Ruslan Rakhmetov, Security Vision
Traditionally, information security tasks were divided into "paper" and "technical" ones: "paper" information security focused on complying with legal requirements, often through the development of internal regulations, while "technical" information security involved configuring security tools, responding to cyber incidents, managing vulnerabilities, and so on. However, the increasing maturity of information security processes, the increasing number of dangerous cyber incidents, and the growing awareness of senior managers regarding cyber risk management have led to the perception of "paper" information security as an irrational approach. Automated and effective cybersecurity that enhances, rather than hinders, business is needed. At the same time, regulatory requirements have not become more lenient. On the contrary, the logical response to cyber challenges has been the improvement of the regulatory framework: government regulators have shifted from the protection of personal data to the protection of critical information infrastructure, import substitution, and the ensuring of digital sovereignty and the cyber resilience of the national digital economy. Thus, modern cybersecurity must combine rapid response to current and constantly evolving cyberthreats, compliance with legal requirements, automated processes, and efficiency. The answer lies in solutions that automate information security compliance management (compliance with various cybersecurity requirements) – we'll discuss them in this article.
Compliance, in a broad sense, refers to a company's compliance with certain requirements – both external (legal, industry-specific, contractual) and internal (adopted by the company or group of companies). Cybersecurity encompasses numerous standards and requirements applied at various levels, covering organizational and technical aspects of operations – from regulating information security processes and selecting responsible individuals to implementing specific protective measures and issuing reports in established formats. Mandatory legal requirements for information security are formulated in regulatory legal acts (RLA), and violation of these requirements carries various sanctions from government regulators – from orders and fines to suspension of operations, license revocation, equipment seizure, and administrative or criminal liability for executives. Industry requirements regulate the activities of companies in specific economic sectors and can be mandatory or voluntary. For example, the requirements of GOST R 57580.1 are mandatory in the Russian financial sector (the requirement to comply with this standard is stipulated in Bank of Russia Regulations No. 683-P, 719-P, and 802-P), while compliance with the international ISO 27001 standard is confirmed voluntarily to demonstrate a high level of maturity of a company's information security management system. Professional, industry, and trade associations (and unions) may also establish standards and requirements that are mandatory for members. Failure to comply with them may result in expulsion from the association, loss of access to markets and sensitive industry information, exclusion from professional communities, a decline in the quality of internal expertise, and a loss of reputation within the industry. Furthermore, membership in self-regulatory organizations (SROs) is mandatory for some industries in Russia. For example, auditing and construction companies are unable to conduct business without SRO membership, which means they must comply with its decisions, rules, and standards. Another aspect of compliance is meeting the requirements of various agencies for licensees. For example, a license for the technical protection of confidential information (TPCI) is issued by the Federal Service for Technical and Export Control (FSTEC) of Russia, while a license for work and services using cryptographic information protection tools (CIPF) must be obtained from the Federal Security Service (FSB) of the Russian Federation. Both types of licenses require the company to meet a number of conditions (having specialists with certain qualifications on staff, having software, equipment, and premises, meeting regulatory requirements for licensees, etc.). Contractual obligations must be fulfilled within the framework of relevant contracts with partners, clients, customers, suppliers, contractors, and other counterparties. Such contracts may contain strict terms and provide for financial penalties for non-compliance. Intra-corporate or holding (within a group of companies or in subsidiaries and dependent companies) requirements are set out in internal regulatory documents (IRD) and reflect corporate standards established for all controlled companies, and failure to comply with them may result in disciplinary action for managers and responsible persons.
