Security 101

How Do You Get a Security Control Approved by the Change Advisory Board?

Stage and test the control, then bring the board measured results. The same board can then review the changes that never came through it.

To get a security control approved by the change advisory board, stage it in a test environment, test it against realistic scenarios and bring the board the results, including the friction it adds. A board deciding on a working, measured change has much less to weigh than a board asked to imagine one.

The same board can also take on the changes that never reach its agenda, by reviewing what changed in the tenant since its last meeting.

The idea in brief

  • Change boards protect availability. A new security control can look like a risk to productivity.
  • Proof changes the conversation. Test results replace the fear of the unknown with a measured cost.
  • Some changes skip the board. Edits in an admin portal and changes made by software may never be proposed.
  • The diff closes that gap. Comparing the tenant with an approved baseline brings those changes to the board.

Why do security controls stall at the change advisory board?

In many organizations the change process exists to prevent downtime and disruption. A control such as a help desk callback or an extra MFA prompt adds a step for users, so the board weighs a risk that has not happened yet against complaints it can expect right away.

69%

Share of employees in a Gartner survey who said they had bypassed their organization’s cybersecurity guidance in the past 12 months. The survey covered 1,310 employees in May and June 2022. Source: Help Net Security.

That concern is reasonable, and it often ends with a compensating control such as more training while the original gap stays open. Our post The Change Management Wall describes how this plays out in the meeting.

How do you stage a security control before asking for approval?

  1. Build it in a test environment. Configure the control in a test tenant or a pilot group, using the same settings you plan to deploy.
  2. Test it against realistic scenarios. Run the attacks the control should stop and the everyday tasks it must not block, and record the results.
  3. Measure the friction. Time the extra steps users will see and note which groups they affect, so the board sees a measured number.
  4. Bring the results as a go or no-go decision. Present the working control with its test results and the rollback steps you tested.

Accelerynt calls this approach the Active Assurance Model, which moves from validating the gap to staging the fix and then governing it once it is live. For an example built on the help desk, read how to protect the help desk from social engineering.

What does the board see with a proposal and with a staged control?

Board questionProposalStaged control
Will it work?A plan and the expected resultTest results against realistic attacks
How much friction will users feel?An estimateA measured figure from the pilot
What could break?Unknown until rolloutKnown from the test environment
Can we roll it back?A rollback plan on paperA rollback that has been tried
A staged control turns a debate about what might happen into a decision about what was measured.

How should a change board review changes made outside the process?

Change boards review the changes people propose. Changes made by hand in an admin portal, or by software acting on its own, may never reach the agenda, and they can weaken a control as much as a rejected proposal can.

Our post Guarding the Wrong Door argues for giving the board a second job. The board declares a configuration baseline for critical services, compares the tenant against it, and decides for each change since the last meeting whether to keep it, revert it or promote that kind of change into the gated process.

  • Alert on the changes that cannot wait. The time between a change and the next meeting is exposure, so changes to the most critical settings should raise an alert when they happen.
  • Make the diff easy to produce. A declared baseline and a tool that compares the tenant against it keep the review short.

For the keep, revert or promote decision in detail, read what to do when configuration drift is detected.

Where does the Accelerynt Security Platform fit?

The Accelerynt Security Platform records configuration changes with before and after values, when they happened and the account responsible, and tracks each event from detection through remediation. That gives the change board its diff without anyone assembling it by hand.

Its What-If Simulator™ lets your team remove a finding and see which attack chains break before making the change, which is useful evidence to bring to the board. The platform works on read-only permissions, so it never changes your tenant itself. For how policy changes affect sign-in, read how Conditional Access policies are evaluated.

For testing controls between audits, read whether passing a security audit is the same as being ready for an attack.

Frequently asked questions

How do you get a security control approved by the change advisory board?

Stage the control in a test environment, test it against realistic attacks and normal user tasks, measure the friction it adds, and bring the results to the board as a go or no-go decision with a tested rollback.

Why do change advisory boards reject security changes?

Change boards are usually built to protect availability, so a control that adds steps for users looks like a risk to productivity. Without test results, the board weighs a possible breach against certain user complaints.

How should a change board review changes made outside the change process?

Declare a baseline for critical services, compare the tenant against it, and review each change since the last meeting. Keep it, revert it, or promote that type of change into the gated process.

What is the Active Assurance Model?

It is Accelerynt’s approach to closing a security gap with proof. You validate that the gap exists, stage and test the fix before asking for approval, and govern the control once it is live.

Talk to a Microsoft security engineer

We work inside your Microsoft environment, with your team, and show you where to focus first.