9 ms·
The SaaS CTO Security Checklist Redux
- vikrum 5y agoPreviously — https://news.ycombinator.com/item?id=16615593 https://news.ycombinator.com/item?id=16615593 With Sqreen's acquisition, the list's previous home unfortunately redirects the their acquisition announcement. We're grateful that they released the list under CCA and we look forward to keeping it updated and relevant to startups on beginning their infosec journeys.
- deleted 5y ago[deleted]
- aahortwwy 5y agoIt's a good list, but like most (all?) of these lists it doesn't offer too much advice on organizational best practices. IMO a security program which cannot justify its own worth to others in the organization is incomplete. Most security professionals I've met (and I've been one of them, too) assume that security is or should be everyone's top priority. They struggle to deal with people for whom security is just one of many competing concerns.
- bitexploder 5y agoI think recognizing that security is just one of the many engineering challenges in building software is important. It must always be prioritized and budgeted like any technical debt. It can’t be ignored, but it is rarely the supreme concern for most software. We do a lot of turn key security engineering for our customers and it’s always about prioritizing the right concerns, both from an implementation perspective and from an organizational perspective. Another thing a lot of folks struggle with is knowing where your product is and where the security fights should be at a given product and organization scale. Risk assessment and threat modeling are huge for creating such a prioritization. Whether it’s formal and in depth or informal depends again on where things are. Beyond these concepts, well engineered software simply has less security defects, so focusing on quality and managing technical debt often means less security debt as well. It’s down to being an immature practitioner to think security concerns are always the primary ones. I think it’s a hard skill to master though, so I am not saying that with great judgement, someone should be a champion for security at most organizations and advocate for it. I think using empathy and curiosity goes a long way to maturing as a practitioner, but it took me many years of practice.
- gsoltis 5y agoI agree, it is absolutely a matter of judgment and is heavily dependent on the stage and specific threats a particular organization faces. It is difficult to balance product velocity with the need to protect a growing "something to lose" that the company is accumulating. I think one of the best things we can do as security professionals is to identify or work to create security measures that have outsized ROI and advocate for those. Using battle-tested software is one, as are, I believe, measures like MFA.
- andrewstuart2 5y agoI'd also submit that one of the most important things is recognizing that ROI requires a net positive return. It's not just the time required to implement a control, you also have to factor in the opportunity cost of the increased friction. I've seen way too many times infosec organizations completely ignoring that the loss outweighs the actual risk. Hyperbolic analogy, but like forbidding driving delivery routes to avoid a parking ticket.
- jollofricepeas 5y agoYep, this. OMG THIS! There are three things that most security types don’t understand: 1. Security is a small component of risk. Impact (in dollars) x Likelihood = Risk 2. Cybersecurity insurance can change the risk equation dramatically 3. It is possible for a security remediation to kill/harm more people than the underlying insecure system that the fix is being applied to Once you realize that security is a risk problem then you’re able to quantify that problem in dollars. Lives affected can be used as a metric too but dollars are the magical language that everyone can understand.
- kenniskrag 5y ago> Cybersecurity insurance can change the risk equation dramatically Do they check if you implement best practices in security? I could imagine, that this will have an impact on the premium.
- windowsworkstoo 5y agoYes and the audits around this change arbitrarily each year and you will be denied coverage if you are doing something otherwise competent but miss their particular flavour of the year
- austinjp 5y agoFully agree that impact x likelihood = risk, although I'd extend it beyond dollars. Impact can include reputation, health, etc. Certainly these could be measured using cash-value as a proxy, but this risks chasing the wrong metric. I also recognise that "when a measure becomes a target it ceases to be a good measure", and cash as the bottom line risks increasing this tendency. Too idealistic, probably :)
- faeyanpiraat 5y agoCorps don’t care about your health, they care about you being healthy enough to bring in the dough. And when you accept this fact, you can skip lamenting about all sorts of ethical questions and just know that everything will be a monetary decision in the end.
- raesene9 5y agoMy reading of this list is that it's not designed to be a starting point for a full security programme, but a starting point for small organizations who don't even have a security function yet. In an ideal world, every company would have dedicated resource for this and a well targeted/justified programme of work, but I think there's quite a few where responsibility falls on the CTO and there lists like this can be useful.
- aahortwwy 5y agoThis list and others like it are for sure useful, but the CTO of a smaller organization still needs to be able to: - Prioritize items on this list relative to each other. - Prioritize items on this list relative to other work. - Communicate the reasons for that prioritization to other members of leadership, at least.
