Processes, procedures and tactical operations must be driven by strategic goals based on your critical assets to ensure that the security program is in step with the enterprise’s business needs. As a result of this alignment with business needs, a strategic security program will enable business and provide tangible metrics to demonstrate its effectiveness.
In an asset-based security program, the information gained by each operational process is tied to the relevant assets. By focusing on the critical assets that your security program is in place to protect, you put in place an underlying foundation that individual security processes can link into. Think of your assets as being the “glue” that holds together a strategic security program, allowing the information gained by one individual process to be readily utilized to by the other processes. And by enabling the flow of information between security processes that are typically isolated “information silos,” you set in place the mechanism that drives continuous improvement across your entire security program.
Tactically speaking, asset-based security allows you to better manage operational workflow by pointing out which security efforts would reduce the most risk. A few days before, several vulnerabilities were publicly disclosed detailing exploitable flaws in your databases. During peak business hours, your IDS detects many possible incidents including a buffer overflow attack directed at your R&D database server. Because your security program is integrated around your assets, the R&D database server is immediately recognized as a highly critical asset that, according to the newly disclosed vulnerability data and ongoing vulnerability scans, is vulnerable to the buffer overflow attack detected by your IDS. The incident stands out from the rest of the alerts and is escalated as the highest priority and your security team reallocates their resources to mitigate the threat immediately, maintaining the integrity of your intellectual property.
Strategically speaking, an asset-based security program keeps intruders out by ensuring that all individual security processes are focused on what matters most to your business-the risk faced by your critical assets. Regardless of what the preferred method of attack will be in the future, the target will still remain the same.
http://www.net-security.org/article.php?id=888