Thus, a modern company finds itself literally surrounded by various legal requirements, standards, restrictions, and conditions, which, moreover, have varying priorities and can overlap, complement, or even contradict each other. Previously, Excel spreadsheets were the traditional means of compliance management, with all their drawbacks, such as the need to manually enter data on requirements, compliance rates, and evidence of compliance. Questionnaires were compiled based on the subjective understanding of the applicability of specific regulatory legal acts by the contractors, the completed spreadsheets were sent to those responsible by email, data was entered manually and "on the word of honor" of the person completing the form, and document versioning became inconsistent due to the low level of automation. Another drawback of this approach is the inability to verify actual evidence of compliance: for example, the lack of administrative privileges for users on workstations, the set password complexity, or system logging parameters can be quickly obtained with a simple Python or PowerShell script. However, integrating and running such a script in an Excel spreadsheet can lead to complications and inconvenience (from running with the required privileges to maintaining the script's relevance when the infrastructure changes). Furthermore, the use of such Excel spreadsheets necessitated manually initiating the filling procedure whenever a new system or device appeared, when the architecture or system components changed, or when business processes were restructured. These triggers had to be detected manually and then a forced re-evaluation of compliance in the spreadsheet had to be initiated, sending it to the entire list of responsible parties, which, moreover, could already have changed. In the event of an inspection by government agencies, reporting also had to be generated manually: finding the current version of the questionnaire, checking the relevance and consistency of the data, transferring all data to templates using established forms, which was exacerbated by the lack of time before a visit from regulators. Such outdated solutions were replaced by SGRC (Security Governance, Risk) systems. Management and Compliance (SGRC) is a suite of products for automating all information security management processes, including compliance management. SGRC systems enable the management of information security strategy, tasks, and documents, the modeling of information security threats, the analysis and assessment of cyber risks, the conduct of self-assessments and audits of compliance with information security requirements, the creation and management of tasks to address identified non-compliance, the generation of reports, and the visualization of a company's cybersecurity status. Security Vision's SGRC product portfolio includes the following solutions:
· Security Vision Compliance Management (CM) – the product allows you to perform an audit of compliance with various requirements, standards and methodologies, generate a list of non-conformities, create tasks to eliminate comments, and issue reports;
· Security Vision Self-Assessment (SA) – the product allows you to build a process for assessing the state of information security in a subsidiary, group of companies, or holding company, conduct an assessment of compliance with corporate requirements, take into account the links between assets and business processes in dependent organizations, and formulate tasks to achieve target compliance indicators;
· Security Vision Personal Data (PDn) – the product allows for the implementation of requirements for the processing and protection of personal data in accordance with Russian regulatory legal acts (152-FZ, PP-1119, order of the FSTEC of Russia No. 21, etc.).
Automated compliance management tools in information security operate in accordance with the following principles:
1. The solution contains a built-in database of requirements of various regulatory legal acts (Russian and international), for example, 152-FZ, 187-FZ, 149-FZ, 161-FZ, Orders of the FSTEC of Russia No. 117, 31, 21, Regulations of the Bank of Russia No. 683-P, 716-P, 719-P, 802-P, Russian standards (GOST R 57580.1-2017, GOST R 57580.3-2022, GOST 57580.4-2022, GOST R ISO/IEC 27001-2021, GOST R ISO 22301-2021), international standards and norms (ISO 27000 series, PCI DSS, GDPR), recommendations and frameworks NIST, MITRE, BDU FSTEC of Russia, CIS Critical Security Controls, etc.
2. Since the provisions of regulatory legal acts and other documents are interrelated and may overlap and duplicate, a preliminary decomposition, deduplication, and correlation of requirements is performed: the essential part (the actual requirements whose implementation is being verified) is selected from each regulatory legal act, a list of these requirements is compiled, the requirements of different regulatory legal acts are compared with each other, duplicate requirements are removed, and similar requirements from different regulatory legal acts are correlated (linked) with each other. For example, FSTEC of Russia Orders No. 21 and No. 31 contain duplicate requirements AVZ.1 "Implementation of Anti-Virus Protection" and SOV.2 "Updating the Decision Rules Database," and many regulatory legal acts contain overlapping requirements on asset accounting and inventory and vulnerability management – such standards can be correlated.
3. For working with external data – corporate documents, internal regulations, industry standards, and other rare or closed/unique requirements – the automation tools support importing requirements from machine-readable formats (the simplest option is CSV/XML files) and creating requirements directly in the solution, followed by their deduplication and correlation. Furthermore, requirements can be grouped by domain – for example, to evaluate malware protection and implemented physical access restrictions in different domains. Standards and requirements created in the SGRC solution support a status model – document versions can be taken into account, new versions can be updated and approved, and old versions can be archived.
