> 00:03:20.780
Bobs in office space. What would you say you

00:03:20.780 --> 00:03:27.169
do here? My day job is lead cybersecurity architect

00:03:27.169 --> 00:03:30.389
at Microsoft. And so a huge amount of that work

00:03:30.389 --> 00:03:33.370
in the past few years has been focused on the

00:03:33.370 --> 00:03:36.810
security adoption framework or SAF. And it includes

00:03:36.810 --> 00:03:39.409
things like the Microsoft cybersecurity reference

00:03:39.409 --> 00:03:43.370
architecture, the MCRA, CISO workshop. Effectively,

00:03:43.370 --> 00:03:46.129
the way I describe it to a lot of folks is...

00:03:46.650 --> 00:03:49.610
I take a look at all the problems and challenges

00:03:49.610 --> 00:03:52.650
that our customers face in security. To start

00:03:52.650 --> 00:03:56.770
out, architects, CISOs, engineers, SOC analysts,

00:03:56.930 --> 00:04:01.530
etc. And then take a look at all the challenges

00:04:01.530 --> 00:04:04.590
they face and all the technology that Microsoft

00:04:04.590 --> 00:04:08.360
offers and kind of boil it down to... what do

00:04:08.360 --> 00:04:11.379
I need to do? What do I need to know? And so

00:04:11.379 --> 00:04:13.439
I build the reference architectures and whatnot

00:04:13.439 --> 00:04:15.460
like that and the workshops to kind of guide

00:04:15.460 --> 00:04:16.959
through, here's the problems that we see that

00:04:16.959 --> 00:04:19.319
challenge you. for security strategy, for security

00:04:19.319 --> 00:04:21.759
architecture, et cetera, and then build the references

00:04:21.759 --> 00:04:23.819
for that and then build workshops around them

00:04:23.819 --> 00:04:27.779
to kind of help people navigate all of the many

00:04:27.779 --> 00:04:30.120
different things, the varied things that they

00:04:30.120 --> 00:04:32.939
face. And so that's kind of what I do. And it's

00:04:32.939 --> 00:04:34.720
mostly been in the past couple of years focused

00:04:34.720 --> 00:04:37.160
on workshops that we deliver directly to customers

00:04:37.160 --> 00:04:40.930
through the Microsoft Unified. Usually most people

00:04:40.930 --> 00:04:43.230
in IT know what a unified formerly premier is,

00:04:43.350 --> 00:04:47.230
but most of the security folks may not have a

00:04:47.230 --> 00:04:49.290
lot of exposure to it. But we've essentially

00:04:49.290 --> 00:04:51.290
been building that library up to make sure that

00:04:51.290 --> 00:04:53.230
folks, hey, I need help with this on security.

00:04:54.129 --> 00:04:56.670
Sure, we've got a workshop for that. So that's

00:04:56.670 --> 00:04:58.490
kind of what I do for a day job. And then I also

00:04:58.490 --> 00:05:03.439
do standards work at the open group. And also

00:05:03.439 --> 00:05:06.540
have interacted many times with NIST and CSA

00:05:06.540 --> 00:05:10.180
and others in the past. And really heavily involved

00:05:10.180 --> 00:05:12.439
in the open group to kind of... write and author

00:05:12.439 --> 00:05:14.379
and contribute to standards. I'm a security forum

00:05:14.379 --> 00:05:15.819
chair over there, which means I help kind of

00:05:15.819 --> 00:05:18.600
steward the overall portfolio and set a vision

00:05:18.600 --> 00:05:20.699
and, you know, help kind of say, hey, that's

00:05:20.699 --> 00:05:23.220
that will be a good one to add to it. And kind

00:05:23.220 --> 00:05:24.600
of, you know, this is what I'm thinking, you

00:05:24.600 --> 00:05:27.800
know, adjust the charter, etc. And then, you

00:05:27.800 --> 00:05:30.279
know, as an author of the book series. So that's

00:05:30.279 --> 00:05:31.920
that's kind of what I what I do for a living.

00:05:32.269 --> 00:05:34.829
All right, so let's start from the very beginning.

00:05:35.230 --> 00:05:37.410
Let's look at the origin story and the intent

00:05:37.410 --> 00:05:41.889
around the SAF, the Security Adoption Framework.

00:05:42.930 --> 00:05:46.870
What problem were you trying to solve when this

00:05:46.870 --> 00:05:51.449
work started? So from the beginning, the first

00:05:51.449 --> 00:05:54.649
question that we really set out to answer was

00:05:54.649 --> 00:05:57.050
from the MCRA. That was really the first piece

00:05:57.050 --> 00:06:01.519
of it. And it was the first basic question of

00:06:01.519 --> 00:06:02.860
what the heck do you do in security Microsoft?

00:06:03.480 --> 00:06:05.420
And that was the question we kept getting from

00:06:05.420 --> 00:06:08.500
customers and that people needed to actually

00:06:08.500 --> 00:06:11.620
have the answer to. And so that's really sort

00:06:11.620 --> 00:06:13.420
of where the MCRA started. And, you know, the

00:06:13.420 --> 00:06:16.000
intent was to not make it just here's a list

00:06:16.000 --> 00:06:17.959
of things, but actually a meaningful architecture

00:06:17.959 --> 00:06:20.860
that related to what people knew about infrastructure

00:06:20.860 --> 00:06:23.500
security and network security and identity security

00:06:23.500 --> 00:06:25.060
and all those kind of different pieces, parts.

00:06:25.240 --> 00:06:27.279
And so the MCRA was sort of that first kind of

00:06:27.279 --> 00:06:30.339
core that we built on. And then over time, you

00:06:30.339 --> 00:06:32.560
know, okay, what strategy does this support?

00:06:32.759 --> 00:06:34.980
And, you know, do you actually know anything

00:06:34.980 --> 00:06:37.459
about security? Microsoft kind of came up a little

00:06:37.459 --> 00:06:40.899
bit. And so, you know, that combination of factors

00:06:40.899 --> 00:06:44.100
led to, because this was in the early days before,

00:06:44.220 --> 00:06:46.279
you know, when we hadn't had products on the

00:06:46.279 --> 00:06:48.339
market for a long time. And that combination

00:06:48.339 --> 00:06:50.600
of things led to the CISO workshop. And we kind

00:06:50.600 --> 00:06:53.310
of... at first viewed those two different things.

00:06:53.629 --> 00:06:55.769
But like, you know, so, you know, what strategy,

00:06:55.889 --> 00:06:57.689
what outcome, what does the CISO need to think

00:06:57.689 --> 00:06:59.149
about for security, et cetera. A lot of those

00:06:59.149 --> 00:07:01.750
kind of related questions all kind of, you know,

00:07:01.750 --> 00:07:03.910
formed together to create the CISO workshop,

00:07:04.050 --> 00:07:05.610
which has gone through a few major revisions

00:07:05.610 --> 00:07:08.769
since its origin. And those two kind of components

00:07:08.769 --> 00:07:11.759
kind of lived on their own for a bit. And then

00:07:11.759 --> 00:07:14.339
over time, as people needed to go deeper into

00:07:14.339 --> 00:07:16.639
the SOC and start working on things like the

00:07:16.639 --> 00:07:19.500
CDOC tour to Cyber Defense Operations Center

00:07:19.500 --> 00:07:22.500
tour to take Microsoft's lessons learned from

00:07:22.500 --> 00:07:24.939
what we were doing, we needed a way to do that.

