Systems and methods for security operations maturity assessment
Systems and methods for assessing, tracking and improving security maturity of an organization are provided. Described is a system for assessing security maturity of an organization. The system receives a list of data sources located across multiple jurisdictions for the organization, collects data sources/data using custom rules from a plurality of data sources of the list of data sources, determine criticality score for each of the plurality of data sources, calculates data source coverage and asset collection coverage, determines use case coverage, and determines security maturity score using a maturity score model. The maturity score model is a logistic equation which is a function of the data source coverage, the asset collection coverage, the criticality score associated with each of the plurality of data sources, the use case coverage, asset coverage by each the plurality of data sources.
1 . A non-transitory processor-readable medium storing code representing instructions to be executed by a processor, the code comprising code to cause the processor to perform the following network cyber security operations:
monitor network traffic of network security devices of a network of an organization;
identify, based on the network traffic, a data source associated with a network security device;
identify, based on whether data is currently collected from the data source, that the data source is an inactive data source;
identify, based on the network traffic and data collected from the data sources, a plurality of active data sources;
determine, based on a number of a set of cyber security use cases covered by the plurality of active data sources associated with an organization and a number of a plurality of cyber security use cases, a cyber security use case coverage value;
determine, for each of one or more of the active data sources of the plurality of active data sources, using a machine learning model and based on a subset of cyber security use cases covered by the active data source, a criticality score for the active data source;
determine, based on a number of the plurality of active data sources and a number of the plurality of data sources, a data source coverage value;
determine, based on a number of a set of jurisdictions with which the plurality of active data sources are associated and a number of a plurality of jurisdictions associated with the organization, an asset collection coverage value;
determine, based on the cyber security use case coverage value, the criticality scores for one or more of the active data source of the plurality of active data sources, the data source coverage value, the asset collection coverage value, a security operation maturity score for the organization;
determine that the security operation maturity score does not satisfy a benchmark maturity score;
determine a security gap of the organization associated with the inactive data source; and
provide, based on identification of the security gap and the determination that the security operation maturity score does not satisfy the benchmark maturity score, output for activation of the inactive data source to improve detection or prevention of cyber threats.
2 . The non-transitory processor-readable medium of claim 1 , the code further comprising code to cause the processor to:
receive input from a user to identify a plurality of data sources that include the plurality of active data sources.
3 . The non-transitory processor-readable medium of claim 1 , the code further comprising code to cause the processor to:
identify, based on analysis of network traffic of the organization, a plurality of data sources that include the plurality of active data sources.
4 . The non-transitory processor-readable medium of claim 1 , the code further comprising code to cause the processor to:
determine, based on the set of cyber security use cases covered by the plurality of active data sources and a plurality of compliance frameworks, compliance coverage of the organization,
the security operation maturity score being further based on the compliance coverage.
5 . The non-transitory processor-readable medium of claim 1 , the code further comprising code to cause the processor to provide, based on the security operation maturity score and one or more benchmarks, a recommendation regarding the security operation maturity score of the organization, wherein:
the one or more benchmarks include a benchmark security maturity score based on the plurality of active data sources.
6 . The non-transitory processor-readable medium of claim 5 , wherein:
the one or more benchmarks include at least one of (1) a security maturity score of an organization similar to the organization, (2) a security maturity score of an industry related to the organization, (3) a security operation maturity score of a state, or (4) a security operation maturity score of a nation.
7 . The non-transitory processor-readable medium of claim 1 , the code further comprising code to cause the processor to:
identify at least one missing cyber security use case not covered by the plurality of active data sources.
8 . The non-transitory processor-readable medium of claim 5 , the code further comprising code to cause the processor to:
identify, based on the set of cyber security use cases covered by the plurality of active data sources and the one or more benchmarks, security gaps of the organization.
9 . The non-transitory processor-readable medium of claim 1 , wherein determining the criticality score for an active data source of the plurality of active data sources comprises using a weighted criticality score based on a score of each cyber security use case covered by that active data source.
10 . The non-transitory processor-readable medium of claim 1 ,
wherein the determining of the cyber security use case coverage value is based on data received in real-time from each active data source from the plurality of active data sources.
11 . The non-transitory processor-readable medium of claim 1 , wherein determining the criticality score for an active data source is based on at least one of (1) whether the active data source includes external authentication capabilities or (2) a direction of network traffic of that active data source.
