Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -4 articles for you...
74

Essential Security Checklist For Revamping Risk Management

Recently, a former student and propective client asked me to send, along with a proposal, a checklist of things he needs to be thinking about to help his company's goal of "revamping security" in 2004. This is that checklist. Be forewarned. While risks change somewhat with network size, bandwidth, and connectivity, while business requirements grow, and while the technology we can use to mitigate and mediate risk gets fancier (it is hoped to meet the changing risks), there is nothing new under the sun. Also, this is purposely very high level. It is a general checklist of things to consider. . . .. NetSec Letter #32, 12 January 2004 Security Checklist Fred Avolio, Avolio Consulting, Inc., Avolio Consulting, Inc. - Internet Security Consulting Recently, a former student and propective client asked me to send, along with a proposal, a checklist of things he needs to be thinking about to help his company's goal of "revamping security" in 2004. This is that checklist. Be forewarned. While risks change somewhat with network size, bandwidth, and connectivity, while business requirements grow, and while the technology we can use to mitigate and mediate risk gets fancier (it is hoped to meet the changing risks), there is nothing new under the sun. Also, this is purposely very high level. It is a general checklist of things to consider. Foundation/Overview 1. Business requirements assessment 1. What is your enterprise's mission/goal? 2. What does it require from computers, networks, and the Internet in support of the mission? 2. Risk assessment 1. Where are your computers? 2. To where do your network connections go? 3. What sorts of threats are there to computers and networks in those environments? 4. Any particular risks unique to your business? (E.g., defense contractor, pharmaceutical firm, furrier.) 5. Any particular risks unique to your organization? (E.g., did your company recently help topple a dictator, spill a lot of oil into the ocean or a fresh water supply, or endorse the wrong political candidate?) 3. Security Architecture 1. What controls are already in place? Did you remember to include physical controls? Someone recently told me that a particular product did not support administrative access using 2-factor authentication. He asked if limiting administrative access to the console was sufficiently secure. I told him, sure. A cipher lock and photo ID is 2-factor. 2. Of those in place (firewalls, desktop AV, routers with ACLs, IDSes, password-protected screen savers, VPNs, etc.), which mitigate the identified risks? 3. Do not forget the "little things." For example, security awareness education is part of the security architecture. 4. System administration procedures 1. Backup and restore 2. Access controls 3. Revision control 5. Acceptable Use Policies (for users) 1. Computer use 2. Mobile computer use 3. E-mail 4. Internet access 5. Home computer use 6. VPN use 7. Screensavers 6. Computer Security Incident Response Procedures 1. Definition of a security incident 2. Who, what, when, where, why, and how. Types of Security and Places to Deploy * Prevention, detection, response * Perimeter, servers, and desktops o Perimeter devices are gateways -- routers, firewalls, etc. o Servers include web, e-mail, name, time, and application servers. o Desktops include mobile computers and hand-held. Periodic Review and Audit This whole process requires review and consideration by a team of individuals. Why? Because every one of us has blind-spots. [In God in the Docket, CS Lewis says every one of us had a fatal flaw to which we are blind. More recently, the late pastor Jack Miller said, smiling, "Cheer up! You're ever so much worse than you think you are."] Every one of us has his own agenda. Also, people make mistakes in executing plans and procedures. Further, things -- risks, requirements, and technology -- change. So the policy and procedures have to change. Promotions, Self and Otherwise My (growing) speaking and teaching calendar is at /. Did you buy your parents or friends apersonal (computer) firewall for Christmas? Personal Firewall Day is January 15th. See NetsecLetter #31 ( / There was an interesting Web Informant this week from David Strom. David seems to be enamored with the dark side. Is he? Read "Web Informant #355, 9 January 2004: Aiding and Abetting Adrian" at https://www.stromspa.com For an excellent editorial on a similar topic, Dave Piscitello wrote "Ethical Hacking could be so much more than an oxymoron..." at . Jon Callas, CTO, CSO, and DSD (Dynamite Sharp Dude) had some very interesting (as usual) comments on a webcast "The Dawn of Pervasive Encryption" at Other related articles and courses are * WatchGuard LiveSecurity * How to Develop an Information Security Incident Response Team and Plan * Avolio, Foundations of Enterprise Network Security words * The Castle Defense * . NetSec Letter #32, 12 January 2004Security ChecklistFred Avolio, Avolio Consulting, Inc., Avolio Con. recently, former, student, propective, client, asked, along, proposal, checklis. . Anthony Pell

Calendar 2 Jan 12, 2004 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here