00:07:25.120 --> 00:07:26.920
And so we built some decks and some workshops

00:07:26.920 --> 00:07:29.000
around that. But then all of a sudden we had

00:07:29.000 --> 00:07:30.600
like three, four, five different things. Then

00:07:30.600 --> 00:07:32.480
people asked about SDL as things were coming

00:07:32.480 --> 00:07:34.620
along, a security development lifecycle that

00:07:34.620 --> 00:07:37.069
you had a big part of. And so, you know, over

00:07:37.069 --> 00:07:38.649
time, we just realized that, hey, we need to

00:07:38.649 --> 00:07:40.230
we need to bring this together in a framework.

00:07:40.329 --> 00:07:42.170
And we kind of took a cue from the cloud adoption

00:07:42.170 --> 00:07:45.089
framework or CAF and the well -architected framework

00:07:45.089 --> 00:07:47.509
or WAF and said, you know, we really do need

00:07:47.509 --> 00:07:49.910
a security adoption framework. And so for a while,

00:07:49.949 --> 00:07:51.750
we kind of, you know, just hosted some of this

00:07:51.750 --> 00:07:54.209
within the cloud adoption framework. But we realized

00:07:54.209 --> 00:07:56.529
that, you know, it wasn't just the security of

00:07:56.529 --> 00:07:58.730
the cloud. It was actually security as its own

00:07:58.730 --> 00:08:01.509
discipline, which was honestly sometimes a bit

00:08:01.509 --> 00:08:05.000
more complex than the cloud is. And so that sort

00:08:05.000 --> 00:08:06.879
of led to that, and it became a series of workshops,

00:08:06.980 --> 00:08:09.560
and we kind of created an overall unifying framework

00:08:09.560 --> 00:08:11.519
and brand and whatnot. We were delivering those

00:08:11.519 --> 00:08:14.819
for years. And then we told people about it a

00:08:14.819 --> 00:08:16.360
little bit, but it was just kind of a basic landing

00:08:16.360 --> 00:08:20.939
page. But then this recent release, we actually

00:08:20.939 --> 00:08:24.980
took the time. It took me several months to convert

00:08:24.980 --> 00:08:28.189
those workshops into. documentation on Learn.

00:08:28.329 --> 00:08:30.870
Like, hey, here's the reference strategy. Here's

00:08:30.870 --> 00:08:32.509
the reference architectures. Here's how it all

00:08:32.509 --> 00:08:34.269
fits together for each of the disciplines to

00:08:34.269 --> 00:08:38.009
make it fully complete and in that sort of written

00:08:38.009 --> 00:08:41.649
form. And so that's sort of what led us to where

00:08:41.649 --> 00:08:45.169
we are today. And we finally just released it

00:08:45.169 --> 00:08:48.090
a little bit before we started recording this

00:08:48.090 --> 00:08:54.870
podcast. So where does this interact? or cross

00:08:54.870 --> 00:08:58.809
paths with zero trust and zero trust adoption.

00:09:00.070 --> 00:09:03.789
I've really struggled with that. Like, I'll be

00:09:03.789 --> 00:09:06.769
frank, I've not read the SAF stuff all the way

00:09:06.769 --> 00:09:09.370
through, but I know that you guys hint at zero

00:09:09.370 --> 00:09:11.470
trust all the time. So where do the two intersect?

00:09:12.409 --> 00:09:14.970
So that's a really good question. And ultimately

00:09:14.970 --> 00:09:19.139
what... What we found is that zero trust, everybody

00:09:19.139 --> 00:09:21.559
wants to, well, at least all the marketing and

00:09:21.559 --> 00:09:23.700
sales people in our industry, want to package

00:09:23.700 --> 00:09:26.019
it up and then sell it as a product, as a license,

00:09:26.179 --> 00:09:28.259
as of this, as of that. But at the end of the

00:09:28.259 --> 00:09:30.830
day, zero trust is a... fundamentally different

00:09:30.830 --> 00:09:35.049
way of looking at security. And it is a transformation

00:09:35.049 --> 00:09:37.429
in the real meaning of the word in that you're

00:09:37.429 --> 00:09:39.309
taking something that exists the way we've been

00:09:39.309 --> 00:09:41.929
doing cybersecurity, you're changing a few foundational

00:09:41.929 --> 00:09:45.009
assumptions of it. And the two big assumptions

00:09:45.009 --> 00:09:47.789
that change, which are the obvious one of, hey,

00:09:47.909 --> 00:09:51.429
everything on the internal network is safe because

00:09:51.429 --> 00:09:53.669
there's this network security perimeter, this

00:09:53.669 --> 00:09:55.889
boundary that protects all the stuff in it. So

00:09:55.889 --> 00:09:57.389
I don't have to worry about data classification

00:09:57.389 --> 00:09:59.929
or any of this other stuff. That's hard, right?

00:10:00.549 --> 00:10:03.009
And we know that's a bad assumption. And so the

00:10:03.009 --> 00:10:04.750
first obvious one that everybody knows about

00:10:04.750 --> 00:10:07.769
that changes with Zero Trust is, hey, you have

00:10:07.769 --> 00:10:09.649
to protect the assets wherever they are, right?

00:10:09.710 --> 00:10:12.409
It doesn't matter if it's sitting out in a cloud

00:10:12.409 --> 00:10:15.110
service or if it's on the internal network and

00:10:15.110 --> 00:10:16.909
the attackers can use phishing and all these

00:10:16.909 --> 00:10:18.330
other ways and credential theft to get through.

00:10:18.970 --> 00:10:20.570
Ultimately, you have to protect stuff where it

00:10:20.570 --> 00:10:22.230
is. That's the mission. And so it's sort of like

00:10:22.230 --> 00:10:25.289
bringing some clarity to that and getting rid

00:10:25.289 --> 00:10:27.240
of that old shortcut. And the other one that

00:10:27.240 --> 00:10:28.740
we found that was sort of a broken assumption

00:10:28.740 --> 00:10:32.419
that Zero Trust addresses is security is a security

00:10:32.419 --> 00:10:35.960
team's job. And so that pervades a lot of organizations.

00:10:36.179 --> 00:10:38.759
And hey, IT and business people are like, I don't

00:10:38.759 --> 00:10:40.059
have to worry about this stuff. I don't have

00:10:40.059 --> 00:10:41.559
to worry about security. I'm just going to do

00:10:41.559 --> 00:10:43.399
things the way I do. I'm going to focus on productivity.

00:10:43.899 --> 00:10:45.519
And if there's an incident, it's security's fault.

00:10:47.500 --> 00:10:50.919
set a financial target that leads to no maintenance

00:10:50.919 --> 00:10:52.940
windows and you can't patch it in a vulnerable

00:10:52.940 --> 00:10:55.320
system, as a business decision, you've just created

00:10:55.320 --> 00:10:58.740
organizational risk through security. And so

00:10:58.740 --> 00:11:01.519
we have to also reverse that assumption and say

00:11:01.519 --> 00:11:04.419
security is part of everyone's job. It's not

00:11:04.419 --> 00:11:06.480
everybody's full -time job outside of security,

00:11:06.720 --> 00:11:08.879
but it is part of everyone's job to do their

00:11:08.879 --> 00:11:10.679
part, just like financial, legal, et cetera.

