Control Reliability Engineering (CRE): Applying SRE Principles to Cybersecurity Controls
This article introduces Control Reliability Engineering (CRE) as a direct application of Site Reliability Engineering (SRE) principles to cybersecurity controls. It argues that many breaches occur not because of sophisticated attacks, but because security controls were broken or misconfigured at a critical moment. CRE addresses this by treating control failures with the same gravity as security incidents, using objective metrics (Control SLIs/SLOs), continuous monitoring, synthetic event injection, and error budgets to manage control reliability. The author outlines ten essential elements for a mature CRE program, including treating controls as code, formal incident management for control failures, and implementing readiness reviews. The core message is that security controls must be engineered for reliability through disciplined, metrics-driven operational practices to counter their natural decay over time.
Comments
Post a Comment