Comments
'Back to Basics' Might Be Your Best Security Weapon
Newest First  |  Oldest First  |  Threaded View
BrianN060
50%
50%
BrianN060,
User Rank: Ninja
1/18/2018 | 10:09:40 AM
Re: Basics do not sound really sexy, do they?
Agreed - "Security is about processes and humans first. Technology is only assisting your teams and help streamline your processes. "

Technology is knowledge - the knowhow to produce some product, or accomplish some task - not the product, task, materials or the tools used. That goes double for IT: Information Technology
Dimitri Chichlo
100%
0%
Dimitri Chichlo,
User Rank: Apprentice
1/15/2018 | 3:35:06 AM
Basics do not sound really sexy, do they?
Security is about processes and humans first. Technology is only assisting your teams and help streamline your processes. 

I was recently discussing this with a Director from a large, international consultancy, and the guy asked: "From your point of view, what are the trends in information security?". My answer was: "The basics. Companies are so far behind industry standards that almost any of the projects re. basics can be sold, like framework, policies and reporting, identify the assets you are protecting, user access and privileged identity management, vulnerability and configuration management, user education, encryption, endpoint security."

I know he did not like it. Basics are probably not as sexy to sell to a Board as a pen test, a SOC with AI or IoT threat. And make you look old fashioned. And oblige your IT teams working differently. 
JohnF782
50%
50%
JohnF782,
User Rank: Apprentice
1/12/2018 | 3:02:18 PM
Re: Basics indeed
CIS CSC20 in priority order. The top 5 solve the highest risk threats.  Gaps in fundamentals are what have tripped up most organizations who have had major breaches in the last 5 years.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
1/11/2018 | 9:45:35 AM
Re: Basics indeed
Thanks - and this is nothing NEW.  In 2000 I remember an actuary at Aon receiving the Anna Kournikovia virus - the famous tennis star picture.  I visited his office and he started to MOVE THE MOUSE to the picture!!!  Why?  He was CURIOUS to see what IT DID!!!  (Killed the cat too).  i told him YOU OPEN THAT UP AND I AM TERMINATING IT SUPPORT FOR YOU FOREVER.  
lee337w
50%
50%
lee337w,
User Rank: Apprentice
1/11/2018 | 9:23:00 AM
Re: Basics indeed
Couldnt agree more. Culture and user awareness are paramount to complimenting solid technology. Technology can be configured but users can only be advised and educated. All users consumer, commercial, or other have a responsibility to help safeguard their digital lives. 
REISEN1955
100%
0%
REISEN1955,
User Rank: Ninja
1/11/2018 | 9:00:24 AM
Basics indeed
Nothing exotic sometimes - one (1) user opening an infected PDF attachment brought the State of North Carolina down through ransomware.  Just one user.    USER EDUCATION is a good place to start too., 


6 Security Trends for 2018/2019
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/15/2018
Most IT Security Pros Want to Change Jobs
Dark Reading Staff 10/12/2018
4 Ways to Fight the Email Security Threat
Asaf Cidon, Vice President, Content Security Services, at Barracuda Networks,  10/15/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-10839
PUBLISHED: 2018-10-16
Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.
CVE-2018-13399
PUBLISHED: 2018-10-16
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
CVE-2018-18381
PUBLISHED: 2018-10-16
Z-BlogPHP 1.5.2.1935 (Zero) has a stored XSS Vulnerability in zb_system/function/c_system_admin.php via the Content-Type header during the uploading of image attachments.
CVE-2018-18382
PUBLISHED: 2018-10-16
Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed through an "Update Profile" "Change Picture" (aka user/edit-profile) action.
CVE-2018-18374
PUBLISHED: 2018-10-16
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.