00:11:10.759 --> 00:11:12.960
As employees of any given company, we're not

00:11:12.960 --> 00:11:15.440
allowed to do illegal or financially irresponsible

00:11:15.440 --> 00:11:19.259
things. We should also not be able to do security

00:11:19.259 --> 00:11:23.539
or irresponsible things. And so zero trust, all

00:11:23.539 --> 00:11:26.080
it is is taking a fresh look at security through

00:11:26.080 --> 00:11:27.700
that lens, and you're going to do a lot of the

00:11:27.700 --> 00:11:29.019
same stuff you had before. You're going to do

00:11:29.019 --> 00:11:30.419
some new stuff, and you're going to stop doing

00:11:30.419 --> 00:11:33.580
some old stuff. And that's all it is, is it's

00:11:33.580 --> 00:11:35.879
that approach. And so this, you know, Microsoft,

00:11:36.000 --> 00:11:38.419
we have our three or four principles, you know,

00:11:38.460 --> 00:11:42.919
the assume compromise, explicitly verify, and

00:11:42.919 --> 00:11:49.429
least privilege. Yep. And we're also looking

00:11:49.429 --> 00:11:51.309
at adding business enablement. We're not sure

00:11:51.309 --> 00:11:52.710
because it's not really a security principle,

00:11:52.789 --> 00:11:54.970
but if you don't do business enablement, you're

00:11:54.970 --> 00:11:58.490
not going to get very far. So we're kind of discussing

00:11:58.490 --> 00:12:00.490
that one as well as a formal fourth principle.

00:12:00.529 --> 00:12:02.820
We're not quite sure about that. But all it is

00:12:02.820 --> 00:12:05.500
is just looking at that fresh lens. And whether

00:12:05.500 --> 00:12:07.259
you use the Microsoft principles, whether you

00:12:07.259 --> 00:12:08.519
use the Zero Trust Commandments from the Open

00:12:08.519 --> 00:12:10.860
Group, whether you use some of the stuff that

00:12:10.860 --> 00:12:13.159
CISA and CSA and whatnot, ultimately they're

00:12:13.159 --> 00:12:15.000
all philosophically aligned. But you've just

00:12:15.000 --> 00:12:17.220
got to be looking at security through that clear

00:12:17.220 --> 00:12:19.919
lens. And that's one of the things that is infused

00:12:19.919 --> 00:12:23.740
throughout this framework. We are doing it in

00:12:23.740 --> 00:12:26.500
that way. If you're excited about zero trust,

00:12:26.580 --> 00:12:28.259
it follows zero trust. If you hate the term because

00:12:28.259 --> 00:12:30.120
you've had too much marketing and sales shoved

00:12:30.120 --> 00:12:32.299
down your throat, then it's just doing security

00:12:32.299 --> 00:12:34.779
right. I don't care as much about the name as

00:12:34.779 --> 00:12:37.820
I do about doing security right. When I was in

00:12:37.820 --> 00:12:40.720
the field, I would actually hear from some customers

00:12:40.720 --> 00:12:43.399
who thought that the notion of zero trust was

00:12:43.399 --> 00:12:45.539
marketecture, like it wasn't actually a real

00:12:45.539 --> 00:12:48.139
thing. If someone were to say that to you, what

00:12:48.139 --> 00:12:51.159
would you say to them? In the early days, they

00:12:51.159 --> 00:12:54.000
were probably right. Um, but a lot of work has

00:12:54.000 --> 00:12:56.220
been done, you know, and I know the way I approached

00:12:56.220 --> 00:12:58.659
it is there's so many broken things about security.

00:12:58.980 --> 00:13:01.480
Um, and there were so many truths that were ignored.

00:13:01.539 --> 00:13:04.100
Like I remember, uh, you had mentioned one times

00:13:04.100 --> 00:13:06.139
in the early days of the STL, you know, Hey,

00:13:06.220 --> 00:13:09.320
um, never trust input. All input is evil or something

00:13:09.320 --> 00:13:13.159
like that. Right. That's zero trust, right? It's

00:13:13.159 --> 00:13:14.820
like, you're not trusting the input. You're explicitly

00:13:14.820 --> 00:13:17.419
verifying it. And so we've been doing some version

00:13:17.419 --> 00:13:18.820
of it. We just haven't been doing it consistently

00:13:18.820 --> 00:13:21.659
well, and we haven't had a name for it. And so

00:13:21.659 --> 00:13:23.419
the way I approached it is like, let's embrace

00:13:23.419 --> 00:13:25.860
this name because it did start out as marketing

00:13:25.860 --> 00:13:27.759
and architecture from one of the analyst firms.

00:13:28.320 --> 00:13:31.220
But it's evolved well beyond that into this is

00:13:31.220 --> 00:13:33.639
the right way to do security. And so, you know,

00:13:33.759 --> 00:13:37.440
you surf the waves that come in, you know, and

00:13:37.440 --> 00:13:39.279
it's about let's make this thing mean something

00:13:39.279 --> 00:13:41.360
and mean it right. And that's where all the standards

00:13:41.360 --> 00:13:44.279
and guidance have really come in and kind of

00:13:44.279 --> 00:13:45.980
brought us to this next generation of security.

00:13:47.419 --> 00:13:50.720
So Word on the street is that the length of this

00:13:50.720 --> 00:13:55.320
documentation is like a small book. So how big

00:13:55.320 --> 00:13:59.299
is this thing? So when we converted it to Word

00:13:59.299 --> 00:14:02.120
to make it easier for people to do some edits

00:14:02.120 --> 00:14:04.379
and track changes and whatnot during the review

00:14:04.379 --> 00:14:06.759
and release process, it ended up being about

00:14:06.759 --> 00:14:10.940
215 pages, give or take. And that includes some

00:14:10.940 --> 00:14:12.659
of the existing privilege access guidance, which

00:14:12.659 --> 00:14:15.100
we can convert over into scenarios and some other

00:14:15.100 --> 00:14:17.840
things as well and technical solutions. But it

00:14:17.840 --> 00:14:21.519
was basically about 185 net new pages. So I kind

00:14:21.519 --> 00:14:23.419
of looked back, and I was like, oh, wow, I wrote

00:14:23.419 --> 00:14:26.980
a book over the winter. If it is basically a

00:14:26.980 --> 00:14:29.679
small book, well, average -sized book, is this

00:14:29.679 --> 00:14:32.039
something you can read from the beginning to

00:14:32.039 --> 00:14:33.480
the end? Or is this something you sort of jump

00:14:33.480 --> 00:14:36.620
around, more like an encyclopedia? It's a little

00:14:36.620 --> 00:14:40.799
of both. So the challenge that we see that our

00:14:40.799 --> 00:14:43.299
customers face is, one, you need to be complete.

00:14:43.519 --> 00:14:45.360
So ideally, you want to be able to read all of

00:14:45.360 --> 00:14:50.809
this at some point. But two, what you do based

00:14:50.809 --> 00:14:53.610
on that single kind of unified, coherent framework

00:14:53.610 --> 00:14:56.649
is different depending on your job. As a SOC

00:14:56.649 --> 00:14:58.850
analyst and I'm responding to incidents, that's

00:14:58.850 --> 00:15:00.830
very different than a red teamer that's attacking.

00:15:00.990 --> 00:15:03.750
That's very different than a GRC person that

00:15:03.750 --> 00:15:05.409
is working through and assessing the financial

00:15:05.409 --> 00:15:07.570
risk to an organization and whether or not we're

00:15:07.570 --> 00:15:10.200
meeting our compliance obligations, etc. And

00:15:10.200 --> 00:15:12.440
it's very different than an architect or an engineer

00:15:12.440 --> 00:15:14.519
that's designing a control or prioritizing which

00:15:14.519 --> 00:15:17.259
ones to do, or a business leader that's trying

00:15:17.259 --> 00:15:19.340
to figure out what risk they can accept or not.

