Point A Before B
You don’t want to know how many prompts it took copilot to create this…
Think of the last time you opened up Google maps (or Apple maps for you savages), dropped in a location and hit “Go”. All you really needed to understand was your destination. The map application knew your start, any required detours, tolls, dirt roads, etc. Decades ago this was not the case. I remember having to carry atlas maps, stopping for directions, printing off MapQuest directions, and not being able to rely on a mobile application. In order to get from Point A to Point B (or C or D etc), you had to know Point A.
This can be applied to almost anything in life as well. Hiking, weight loss, building legos, but I want to apply this specifically to IT and Security Architecture, surprise surprise, specific to DLP. Go get a bevy, this one will be good.
The Why Behind Point “A”
Pulling back in my parable of “Google Maps”, knowing Point A is important, because if it’s not known and taken into account when trying to get to Point B, there could be potentially catastrophic results. Example: I live in the great state of Michigan. I cannot get to the Upper Peninsula by car without leaving the state except for going over the Mackinac Bridge. If I wanted to visit the Porkies (Porcupine Mountains), I would absolutely have to cross the bridge.
Of course, I am fully well aware that I exist in the Lower Peninsula without ever crossing the bridge, in fact, if you blind folded me, dropped me off anywhere in the state I could still probably tell you this (thanks Geoguessr), but bear with me. The critical point of crossing a bridge to get to my Point B, is relevant because I know my Point A of my existence in the Lower Peninsula.
The same is absolutely true of creating infrastructure, or policies in IT and Security.
Your director comes to you one day and asks you to “Make the wifi better!”. You may sit in a part of the building with perfect signal, so it may not even be something you’re aware of. But, by process of signal mapping and wire chasing, you find a dead spot by his office. Boom. Point A.
Alternatively, bringing this relevant to the site, your CISO comes and tells you to deploy DLP org wide. My mind immediately goes to questions like “What’s currently out there?” or “What budget, design, tolerances can we take into account?”. Anyone can implement DLP. It’s whether or not that implementation is tailored to the goals of the organization, that makes it valuable to the stakeholders. So, if you’re ever in the position I was in, that is standing up DLP from a mostly clean slate, ask questions and determine your Point A.
Don’t Limit to Point B
If you asked, most people would say the world is getting more complex, in more facets than one. Expecting your Point B to be the grand finale might be leaving out intricacies or complexities out of the equation. Applying this again to the DLP discussion, I can absolutely block everyone in the org from sending sensitive information outbound. But things are not that simple, anymore.
Perhaps blocking any external sharing is point B, only to build out more controls to whitelist certain individuals to be able to send specifically labeled data outside the organization, which adds Point C, Point D and so on.
Also, when you start whatever process, project, or goal you seek to complete, your Point B might actually be the end goal. However, expect (especially in complex environments) other points or pit stops to creep in. PMs would call this scope creep, though I find it more appropriate to call this “I drank all of my pop/water/coffee too quickly and now I have to use the restroom.”.
Road Blocks in the Way
Inline with accepting the possibility of “pit stops” or scope creep, there may actually be hard stops or road blocks.
Take for example, you’re driving to a wedding across the state/country. The wedding is Point B, right? So you’re driving to Point B, only to get stopped by massive construction. You miss the wedding entirely, because of this road block and lack of planning. In this case you might have even known “Point A”, perhaps you didn’t consider the path to Point B or C.
If I know how to develop a DLP policy and I know the overall end result of the policy, great, but I might be missing some important details in between, like testing, identifying exceptions, etc.
Finito
Well, I hope this was useful to someone. It’s something I had to process on a near daily basis when coming into my new role. It’s helped me immensely in situations where I wasn’t exactly sure how to get to the final product.
Even in times where I knew how to get there, it’s slowed me down enough to process small road blocks that might come up. For analytical thinkers who also seek to drive progress, remembering your Point A is truly a skillset most companies should search for. Until next time!