Security processes are meant to reduce human vulnerability, but poorly defined, undocumented, or outdated procedures introduce their own risks. Understanding where process gaps exist is the first step toward building consistent, reliable security controls.
Process Vulnerabilities
Humans are susceptible to certain types of tricks and vulnerabilities, and so what we need to do is start putting processes into place to help guard against that. But those processes themselves can have vulnerabilities with them. So let's talk about some common process vulnerabilities.
In each one of these areas, we see a lot of common vulnerabilities, but we compensate sometimes by putting a process into place. One example might be a change management process, a process in which people roll out changes within our networks and within our infrastructure. The problem is that this process in itself could have some vulnerabilities in it — things that we have to change over time and make sure that we get rid of these vulnerabilities.
I find when it comes to processes and the vulnerabilities of those processes, there's really a spectrum. The spectrum starts on one side where nothing really exists in writing, or nothing's written down, or there's really no processes at all. So the process is non-existent. This is a problem, because not having any process at all, you can't really create any kind of consistency with it, and so that is problematic.
The other side of it is that you can create processes that are way too complex, that people don't really want to do, or time consuming, or become a hindrance to the business. What I find is that most people veer towards this side of it and just have some underdeveloped processes. Maybe they have some processes in place but they're just not really defined well and cause problems.
So our goal is to get things well defined, making sure that they're documented, making sure that they stay up to date, and making sure that they're the right process in place. These are the other things that I find: that things are not documented, or they're outdated, or they have the wrong process in place. They need to change the process. And so these are the things that create vulnerabilities with how we do things.
So where do we create processes? There's a whole course on that. I have a whole course on how to create these processes and these policies. We need to follow basic security principles, and there's a lot of basic security principles that we need to implement. We put those basic security principles in as some sort of policies that people are going to approve of, that the execs and the management is going to approve of, so that way we can reinforce this. And then we create these procedures that we'll follow in order to implement these processes, and then people will follow those. And then we'll use encryption and logging and monitoring alerts and SIEM to monitor, to make sure all of our processes are being done accurately.
A lot of this involves rolling out and creating a full security program. Once again, I've got other full courses on how to do this. So I could get real in depth into any one of these components. In fact, any one of these components could be a course in themselves.
Now, we put the process into place to create change, but change itself comes with a large amount of risk. Anytime we change things, then that can be problematic and create vulnerabilities. It adds a level of risk, and so one thing we need to do is just be conscious of that, which is one reason why we have a change control process. But even rolling out a change control process is a change in itself.
A lot of vulnerabilities come into place when we see staffing changes — when somebody moves up in a position, or moves into a different position, or maybe somebody gets hired, or maybe somebody gets fired. During those times, we see that there's potential for a lot of vulnerabilities to happen. For instance, if somebody gets fired and then they're mad against the company, but their account wasn't properly turned off, that can be problematic.
Many vulnerabilities could happen also when there's big changes to the organization. In fact, a lot of vulnerabilities can occur during this time. For instance, mergers. A merger is when two companies come together and merge together. Or there could be some sort of acquisition. Acquisition is when one company buys another company. And then divestiture is when a company splits into two companies. Anytime that all of this happens, there's really a lot of turmoil in processes and the way we do things, and there's a lot of vulnerabilities that open up during this time.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →