Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Risk Management

A New Model for Cyber Risk Management: Observe, Orient, Decide, and Act

To respond to mounting cyber-attacks, advanced persistent threats, and insider leaks, enterprises and government entities need reliable, real time visibility into their IT security posture. Unfortunately, it can take weeks or months to detect intrusions using traditional methods, during which time attackers can exploit vulnerabilities to compromise systems and extract data.

To respond to mounting cyber-attacks, advanced persistent threats, and insider leaks, enterprises and government entities need reliable, real time visibility into their IT security posture. Unfortunately, it can take weeks or months to detect intrusions using traditional methods, during which time attackers can exploit vulnerabilities to compromise systems and extract data. To address these challenges, organizations are exploring the use of a military concept called the OODA (Observe, Orient, Decide, Act) Loop in their day-to-day cyber risk management operations.

The OODA Loop was originally developed by Colonel John Boyd, one of the most decorated fighter pilots in U.S. Air Force history. The concept describes the process needed to win at war. Boyd used the model to win aerial dogfights in Korea and Vietnam, and later to describe how to gain a competitive advantage in any situation. The OODA Loop is a succinct representation of the natural decision cycle seen in virtually every context. Many experts believe it can be used to identify, visualize, prioritize, and orchestrate the remediation of most cyber threats.

So what are the four steps of the OODA Loop and how do they apply to today’s cyber risk management practices?

Observe

In order to understand what “Act” (a.k.a. remediation actions) is needed to minimize an organization’s cyber risk exposure, observation is the first step. With so many organizations being overwhelmed with the volume, velocity, and complexity of internal security data, it has become crucial to streamline the observation process. For many enterprises, data overload has become the Achilles heel of day-to-day security operations. The

OODA Loop concept calls for automated aggregation of data across different data types; mapping of assessment data to compliance requirements; and normalization for ruling out false-positives, duplicates, and to enrich data attributes.

Orient

Many organizations have primarily focused on their internal security posture when it comes to cyber risk management and therefore have a difficult time prioritizing their remediation actions based on business criticality. Combining the OODA loop model with cyber risk management tools enables organizations to place internal security intelligence, external threat data, and business criticality into context to derive a holistic view of risk posture across networks, applications, mobile devices, etc. In this way, security teams can determine what imminent threats they face from cyber adversaries.

Advertisement. Scroll to continue reading.

Decide

In cyber war, decisions need to be made swiftly. The OODA Loop concept calls for applying advanced risk scoring and machine-learning technology to classify the severity level that individual threats pose to assets, applications, and business processes. This approach can be used to drill-down and visualize correlated data and application attack paths. Applying intelligence-driven analysis enables security operations teams to focus on risks that threaten the business and in turn significantly speed up the decision process.

Act

Increasing collaboration between security and IT operations teams, with one being responsible for identifying security gaps and the other focused on remediating them, continues to be a challenge for many organizations. In this context, the OODA Loop concept calls for combining workflow, ticketing, and remediation capabilities, assigning detailed remediation steps for each vulnerability and automating real-time risk management.

Using OODA as a blueprint, it’s possible to implement automated processes for pro-active security incident notification and human-guided loop intervention. By establishing thresholds and pre-defined rules, organizations can also orchestrate remediation actions to fix security gaps. Meanwhile, the OODA loop provides a way to measure the effectiveness of remediation actions and ensure risks have been successfully eliminated.

To implement the OODA Loop concept, progressive organizations are using cyber risk management software as an overlay to their existing security infrastructures. This approach provides the necessary aggregation, intelligence-based analysis, and orchestration capabilities to identify and respond to cyber threats early in the kill chain.

Written By

Dr. Torsten George is an internationally recognized IT security expert, author, and speaker with nearly 30 years of experience in the global IT security community. He regularly provides commentary and publishes articles on data breaches, insider threats, compliance frameworks, and IT security best practices. He is also the co-author of the Zero Trust Privilege for Dummies book. Torsten has held executive level positions with Absolute Software, Centrify (now Delinea), RiskSense (acquired by Ivanti), RiskVision (acquired by Resolver, Inc.), ActivIdentity (acquired by HID® Global), Digital Link, and Everdream Corporation (acquired by Dell).

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed the new CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybersecurity Funding

2022 Cybersecurity Year in Review: Top news headlines and trends that impacted the security ecosystem

Endpoint Security

Today, on January 10, 2023, Windows 7 Extended Security Updates (ESU) and Windows 8.1 have reached their end of support dates.

Email Security

Many Fortune 500, FTSE 100 and ASX 100 companies have failed to properly implement the DMARC standard, exposing their customers and partners to phishing...

Artificial Intelligence

Two of humanity’s greatest drivers, greed and curiosity, will push AI development forward. Our only hope is that we can control it.

CISO Strategy

Cybersecurity-related risk is a top concern, so boards need to know they have the proper oversight in place. Even as first-timers, successful CISOs make...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...