Security and Resiliency as Risk Reduction Strategies in IT
Dr. Ravi R, D.B.A, M.B.A, M.tech, B.E

Security and Resilience as Risk Reduction Strategies in IT
Dr. Ravi R, D.B.A, M.B.A, M.Tech, B.E
Release Date: 06th October 2024
Have you ever wondered how security and resiliency in information technology are reshaping our future?
In a world where innovation unfolds at an unprecedented pace, understanding these changes is more crucial than ever. As we stand on the brink of a new era, it’s essential to grasp the potential and challenges of these emerging technologies.
Evolution of Security and Resiliency:
Security as a role in the information technology field has existed for a long time. Around a few decades ago, this role was played by system administrators; they were responsible for securing access to mainframes and other systems. At those times, the number of systems were less, and it was manageable by system administrators.
The size and complexity of IT started to grow, and the role of security moved out of system administrators to a dedicated team called Network & IT Security. This team was responsible for managing the network and security of IT assets. Later, as the technology grew, the network and security teams were split into two different teams, and there came a dedicated IT security team to manage and monitor the security responsibilities for the IT estate. The IT estate, which consisted of high-end processing and storage, was previously located in a data center. End-users operated the system using terminals, while the processing was conducted in the data center's back end.
As the technology landscape changed and distributed processing came into the picture, where in distributed processing the end-user systems had higher processing capabilities similar to systems inside the data center, the security protection measures had to change their posture, which gave birth to information security to protect the data that makes value to a business, and this information can be on the systems inside a data center or onto a mobile end-user system that doesn’t have a fixed location; it can also be traveling on the internet, which is a no man’s zone. Information security concentrates on the data that is residing within the digital environment and also in the form of hardcopy. The security operations centers were established to monitor the threats to an organization’s IT landscape.
The security controls that safeguard the information lifecycle and the fundamental infrastructure that processes, shares, and stores the information are referred to as information security. It also included controls on continuity or availability of information for the right person at the right time.
Information security covers IT security, human resource security, physical and environmental security, third-party suppliers, security for business continuity, and many other domains. The opportunity for IT was growing across industry sectors; the threats to IT were also increasing. Today, any smartphone can communicate like a system and transact with any authorized organization through an application program interface. That was the time cyber security was coined, which was a subset of information security but concentrates on protecting the IT infrastructure that interfaces to the internet for business purposes. Cybersecurity focuses more on strengthening the security controls of the IT infrastructure of an organization from threats on the internet so that business can continue and grow with less downtime.
The resilience domain in the information technology field was also born more or less in the same period as cybersecurity was coined; it concentrated on the continuity of business. As we know, the term business involves many enablers like people, finance, processes, IT, and others. When we think about continuity of business or the availability of business services, all the above enablers must be resilient, but out of all enablers, making people resilient is a challenge.
Both security and resiliency help the business to identify and reduce the risk.
What is security?
Security, from the information technology (IT) perspective, is a method or mechanism to safeguard the data, which is considered the crown jewel of any personnel or organization. The data that needs protection might be personally identifiable information (PII), personal health information (PHI), or business secrets.
What is resilience?
From the information technology perspective, resilience is the capacity to withstand or recover quickly from any minor or major incidents that affect the business services.
Security, from the information technology (IT) perspective, is a method or mechanism to safeguard the data, which is considered the crown jewel of any personnel or organization. The data that needs protection might be personally identifiable information (PII), personal health information (PHI), or business secrets.
What is resilience?
From the information technology perspective, resilience is the capacity to withstand or recover quickly from any minor or major incidents that affect the business services. When we combine these two terms, security, and resilience, there is a close interrelationship; any breach of security will lead to resilience impact.
Security of data in IT relies on three dimensions: confidentiality, integrity, and availability. Confidentiality describes the protection of data, integrity describes accuracy, and availability describes continuous access to essential information.
The business in any organization revolves around the data; the data can be in the form of financial, business, legal, or personnel data. The business's survival is contingent upon the security of its data; however, the volume of data is a significant obstacle to data security. The cost of data security increases as the volume of data increases. To overcome this challenge, the data must be classified to understand which data to secure. The classification of data will lead to the selection of the type of protection measures.
How do we classify the data?
The data is categorized based on its value when it is disclosed to others. The data owner or the creator of the data will be the best person to decide its value. Before classifying the data, there should be a classification framework with levels to be established. Generally, across the industry, they create categories like top secret, secret, private, and public, and they describe each category, which explains what type or category of data might fit into each of these levels. After the categories are defined, they must identify the security measures to protect these data; these measures are named controls. The value of data will change as time progresses; the data that is valued as a top secret today might change its value to the public category after a certain period. As the category of data changes, the security controls have to be decreased or increased; otherwise, this will lead to a financial impact, there is no use in providing a level of security measures for public data similar to top secret data.
The data has a lifecycle that starts with creating, storing, using, sharing, archiving, and destroying. Based on the data classification, the security controls are to be implemented in each phase of this lifecycle. Top secret data will have a higher level of security controls than public data, top secret data is not accessible by everyone; it is accessible or available to only a few people, whereas the data categorized as public data is available to everyone. When the level of security control increases, the cost of procuring, implementing, and maintaining those security controls also increases.
At what point does the data qualify as information?
Even though the data owner knows the value of the data, the real value of the data will be gauged by others or the public. In the case of any business, there might be some unique idea that is driving their business, which is nothing but data that are valuable for their business, it can be a formula to prepare a recipe, a workflow to create a product that is acceptable in the market, a unique way of design. Not all data in your personal life or business will get converted as information; only those data that make value to your business or create a growth path in your career or business will be qualified as information; this will retain its state as information until someone else has invented the same or it has been decategorized to a lower level of classification by the data owner. In the industry, we find these two terms, data, and information, are closely interchanged.
