SMB1001 and the Role of Identity Security

SMB1001 is an emerging cybersecurity standard which has gained significant traction, mostly because your clients are now demanding it. It’s a different approach to cybersecurity standardisation and I’ll explain why later. The standard functions as a framework and aims to guide small and medium enterprises to a higher level of cyber maturity through tangible and realistic security controls.

This contrasts to frameworks like ISO 27001, which are too robust and costly to maintain for many SMBs. This brought into question whether cyber resilience was being achieved, and if organisations were losing agility at the expense of red tape and cumbersome process.

Tell anyone that’s been through ISO 27001 certification that you’re starting that journey and they’ll just look at you with sympathetic eyes.

Identity Security forms a core pillar of any serious cyber security framework, and SMB1001 is no different. In this article, I’ll list the cyber security controls relevant to identity and what to expect in addressing them. Be aware, SMB1001 covers a lot more ground than just identity security controls, beyond the scope of this article!

To make sure nothing slipped through the cracks, I went old-school with my approach. After Assertiv purchased the standard, I printed the whole thing, grabbed my pen and highlighter and read it cover to cover (I do have a life, I swear). I took this bullet so you don’t have to.

Reading Standards
Going through standards the old fashioned way

So why is SMB ‘different’? It’s in the approach to certification, it’s a 5 level model, which the standard creatively names level 1 to 5, but is now referenced in the industry as the marginally more interesting; bronze, silver, gold, platinum and diamond.

Level 1 (bronze) is a basic level of cybersecurity control, and this progresses up through the tiers to Level 5 (diamond) which is far more comprehensive and covers more ground.

Each level offers a certification, which is overall easier to attain than ISO 27001, but the controls are real and tangible. Don’t assume you’re taking a walk in the park.

Level 1 to 3 can be ‘self-attested’ by a company director, and 4-5 require a third-party auditor to certify your controls.

SMB1001 casts a wide net across the cyber spectrum, and you must certify your whole organisation (unlike ISO 27001 which can be scoped down).

At Level 1 (Bronze), organisations must implement the following rudimentary identity controls:

  • Demonstrate strong password hygiene across the organisation
  • Security training for all employees which may involve identity security best practice for end users.

At Level 2 (Silver), all controls from level 1 must be met, plus the following:

  • Ensure regular employee accounts do not have admin privileges
  • Ensure all employees have their own account and password sharing is eliminated.
  • Implement a password manager
  • Enforce MFA on all employee email access
  • Confidentality agreements must be in place for all employees, contractors, and third parties

So that is a reasonable jump from level 1 to level 2 with a decent level of maturity for smaller organisations which may require some re-work to existing processes and implementation of new technologies.

Level 3 (Gold) requires all previous controls plus:

  • Multi Factor Auth on all business applications and social media accounts
  • Cyber insurance (which quite often has their own identity security requirements before issuance)
  • Implement a cybersecurity policy

From here on, remember that Level 4 and 5 require third party auditing of your controls and cannot be self-attested.

Level 4 (Platinum) requires all previous controls plus:

  • Management of remote access cloud credentials, e.g. implementing least-privileged principles, vaulting secrets, use federated identity (e.g. Single Sign-On) and phishing resistant MFA.
  • MFA where any important information is stored
  • MFA on VPN and RDP connections

To pass auditing organisations need to demonstrate and prove the existence and effectiveness of the controls.

Level 5 includes all previous controls plus:

  • Social engineering testing
  • RDP can only occur over a VPN
  • Implementation of a response plan for cyber-related incidents – which may involve rapid response to identity management.
  • Police vetting on all users holding admin or controlled access.
  • Testing of the incident response process.

Each of the controls above have criteria to meet at a more granular level, far beyond the scope of this article. For example, assuming you have great password hygiene may not mean you meet the requirements of forcing password change on device first-use, implementing strong passwords or expiry, ensuring employees have home Wi-Fi devices password protected, password protecting personal devices and rotation of passwords after a suspected breach.

Controls at different levels also have additional criteria to meet. E.g. At Level 3 (gold), the Password Manager requirement extends to eliminating passwords through Single Sign-On/SAML, using FIDO2/WebAuthn for Passwordless, and implementing phishing-resistant MFA. This isn’t a requirement at lower levels.

Overall, I believe this is a great step towards lifting identity security standards for the smaller end of town. For years, identity vendors have ignored SMBs and SaaS applications only offered strong security to enterprise customers.

SMB1001 rips up the traditional playbook and shows that smaller orgs can demonstrate maturing cyber posture.

Furthermore, the SMB1001 standard is ‘dynamic’, meaning it’s routinely updated and modernised, as today’s controls may not address tomorrow’s threats. This means organisations must recertify yearly to stay up to date.

If you’re a company director or responsible for information systems at a small or medium enterprise, look at SMB1001. The roadmap provides a clear path to demonstrating to your customers that you take the stewardship of their data seriously.

As with anything in this arena, “going it alone” is definitely possible. But it’s always more comfortable to travel this path with someone who’s seen it before. If you’re finding it hard to implement these controls, get in touch and we’ll guide you through a clear strategy to accelerate your certification.

Share this post

Ready when you are, for a discussion about how we can help.

Copyright © 2024  •  Contact Us  •  Privacy Policy         

Discover more from Assertiv

Subscribe now to keep reading and get access to the full archive.

Continue reading