Recent information leakage studies (verizon one) identify that intrusions occur from vulnerabilities that are more than a year old and often easily fixed by patching. The poorly informed would cry "just apply the patches" well here are some of the challenges:
- it's easy to test, if you aren't running apps, umm but aren't all partner facing or internet facing systems.hhmmm
- you need to test, sometimes patches break things, especially poorly coded legacy apps. Sometimes those apps aren't supported and you may have a situation where you can't turn off the vulnerable functionality or apply the patch.
- testing, proper testing involves functional and non functional testing, maybe even performance and volume testing. No surprises that costs big bucks, and which app owners are going to cough up for testing on apps already in production that are not cashed up with capex approvals etc.
Approaches:
-risk assess systems, focus on most critical
-have a regular patch schedule aligned with testing, that also updates the SOE.
-deploy IPS/WAF/reverse proxy/in listen only mode ready to help block an exploit that has pwned you, so that after you have rebuilt you can protect again re=pwnage.
About Me
- Matthew Hackling
- Matt runs his own security consultancy called Ronin Security. His focus is information security management and he has a keen interest in infrastructure and web application security. He's a CISSP and the current Branch Executive of the Melbourne chapter of the Australian Information Security Association.
Blog Archive
-
▼
2008
(24)
-
▼
September
(13)
- Good security awareness program at the royal show
- Mobile phone products to invent
- How to raise the profile of your information secur...
- First jobs
- info-sec car analogies
- challenges with vulnerability management
- The simple things in inosec are often the most eff...
- Former federal privacy commissioner addressing AIS...
- my first security haiku
- Security governance - launching the offensive
- Security Governance: The First battle
- Security governance: The Initial Skirmish
- Reflections on the Australian Infosec market
-
▼
September
(13)
Labels
- AISA (1)
- australian information security market (1)
- career advice (1)
- causes (1)
- DoS (1)
- economics (1)
- FUD (1)
- futurism (1)
- information security governance (4)
- IPS (1)
- privacy (2)
- sacred cows (1)
- security patching (1)
- vulnerability management (1)
- webappsec (1)
Wednesday, September 10, 2008
Subscribe to:
Post Comments (Atom)
Handy Links
Matt's list of blogs
-
-
-
TEDxMaui -- Hack Yourself First3 weeks ago
-
-
-
FedRAMP: It’s Here but Not Yet Here2 months ago
-
Bunraku V0.0.36 months ago
-
GoGrid Security Breach10 months ago
0 comments:
Post a Comment