00:15:19.639 --> 00:15:21.779
And so they all need sort of this foundational

00:15:21.779 --> 00:15:24.299
kind of core understanding, but the way that

00:15:24.299 --> 00:15:27.879
people use it is very, very, very different.

00:15:28.100 --> 00:15:32.919
And so the way that we broke it out is for the

00:15:32.919 --> 00:15:34.940
core framework, we broke it into like a business

00:15:34.940 --> 00:15:37.659
column on the left, a security column in the

00:15:37.659 --> 00:15:40.750
middle. and a technology column on the right.

00:15:41.110 --> 00:15:43.210
Because at the end of the day, you know, the

00:15:43.210 --> 00:15:45.830
first thing is, is that does the business even

00:15:45.830 --> 00:15:48.409
care? Because security, if there were no attackers

00:15:48.409 --> 00:15:50.429
and the business didn't care about, you know,

00:15:50.429 --> 00:15:52.570
things going down, then we wouldn't have a security

00:15:52.570 --> 00:15:56.309
department because why bother? And so right now,

00:15:56.330 --> 00:15:58.669
business kind of frames security and the security

00:15:58.669 --> 00:16:00.990
leaders often have this implicit promise they

00:16:00.990 --> 00:16:03.690
have to keep, which is wrong, which is if there

00:16:03.690 --> 00:16:05.529
are breaches, it's the security team's fault.

00:16:05.590 --> 00:16:06.610
We're going to fire and replace them with someone

00:16:06.610 --> 00:16:08.769
who can stop the breaches. But that's a fantasy

00:16:08.769 --> 00:16:10.809
that doesn't exist. And so what do you replace

00:16:10.809 --> 00:16:12.950
that with? And that's where the business scenarios

00:16:12.950 --> 00:16:15.029
come in. And so that's really what we're kind

00:16:15.029 --> 00:16:17.029
of focused on there. And that helps guide the

00:16:17.029 --> 00:16:20.360
business leaders. Do I expect the Fortune 500

00:16:20.360 --> 00:16:23.919
CEOs to read that? Not necessarily. But can the

00:16:23.919 --> 00:16:27.279
CISOs of any organization or business leaders

00:16:27.279 --> 00:16:29.700
of smaller organizations read that and then kind

00:16:29.700 --> 00:16:31.379
of translate it and bring it out there? And can

00:16:31.379 --> 00:16:33.120
the CISO then use that as a way to say, these

00:16:33.120 --> 00:16:35.500
are the promises that we're working on. I want

00:16:35.500 --> 00:16:37.460
to be able to adopt AI effectively and safely,

00:16:37.700 --> 00:16:43.460
et cetera, et cetera. That's kind of the way

00:16:43.460 --> 00:16:46.779
that we, that's a core kind of use case, right?

00:16:47.000 --> 00:16:48.539
And then the security team would look at the

00:16:48.539 --> 00:16:50.279
security disciplines in the middle and the technology

00:16:50.279 --> 00:16:52.799
teams would look at the technology on the right.

00:16:53.100 --> 00:16:55.659
You know, that's kind of the core piece of it.

00:16:56.250 --> 00:16:57.970
And we know that's not enough, right? Because

00:16:57.970 --> 00:16:59.230
it's like, okay, this is a reference. This is

00:16:59.230 --> 00:17:02.110
my job. Great. What do I do about it? And so

00:17:02.110 --> 00:17:04.109
that's where we're taking those business scenarios.

00:17:04.130 --> 00:17:05.750
And this is the work that isn't done yet because

00:17:05.750 --> 00:17:08.250
we're continuing to do it. Privilege access is

00:17:08.250 --> 00:17:10.029
the first one we've done. But I'm going to take

00:17:10.029 --> 00:17:12.089
that business scenario and say, okay, what technical

00:17:12.089 --> 00:17:15.109
solutions are required to be able to do AI safely

00:17:15.109 --> 00:17:18.130
and security, to be able to continuously improve

00:17:18.130 --> 00:17:23.029
my security posture and compliance, to be able

00:17:23.029 --> 00:17:25.329
to allow people to work safely from anywhere?

00:17:26.210 --> 00:17:28.769
to be able to handle a big incident that comes

00:17:28.769 --> 00:17:30.710
through? What are the technical solutions that

00:17:30.710 --> 00:17:32.930
enable each of those five, six business scenarios?

00:17:33.390 --> 00:17:35.230
And so that's what we're working on right now

00:17:35.230 --> 00:17:37.549
is defining that and making it actionable so

00:17:37.549 --> 00:17:39.710
they can walk that journey through there. And

00:17:39.710 --> 00:17:41.289
then, hey, as you do one of them, by the way,

00:17:41.329 --> 00:17:43.549
we already did this technical solution, so it's

00:17:43.549 --> 00:17:45.049
going to make the next scenario a lot easier

00:17:45.049 --> 00:17:46.970
because we've got three out of four of them done.

00:17:47.690 --> 00:17:51.210
So we're in the process of doing that. And then,

00:17:51.230 --> 00:17:53.750
of course, on the right on the technical piece,

00:17:56.019 --> 00:17:58.279
We call them zero -trust pillars, technical pillars,

00:17:58.339 --> 00:18:01.299
same thing. It basically says, hey, if I own,

00:18:01.440 --> 00:18:04.900
say I'm like an engineer, right? I own all the

00:18:04.900 --> 00:18:07.559
identity assets, right? I'm an identity engineer

00:18:07.559 --> 00:18:12.200
or architect, and I do that for our operations

00:18:12.200 --> 00:18:15.210
team. I do that for a living. That tells me the

00:18:15.210 --> 00:18:17.609
controls I need on the right. And so we're trying

00:18:17.609 --> 00:18:20.789
to get that narrative story through there. But,

00:18:20.849 --> 00:18:22.450
you know, the first thing is you have to have

00:18:22.450 --> 00:18:24.630
foundation before you start designing, you know,

00:18:24.650 --> 00:18:26.730
what mirror is going to go in the bathroom, if

00:18:26.730 --> 00:18:30.269
that makes sense. Okay. I've never heard mirror

00:18:30.269 --> 00:18:32.869
in the bathroom, but okay. Actually, isn't that

00:18:32.869 --> 00:18:35.690
a song? It's a song from the old reggae song.

00:18:35.690 --> 00:18:37.849
Perhaps I should have said sync. Fair enough.

00:18:39.410 --> 00:18:42.470
Anyway. Okay. I want to turn a bit cynical at

00:18:42.470 --> 00:18:46.619
this point. So look, there's plenty of frameworks

00:18:46.619 --> 00:18:51.480
out there from folks like NIST and CISR and so

00:18:51.480 --> 00:18:57.460
on. So what gap does this model fill? And probably

00:18:57.460 --> 00:19:00.000
more importantly, I mean, does this model complement

00:19:00.000 --> 00:19:02.640
or compete or replace these existing frameworks?

00:19:03.140 --> 00:19:06.660
Sort of clue me in there. So this absolutely

00:19:06.660 --> 00:19:09.619
builds on, connects, and maps to all of those

00:19:09.619 --> 00:19:11.579
kind of things. The NIST, the CISA, the MITRE,

00:19:11.619 --> 00:19:14.339
all those great standards that are put out by

00:19:14.339 --> 00:19:16.759
those organizations. So first and foremost, we

00:19:16.759 --> 00:19:18.799
are not trying to replace or displace those.