12 . The non-transitory processor-readable medium of claim 1 , wherein determining the security operation maturity score includes code to calculate the security operation maturity score for the organization comprising employing a security maturity model that comprises a logistic equation that employs inputs comprising the cyber security use case coverage value, the criticality scores for one or more of the active data source of the plurality of active data sources, the data source coverage value, and the asset collection coverage value.
13 . The non-transitory processor-readable medium of claim 1 , wherein:
the security operation maturity score for the organization includes an overall security operation maturity score based on a plurality of security operation maturity scores, each security operation maturity scores from the plurality of security operation maturity scores indicating a security operation maturity level of a segment from a plurality of segments of information technology infrastructure of the organization, and
the plurality of security operation maturity scores including at least one of a security operation maturity score of data centers, a security operation maturity score of cloud service providers, or a security operation maturity score of software as a service (SaaS).
14 . The non-transitory processor-readable medium of claim 1 , wherein:
the security operation maturity score for the organization is determined based on a plurality of security operation maturity scores, each security operation maturity score of the plurality of security operation maturity scores associated with at least one of a cyber security use case from the plurality of cyber security use cases or an active data source from the plurality of active data sources.
15 . The non-transitory processor-readable medium of claim 5 , the code further comprising code to cause the processor to:
generate based on the one or more benchmarks, a prediction of improvement of the security operation maturity score of the organization as each data source from a plurality of inactive data sources is activated to be an active data source,
wherein a recommendation to improve the security operation maturity score of the organization comprises the prediction of improvement of the security operation maturity score of the organization.
16 . The non-transitory processor-readable medium of claim 15 , wherein the recommendation to improve the security operation maturity score of the organization comprises an indication of the security operation maturity score of the organization.
17 . A method for network cyber security, comprising:
monitoring network traffic of network security devices of a network of an organization;
identifying, based on the network traffic, a data source associated with a network security device;
identifying, based on whether data is currently collected from the data source, that the data source is an inactive data source;
identifying, based on the network traffic and data collected from the data sources, a plurality of active data sources;
determining, based on a number of a set of cyber security use cases covered by the plurality of active data sources associated with an organization and a number of a plurality of cyber security use cases, a cyber security use case coverage value;
determining, for each of one or more of the active data sources of the plurality of active data sources, using a machine learning model and based on a subset of cyber security use cases covered by the active data source, a criticality score for the active data source;
determining, based on a number of the plurality of active data sources and a number of the plurality of data sources, a data source coverage value;
determining, based on a number of a set of jurisdictions with which the plurality of active data sources are associated and a number of a plurality of jurisdictions associated with the organization, an asset collection coverage value;
determining, based on the cyber security use case coverage value, the criticality scores for one or more of the active data source of the plurality of active data sources, the data source coverage value, the asset collection coverage value, a security operation maturity score for the organization;
determining that the security operation maturity score does not satisfy a benchmark maturity score;
determining a security gap of the organization associated with the inactive data source; and
providing, based on identification of the security gap and the determination that the security operation maturity score does not satisfy the benchmark maturity score, output for activation of the inactive data source to improve detection or prevention of cyber threats.
18 . An apparatus, comprising:
a memory; and
a processor operatively coupled to the memory, the processor configured to perform the following network cyber security operations;
monitor network traffic of network security devices of a network of an organization;
identify, based on the network traffic, a data source associated with a network security device;
identify, based on whether data is currently collected from the data source, that the data source is an inactive data source;
identify, based on the network traffic and data collected from the data sources, a plurality of active data sources;
determine, based on a number of a set of cyber security use cases covered by the plurality of active data sources associated with an organization and a number of a plurality of cyber security use cases, a cyber security use case coverage value;
determine, for each of one or more of the active data sources of the plurality of active data sources, using a machine learning model and based on a subset of cyber security use cases covered by the active data source, a criticality score for the active data source;
determine, based on a number of the plurality of active data sources and a number of the plurality of data sources, a data source coverage value;
determine, based on a number of a set of jurisdictions with which the plurality of active data sources are associated and a number of a plurality of jurisdictions associated with the organization, an asset collection coverage value;
determine, based on the cyber security use case coverage value, the criticality scores for one or more of the active data source of the plurality of active data sources, the data source coverage value, the asset collection coverage value, a security operation maturity score for the organization,
determine that the security operation maturity score does not satisfy a benchmark maturity score;
determine a security gap of the organization associated with the inactive data source; and
provide, based on identification of the security gap and the determination that the security operation maturity score does not satisfy the benchmark maturity score, output for activation of the inactive data source to improve detection or prevention of cyber threats.