4. To automatically obtain up-to-date and reliable information about the cybersecurity status, SGRC solutions integrate with the company's internal IT/IS systems, providing, for example, the ability to obtain information on the status of antivirus protection, the relevance of IDS/IPS signatures, the completeness of inventoried assets, the number of unpatched vulnerabilities with a CVSS rating higher than eight, the status of event sources in the SIEM system, and the number of outstanding incidents in the SOAR solution. Advanced SGRC solutions build a resource-service model of the company's infrastructure, consider the relationships between assets (business processes, systems, equipment, accounts, products, services, suppliers, premises, etc.), and allow for the automatic population of asset attributes (e.g., based on device inventory results). For a thorough compliance assessment, a detailed analysis of information systems can be conducted to determine the applicability of regulatory legal acts/internal regulations and compliance with requirements. For example, the discovery of personal data in an information system (based on data flow analysis, regex searches, or AI/ML mechanisms) initiates a verification process for the system's compliance with the applicable requirements of Federal Law No. 152, Federal Law No. 1119, and Order No. 21 of the Federal Service for Technical and Export Control of Russia. If active actions are required to comply with legal requirements (e.g., reconfiguring information security systems, depersonalizing personal data, or deleting sensitive information), this can also be performed automatically upon confirmation from the responsible person.
5. If compliance with requirements cannot be assessed using technical means (for example, to verify the completeness of a certain information security process or the depth of candidate screening), SGRC solutions can generate questionnaires and provide the ability to complete them via a web interface and built-in chat, as well as parse the responses of responsible respondents from email and instant messaging apps. The completeness and timeliness of questionnaire completion, as well as the routing logic (for example, escalation conditions for questions in the event of a lack of response within the specified timeframe), can be configured within the SGRC solution's internal logic. For example, the Security Vision platform uses a no-code / low-code designer that allows for the customization of workflows, integrations, card forms, and questionnaires in a user-friendly interactive format.
6. Compliance levels are calculated using customizable mathematical formulas, where each parameter and requirement can be weighted, an overall integrated assessment of compliance with information security requirements can be derived, and the security of the infrastructure can be analyzed. GAP analysis allows for assessing compliance with information security requirements, identifying the gap between the current (AS IS) and target (TO BE) process states, determining the causes of non-compliance, and formulating an action plan to address deficiencies. It is important to create a list of clear goals that adhere to the SMART principles (specific, measurable, achievable, relevant, and time-bound), assign tasks to responsible individuals, and monitor the deadlines and completeness of their execution. The results of addressing these issues should be used as feedback when planning and conducting reassessments of compliance with requirements in accordance with the Deming PDCA cycle (Plan -Do-Evaluate-Act). If, based on the results of the compliance assessment, a decision is made to implement an information security system or reconfigure the current security solution, effective security settings can be obtained after their implementation using the SGRC solution integration mechanism. This will help assess the quality of the task and the completeness of the applied configurations in the infrastructure.
7. Compliance assessment should not be an episodic or one-time event – it is important to continuously monitor the level of compliance with requirements, since penalties for non-compliance are assigned based solely on the state of the infrastructure at the time of the audit, regardless of the security level “yesterday.” Key compliance indicators (KCIs) Compliance Indicator ) and key risk indicators (KRI, Key Risk Indicator ) form a system of control indicators for the level of compliance and cyber risks, which allows for a real-time assessment of a company's cybersecurity and a response if the specified indicators are exceeded.
8. An important component of compliance management is reporting and visualization of information security status across various dimensions, including issuing reports in accordance with regulatory standards and parent organization and subsidiary/associate requirements, and displaying compliance and security indicators on various dashboards, widgets, tables, graphs, and diagrams. It is important to present information in a user-friendly and understandable format at the strategic level for stakeholders and top managers, at the tactical and analytical levels for auditors, and at the operational level for specialists and implementers, while implementing drill-down functionality that allows for the transition from graphical displays and high-level information to the technical data underlying the visualization.
9. Using automated information security compliance tools helps you easily perform self-assessments and quickly prepare for external audits. Reports can be generated automatically in a matter of seconds, and the relevance and verifiability of the data used in the reports allows you to confidently respond to regulators' requests.
10. The use of automated information security compliance management tools allows for the linking of regulatory compliance with practical cybersecurity: the use of reliable and up-to-date technical data from the infrastructure and integrated IT/IS systems, continuous monitoring of risk and compliance indicators and response to violations, and the logical coherence of all cybersecurity processes help minimize the risks of non-compliance with information security requirements and improve the overall level of company security using the SGRC solution.