00:19:19.319 --> 00:19:20.960
The challenge that a lot of our customers have

00:19:20.960 --> 00:19:24.819
is like, how do I do this in a complete way without

00:19:24.819 --> 00:19:26.819
being comprehensive and super detailed? They're

00:19:26.819 --> 00:19:28.660
not trying to replicate any of that. But how

00:19:28.660 --> 00:19:32.420
do I do this in a complete way that I can then

00:19:32.420 --> 00:19:36.410
turn into action? and implementation with Microsoft

00:19:36.410 --> 00:19:39.309
technology. And so that's sort of the magic of

00:19:39.309 --> 00:19:41.950
this is it kind of gives you that strategy and

00:19:41.950 --> 00:19:43.569
architecture layer. Here's a reference strategy.

00:19:43.970 --> 00:19:45.990
Here's a reference architecture that supports

00:19:45.990 --> 00:19:48.750
and enables it in multiple different ones. And

00:19:48.750 --> 00:19:50.470
then here's all the technologies that then make

00:19:50.470 --> 00:19:53.230
that real. And then in the future, as we go forward,

00:19:53.329 --> 00:19:56.109
here's the solutions that then guide you through

00:19:56.109 --> 00:19:58.089
prioritizing which controls you need to have

00:19:58.089 --> 00:20:00.109
in case you don't have time to implement all

00:20:00.109 --> 00:20:04.099
of them. And so that's sort of... The gap that

00:20:04.099 --> 00:20:06.440
we're filling there is we want to definitely

00:20:06.440 --> 00:20:08.220
play friendly with all those other ones that

00:20:08.220 --> 00:20:09.559
are out there because people have to meet them,

00:20:09.619 --> 00:20:10.900
they want to meet them, they've adopted them

00:20:10.900 --> 00:20:13.480
voluntarily, etc. And this is really just the

00:20:13.480 --> 00:20:15.599
Microsoft perspective on it that fills the gaps

00:20:15.599 --> 00:20:19.259
that we see and connects our technology to it.

00:20:19.420 --> 00:20:22.119
Because if you take away the technology links,

00:20:22.200 --> 00:20:23.900
it is a vendor -neutral framework that kind of

00:20:23.900 --> 00:20:26.039
brings all that stuff together. But we wanted

00:20:26.039 --> 00:20:28.500
to also take it all the way into here's how to

00:20:28.500 --> 00:20:31.589
implement and drive the controls. So as you mentioned

00:20:31.589 --> 00:20:35.829
at the beginning, it's a large body of work,

00:20:35.849 --> 00:20:39.289
over 200 pages. So can you walk us through the

00:20:39.289 --> 00:20:43.190
three core elements that make up the SAF? Absolutely.

00:20:44.039 --> 00:20:46.200
So as I mentioned, you know, I have this visual

00:20:46.200 --> 00:20:47.859
in my head, you know, on the left. So you'll

00:20:47.859 --> 00:20:49.880
have to kind of imagine that if you're driving,

00:20:49.980 --> 00:20:53.039
please drive safe. But on the left is those outcomes,

00:20:53.200 --> 00:20:55.039
right? This is what we're driving. That's the

00:20:55.039 --> 00:20:57.579
I want to be able to do something. I want to

00:20:57.579 --> 00:21:00.339
be able to secure the AI and do it safely and

00:21:00.339 --> 00:21:03.960
adopt it quickly and, you know, deal with major

00:21:03.960 --> 00:21:06.759
incidents when they happen, etc. And so that's

00:21:06.759 --> 00:21:09.460
really the first focus. And each of those scenarios

00:21:09.460 --> 00:21:11.980
has at least a landing page and often more guidance.

00:21:12.480 --> 00:21:14.500
This is the first release, so we will be adding

00:21:14.500 --> 00:21:17.660
additional guidance as we go. And so that's that

00:21:17.660 --> 00:21:19.960
first piece, which is how do we translate what

00:21:19.960 --> 00:21:22.619
security does into business terminology? And

00:21:22.619 --> 00:21:24.000
then that middle part, security disciplines,

00:21:24.079 --> 00:21:26.400
is, okay, how do we take those business outcomes,

00:21:26.519 --> 00:21:28.779
those promises that we made, and turn that into

00:21:28.779 --> 00:21:31.660
technical reality? And the example I always like

00:21:31.660 --> 00:21:33.539
to use on this one is the difference between

00:21:34.319 --> 00:21:38.680
having data security as an outcome versus security

00:21:38.680 --> 00:21:41.200
controls that apply to data. Because if I'm trying

00:21:41.200 --> 00:21:43.519
to keep data secure wherever it is, I need a

00:21:43.519 --> 00:21:45.720
bunch of controls. I need it built into the infrastructure,

00:21:45.920 --> 00:21:49.759
to the endpoints, the identity. If I don't do

00:21:49.759 --> 00:21:51.579
that and I just have controls in the data itself,

00:21:51.640 --> 00:21:53.420
I can't keep that secure if it's on an insecure

00:21:53.420 --> 00:21:56.400
device, if the identity that's accessing it is

00:21:56.400 --> 00:21:59.740
not secured and locked down, if it's not encrypted

00:21:59.740 --> 00:22:03.869
at rest, etc. We have both a data security discipline,

00:22:04.009 --> 00:22:07.009
but also a data pillar, along with endpoint and

00:22:07.009 --> 00:22:09.930
infrastructure and network and so on. And so

00:22:09.930 --> 00:22:11.490
the security disciplines are really about how

00:22:11.490 --> 00:22:13.529
do you translate those business promises, those

00:22:13.529 --> 00:22:14.970
things that security should be working towards,

00:22:15.130 --> 00:22:19.470
into a coherent approach that then uses a bunch

00:22:19.470 --> 00:22:21.309
of different controls. And then the technology

00:22:21.309 --> 00:22:23.170
pillars are the controls. And we broke those

00:22:23.170 --> 00:22:25.069
out by the technologies, very similar to the

00:22:25.069 --> 00:22:29.890
CISA Zero Trust pillars. which is data endpoint,

00:22:30.049 --> 00:22:31.890
et cetera, and making sure that you have that.

00:22:31.970 --> 00:22:34.750
And again, a lot of this, the thing that was

00:22:34.750 --> 00:22:36.329
really interesting as we went through this is

00:22:36.329 --> 00:22:39.680
just... the many to many mapping. So like, it's

00:22:39.680 --> 00:22:42.079
amazing how many technical controls support multiple

00:22:42.079 --> 00:22:43.859
different initiatives, support multiple different

00:22:43.859 --> 00:22:46.400
outcomes, but you can't just munch them all together.

00:22:46.460 --> 00:22:47.819
You're going to get confused and it doesn't make

00:22:47.819 --> 00:22:49.559
sense and stuff gets lost. You have to separate.

00:22:49.700 --> 00:22:51.599
This is what the tech teams do versus what the

00:22:51.599 --> 00:22:54.660
security people kind of steer with the strategy

00:22:54.660 --> 00:22:56.839
and architecture versus the outcomes that everyone

00:22:56.839 --> 00:23:00.019
is trying to get to. So you touched on sort of

00:23:00.019 --> 00:23:03.140
business scenarios there. So how should a CISO

00:23:03.140 --> 00:23:05.799
or a business leader actually use this model

00:23:05.799 --> 00:23:10.640
in real life? I think the reason why I ask that

00:23:10.640 --> 00:23:15.359
is I've often seen a real impedance mismatch

00:23:15.359 --> 00:23:19.940
between security and business value and prioritizing

00:23:19.940 --> 00:23:24.819
security. thinking about business value and how

00:23:24.819 --> 00:23:27.400
it impacts the business. So can you just talk

00:23:27.400 --> 00:23:31.700
to that just briefly? Yeah, it's a really challenging

00:23:31.700 --> 00:23:34.700
space because business leaders at the end of

00:23:34.700 --> 00:23:37.480
the day, they deal with exchange rates. They

00:23:37.480 --> 00:23:40.099
deal with geopolitical turmoil. They deal with,

00:23:40.119 --> 00:23:42.819
is the Strait of Hormuz going to open? And they

00:23:42.819 --> 00:23:44.480
also deal with cybersecurity attacks. They deal

00:23:44.480 --> 00:23:46.660
with a whole bunch of different risks and opportunities

00:23:46.660 --> 00:23:51.299
because AI presents both. And so they don't see

00:23:51.299 --> 00:23:54.099
the world like security people do. And so a big

00:23:54.099 --> 00:23:56.660
part of this is to help security people build

00:23:56.660 --> 00:23:59.160
that bridge to use those business scenarios.

