3 Page Paper and 4, 200-300 Discussion Questions for $40 for COMP_SCIENCE PROF

profilejohndoe74
manage_your_network_security.docx

Manage your network security

false Herberger, Carl . Communications News 42.4 (Apr 2005): 60.

Turn on hit highlighting for speaking browsers by selecting the Enter button

Abstract (summary)

Translate Abstract Undo Translation TranslateUndo Translation

Press the Escape key to close

FromTo

Translate

Translation in progress...

[[missing key: loadingAnimation]]

The full text may take 40-60 seconds to translate; larger documents may take longer.

Cancel

The differences between vulnerability management and poor security may be minor, but they are monumental in practice. Vulnerability management is at the crux of an organization's ability to sense and then respond to changes in the security environment. It should include taking an inventory of an organization's existing technology to get an assessment of vulnerabilities, and devising to get an assessment of vulnerabilities, and devising a plan for improvement. To improve vulnerability management, regularly conduct routine vulnerability assessments and third-party penetration testing. Maintain a proactive patch-management program and combine that with strong configuration-management.

The differences between vulnerability management and poor security may be minor, but they are monumental in practice. Vulnerability management is at the crux of an organization's ability to sense and then respond to changes in the security environment. It should include taking an inventory of an organization's existing technology to get an assessment of vulnerabilities, and devising to get an assessment of vulnerabilities, and devising a plan for improvement. To improve vulnerability management, regularly conduct routine vulnerability assessments and third-party penetration testing. Maintain a proactive patch-management program and combine that with strong configuration-management.

You have requested "on-the-fly" machine translation of selected content from our databases. This functionality is provided solely for your convenience and is in no way intended to replace human translation. Show full disclaimer

Neither ProQuest nor its licensors make any representations or warranties with respect to the translations. The translations are automatically generated "AS IS" and "AS AVAILABLE" and are not retained in our systems. PROQUEST AND ITS LICENSORS SPECIFICALLY DISCLAIM ANY AND ALL EXPRESS OR IMPLIED WARRANTIES, INCLUDING WITHOUT LIMITATION, ANY WARRANTIES FOR AVAILABILITY, ACCURACY, TIMELINESS, COMPLETENESS, NON-INFRINGMENT, MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. Your use of the translations is subject to all use restrictions contained in your Electronic Products License Agreement and by using the translation functionality you agree to forgo any and all claims against ProQuest or its licensors for your use of the translation functionality and any output derived there from. Hide full disclaimer Translations powered by LEC.

Translations powered by LEC.

Full text

· Translate Full text Undo Translation TranslateUndo Translation

Press the Escape key to close

FromTo

Translate

Translation in progress...

[[missing key: loadingAnimation]]

The full text may take 40-60 seconds to translate; larger documents may take longer.

Cancel

· Turn on search term navigation Turn on search term navigation

· Jump to first hit

Headnote

Differences between poor security and technical vulnerabilities are monumental.

Vulnerability management is not the most important component of a security management program. Poor security is at least as large a problem as technical vulnerabilities in gaining unauthorized access to an enterprise's network. The differences may sound minor, but they are monumental in practice.

Security is process related and vulnerabilities are technically related. Examples of vulnerabilities are problems with application code, operating systems or system architecture that can allow unauthorized access. Examples of poor security are processes that lead to faults and flaws-bad passwords, default installations of applications/ operating systems, lackluster compliance.

Security is not a device or software-it is a process. As such, all the defenses in the world are useless if they are not properly managed. In fact, having superior technology and a great vulnerability management program will only carry you so far-like having indestructible walls that are only two feet high.

A vulnerability test reviews and itemizes possible flaws. A penetration test, on the other hand, attempts to gain unwelcome access in order to show that it can, in fact, be done. After that, a penetration test report will show exactly how access was achieved.

A penetration test measures the time to get to a selected target and seeks to ensure that an organization's detection controls were effective in noticing and recording the action. So, a penetration test should demonstrate that an organization's potential vulnerabilities have been minimized to the point they are not detrimental, and that the organization became aware of the attempted break.

At a minimum, a well-designed penetration test should start with defined targets-which should be critical and confidential information and systems-and the reason security is necessary and deployed within a company. Typical targets include: private customer information; financial information; personal information of key executives; personal employee information; critical data flows between applications; critical applications; and B2B connections and data flows.

From there, discuss and understand the access vector that is being tested, which is often internal or external test, but rarely both. The deliverable should be simple and include:

* a list of the desired targets and individual statements on access success or failure;

* a list of the notable strengths of the security posture that was witnessed;

* a diagram of how each successful access was achieved, including each propagated access step, along with a discussion of how difficult each step was to accomplish;

* a technical walk-through of each propagated access point; and

* a list of all notable vulnerabilities and suggested remedies.

Vulnerability tests present a complete picture of an organizations technical vulnerabilities. They provide both a baseline of the environment to be used for future analysis and a demonstration tool for process effectiveness within the overall security posture. Vulnerability assessments, however, are most useful when combined with a program assessment to detail the "why" behind the "what."

Vulnerability management is at the crux of an organization's ability to sense and then respond to changes in the security environment. It should include taking an inventory of an organization's existing technology to get an assessment of vulnerabilities, and devising a plan for improvement. Vulnerability management is about a proactive approach to inherent technological risk, threats and practices.

To improve vulnerability management, regularly conduct routine vulnerability assessments (network and application architecture, operating system configuration, and internal and external reviews) and third-party penetration testing. Become aware of real-time changes in the technical vulnerability landscape and understand the implications on your enterprise systems. Maintain a proactive patch-management program and combine that with strong configuration-management.

For more information from Sungard:

www.rsleads.com/504cn-250

English

Arabic

English

Arabic