Compliance in Regulatory Frameworks with Lavish Jhamb and Nikhil Vaidya | Qualys QSC23
Nikhil Vaidya, director of vulnerability management at Elevance Health, and Lavash Jhamb, director of product management for compliance solutions at Qualys, discuss the complexities of compliance in the ever-evolving landscape of regulatory frameworks
Transcript
This is Textron tv. Welcome back to the QU Security Conference for the Americas. We're here with Nickel Baja, who is Director of Vulnerability Management for Elance Health.
And then we have Lavish Yam, who's Director of Product Management for Compliance Solutions at Qualys. I got that right. All right, gentlemen, we're talking about compliance.
Let's start with you for a second. On the face of it, it seems relatively simple. I, I run a scan, I'm supposed to figure out my compliance, I check the boxes, yes or no, and I go get it fixed.
It seems like in real life it's a lot more difficult than that. So what are the challenges? What goes on and what should people be thinking about?
Yeah, a hundred percent. So firstly, the issue is that there, there's so many requirements that you have to eventually comply with. There's so many regulatory frameworks that exist, and we as a company have contractual obligations with governments that we have to make sure we satisfy them in, in, in a timely manner.
So the ability to, uh, a, identify what those are and test against them in a timely manner is the actual problem, or even seeing them in a common spot. So that's, that's what people need to think about more is what exactly is it that you're looking to solve or you're looking to measure against. And then how do you measure against it?
Is the other big challenge that you, that you have Lavis you talked to a lot of customers. Yeah. What are they telling you?
What's stressing 'em out? 1, right? So there were multiple requirements in it.
You are complying with it. 0, the previous requirements. Some of them got restructured, some of them got deprecated.
There are new requirements that are added. Customers are freaking out. Like, gimme a solution that auto maps everything.
And I am like, I stay compliant. I do not need to change my compliance tools and do something else. Because if you're using some traditional tools, as you were saying, you're not mapping to the new requirements that are coming up.
You are just, uh, saying that, okay, this many are your mis confis that you need to fix, but you're not saying that, okay, this mis config can lead to PCI four auto failure. This mis config can cause HIPAA failure, right? So these, uh, you need to have some, some sort of compliance tool, which has this autocross mapping of your various mis configs or configs with lot of security, uh, like benchmarks and frameworks like N-I-S-D-P-C-I-D-S-S, hippa.
So you gotta have some solution like that. And that's what we, in my session as well, I said Qualys Compliance Solutions have this mapping of 20,000 not controls with 65 regulations. Thanks.
Um, you guys jointly did a presentation today. Give us the highlights of that. You know, I know you're a customer, so what brought you to Qualys and Sure.
So we, we've had a pretty distributed and a pretty well architected Qualys implementation, and we've been using it for, for a very long time now. But we were more like traditional VMDR customers. We had cloud agents deployed.
We used to do scans, but that was more vulnerability focused. Uh, at the beginning of the year, my team, uh, or my entire organization, we were handed over the secure configuration program to, to run. And, uh, we didn't know where to start, to be honest, right?
Because the technical configuration standard defining sat on another team. There was another team that managed the tool that ran checks against, uh, those, uh, controlled and compliance requirements that we had. And then when we looked at Qualys policy compliance solution, um, we saw an opportunity there to utilize all of the existing infrastructure, all of the existing scanners, all of the existing agents.
And, and the ability that they, that we get with Qualys to import all of these benchmarks that LAVISH was talking about earlier, right? And, and deploy them. It's, it just makes sense.
Mm-Hmm. So that's, that's the reason why we are migrating towards using Qualys more. We, we want to get a more return on our investment as well.
And, and all of this, like adding additional modules on top of what you like, what you already have deployed, it just makes, makes sense from a technical perspective. Uh, but from a people process and technology perspective as well, It's been a while since I've been involved in an audit, but as I remember the process, it was, we spent some months getting ready and everybody would send, you know, paperwork and we'd check every little thing auditor come around. And most, I think we passed most of the time, but, you know, honestly, we were compliant for about a couple hours later.