- sublimefire 5y agoAn interesting parallel is how these similar issues are solved in other engineering domains. In civil engineering you have heavy regulation and accountability. If a building falls then the engineer is responsible and she could get a jail sentence. To prevent buildings from falling there are regulations around minimum requirements, audits, material quality, etc. Regulation in software "does not exist" as the actual threat is minimal. If your program crashes then nobody dies ('m not talking about rockets). Therefore it always looks like security people always have temper tantrums as there is no meaningful quantifiable risk. In our org we ended up asking pentesters to get into the systems instead of just giving us an automatically generated report that contains links to CVEs. If they cannot use existing risks to get into the system then that risk is trivial.
- berkay 5y agoGood point. There are also some software solutions (picus security, etc.) that tests your validates whether your environment is exposed due to specific CVEs. It's a good way to prioritize which vulnerabilities that you should tackle first.
- bhartzer 5y agoI don’t see any mention of domain names. Domain names should be set up properly, like implementing dnssec, dmarc, dkim, spf, and using a secure registrar. So many overlook domain security.
- k__ 5y agoAny resources on this?
- ramimac 5y agohttps://labs.bishopfox.com/tech-blog/2017/05/how-we-can-stop-email-spoofing https://labs.bishopfox.com/tech-blog/2017/05/how-we-can-stop... is a pretty good primer on spoofing (SPF, DKIM, DMARC)
- StavrosK 5y agoWhat's a good secure registrar?
- bhartzer 5y agoI can tell you which ones not to use based on which registrars have had domain names stolen frequently.
- StavrosK 5y agoThat helps as well.
- toomuchtodo 5y agoCloudflare, but you can’t register with them, only transfer in. I buy at Namecheap, and then transfer in. Edit: Based on Austin’s below reply it looks like you can register directly with Cloudflare now. Thanks Austin!
- austinkhale 5y agoYou actually can register with them and they promise to provide registration at cost forever: https://www.cloudflare.com/products/registrar/ https://www.cloudflare.com/products/registrar/ Note: They released the beta fairly recently, which is why a lot of folks don’t know about it yet.
- mwcampbell 5y agoThis is the first I'd heard of RASP (runtime application self protection), so thanks for that, I think. Now I need to decide which RASP tool to use.
- ramimac 5y agoJust in case you weren't aware - this Checklist is adapted from the Sqreen SaaS CTO Security Checklist. Sqreen is a RASP that was recently acquired by Datadog. Keep in mind that potential bias before diving in too deep on the sales pitch!
- FreshFries 5y agoWe are experimenting with a couple of RASP providers, let me tell you that it does help with certain aspects (of finding issues) but it does not replace the other tooling we are already using. So the costs / resources are not to be underestimated. Good thing about many RASP solutions is that they integrate easily into our existing developers processes / tooling, so that's a big endorsement.
- taf2 5y agoI didn’t see ssh security mentioned maybe I missed it? I recommend, in addition to public key only authentication to also use an 2nd factor as well
- maximilianburke 5y agoSSH security becomes less important when all the machines that are accessible by SSH only expose those ports to a VPC.
- rorykoehler 5y agoIt's hard to implement if you are doing machine to machine automation (for example SFTP over SSH).
- iou 5y agoI didn't see ransomware mentioned anywhere in there. At best being ignorant of that risk is going to result in fiscal losses and dubious legalities wrt sanctions, at worst existential risk to the company.
- ramimac 5y agoIt makes sense (to me) that ransomware isn't mentioned, as this is a checklist of controls - not of threats. Many of these controls do help in preventing ransomware: 2FA, "Backup, test your backups, then backup again", "Isolate assets at the network level", etc.
- iou 5y agoOh didn't notice they mentioned backups, my mistake then.
- ledauphin 5y agoI think of myself as pretty security-conscious. But it's striking to me just how _long_ this list is. Even as someone who is trying to constantly think about this stuff, if I were faced with a list of this magnitude, I'd be tempted to throw in the towel and admit defeat right off the bat. It's no wonder so many SaaSes end up getting exposed. Even with a lot of best practices built in to so many cloud providers... how did we as an industry end up in a place where it's this dang hard to keep systems secure?
- vishnugupta 5y agoAs a CTO of a resource constrained small startup I totally empathize with you. I thought security checklists were long until I ran into ISO. Edit: Typo (and coffee).
- user3939382 5y agoAnother thing that comes to mind is the list of NIST Cybersecurity Framework’s controls. The length of these lists is a reflection of the real complexity that are inherent to computer networks.
- InvertedRhodium 5y agoEmpathize? :)
- mwcampbell 5y agoI can empathize as well. And it gives me a greater appreciation of how most developers must feel about accessibility, which is my own specialty and passion.
- rorykoehler 5y agoI have to work with both constraints and I find accessibility standards to be easier to align with as they can become part of the SDLC pipeline (like code level testing). Securities' scope is far more all encompassing. The hard part for accessibility generally comes down to ensuring that people don't forget they need to think about it when they are designing features and especially changes.