00:23:59.319 --> 00:24:01.519
We even included a whole article on communication

00:24:01.519 --> 00:24:04.680
tips and how security people should be communicating

00:24:04.680 --> 00:24:07.759
with business leaders to help them frame those

00:24:07.759 --> 00:24:13.309
business scenarios and other topics well. We

00:24:13.309 --> 00:24:15.470
also see this guidance as helping kind of improve

00:24:15.470 --> 00:24:17.849
that communication, help develop that common

00:24:17.849 --> 00:24:19.910
language. Because at the end of the day, we're

00:24:19.910 --> 00:24:22.089
just humans with two different jobs. And we have

00:24:22.089 --> 00:24:23.750
to understand and respect each other's jobs.

00:24:23.890 --> 00:24:26.029
But we also have to recognize they're different.

00:24:26.170 --> 00:24:28.930
And we have to do some translation. And so that's

00:24:28.930 --> 00:24:32.529
a big thing that falls, I'd say, 80 % on security

00:24:32.529 --> 00:24:34.970
leaders. But there's also like a 20 % on the

00:24:34.970 --> 00:24:36.990
business leaders to understand the basics of

00:24:36.990 --> 00:24:39.069
security. And we kind of address some of that

00:24:39.069 --> 00:24:42.859
through the open group standards as well. what

00:24:42.859 --> 00:24:44.819
are the basics of security for business leaders?

00:24:45.460 --> 00:24:47.539
So that's kind of the way we approach that one.

00:24:48.039 --> 00:24:50.380
All right, let's get down to some real practicalities.

00:24:50.380 --> 00:24:53.740
I'm a brutally practical person. So if someone

00:24:53.740 --> 00:24:55.160
were to start with us tomorrow, they've got the

00:24:55.160 --> 00:24:59.019
SAF in hand, they may or may not be a manager

00:24:59.019 --> 00:25:01.140
slash middle manager slash CISO or something,

00:25:01.339 --> 00:25:03.039
or even a developer for that matter, an engineer.

00:25:03.500 --> 00:25:05.559
What are the first two or three actions that

00:25:05.559 --> 00:25:07.279
people should take? Because there's a lot of

00:25:07.279 --> 00:25:11.920
documentation in there. First off, It really

00:25:11.920 --> 00:25:14.240
depends on the role you're in, as you kind of

00:25:14.240 --> 00:25:18.900
hinted at. And so it's about understanding. And

00:25:18.900 --> 00:25:21.420
so we put guidance together for each of the kind

00:25:21.420 --> 00:25:23.880
of main role groupings, the business folks versus

00:25:23.880 --> 00:25:27.660
the security architects, security operations

00:25:27.660 --> 00:25:31.200
center, SOC or SEC ops. You know, we have about,

00:25:31.259 --> 00:25:33.539
I think, six or eight groupings, if I recall

00:25:33.539 --> 00:25:35.720
correctly off the top of my head, that's in the

00:25:35.720 --> 00:25:37.740
role page that basically says, here's your reading

00:25:37.740 --> 00:25:40.000
guide. We do want to develop those in the future

00:25:40.000 --> 00:25:42.960
releases to be a full landing page to kind of

00:25:42.960 --> 00:25:44.940
give you a much more rich experience that is

00:25:44.940 --> 00:25:47.180
specific to security operations and SOC, etc.

00:25:48.910 --> 00:25:51.349
But in almost all of those, the way we basically

00:25:51.349 --> 00:25:54.730
structure it is read up on the discipline you're

00:25:54.730 --> 00:25:56.630
in. So if you work in the SOC, you're a threat

00:25:56.630 --> 00:26:00.529
hunter, attack simulation, tier one, tier two,

00:26:00.609 --> 00:26:03.369
triage investigation analyst, SOC manager, et

00:26:03.369 --> 00:26:06.150
cetera, then you need to learn about the SOC

00:26:06.150 --> 00:26:07.710
and the mission and the purpose and the other

00:26:07.710 --> 00:26:09.250
people in it and all that stuff. And that's what

00:26:09.250 --> 00:26:12.089
the security discipline is about. So it's a security

00:26:12.089 --> 00:26:14.230
role, learn your security discipline. Technology

00:26:14.230 --> 00:26:16.670
role, learn your technology controls and probably

00:26:16.670 --> 00:26:20.380
the disciplines that they support. That's kind

00:26:20.380 --> 00:26:22.539
of the first main thing is kind of get that context.

00:26:22.900 --> 00:26:25.160
And then depending on whatever project is going

00:26:25.160 --> 00:26:27.900
on or whatever priority the organization has

00:26:27.900 --> 00:26:31.140
in the state that you're in, this is where the

00:26:31.140 --> 00:26:34.920
it depends kicks in a lot. So if you're in the

00:26:34.920 --> 00:26:36.920
access and identity space or your organization

00:26:36.920 --> 00:26:42.500
doesn't have great MFA consistency across the

00:26:42.500 --> 00:26:45.529
board, et cetera. then starting there with the

00:26:45.529 --> 00:26:48.049
access and identity and the phishing resistance.

00:26:48.210 --> 00:26:49.869
That tends to be a very popular one if you haven't

00:26:49.869 --> 00:26:55.450
gotten that basic done. SOC -wise, getting an

00:26:55.450 --> 00:26:58.049
XDR technology in there and getting clear outcomes,

00:26:58.309 --> 00:27:02.009
processes, goals, and metrics. So it really kind

00:27:02.009 --> 00:27:03.549
of depends on where you're at, but we do have

00:27:03.549 --> 00:27:05.789
a starting point for each of the roles in there.

00:27:06.930 --> 00:27:10.150
So I've worked in security for a long time, and

00:27:10.150 --> 00:27:16.000
I've seen... Many people underestimate all aspects

00:27:16.000 --> 00:27:19.319
of security from the risk to the cost to the

00:27:19.319 --> 00:27:23.559
time frame to the work required and everything

00:27:23.559 --> 00:27:26.700
in between. So which discipline do you think

00:27:26.700 --> 00:27:32.700
organizations underestimate the most? I would

00:27:32.700 --> 00:27:36.759
have to say posture management. Because when

00:27:36.759 --> 00:27:39.660
you... Imposter management is the left of bang

00:27:39.660 --> 00:27:42.039
or preventative version of security operations.

