Defenders think in lists. Attackers think in graphs
blogs.technet.com
blogs.technet.com
Assuming basic competence (i.e., neither blithering ignorance nor any sort of extreme skill), both sides are well aware that it's a graph. If the defenders have a list, well, it's because they have responsibility over all the things and the list is useful, because nobody is going to do something like "apply a patch" based on literally doing a depth-first traversal of the graph or something.
- Hosts which process credit cards (PCI)
- Hosts which reconcile the general ledger (SOX)
- Hosts with medical data (HIPAA)
- Hosts with student data (FERPA)
The problem is that while the security of the enumerated hosts is taken quite seriously, systems which have security trust relationships which grant access to the enumerated hosts are not locked down. - PCI Payment Processing Application server: locked down.
- CI system with deployment keys to said host: zero authentication.The actual point Lambert seems to be making is, "Recognize the existence of security dependencies between your assets." I wouldn't be terribly surprised to learn that there are a number of security professionals who fail to do this, but I'm not surprised to learn there are well-paid programmers who can't do FizzBuzz either. It's not a useful thing to point out unless most of your audience isn't already aware.
The remaining 2% include the KDC, the build system, and the default shell servers for dev and ops. To catch this slip-up, I have to understand the dependencies that even the supervising managers don't. And I have to be able to explain such to management. Every time.
I sympathize greatly with the point the author's making. Like him, I don't have a fix in mind.