Calculating The Environment Protection Score (EPS)
This companion piece accompanies the web-based tool I’ve been working on for a few weeks, Environment Protection Scorer (EPS).
The EPS tool simplifies identifying the necessary cybersecurity controls to protect your business.
By providing a well-defined set of security controls, the EPS tool provides control recommendations that complement each other to help form an effective end-to-end control strategy.
The EPS is flexible in that it aligns with your risk appetite based on your chosen selection criteria, depending on your business needs.
What Is An Environment Protection Score?
First, defining “environment” in this context may help understand how the EPS relates to a given business environment.
With today’s modern ways of working, organisations worldwide focus on reducing capital expenditures and operational costs to support their business model while actively pushing to increase customer value and innovation.
Business Operating Environments - High Level Concept
This significantly increases cloud service adoption and distributed technology environments, which underpin these high-level business drivers. It enables highly available products and services and rapid scalability while decreasing the total cost of ownership (TCO).
At a high level, we can categorise these technology environments into four distinct areas, as shown below.
External Environment where customers, remote workers, contractors, and anyone can access your externally-facing applications, systems and networks.
Cloud Environment Public cloud services are hosted externally using one or more major cloud service providers (CSPs). Depending on your business needs and security requirements, infrastructure can be shared or dedicated (or a mix of the two).
Data Centre Environment (or “private cloud”): where internal systems, applications, and data are hosted and stored. It is often located in the same city/state as your head office and uses dedicated infrastructure to host internal company resources.
On-premises Environment: This is where users, systems, and applications are hosted on-site in the exact physical location of your organisation’s head office.
An Environment Protection Score (EPS) is a single, actionable score (Low, Medium, High, or Very High) that uses seven (7) weighted requirements to represent the level of protection (security control) aligned to your business environment needs.
A protection score is inversely correlated to the risk tolerance of an organisation.
For example, An organisation with a low protection score, as defined by the business leadership team, will translate to a high risk tolerance level. This is because a low protection requirement will result in a high level of risk, given the low level of security controls available to protect the business in the event of a cyber-attack or data breach.
The reverse is also true. A high or very high protection score will translate to a low tolerance for risk and, thus, require greater security control.
How Is The EPS Calculated?
The Environment Protection Score is calculated by weighing the specific selection criteria for the following seven key requirements:
Confidentiality Requirement (CR)
Confidentiality refers to limits on who can get what kind of information in this environment.
Low: Public information is generally not sensitive and has minimal impact/harm if disclosed.
Medium: Data is somewhat sensitive and should be protected from unauthorised access.
High: Data is highly sensitive, and unauthorised access could lead to serious harm, including financial loss, legal penalties, or severe damage to reputation.Integrity Requirement (IR)
Integrity refers to being accurate or consistent with the intended state of information. Unauthorised modification of data, whether deliberate or accidental, breaches data integrity.
Low: Data integrity is not critical, and minor inaccuracies or modifications would have little to no impact.
Medium: Data integrity is essential, and some inaccuracies could cause issues, but they would be manageable.
High: Data must remain accurate and trustworthy at all times. Unauthorised changes could lead to significant harm.Availability Requirement (AR)
Availability ensures that systems and data are consistently accessible and resilient, maintaining operational continuity even during disruptions.
Low: Occasional downtime is acceptable. The system or data does not need to be highly available.
Medium: Availability is essential, and downtime would cause some inconvenience or moderate disruption to operations. Limited downtime is tolerable.
High: Continuous availability is crucial, and any downtime could lead to severe consequences, including financial loss, reputational damage, or disruption of critical operations.Possession Requirement (PR)
Possession in this context is about the level of control you require over the system(s) and data in your environment.
Low: The environment contains non-sensitive data or systems where possession control is less critical. The impact of a loss would be minimal.
Medium: The environment holds moderately sensitive data or systems. While possession control is necessary, the impact of a loss would be moderate and manageable.
