Could you describe a challenging opportunity as an oxymoron? If so, then Nexor has embraced the challenge and delivered, particularly the Information Assurance and Cyber Risk team where we have had to adapt in the way we deliver Information Assurance services to our customers, whilst keeping them on a leading edge of performance. A significant driver for change was Secure by Design (SbD), launched in July 2023, by the MoD. However, customer requirements continue to mandate the use of the NIST Cyber Security Framework (CSF) and operating in agile environments to fit customer needs often requires modifications to methodology, while remaining compliant and risk aware. These are examples of successful approaches to strategy (SbD) and methodology (NIST CSF). If nothing else, we must remain cognisant that ‘one shoe does not fit all’ and there are often circumstances that demand assurances when operating within the ‘grey’ where neither strategy nor methodology quite align to a desired result.
Research and Innovation (R&I) style projects, where Nexor have strong experience, never really have the appetite (or time) to apply commonly practiced and preferred strategies and methodologies for the implementation of a robust Information Assurance process. R&I projects are managed to maintain momentum and ‘fail fast’ through pragmatic solutions rather than attempting compliance with ironclad principles. There is no explicit guidance on how to approach Information Assurance in experimentation style projects: One of the challenges in a world driven by Minimum Viable Products (MVPs) and Agile. Even SbD assumes the development of an actual capability and, whilst many components of SbD are relevant, following the full process is not suitable for rapid pace prototyping and experimentation.
Nexor’s consultants have been solving the Information Assurance challenges in the ‘grey’ using a more dynamic approach applicable to any project, organisation or customer requirements across any industry. Using an approach that begins with a clear focus on an overall risk profile, Nexor assimilates a holistic evaluation of all aspects of Information Assurance balanced against determined risk appetite across timescales to assess and prioritise the risks at any given point of maturity or development.
Dynamic Assurance Processes (DAPs) can supplement any other assurance process rather than replace them. Considering SbD, for example, the common principles remain the same; most notably that the Senior Risk Owner (SRO) is accountable for security risks. The ‘risk on a page’, an element of the DAP process, has proved to be a very useful tool for SRO discussions and approvals. Similarly, DAPs can be adapted for ‘System of Systems’ type programmes where a number of project risk profiles feed into an aggregated programme or enterprise assessment.
Nexor’s expertise and refinement of DAPs has proven essential in proportionately managing the security risks within cross-industry customer programmes and projects. This approach has also improved understanding across multi-disciplinary teams and facilitated ongoing momentum in managing complex tasks.