Here at ECS, we understand the importance of maintaining robust IT processes to ensure smooth operations and protect against potential threats. To help achieve this, we've developed the DREAM framework, a comprehensive approach to managing IT processes. DREAM stands for Deploy, Review, Enforce, Alert, and Mitigate. Here's a detailed look at each component and how it contributes to maintaining a secure and efficient IT environment.
D.R.E.A.M.
Deploy
The first step in the DREAM framework is Deployment. This involves the initial implementation of protective measures designed to satisfy controls in compliance frameworks, reduce the attack surface, and guard against potential attack vectors. Whether it’s deploying new software, hardware, or security protocols, the goal is to establish a solid foundation of protection.
- Creating baselines for new devices
- Making the initial configuration changes in cloud systems
Review
Once protective measures are deployed, continuous monitoring is essential. The Review phase ensures that each protective measure is actively monitored across all associated entities. This step is critical to identify any deviations from the expected performance or emerging threats that could compromise the deployed protections.
- Creating a monitor in your RMM tooling to see if your change was effective
- Using vulnerability management tooling to see if protections or updates are applied
Enforce
Enforcement is about maintaining the integrity of the deployed measures. This involves implementing systems and policies to prevent the subversion or circumvention of these protections. Enforcement ensures that the deployed measures remain effective and that all compliance requirements are consistently met.
- Creating and applying self-healing scripts for failures in monitoring
- Creating group policies, configuration policies, or compliance policies to force settings to specific values
Alert
Despite the best efforts in deployment, review, and enforcement, there may be instances where protections fail. The Alert phase is designed to detect these failures promptly. When enforcement mechanisms fail, this phase ensures that the failure is detected and creates actionable alerts for the IT team to address the issue. Rapid detection is crucial to minimize potential damage and restore protections swiftly.
- Creating tickets, alerts, or other notifications when enforcement fails
Mitigate
The final phase is Mitigation. This involves responding to and resolving alerts in a timely fashion. IT agents must act quickly to solve the issues raised by alerts, ensuring that protections are reinstated, and any potential vulnerabilities are addressed. Effective mitigation ensures that the IT environment remains secure and resilient against threats.
- Someone needs to be engaged in investigating alerts that aren't resolved, starting with the most common and easiest to resolve alerts
To be effective, the DREAM framework should be applied to any potential problem in the environment. Organizations should use threat intelligence tooling, cybersecurity frameworks, best practice recommendations from trusted sources, as well as their own experience to determine the issues to be addressed by this framework. As your team starts to implement controls with this framework in mind, you'll unlock more organizational efficiency. Issues will occur less frequently, manual processes will go away, and you'll have less attack surface to exploit.
Some examples of tooling to give you a starting point include:
- Microsoft Secure Score, especially after deploying Defender for Endpoint
- MITRE D3fend (https://d3fend.mitre.org/)
- CIS - Center for Internet Secrity (https://www.cisecurity.org/controls/cis-controls-list)
- NIST CSF 2.0 or SP 800-53
- ISO 27001
As one might imagine - applying such rigorous steps to hundreds of potential issues, across multiple systems, can be overwhelming. Additionally, it's not reasonable for every IT admin in every organization to implement this level of control over every issue - you should focus first on the issues that are causing the most trouble, those that keep you up at night, and those that are required by your line of business.
