One of the primary reasons that the Bitsight Security Rating is widely respected and closely correlated with real-world security outcomes is the scale and sophistication of our asset attribution capabilities. In a recent post, my colleague Francisco Ferreira shared an update on the momentum building with Bitsight Graph of Internet Assets (GIA), the AI-powered engine we use to map assets to organizations and build our Ratings Trees. As a follow-up to this, I’m going to dive deeper into a specific area where asset attribution can be particularly nuanced: assessing service providers’ security posture. This is an area where we have worked closely with leading cloud service providers like Amazon, Microsoft, and Google for years to continually refine our approach and extend it to thousands of service providers globally.
Key takeaways
- Asset attribution for service providers is complex, since they operate under a shared responsibility model where many of their associated assets are under the control – and security oversight – of their downstream customers
- Through a collaboration with leading cloud service providers that began in 2022, Bitsight developed a framework for excluding assets with delegated security controls from Bitsight Rating calculations
- In the years since, this model expanded to include other types of service providers operating under a shared responsibility model with customer-controlled assets
- Bitsight’s next-generation delegated security control framework, which was introduced in late 2023, has now scaled this capability up to thousands of service providers globally and contributed to a 50 percent increase in subscriptions to service provider security ratings in the Bitsight platform
First-in-class industry collaboration with leading cloud service providers
Asset attribution for technology service providers and IT infrastructure service providers is a complex task. After all, organizations in the cloud service provider, internet service provider, and telecommunications spaces operate vast infrastructure, and due to the nature of the services they provide, many of the connected assets in these environments operate under a shared responsibility model with customers. In this model, the customer, not the service provider, is responsible for certain controls. For example, while cloud service providers like AWS, Microsoft, and Google provide the underlying computing infrastructure for their customers, the functionality sitting on top of it and, by extension, the security posture of these assets, is primarily the customer’s responsibility. Similarly, internet service and telecommunication providers have little control over the systems that their customers connect to their networks – or how secure they are.
This poses an interesting challenge as organizations like Bitsight assess the security posture of service providers. On one hand, service providers have a responsibility to guide their customers toward secure computing practices and compliance with acceptable use policies. At the same time, the security posture of individual customer assets is not necessarily reflective of the service provider’s overall security execution.
Bitsight was the first in the industry to develop a more sophisticated approach to asset attribution for service providers. In 2022, we began a collaboration with several top-tier cloud service providers – including Google Cloud Platform, Microsoft Azure, and AWS – to better understand the problem and develop an initial model for identifying cloud assets with delegated security controls. We implemented this model to better assess cloud service provider ratings and soon after rolled it out for dozens of additional cloud service providers. This provided an immediate impact by giving organizations using or considering a cloud service provider a more accurate view of the provider’s security posture and execution.