Sure, it's punchy, but I hope this illustrates it:
The basic problem with them is that they are bottom-up models of threat scenarios that originate with artifacts of technology implementations, which conflate vulnerabilities with attacks, and use news hits as threat actors/agents to justify their importance.
It's %90 an exposition vehicle for displaying how esoterically knowledgeable the practitioners are about hacker trivia and jargon, and from a business perspective, it's just kids playing in the sandbox that produce the compliance artifacts you want to get your project approved. Geeks get to geek, and project managers get their amber status risk, and when Equifax/OPM/LifeLabs happens, everyone says it wasn't foreseeable because they were "compliant." The frameworks externalize risk into models that are divorced from reality, which hides it, and that's why institutions buy into them. I'd say they're the collateralized debt obligations of engineering.
Real world threat scenarios are the counter cases to your business model. It's the top down, "if the C/I/A of this thing we care about is compromised, do we survive?"
People who ask questions like "how do I prevent spoofing in this tech stack?" without first asking "what if these STD test records and results end up on the dark web, and what are we doing to prevent that?" are culpable.
It's when one of the key factors that makes your business viable - goes wrong. The threat actors create the likelihood via their means and opportunity (independent of patch levels), and their motive is literally driven by the consequences of an attack.
Worrying about APT group x is meaningless when it is more plausible and serious that a grad student is going to publish a paper demolishing your elliptic curve implementation at a conference and get you laughed out of your industry.
Vulnerabilities and attacks are random, but the risks and controls are not. Threat scenarios are what happens when a business factor fails hard.
In these ways, the bottom-up focus of modern security frameworks and scoring systems serve more to enable poor quality decision making and the project and product management level anti-patterns that hide risk. That's literally their value. They let cynical people bring crap to market.
The reason they do this is because security people are stuck in the cycle of thinking they still need to explain themselves and convince others they are knowledgeable, and that there is a problem they solve. Everybody already knows, and compliance people have become just marks who hold the bag of bundled risk they think isn't theirs because they explained it all with their framework.
>...that security compliance has become a make-work field for the unskilled, whose role is to be both an easy mark and a scapegoat for reckless corporate behaviour.
I like the cut of your gib, sir.
>It's %90 an exposition vehicle for displaying how esoterically knowledgeable the practitioners are about hacker trivia and jargon, and from a business perspective, it's just kids playing in the sandbox that produce the compliance artifacts you want to get your project approved. Geeks get to geek, and project managers get their amber status risk, and when Equifax/OPM/LifeLabs happens, everyone says it wasn't foreseeable because they were "compliant." The frameworks externalize risk into models that are divorced from reality, which hides it, and that's why institutions buy into them. I'd say they're the collateralized debt obligations of engineering.
I think these risk models are part of a mutually-agreed kabuki illusion. It's hard work to assume prudent risk, to identify hazards specific to an organization's objectives, devise appropriate controls, etc. These frameworks offer a solution: if "industry groups" agree to hold them as valid, then it's like you say -- project managers get their amber risk status, and the large scale breaches are simply "Who could've known?" events, where lessons learned are drafted, reports are produced, commitments are made, and life moves on.
Building up the compliance industry - and I'd add no small part of the cybersecurity industry, tier 1 SOC personnel, etc - seems to be me to be creating a class of worker ripe for having the floor yanked out from under them in a recession. It's cost-center work, but it's marketed as 'cutting edge skills for the burgeoning cybersecurity industry'. What's the revenue generated, or costs cut, by monitoring those dashboards with human eyeballs?
The basic problem with them is that they are bottom-up models of threat scenarios that originate with artifacts of technology implementations, which conflate vulnerabilities with attacks, and use news hits as threat actors/agents to justify their importance.
It's %90 an exposition vehicle for displaying how esoterically knowledgeable the practitioners are about hacker trivia and jargon, and from a business perspective, it's just kids playing in the sandbox that produce the compliance artifacts you want to get your project approved. Geeks get to geek, and project managers get their amber status risk, and when Equifax/OPM/LifeLabs happens, everyone says it wasn't foreseeable because they were "compliant." The frameworks externalize risk into models that are divorced from reality, which hides it, and that's why institutions buy into them. I'd say they're the collateralized debt obligations of engineering.
Real world threat scenarios are the counter cases to your business model. It's the top down, "if the C/I/A of this thing we care about is compromised, do we survive?"
People who ask questions like "how do I prevent spoofing in this tech stack?" without first asking "what if these STD test records and results end up on the dark web, and what are we doing to prevent that?" are culpable.
It's when one of the key factors that makes your business viable - goes wrong. The threat actors create the likelihood via their means and opportunity (independent of patch levels), and their motive is literally driven by the consequences of an attack.
Worrying about APT group x is meaningless when it is more plausible and serious that a grad student is going to publish a paper demolishing your elliptic curve implementation at a conference and get you laughed out of your industry.
Vulnerabilities and attacks are random, but the risks and controls are not. Threat scenarios are what happens when a business factor fails hard.
In these ways, the bottom-up focus of modern security frameworks and scoring systems serve more to enable poor quality decision making and the project and product management level anti-patterns that hide risk. That's literally their value. They let cynical people bring crap to market.
The reason they do this is because security people are stuck in the cycle of thinking they still need to explain themselves and convince others they are knowledgeable, and that there is a problem they solve. Everybody already knows, and compliance people have become just marks who hold the bag of bundled risk they think isn't theirs because they explained it all with their framework.