Effect of Security Controls on Patching Window: A Causal Inference based Approach

Aditya Kuppa, Lamine M. Aouad, Nhien‐An Le‐Khac · Annual Computer Security Applications Conference · 2020

In many organisations there are up to 15 security controls that help defenders accurately identify and prioritise information security risks. Due to the lack of clarity into the effectiveness and capabilities of these defences, and poor visibility to overall risk posture has led to a crisis of prioritisation. Lately, organisations rely on scenario based red teaming exercises which test the contribution of a security control to the security preparedness of the organisation, and testing the resilience of a control. However, these assessments don’t quantify the effect of controls on the security policies already in place. Measuring this effect can help stakeholders to re-calibrate and effectively prioritise their risks.

Read the paper · More papers on PaperTik