High: The environment has sensitive data or critical systems that need strong possession controls.
Very High: The environment contains highly sensitive data or critical systems that require stringent possession controls.Deployment Model (DM)
Deployment models define how resources are structured and managed across cloud and on-premises environments, offering varying levels of control, security, and flexibility.
Public: Cloud resources are hosted on shared infrastructure—accessible over the Internet, highest risk.
Private: Dedicated cloud environment offering enhanced control and security, either on-premises or hosted by a third party. Moderate risk.
Hybrid: A mix of public and private cloud environments offers greater flexibility and balanced risk.
On-premises: Locally hosted and managed within an organisation’s physical infrastructure, with the lowest risk.Supply Chain Dependency (SCD)
Supply Chain Dependency gauges the organisation's reliance on third-party suppliers and the severity of the business impact in the event of a disruption to (or via) third-party services.
Low: Low dependency on external suppliers; primarily self-sufficient.
Medium: Balanced risk with moderate outsourcing of services and software.
High: High dependency on third parties; significant risk if disrupted.Attack Vector (AV)
An attack vector is a method or pathway through which an attacker gains unauthorised access to data, a system, or a network to exploit vulnerabilities. Your application or network deployment model will determine/influence the attack vector.
Network: Exploitable remotely over the Internet or a network connection.
Adjacent: Requires access through a shared physical or logical network, such as Wi-Fi or Bluetooth, but not over the Internet.
Local: Requires direct access to the local device or system.
Physical: Requires physical access to the device or system.
Each of the above attributes has a numeric weighting assigned to each available option where the more risky option(s) have a higher weight, and the less-risky/more controlled options have a lower weight assigned.
Recommended Security Controls
First and foremost, I want to preface this section by saying that the calculator's recommended security controls are not meant to be a prescriptive guide to the Cybersecurity equivalent of Nirvana. As shown below, the EPS calculator's recommended controls are just a subset of the many security controls available in each domain.
My primary objective in developing these recommended controls is to provide a practical set of security controls that can add immediate business value, strengthen an organisation's security posture, and provide a pathway for a defence-in-depth security strategy that meets the required level of protection to suit the business's needs.
Recommended Security Controls: NIST + MITRE ATT&CK
It is always a challenge to strike the right balance between business drivers and robust security.
The most enjoyable part of this project was developing a control strategy that could provide the most robust defence for environments with a moderate to high risk tolerance (low to medium protection score), as these types of environments don’t always require a lot of defensive controls, it’s more about getting the most protection from a smaller set of controls. Quality over quantity, always.
However, as the protection requirements increase and the score rises, so does the depth of control coverage against the NIST CSF.
The Environment Protection Scorer contains twenty-two (22) security controls. I aligned it to the NIST Cybersecurity Framework (CSF) v2.0 and the MITRE ATT&CK framework to ensure optimal coverage and validity for each control against the modern threat landscape.
Each control contains tags to show additional metadata, such as:
NIST CSF Domain: “GOVERN”, “IDENTIFY”, “PROTECT”,…
NIST Control ID: “PR.AC-1”, “ID.SC-2”
ATT&CK Tactics: “initial access”, “defense evasion”, “lateral movement”,…
Each tag contains links to the respective NIST CSF categories and MITRE ATT&CK tactics for additional guidance on control implementation and the techniques addressed.
Conclusion
The EPS tool is a quick and easy way to get a robust set of security control recommendations based on a standard set of requirements used to gauge the level of risk according to your answers.
These controls will significantly improve your security posture when applied to the context of your organisation, the operational environment, and the tech stack.
This tool isn’t intended to be the silver bullet for security. Still, the control recommendations provide a solid roadmap towards a deep defence-in-depth security strategy aligned to the NIST and MITRE ATT&CK frameworks.
Head to my resources page to try the Environment Protection Scorer and see how these control recommendations compare to your environment!