00:27:42.359 --> 00:27:45.819
The right of bang is SOC or SecOps. Essentially,

00:27:46.200 --> 00:27:48.960
when you look at SOC, it's dealing with the problems

00:27:48.960 --> 00:27:51.400
that happen. And then imposter management is

00:27:51.400 --> 00:27:53.700
the operational discipline focused on, let's

00:27:53.700 --> 00:27:56.579
make sure these problems don't happen. And it's

00:27:56.579 --> 00:27:58.299
sort of like the operational arm of governance

00:27:58.299 --> 00:28:02.079
or GRC sometimes. It's the progression of vulnerability

00:28:02.079 --> 00:28:05.279
management is another way to look at it. We realized

00:28:05.279 --> 00:28:07.359
when we released the Azure Security Center, now

00:28:07.359 --> 00:28:10.599
Defender for Cloud, the question was, who uses

00:28:10.599 --> 00:28:12.559
this tool? And there was a bunch of people that

00:28:12.559 --> 00:28:14.299
could use the tool, but who was the primary owner

00:28:14.299 --> 00:28:15.839
that drove change in the organization? We're

00:28:15.839 --> 00:28:18.619
like, oh, there kind of isn't one. We mostly

00:28:18.619 --> 00:28:20.180
have vulnerability management teams that just

00:28:20.180 --> 00:28:23.359
scan and send out a shameful report that you

00:28:23.359 --> 00:28:25.859
guys suck at this, and then move on and felt

00:28:25.859 --> 00:28:27.839
like their job was done. That's kind of the worst

00:28:27.839 --> 00:28:32.690
case scenario. And so what we realized is, Security

00:28:32.690 --> 00:28:35.009
just was missing an operational discipline on

00:28:35.009 --> 00:28:37.210
left of bang. And so we spent some time working

00:28:37.210 --> 00:28:39.250
with organizations, picking up the bright spots

00:28:39.250 --> 00:28:40.529
of people that had figured this out. They were

00:28:40.529 --> 00:28:42.809
active early in the cloud. And we realized that

00:28:42.809 --> 00:28:44.329
there was a discipline they were doing called

00:28:44.329 --> 00:28:47.710
posture management. And it's really about, hey,

00:28:47.829 --> 00:28:49.829
we need to help the technology and other teams

00:28:49.829 --> 00:28:53.190
understand. here's the challenges, here's the

00:28:53.190 --> 00:28:55.309
prioritization, because these people are busy

00:28:55.309 --> 00:28:56.910
keeping things running and they've got other

00:28:56.910 --> 00:28:59.730
jobs to do, other thankless jobs to do. And so

00:28:59.730 --> 00:29:01.470
how do we make sure that we're making their lives

00:29:01.470 --> 00:29:03.910
easier and making it easier for them to do security?

00:29:04.869 --> 00:29:07.349
And so that's really what posture management

00:29:07.349 --> 00:29:09.829
is. So it's looking at it not just as software

00:29:09.829 --> 00:29:12.369
vulnerabilities, but also configuration vulnerabilities.

00:29:12.970 --> 00:29:14.970
Because, hey, if someone decided to turn off

00:29:14.970 --> 00:29:19.470
encryption or turn off requiring a password or

00:29:19.470 --> 00:29:21.920
set a default password, Those are configurations.

00:29:22.119 --> 00:29:23.920
Those aren't actually a flaw in the software

00:29:23.920 --> 00:29:25.779
themselves. Yes, you can shape that behavior

00:29:25.779 --> 00:29:28.160
with the defaults in the software not allowing

00:29:28.160 --> 00:29:30.579
those configurations. But at the end of the day,

00:29:30.720 --> 00:29:32.859
there was a choice that was made during configuration.

00:29:32.940 --> 00:29:35.839
That's a vulnerability. And then how people use

00:29:35.839 --> 00:29:37.839
their credentials day to day. This is what led

00:29:37.839 --> 00:29:39.940
to Pass the Hash and all the credential theft

00:29:39.940 --> 00:29:43.200
stuff that blew up starting in 2008, 9, and 10

00:29:43.200 --> 00:29:46.660
and continuing today. If an operator decides

00:29:46.660 --> 00:29:49.740
to log in using a domain admin, global enterprise

00:29:49.740 --> 00:29:55.380
admin, whatever, to a BYOD device that isn't

00:29:55.380 --> 00:29:58.099
secured very well and already is part of a botnet,

00:29:58.299 --> 00:30:00.819
then that's an operational decision that led

00:30:00.819 --> 00:30:04.319
to it. It's a vulnerability there. And so posture

00:30:04.319 --> 00:30:06.119
management, really looking at all those types

00:30:06.119 --> 00:30:08.559
of vulnerabilities. And then what do we need

00:30:08.559 --> 00:30:10.839
to do to fix it? Are they lacking time? Are they

00:30:10.839 --> 00:30:13.579
lacking tools? Are they lacking visibility? What

00:30:13.579 --> 00:30:16.279
is it about this? And we love to see people coming

00:30:16.279 --> 00:30:18.619
from an IT ops background to graduate into master

00:30:18.619 --> 00:30:21.240
management that have a security kind of flair

00:30:21.240 --> 00:30:24.759
because that allows them to be able to speak

00:30:24.759 --> 00:30:26.819
the language, communicate, understand the challenges,

00:30:26.880 --> 00:30:28.720
and then say, how do we get security in here

00:30:28.720 --> 00:30:31.380
smoothly? And so that's the one that we see people

00:30:31.380 --> 00:30:34.160
underestimating the most because... You can be

00:30:34.160 --> 00:30:35.920
great at dealing with the incidents that happen,

00:30:36.019 --> 00:30:38.180
but if you spend all your time on that and you're

00:30:38.180 --> 00:30:39.920
not trying to block the ones that are happening

00:30:39.920 --> 00:30:42.279
all the time, then you're paying a whole lot

00:30:42.279 --> 00:30:44.200
of money for SOC analysts and tools to do stuff

00:30:44.200 --> 00:30:46.900
that you shouldn't need to do. Stuff always sneaks

00:30:46.900 --> 00:30:49.440
through. You always need a good SOC. But you

00:30:49.440 --> 00:30:51.720
also don't want to deal with avoidable incidents.

00:30:52.759 --> 00:30:55.380
So, yeah, posture management is the big one I'd

00:30:55.380 --> 00:30:58.759
say is overlooked. I'll be honest with you, I

00:30:58.759 --> 00:31:00.200
didn't even know what posture management was

00:31:00.200 --> 00:31:02.759
until five or six years ago. I'm so deep in the

00:31:02.759 --> 00:31:05.079
weeds with programming and secure software development

00:31:05.079 --> 00:31:09.019
in crypto that I didn't really consider things

00:31:09.019 --> 00:31:12.549
like that, but now I do. All right, so let's

00:31:12.549 --> 00:31:14.710
ask one final question, then we'll start to bring

00:31:14.710 --> 00:31:17.369
this episode to an end. We sort of started off

00:31:17.369 --> 00:31:19.329
at the very top talking about zero trust and

00:31:19.329 --> 00:31:22.289
me cynically saying, you know, some people have

00:31:22.289 --> 00:31:24.210
talked about zero trust being my architecture.

00:31:25.150 --> 00:31:29.329
Is there one myth about zero trust that you would

00:31:29.329 --> 00:31:33.450
really like to see killed? Yes. So it's been

00:31:33.450 --> 00:31:38.069
starting to die off a little bit. But when people

00:31:38.069 --> 00:31:41.819
think zero trust is just ZTNA, Very good marketing

00:31:41.819 --> 00:31:44.740
on some vendors' parts. The Zero Trust Network

00:31:44.740 --> 00:31:48.160
Access, now often called Security Service Edge,

00:31:48.259 --> 00:31:52.880
SSE. When people say that that's Zero Trust...

