Towards Automated Assessment of Organizational Cybersecurity Posture in Cloud
Roy Bar-Haim, Lilach Eden, Yoav Kantor, Vikas Kumar Agarwal, Mark Devereux, Nisha Gupta, Arun Kumar, Matan Orbach, Michael Zan · 2023
In a world where reliance on digital services becomes more critical every year with billions of dollars in penalties being levied annually by regulators and the impacts from security control failures growing, the potential consequence of organizations being unable to determine the completeness of their cybersecurity strategy and control environment are worsening. Established standards such as NIST 800-53, Cloud Security Alliance Cloud Controls Matrix (CSA-CCM) and CIS 20 Security Controls offer baselines against which organizations can mandate compliance, in the support of managing their security control environment and meeting risk and regulatory expectations. While there is increased security and compliance automation, it is hampered by the fact that control requirements are expressed in natural language text. With large organizations often needing to comply with several thousand security requirements across their IT enterprise, it becomes humanly impossible to assess coverage and identify potential gaps.