And then, you know, somebody changed something. So, so how do we kind of, so When you say paper spreadsheets, things have changed. Now the compliance, uh, regulations have become much more stringent.
Every role wants, ORT wants to see different kind of, uh, compliance posture, for example. They need to have some comprehensive reports now or dashboards that tell you what's the overall posture posture without going into in depth, right? The CSOs want to know, am I, am I at the risk of compliance failures or not?
What's my passing posture? Is it 86% or less? Right?
So, uh, now the tools, the paperwork, the spreadsheet has, uh, is gone now. So it's more of dashboards, click there, NISD template fade in, send me a report of all the assets in the organizations. Do we have inventory in place?
Yeah, we call it css. A do we have vulnerability management in place? Yes.
0, it wants you to have inventory. It wants you to have, uh, this, uh, vulnerability management. It wants you to have patch management, fix all the patches within 30, 30 days.
So, uh, things have moved much more dynamic. And if you can show via comprehensive reports that you are filling in all the gaps via one solution, single pane of glass, that is what required by the auditors these days. It used to be that, that audit I described was an event.
Has this kind of morphed into a continuous process? I mean, basically you have to know what's happening at all times. It does.
Uh, compliance measurement has now become a more of a continuous monitoring thing rather than something that you do every three months. When an audit, it comes your way. So today, what most CSOs and what most teams are looking at is to say, okay, when I drift against what I have defined, I want to know that soon.
So I don't have to wait three months for that to turn into a finding or for that to be a hole that can be exploited by a vulnerability for that matter. So for example, it, I, we see VM and compliance as two sides of a coin, which many people don't, or I don't know if they do, but they should. It's, it's like saying if you have a compliance issue or a misconfiguration that can turn into a vulnerability pretty fast and having that compliance problem can actually increase the risk of that vulnerability itself or can reduce it if you don't have it in place or if you have measures in place.
But, but the ability to monitor continuously for both of these things at the same time is, is something that, you know, everyone should be looking at today. Well, how automated can all this stuff get? I mean, we hear a lot about AI these days, but you know, how much of a manual task today can get automated and how can we make this whole thing less painful?
So if I, if I talk about the manual process, number one, it's very much time consuming. And number two, it's going to give you, uh, inaccurate results at time because of human errors and everything. And it cannot happen at continuous basis.
So automating the compliance is a must have today. And the tools like quality's policy compliance, that really helps you to add your asset tags in your inventory and then you're good, right? You just say, I want to monitor this for this particular compliance because we have all of those mandates.
As I said, 65 plus security benchmarks. Things are all mapped and the policies do exist. Nine, uh, there's a big number of policies.
I forgot 9 97 to be exact. There are 997 policies for various benchmarks available. Now, why do we have all of this so that you don't have to do anything manually.
Those things are present. Just have your asset tagged. All of the asset tags, call it like my PCI scope.
You have 200,000 assets in your PCI scope, import a policy PCI policy from the library, add that asset tag into it and your 2,200,000 assets will be scanned in 30 minutes and you'll get to know the compliance posture. This level of automation mapped with various regulations is something that was needed. And that is something that we are providing today.
We have this term GRC, governance, risk and compliance. You know, the one thing that's not in there is security. Um, are these things starting to converge more GRC and security?
Is it becoming one motion? And how is that evolving? They are.
So we have to work closely with our GRC teams because they're the ones who sometimes are the ones defining what these control standards are. So we have to work closely with them. 'cause they're a governance function at, in the end, if they are defining what these standards are, we are the ones implementing them.
So security is responsible for, let's say traditionally security used to be responsible for fixing the issues that were found, but now the security teams actually have to work with the governance team, with the risk team to say, what can we do to make sure we are looking at the right things? And, and that is an important factor to consider when working closely with the GRC teams. Is this a more cost effective way to think about doing this whole thing?
Because as I understand the platform, there's a single agent, and if I go with all this other stuff, I get 5, 6, 7, 8 different agents doing different things. Exactly. You are to the point.
Alright, can I streamline this thing? Yeah. So the thing is not only the cost, I I will say I'll keep cost at the end, right?
