Root cause analysis is not just about figuring out the technical problems that may have occurred, as Forbes describes. Technical problems rarely exist in isolation. They often occur within the context of a larger process or workflow. If that process is inefficient, it can create conditions that make technical problems more likely to occur, or harder to detect and fix.
So many interesting interactions with peers over the last few months are making me realize that there is still a major disconnect between finding and fixing vulnerabilities and the culture that drives it. Too many security leaders don’t care about culture and care more about resolving risk. But I would argue that creating a positive security culture will naturally help to address vulnerabilities faster (
mean time to respond/remediate [MTTR]) and create less vulnerabilities as time goes on (
vulnerability escape rate [VER]). Why can’t we get over this hump?
*** This is a Security Bloggers Network syndicated blog from AppSec Observer authored by David Lindner, Director, Application Security. Read the original post at: https://www.contrastsecurity.com/security-influencers/cybersecurity-insights-with-contrast-ciso-david-lindner-09/13/24-0