- ramimac 5y agoWhile I'm generally a fan of the Sqreen checklist that this is built on, looking over it with fresh eyes I have quite a few quibbles: "Require 2FA wherever possible" - Given the target audience, it would be nice if this was explicit about the reason to use hardware keys (including those builtin to TouchID + chromebooks). "Accustom your team to locking their computers" - This is good advice, but I'd recommend configuring locking on inactivity a higher leverage effort "Hire your first security engineer" - "do we have a security roadmap? do we manage to deliver on it?" is not a good heuristic for whether you need a security hire. I'd argue that most startups will lack a formal security roadmap when they don't have dedicated security staff. For example, the linked First Round article [1] has a more actionable recommendation, with justification: "Onboard your first, full-time security hire between 30-100 employees." "Set up a bug bounty program (NEXT)" and "Monitor your user’s suspicious activities (NEXT)" being placed before "Have a security incident response plan (LATER)" [1] https://review.firstround.com/how-early-stage-startups-can-enlist-the-right-amount-of-security-as-they-grow https://review.firstround.com/how-early-stage-startups-can-e...
- Kalium 5y agoOn the security engineer item, I think this piece falls into a common trap. It regards security work as mostly technical work, to be handed to an IC who can also handle technical questions. As the company will probably lack a decent security roadmap and be poorly positioned to develop one, the right move is generally to hire someone equipped to do so. Which is to say a Director of Security. They will need that rank for the inevitable political battles with Product and Marketing / Sales. Those early political fights will do more than you think to shape the culture for years to come.
- rorykoehler 5y agoThat's why I recommend to start with a external consultancy until you are mature to bring it in house.
- RandyRanderson 5y agoThis list is the "brute force" security algo. Eg 'just make everything more secure'. This would have someone upgrading a door lock with a hole in an adjacent wall. There are at least the following major factors: * what might happen (event A,B, ...) ? * how probable is eventi? * what is the cost if eventi happens? * how can one deal with eventi? (action 1, 2 ...) ? * how much / how long does actioni take? * what actions should we perform with the skills/resources/time we have? My algo: 1 enumerate possible security issues 2 assign approx probability and cost to business 3 re-order by prob*cost 4 imagine ways to address issues, assign cost to address 5 decide on courses to address issues 6 for next epoch, address issues 7 goto 1
- blowski 5y agoThat’s a good list and will improve the security of your own software. But in a bigger team, how do you make sure everyone is following the list effectively and consistently?
- aahortwwy 5y agoA starting point would be to have a dedicated team perform steps 1-3 as a service to all teams, individual teams become responsible for steps 4-6, and management assume responsibility for step 7 as well as overall goal setting (e.g. deciding by how much they want all teams to reduce/mitigate their risk over the coming epoch).
- ryanbrunner 5y agoThis definitely presumes a certain company size. The company I work for has 5 employees (2 in an engineering capacity), there's zero room for dedicated teams for anything. I've found even in a 100 person startup there's probably appetite for 1, MAYBE 2 people who are 100% dedicated to security.
- aahortwwy 5y agoWell sure, the comment that I replied to specifically asked how you might apply the heuristic in a larger organization. With just a handful of people it can be applied by one security-conscious member of the team, and at that scale it's also viable to get everyone on board with applying it consistently.
- hackburg 5y agoAre you in need of a professional hacker? We offer the following services and more... . Consulting services. . Email password retrieval. . Credit repair [revolving and installment tradelines}. . Phone hack. . Clearing of criminal records. . Recovery of lost funds on Binary Options and Capital investments. *. Database retrieval..e.t.c... Visit us to know more: Hackburg.blogspot.com
- sileht 5y agoCompany that want to become SOC2 or iso27001 can automate all of this and more with https://www.vanta.com/ https://www.vanta.com/. This helps us a lot at https://mergify.io https://mergify.io for our SOC2 certification.
- deleted 5y ago[deleted]
- unixhero 5y agoI work within the Cyber Security domain, and I have to say this was a very solid list. Great work!
- a_imho 5y agoWhenever I'm forced to use 2fa the most probable outcome is that I will get locked out when I need to log in the most. Not to mention most implementation in the wild trivially reduces to 1 factor. I could make a case for MFA if really pressed, but M=2 is such a bad choice too.
- hyperman1 5y ago2FA on itself is good, but should not be an excuse for corporate to own my cell phone. They want to send messages with codes to my phone? I'll live with it. But then they want me to buy a phone with more recent android version. Then they want to enforce biometrics and encryption on my phone. Then they want to remotely erase my phone? No. If central IT wants that kind of access, they should buy me a phone.