Cost is for CSOs, I'll be talking more technical over here. If you have multiple agents, number one, they're not compatible with each other most of the times. And one could be hampering the other as well, right?
And it could be opening back doors. For example, if you have one agent for real time monitoring and is it's hooking your kernel, right? It's hooking into Kernel and you have another agent that wants to talk to Kernel, it'll not be able to ever, so the other agent will never, never get the results that it want to.
So having one agent in place doing all the activities, like s does, vulnerability management, inventory patch management file integrity monitoring, configuration assessment. If you do all these activities with one agent, no need of siloed solutions, you are secure, right? There is no one else tapping into your communication and the other party is cost effective.
Yeah. One of the issues that I think people encounter out there is, while, you know, if you fail the audit, people will yell at you, but if you pass the audit, no one stands up and cheers. So how do we make this, you know, something that the business appreciates more?
So what we've utilized more is, um, showing all of this data in a single pane of glass, be it within the quass platform. But the real value that we are getting out of this now is with our ServiceNow integrations. So we have dashboards that are built in that actually drill down or drill up to like a CSO level or their level where they can click and say, okay, tell me what my, what, what percentage is this group at?
So if for some, for some reason their number is at 80%, but they're able to like drill it down into, let's say director one is at 50%, but director two is a hundred percent, they're actually able to go and tell the guy like, Hey, you are the one bringing my compliance down. It's kinda like a game. I, I don't wanna call it like a wall of shame or anything like that because it's not, uh, but it's, it's like, it's like the more you gamify it, the more you make it interesting for people to say, okay, my goal is for you to go from 50% to 80% today.
And those are measurable goals. And as long as you set them that that actually helps you, you know, well it helps on your performance reviews and everything as well. But eventually it's, it's kind of like saying if you want to increase the posture of the organization by 20%, that's what we need to do.
Do I get a prize? You can, Do you have the budget for it? Are you starting to see more customers?
Essentially what they're doing is kind of converging security operations, governance and IT management a little bit more. So are you seeing more customers do something similar? Oh Yeah.
Yeah. So a lot of customers that we are encountering these days are coming from different platforms to be honest. And they're saying, okay, we are using call VMDR because VMDR is big, right?
Everybody uses call VMDR, it's a top product. We all know that, right? So earlier they were using solution A for file integrity monitoring solution B for configuration assessment, solution C for something like patch.
And then they were using VMDR on like below it, everyone was using call VMDR. Now, now they're seeing the value of this agent. They're coming to us and say, okay, gimme one consolidated solution.
I don't need multiple agents on my list. Right? So that is a kind of, uh, conversation that we have been, we have been having.
And we had to write tools, literally we had to like write tools that convert their policies that we are, that they're using right now to call us policies so that they, they don't change the attack surface, they monitor the same stuff, but with call now, right? Remove the earlier they didn't have hours. So you went down the compliance rabbit hole, what was that, six months ago?
A year ago? Mm-Hmm. Um, what do you know now that you wish you knew then?
Interesting question. Um, I don't know. I, compliance is is a complicated subject, right?
Like when we first moved into it, I was, I was of the same opinion that you, you brought up at the beginning. Like, okay, it's pretty simple. Check a box that that's what you need to look at.
But when you get into the weeds of, you know, what do these technical configuration standards eventually map to that mapping exercise that that's really been a pain to, to do. But if that's an automated solution that we have out there, that that definitely helps. So on, on the brink of it, it might seem a straightforward job, but then when you see that one control can apply to 10 different policies or 10 different regulatory requirements that you have, and we need all of those mapped, it's, it's kind of like a exercise in pain management more than anything else after a point.
Mm-Hmm. You clearly track a lot of the compliance regulations. Are they getting tougher, stricter?
Are the penalties starting to add up? What, you know, what, what should we be thinking about here? If you're not compliant, it can lead to like $4 million of, uh, loss at the point, right?
Revenue, uh, the fines are increasing GDPR, right? Um, if you, in the European country, it's mostly GDPR that you need to follow, you fail hipaa, right? These penalties and penalties can result into around two to 10% of your profits per year.
