{"id":890,"date":"2009-12-22T09:11:51","date_gmt":"2009-12-22T03:41:51","guid":{"rendered":"https:\/\/www.qadit.com\/blog\/?p=890"},"modified":"2009-12-22T09:16:52","modified_gmt":"2009-12-22T03:46:52","slug":"security-resolutions-for-2010","status":"publish","type":"post","link":"https:\/\/qadit.com\/blog\/security-resolutions-for-2010\/","title":{"rendered":"Security Resolutions for 2010"},"content":{"rendered":"<p>What the Information Security manager should aim for <\/p>\n<p> &nbsp;<\/p>\n<p><!--more--><br \/>\n&#8211; I will identify &amp; locate my critical data<br \/>\n&#8211; I will make sure that critical data is not placed in insecure locations eg. a pen drive or a PC with no password<br \/>\n&#8211; I will have a relevant set of policies and procedures in place<br \/>\n&#8211; I will see that my password policy is implemented across all my applications<br \/>\n&#8211; I will ensure that users are not given administrative rights to their PCs<br \/>\n&#8211; I will have a good asset &amp; license management system so that I<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; a) know what I have<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; b) can comply with licensing requirements<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; c) can deploy my assets based on need and priority<br \/>\n&#8211; I will make sure that I have a comprehensive anti-virus solution that<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; a) is installed on all nodes<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; b) is set to run scans regularly<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; c) has the latest virus definitions on all nodes<br \/>\n&#8211; I will ensure that I have a good patch management solution in place<br \/>\n&#8211; I will evaluate my backup process and ensure that all critical data is backed up and is retreivable<br \/>\n&#8211; I will audit all administrative access; make sure<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; a) it is given only to those who require it<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; b) administrators do not have access to systems where they are not  administrators<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; c) that administrative activities are logged and that the admins cannot change these logs<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; d) I have a monitoring system that flags unusual administrative activities<br \/>\n&#8211; I will ensure that all unnecessary ports are closed, especially on external facing systems<br \/>\n&#8211; I will ensure that default passwords are not used on any of my network devices<br \/>\n&#8211; I will have an effective change monitoring system in place for<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#8211; configurations<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#8211; new software installations<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#8211; new asset installation<br \/>\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  &#8211; access rights modification; especially when admin rights are given<br \/>\n&#8211; I will do a vulnerability assessment and penetration testing exercise of all my critical systems and those that face the outside world<\/p>\n<p> &nbsp;<\/p>\n<p>and the most difficult one&#8230;<\/p>\n<p> &nbsp;<\/p>\n<p>&#8211; I will try to bring in a culture of security into the organisation<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What the Information Security manager should aim for &nbsp;<\/p>\n","protected":false},"author":6,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[52,8,24,78,12],"tags":[24,115,33],"class_list":["post-890","post","type-post","status-publish","format-standard","hentry","category-bcpdr","category-erp","category-grc","category-information-technology","category-itsec","tag-grc","tag-resolutions-for-2010","tag-security"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9AH7Q-em","_links":{"self":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/890","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/comments?post=890"}],"version-history":[{"count":0,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/890\/revisions"}],"wp:attachment":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/media?parent=890"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/categories?post=890"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/tags?post=890"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}