Thank you for Subscribing to CIO Applications Weekly Brief
A featured contribution from Leadership Perspectives, a curated forum for enterprise technology leaders, nominated by our subscribers and vetted by the CIOApplications Editorial Board.

Bankunited
Felipe Medina, Avp Of Information Security Engineering
Why Use Security Analytics For The Enterprise?


First, let’s ensure we level set, this methodology requires executive buy in and investment in IT and IS departments. This will require collaboration with your business lines as well to ensure you are addressing the money makers for your enterprise/ business. So, the first thing is learning from any issues or attacks and adding this intelligence into our platforms to alert at proper thresholds. I am a big fan of using standard deviations which allow me to baseline traffic on platforms, like a SIEM (Security Information and Event Monitoring), based on a control set of data ranging from hours to months as needed. I would not recommend years as this could take a while as well as the cycles that the device would need to take from normal processing. This gives organizations an early detection capability for network as well as device level events to ensure proper health or in early detection of a DDoS or outage.
Another perspective for proper analytics would be to ensure to understand what your providers can do for you. Let’s take O365 and Azure.
This service provided by Amazon allows threat detection across the environment both network and user anomaly based on a continuous basis. The caveat is that it will not look back, meaning that this is not a historical service you can use post incident, making it critical to be one of the fundamental security analytics services you must set up within your AWS tenant. Using the well architected framework to further analyze your environment and misconfigurations are an additional security analytics tool for customers to check their workloads against AWS security best practices before deploying them into production.
As far as proactive controls to have, all organizations should have a vulnerability management program. This is one of the most critical programs to have analytics around a whole program. A vulnerability scanner should be set up to ensure that your applications and infrastructure allow reportable key risk indicators, KRI’s, of any vulnerable operating systems and software running in your environment. The key here is to stay on top of patching but from a security analytics you should be tracking key risk indicators as part of this which adds the next layer of security analytics needed in any environment. What this security analytics provides is the trend of the organization’s vulnerability and patching program. This is important along with others because what it provides is executive management a high level of what the company’s security posture is and an early indication of the security program needs given the trends detailed within this KRI’s. Of course, this is only one KRI but depending on the organization and the needs from the executive board there are many others that can provide a good overall insight into your security program and its maturity.
Security analytics takes operational elements to the next level by applying the knowledge of how a hacker thinks to be proactive in the analysis