Right? This is big, big amount that we're talking about in terms of penalties and the regulations. They're getting more and more stringent.
0, right? 0 and then I got to know that now it moves towards the container space as well. Earlier it was all talking about the technologies being used in the past, like virtual machines and all.
But now the cloud thing coming in, the containerization coming in Docker, Kubernetes, you have these stringent policies that your cloud environment should also be secure. You should, earlier it was scan six months, every six months we are good now scan every four hours or less, right? Earlier it was patch when your audit is there or patch whenever you want to, or whenever you can today patch as soon as Tuesday patch comes in, right?
So the thing is going more towards dynamic environment and continuous also the latest technologies that are coming in, like cloud containers, et cetera. You've got to be compliant for those as well. And trust me, having uh, runtime security on containers is not an easy task.
Yeah. As I said, it's been a long time, but we used to kinda shop around for auditors 'cause we kind of knew that some were tougher than others. Um, are they, are the audits more consistent these days or what's, you know, what should I be thinking about when I look at who's coming in?
Uh, It, sometimes it's a flare of the month kind of thing. Um, I I, I don't wanna bash auditors or say anything bad about them, but, but in general, most of them have been streamlined into knowing what they need. Uh, the requirements are decently clear, I would say, uh, given that their audit requirements.
So it's, it's not, they're not like super clear, but I I think most people get it right now. So I, I don't think it's, uh, it's that sort of a situation where it is shop around these days, but some people are more comfortable with certain auditors, so you could keep that relationship going. But for the most part, I think it's, it's pretty much standardized now.
Mm-Hmm. Do you think the auditors are gonna get better at tools? 'cause you know, at the end of the day they have tools and so what does that look like?
Yeah, they're getting more smarter, right? So, uh, it's not like earlier you show them the dashboard and they're good. Now they want the demos.
That's what we have seen, right? So we were like, okay, we are doing this, we are doing that and this is the end result. This is the dashboard that we got.
Like, no, show me the demo. How did it work? How did you get to this widget in this dashboard?
This is the kind of audit that we face these days. Because at the end of the day, we have to be transparent. If they're writing something about us, if they're saying, you're past this audit, they, they also have to justify that.
Yeah. And, and we are getting a, we are getting asked a lot more questions like, yeah, how, how, how are you monitoring? Earlier if we were saying, okay, we're scanning every four hours today, they want proof saying that, okay, show us that you're scanning every four hours.
Mm-hmm. Show us that you're scanning all of the inventory that you're supposed to be scanning. So, which is not a bad thing.
They need to be asking those questions, but I think those are coming up a lot more than they used to. Yeah, that's what I wanted to convey when I was saying, What is that one thing you see customers doing that just makes you shake your head and go, I can't believe we're still doing this, guys, we're better than this. Uh, with the, with the tools in place, I think it's, uh, you, you are, you're bound to give the results to your auditors, right?
Because, uh, they also have to prove this, justify this to their organizations. So I think, uh, uh, that you gotta have some automation in place to give them the, uh, dash, give them the comprehensive reports, which can then be communicated to every level. Because communication, basically in compliance is multifold.
There's a lot of anxiety when it comes to this stuff. What's, you know, last question to you. What's your best advice for coping with the anxiety?
How do I reduce the stress in this whole process? It gets better. Use our solution.
You'll not have anxiety. Yeah, I Mean, in, in general, if you put the right people, process and technology in place, think things will get better. As long as you have a clear vision of what you want to do.
If you know what you need to monitor, if you have the right tools in place, uh, if you have the right communication strategy in place, I think, I think you're doing the right thing. So keep on, keep on doing the right thing. Fight the good fight.
You know, you, you've heard all of those words before, but don't wanna be like a buzzword magnet or anything, but, but essentially things do get better. This guy is stealing everything I wanted to say. There you go.
Well, folks, it's always gonna be a certain amount of anxiety when you do anything that looks like compliance or audit. But the more you do it, the less stressful it becomes. And in most cases, things are not nearly as big and ugly as they seem when you first get started.
Gentlemen, thanks for stopping by. Thank you. Thanks.
Thank you.