How do we decide the security measures for data?
The security measures are also called security controls, the types of security controls are preventive, detective, corrective, and deterrent controls. The preventive controls are used to stop the threats from materializing, the detective controls are used to detect the threats when they occur, and the corrective controls are used to recover the business after a failure. The deterrent controls are used to discourage users from violating the security controls.
The security architecture in any organization follows a defense-in-depth approach, where multiple types of security controls are implemented, such as deterrent control as the first layer and the second layer as preventive controls, and the next layer as a detective, finally the corrective controls. The other common term in security architecture is multi-layer/multi-tier security controls, if we look at the security architecture of an organization, when we enter the campus of an organization there will be a solid wall with fencing at the top, sufficient lighting to illuminate the surroundings, security guards guarding the perimeter and the entrance to the campus, CCTV surveillance and monitoring, security dogs, Physical access controls to enter into the secure access areas, visitor management and other controls. These controls are used to protect the people and the data in an organization.
How do we decide the resiliency measures for data?
Most of the data classification is concentrated on confidentiality and integrity triads of security, to extend the same with availability we can include mission-critical, critical, and regular categories, example the top-secret category can be extended with mission-critical, which means the data that is classified as top secret should not be accessible by unauthorized users and at the same time the data when it has to be accessed it should be available.
Based on the classification, resiliency measures should be implemented to make the data available at the right time and the right location for authorized users. The resiliency measures for IT infrastructure include High Availability, Fault Tolerance, and Backup.
Once the classification standard is documented, the IT assets must be subjected to impact analysis to categorize the data into respective classifications. Impact analysis in the industry is termed as business impact analysis (BIA) or business process impact analysis (BPIA). Impact analysis forms a part of the Risk management domain. When an IT asset such as servers or database is subjected to Impact analysis, the first step is to identify the data owner or the business process owner, and the second step is to discuss with the owner to identify the value of the data, few questions are
1) What might happen to the business, if the data is lost, misplaced, or tampered with?
2) Is the data regulated by any legal and regulatory requirements?3) Is there a way to continue the business, if the data is not available for a short time?
4) If the answer to the above question 2 is yes, how long they can wait?
The response to the above questions will lead to preparing and proposing the budget for procuring, implementing, and maintaining the resilience measures, this stage is also called deciding the IT continuity strategy.
The IT continuity strategy once it is agreed upon and approved by the organization will lead to designing the IT security and resiliency architecture. As part of the architecture the security and resiliency consultant and architecture will choose the required security controls to build the defense-in-depth model to protect the classified data and will also design the disaster recovery posture for the IT assets, so that the business can continue to provide the business services in case of any business disruptions. The outcome of the architectural design will be a blueprint in the form of a High-Level design (HLD) that captures the security and resiliency components to be included. For example, to protect highly classified data, security controls like Zero Trust will be implemented, to protect against loss of data, disaster recovery measures like Cyber recovery solutions, Fault Tolerance measures in the form of secondary data centers named Disaster recovery sites with data replication measures between the primary and secondary data centers are considered. The primary data centers are those sites that are operational round the clock for the business to access and process, in case of any disruption to the primary sites the secondary data centers or disaster recovery sites are activated.
Now, we are clear that data is subjected to security and resiliency measures depending on the data classification, certain industry sectors have regulatory requirements that necessitate the secure storage of data for an extended period and the ability to access it when necessary. In the past, for the data to be secure and available, they used to back up the data on tapes and store it in far-off locations, that don’t fall in the same risk zone as your primary site or operations center. The location where the backup data is stored was named off-site, and the backup tapes were stored in a secure locker with environmental measures for the tapes to be readable, by doing this they achieved security and resiliency. In the case of data backed up on tapes, there was one constraint the backup tapes would be readable only by the same type of tape drive, if the type of tape drive changes the data will not be readable, since the recording format changes. Today, the technology is so advanced that we can take a snapshot of the data and store it on a device in another location through a network or on a secure device like a cyber vault. The cyber vault device is capable of storing clean data in a read-only format, which is free of any malicious code. If your primary and secondary data centers or sites are compromised by malware or ransomware, the data stored in the cyber vault can be restored to a clean room or platform. The process of deciding where and how to restore the data from a cyber vault to a clean room is documented as a cyber recovery solution.
Fusion of security and resiliency?
Today, the cyber security, network, and resiliency domains are integrated to form a new field called cyber resiliency. This fusion is achieved to reduce the duplication effort across the security and resiliency domains, many IT processes are common across these two domains, such as change management, risk management, incident management, capacity management, configuration management, and capacity management.
Conclusion:
Security and resiliency play a major role in enabling the business to achieve its objectives and also prepare the business to continue by overcoming any known business disruptions. Data is one of the business's most valuable assets, and both security and resilience are essential for its protection. These two are the growing domains of this decade and one article is not sufficient to explain the depth and width. Automation, orchestration, and Artificial Intelligence are the future of security and resilience, as they will enhance the efficiency and effectiveness of the business in protecting and sustaining it.
Details of the Author:
Dr. Ravi R
Email Id: [email protected]
LinkedIn Id: www.linkedin.com/in/ravi-r-director-it-cloud-consulting-8b91b15
About the Creator
Dr Ravi R
A security and resiliency consultant with over 29 years of experience in Cyber resiliency, Information Security, Data Privacy, Cloud technology, Digital transformation, Business Continuity, Crisis Management, and Disaster Recovery.
Enjoyed the story? Support the Creator.
Subscribe for free to receive all their stories in your feed.
Comments
There are no comments for this story
Be the first to respond and start the conversation.