![]() |
![]() |
|
November 14, 200310 tips for improving security inside the firewallComputerWorld has published an article that illustrates 10 ways to address the security challenges of large, active internal networks. Additionally, since they involve defensive tactics, they provide a game plan for improving the security of a large enterprise network. They could have went into greater detail, but to sum it up, the 10 tips are:
As I look at this list, I think this is too generic. (It makes more sense if you read the article). The defense of one's network is going to be different in each individual scenerio. Risk mitigation is not something that can be designed by following a checklist without first analysis of what needs protecting. The last bullet really needs to be near the top. Its to easy to throw money at technology to solve "security problems". This call to action to "bolt" on security after the fact is ineffective. Security is not a technology problem! It is a business ones, and will be different in every scenerio. Although its easy to say things like "shut off network services" and "defend critical resources first", one has to evaluate WHAT is expected of the network. By applying the principles of least privilege when setting policy, you restrict the network with only those services needed, and then shore up and provide defense in depth layered security to critical business resources, based on its perceived value (each person in an organization will rank their stuff more important, so this process has to be more objective, and done by a bigger group). This is one of the fundamental reasons so many Windows environments had the huge worm debocle this summer. After the first strain of RPC type vulnerabilities were attacked, policy should have been modified to secure this type of communcation from going on in the network. Simply "patching" the hole was not enough. They should have placed strict access control to RPC/DCOM ports and reduce the attack surface of each Windows host/server. If this was done, the secondary strains (there were what 3 different ones) would have been totally ineffective. I could go on for hours, but you get the point. Information security is more about mitigating risks by learning from your mistakes (and those of others), and implimenting policy correctly. Technology is an enabler, not the solution. Posted by SilverStr at November 14, 2003 07:17 AM | TrackBack |
![]() ![]()
My 5 Favorite Books
Writing Secure Code
Secure Programming Cookbook Security Engineering Secure Coding Principles & Practice Inside the Security Mind ![]()
My 5 Favorite Papers
Smashing the Stack
Penetration Studies Covert Channel Analysis of Trusted Systems DoD Trusted Computer System Evaluation Criteria NSA Security Recommendation Guides ![]()
Archives
December 2005
November 2005 October 2005 September 2005 August 2005 July 2005 June 2005 May 2005 April 2005 March 2005 February 2005 January 2005 December 2004 November 2004 October 2004 September 2004 August 2004 July 2004 June 2004 May 2004 April 2004 March 2004 February 2004 January 2004 December 2003 November 2003 October 2003 September 2003 August 2003 July 2003 June 2003 May 2003 April 2003 March 2003 February 2003 January 2003 December 2002 November 2002 October 2002 September 2002 August 2002 July 2002 ![]() |
|