Automation of Security Controls for Continuous Compliance in Vulnerability Management

  • Raiff Silva UFCG
  • Andrey Brito UFCG
  • Jean Paulo de Lima Filho UFCG

Resumo


The current security landscape demands efficient processes that match the advancement of cyberattacks techniques. Therefore, the automation of processes encompassing security activities is considered an alternative to meet the protection needs at the pace required by information systems, benefiting manual activities with optimizations, automation, and enabling scalability and cost reduction. In this work, we propose a vulnerability management process that supports continuous compliance verification, specifically targeting security challenges in IaaS cloud systems, and focusing on addressing vulnerabilities in components under the responsibility of cloud service users. For this purpose, we defined the operationalization of compliance considering a base of recommendations using security frameworks from CIS and NIST to support the creation of security policies and mechanisms, as well as the technical resources for implementing recommendations alongside the automated execution of security tools. Additionally, we established the key factors needed to measure compliance using CVSS-based metrics defined as Node Verification Metric (NVM) and the decomposition of security recommendations into actions and conditions that structurally constitute them for defining evidence.
Palavras-chave: Vulnerability, Security, Tool, Compliance, Automation, Cloud, IaaS
Publicado
26/11/2024
SILVA, Raiff; BRITO, Andrey; LIMA FILHO, Jean Paulo de. Automation of Security Controls for Continuous Compliance in Vulnerability Management. In: LATIN-AMERICAN SYMPOSIUM ON DEPENDABLE COMPUTING (LADC), 13. , 2024, Recife/PE. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2024 . p. 1–10.