Hundreds of denies in a migrated rulebase are unreachable and an intruder can ride them, but their owners have left — what do you fund, and what do you accept?
answer
- Detection was never the constraint
- Ask for a decision, not a tool
- Unowned flow is not a reason to keep a permit
- A project with an end can be staffed
- Accepted and written down beats silently open
basics
~20 sAsk for a decision, not a tool. Detection is already solved; triage capacity and rule ownership are the constraints. Seek a named owner, an announced maintenance sequence, and authority to break unowned flows — then record what stays open as accepted.
solid answer
~60 sDo not take a finding count to leadership; it invites a demand to remediate all of it and you will fail. Take the exposure: the policy currently permits *n* paths that the policy document says it denies, and here are the handful that cross a trust boundary an intruder could plausibly stand behind. Then be explicit that the blocker is not detection and not tooling — it is that every fix risks a flow whose owner no longer exists, so the authority you actually need is a standing decision that an unowned flow is not a reason to keep a permit: it will be closed in an announced window and restored quickly if someone speaks up. That decision belongs to whoever owns business availability, not to security, and without it every ticket stalls forever. Fund a time-boxed re-baselining with a named owner, plus the change gate that stops the population growing. Everything else is written down as accepted, with the reason, so an auditor reads a decision rather than a lapse.
go deeper
Understand that removing an old firewall permit is a change with a blast radius, and that the person who requested it years ago may no longer be reachable to confirm it is safe.
Be able to explain why a large clean-up stalls: the technical fix is trivial, the search for someone willing to authorise the breakage is not, and no analyser resolves that.
Show that you would scope a time-boxed piece of work around the exploitable class, run it in announced windows with rollbacks, and pair it with a change gate so the population stops growing.
Own the organisational asks: a standing decision that unowned flows may be closed, a named owner, and a documented acceptance line for what stays open — plus the honest assurance position when a control that was attested turns out never to have been in effect.
## What you are actually asking for The instinct is to present the analysis output — thousands of findings, hundreds of unreachable denies — and ask for headcount to work it. That framing loses, in both directions. If leadership says no, you have documented an unaddressed risk you named yourself. If they say yes, you have committed to clearing a backlog whose true blocker is not effort. The blocker is authority. Almost every fix in this backlog is a change to a rule whose requester, approver and business owner have all left the organisation, on a path whose current traffic you cannot see. The technical work per fix is minutes; the search for someone willing to say *yes, close it* is unbounded. ## Frame it as exposure, not as findings What travels upward is: **this policy permits paths it claims to deny.** Not an anomaly count. Concretely — of the unreachable denies, these ones cover paths from a lower-trust segment into an administrative plane, and an intruder with a foothold in that segment does not have to defeat any control to use them; the control is not in effect and has not been for years. That is a statement a non-specialist can act on, and it survives being repeated by someone else in a meeting you are not in. "Four thousand policy anomalies" does not. ## The three asks **1. A decision, not a tool.** State plainly that another analyser would produce a longer report and no change in outcome, because detection is not the constraint. What you need is a standing rule: *a flow with no identifiable owner is not a reason to keep a permit.* Such flows are closed in an announced window and restored within an agreed time if a genuine user appears. That is a business-availability decision — somebody with authority over service continuity has to own it, and if nobody will, that itself is the honest answer to why the rulebase never gets cleaner. **2. A time-boxed re-baselining with a named owner.** Not "clean the rulebase" but a scoped piece of work: the exploitable class only, ranked by what each deny names, worked in announced windows with rollbacks, ending on a date. A project with an end can be staffed; an ongoing hygiene commitment cannot. **3. The change gate.** Whole-policy analysis on proposed changes, failing only on anomalies the change introduces against the recorded baseline. This is the cheapest item on the list and the only one that makes the problem finite. Without it, cleaning is a permanent staffing line, because every removal is replaced by the next migration or the next urgent permit. ## What you accept, out loud Acceptance is not defeat; undocumented acceptance is. Write down which classes stay open and why — redundancy carries no exposure and is not funded; broad-below-narrow structure is intentional and is touched only when someone is already editing that area; partial overlaps are reviewed by segment on a schedule. A recorded acceptance with a reason and a review date is a defensible position in front of an auditor or a customer's security questionnaire. The same findings sitting unread are indistinguishable from negligence, and the only difference between the two is the write-up. ## The assurance conversation nobody wants If a deny rule was ever presented as evidence of a control — in an audit, an attestation, a customer questionnaire — and analysis now shows it unreachable, the honest position is that the control was not in effect for that period. Scope the window, hand over the analysis output as the evidence, and change what you present in future: a rule's text is a claim, and the analysis result is the evidence. Continuing to present rule text you now know may be unreachable is where a documentation problem becomes a misrepresentation. ## Where a principal answer earns its level - It distinguishes what money buys (a time-boxed project, a gate) from what money cannot buy (permission to break an unowned flow). - It refuses to promise full remediation and says why the refusal is the trustworthy answer. - It names who owns each decision — availability owns the breakage rule, security owns the ranking, engineering owns the gate — rather than absorbing all of it into the security team and quietly missing. - It treats the accepted remainder as a deliverable with a review date, not as silence. ## The failure modes Committing to zero findings. Asking for tooling when capacity is the constraint. Deleting unowned permits without a window because the analysis says they are shadowed — the analysis says nothing about who depends on them. And reporting a falling anomaly count as progress while the exploitable class is untouched, which is how a metric replaces the outcome it was meant to represent.
- Leadership offers budget for a better analysis product instead. What do you say?That the current analysis already returns more than the team can act on in a year, so a second one changes the report length and not the estate. Redirect the money to a named owner, an announced maintenance sequence, and the authority to close flows nobody claims.
- How do you stop the backlog regrowing while you drain it?Gate proposed changes against the recorded baseline so no change may introduce a new unreachable deny. It is the cheapest item on the list and the only one that turns the clean-up into a finite project rather than a standing headcount request.
- What do you tell an auditor who was previously shown that deny rule as evidence of a control?That for the period concerned the control was not in effect, with the analysis output as the supporting evidence and the affected window scoped. Then change what you offer as evidence in future — rule text is a claim, the reachability analysis is the proof.
- Business owners refuse every window you propose. What now?Then the decision has been made, and you record it as such: the exposure is accepted by the people who declined the change, with the paths named and a review date. Escalation is not the same as writing it down, and the write-up is what survives the next reorganisation.
saying these in an interview costs you the question
- Takes a finding count to leadership instead of the exposure
- Commits to remediating every finding
- Requests tooling when triage capacity is the constraint
- Closes unowned permits with no announced window or rollback
- Leaves accepted findings undocumented so they read as a lapse
- Reports a falling anomaly count as evidence the exposure shrank