00:31:53.410 --> 00:31:55.569
that's the one that sort of really annoys me

00:31:55.569 --> 00:31:57.910
because at the end of the day, we did a lot of

00:31:57.910 --> 00:31:59.569
work to define, hey, this is the right way of

00:31:59.569 --> 00:32:02.589
doing security because we all need it. It doesn't

00:32:02.589 --> 00:32:04.210
work that way. And if you treat zero trust as

00:32:04.210 --> 00:32:06.230
just that and then say, I'm going back to my

00:32:06.230 --> 00:32:08.309
old ways of vulnerability management or this

00:32:08.309 --> 00:32:10.730
or that, as opposed to the sort of modern thoughtful

00:32:10.730 --> 00:32:13.910
approach that breaks the broken assumptions or

00:32:13.910 --> 00:32:17.650
that changes the broken assumptions, it's just

00:32:17.650 --> 00:32:20.269
not going to work. Because at the end of the

00:32:20.269 --> 00:32:22.809
day, ZTNA and SSE are really just a really good

00:32:22.809 --> 00:32:25.950
modern VPN. And it can do so much more than a

00:32:25.950 --> 00:32:28.970
classic VPN, but it's not enough. It doesn't

00:32:28.970 --> 00:32:31.150
fix the rest of it. So that's the one that I

00:32:31.150 --> 00:32:34.410
would wish we could kill, is that believing that

00:32:34.410 --> 00:32:37.650
ZTNA is zero trust. It is a part of it, but it

00:32:37.650 --> 00:32:39.690
is certainly not the whole thing. Yeah, there

00:32:39.690 --> 00:32:41.410
is definitely a lot of confusion I've seen in

00:32:41.410 --> 00:32:44.029
the industry about zero trust in general. So

00:32:44.029 --> 00:32:46.250
it's good to see something sort of clarify some

00:32:46.250 --> 00:32:50.960
of those. Some of those myths. So as you are

00:32:50.960 --> 00:32:54.759
very well aware, as we get to the end of an episode,

00:32:54.880 --> 00:32:57.400
we always like to ask our guests a couple of

00:32:57.400 --> 00:33:00.079
questions. So the first question is, so what

00:33:00.079 --> 00:33:02.420
does a typical day in the life of Mark look like?

00:33:03.819 --> 00:33:09.880
So a typical day is never a typical day. The

00:33:09.880 --> 00:33:14.240
way I work is I generally have one or two big

00:33:14.240 --> 00:33:17.220
projects I'm working on. Um, it was like my day

00:33:17.220 --> 00:33:20.500
job at Microsoft. Um, in this case, you know,

00:33:20.500 --> 00:33:22.180
this year was heavily focused on the, on the

00:33:22.180 --> 00:33:25.299
SAF documentation and then, you know, deal with

00:33:25.299 --> 00:33:28.019
kind of the, the, the, the hot things that come

00:33:28.019 --> 00:33:29.640
up, you know, that, Hey, can you look at this?

00:33:29.740 --> 00:33:31.279
Hey, can you prepare this? Hey, can you do this

00:33:31.279 --> 00:33:33.779
training or whatever it is? And so it tends to

00:33:33.779 --> 00:33:36.480
be kind of like a core base of I'm trying to

00:33:36.480 --> 00:33:39.519
focus on getting something longterm done mixed

00:33:39.519 --> 00:33:43.460
in with some short term kind of urgent, um, priorities.

00:33:44.200 --> 00:33:47.490
And then, you know, On the side, beyond my work

00:33:47.490 --> 00:33:50.650
hours is when I do the Zero Trust Playbook and

00:33:50.650 --> 00:33:53.809
whatnot, which fits in the long -term strategy

00:33:53.809 --> 00:33:57.809
piece. That's generally how I work. It shows

00:33:57.809 --> 00:33:59.589
up as a bunch of meetings and focus time and

00:33:59.589 --> 00:34:02.089
all that kind of stuff. I try to always be pushing

00:34:02.089 --> 00:34:05.190
something big at any given time, despite the

00:34:05.190 --> 00:34:10.429
interruptions. Very cool. As you also were very

00:34:10.429 --> 00:34:13.929
well aware, the very final question we ask our

00:34:13.929 --> 00:34:16.579
guest is, If you had one final thought to leave

00:34:16.579 --> 00:34:20.900
our listeners with, what would it be? Other than

00:34:20.900 --> 00:34:24.360
buy the playbook? No, just kidding. I would say

00:34:24.360 --> 00:34:27.860
read the SAF. You don't have to read the whole

00:34:27.860 --> 00:34:31.320
thing, but read the overall intro kind of landing

00:34:31.320 --> 00:34:33.800
page. Read to the part that's most applicable

00:34:33.800 --> 00:34:36.460
to you, whether it's security operations, whether

00:34:36.460 --> 00:34:38.139
it's the business scenarios, because you're in

00:34:38.139 --> 00:34:40.539
more of a sort of CISO or security director role.

00:34:41.260 --> 00:34:43.820
Or if you're more of a technologist, read through

00:34:43.820 --> 00:34:47.760
the technology pillars. But find the thing that

00:34:47.760 --> 00:34:50.519
is your part of it. If you do AppSec, it's the

00:34:50.519 --> 00:34:52.900
developer security. If you do identity and access,

00:34:53.039 --> 00:34:55.739
it's the access and identity discipline. But

00:34:55.739 --> 00:34:58.019
read through the parts that are relevant to you.

00:34:59.029 --> 00:35:01.349
And honestly, tell us what you think. Is there

00:35:01.349 --> 00:35:03.809
questions that come up? And I wish there was

00:35:03.809 --> 00:35:06.590
more on this. And if there's like, oh my gosh,

00:35:06.670 --> 00:35:08.289
I never thought about it this way. This was super

00:35:08.289 --> 00:35:10.849
helpful. Can we have more of these? Any kind

00:35:10.849 --> 00:35:14.389
of feedback that you have on that. So just kind

00:35:14.389 --> 00:35:15.829
of read through the part that's applicable to

00:35:15.829 --> 00:35:17.670
you and tell us what you think and tell us how

00:35:17.670 --> 00:35:19.829
to make it better. All right, let's bring this

00:35:19.829 --> 00:35:23.750
episode to an end. Again, thank you, Mark, for

00:35:23.750 --> 00:35:27.630
coming on the podcast. Thank you for having me.

00:35:29.469 --> 00:35:32.429
But no, it's great. I mean, I think the SAF is

00:35:32.429 --> 00:35:36.230
such an important set of documentation. I think

00:35:36.230 --> 00:35:37.989
a lot of people will get a lot out of it. Again,

00:35:38.070 --> 00:35:39.829
to your point, just take a look. Just take a

00:35:39.829 --> 00:35:41.909
look. Just jump to the parts that sort of stand

00:35:41.909 --> 00:35:44.269
out to you. And if you have any feedback, just

00:35:44.269 --> 00:35:46.769
provide it to Mark. So with that, let's bring

00:35:46.769 --> 00:35:50.139
our episode to an end. We hope you found this

00:35:50.139 --> 00:35:53.519
episode of use. Stay safe and we'll see you next

00:35:53.519 --> 00:35:55.920
time. For listening to the Azure Security Podcast,

00:35:56.380 --> 00:35:59.320
you can find show notes and other resources at

00:35:59.320 --> 00:36:03.920
our website, azsecuritypodcast .net. If you have

00:36:03.920 --> 00:36:07.099
any questions, please find us on Twitter at AzureSecPod.

00:36:07.960 --> 00:36:11.699
Background music is from ccmixter .com and licensed

00:36:11.699 --> 00:36:13.380
under the Creative Commons license.
