Comments
'Back to Basics' Might Be Your Best Security Weapon
Newest First  |  Oldest First  |  Threaded View
BrianN060
50%
50%
BrianN060,
User Rank: Ninja
1/18/2018 | 10:09:40 AM
Re: Basics do not sound really sexy, do they?
Agreed - "Security is about processes and humans first. Technology is only assisting your teams and help streamline your processes. "

Technology is knowledge - the knowhow to produce some product, or accomplish some task - not the product, task, materials or the tools used. That goes double for IT: Information Technology
Dimitri Chichlo
100%
0%
Dimitri Chichlo,
User Rank: Apprentice
1/15/2018 | 3:35:06 AM
Basics do not sound really sexy, do they?
Security is about processes and humans first. Technology is only assisting your teams and help streamline your processes. 

I was recently discussing this with a Director from a large, international consultancy, and the guy asked: "From your point of view, what are the trends in information security?". My answer was: "The basics. Companies are so far behind industry standards that almost any of the projects re. basics can be sold, like framework, policies and reporting, identify the assets you are protecting, user access and privileged identity management, vulnerability and configuration management, user education, encryption, endpoint security."

I know he did not like it. Basics are probably not as sexy to sell to a Board as a pen test, a SOC with AI or IoT threat. And make you look old fashioned. And oblige your IT teams working differently. 
JohnF782
50%
50%
JohnF782,
User Rank: Apprentice
1/12/2018 | 3:02:18 PM
Re: Basics indeed
CIS CSC20 in priority order. The top 5 solve the highest risk threats.  Gaps in fundamentals are what have tripped up most organizations who have had major breaches in the last 5 years.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
1/11/2018 | 9:45:35 AM
Re: Basics indeed
Thanks - and this is nothing NEW.  In 2000 I remember an actuary at Aon receiving the Anna Kournikovia virus - the famous tennis star picture.  I visited his office and he started to MOVE THE MOUSE to the picture!!!  Why?  He was CURIOUS to see what IT DID!!!  (Killed the cat too).  i told him YOU OPEN THAT UP AND I AM TERMINATING IT SUPPORT FOR YOU FOREVER.  
lee337w
50%
50%
lee337w,
User Rank: Apprentice
1/11/2018 | 9:23:00 AM
Re: Basics indeed
Couldnt agree more. Culture and user awareness are paramount to complimenting solid technology. Technology can be configured but users can only be advised and educated. All users consumer, commercial, or other have a responsibility to help safeguard their digital lives. 
REISEN1955
100%
0%
REISEN1955,
User Rank: Ninja
1/11/2018 | 9:00:24 AM
Basics indeed
Nothing exotic sometimes - one (1) user opening an infected PDF attachment brought the State of North Carolina down through ransomware.  Just one user.    USER EDUCATION is a good place to start too., 


Google Engineering Lead on Lessons Learned From Chrome's HTTPS Push
Kelly Sheridan, Staff Editor, Dark Reading,  8/8/2018
Election Websites, Backend Systems Most at Risk of Cyberattack in Midterms
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-8405
PUBLISHED: 2018-08-15
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, ...
CVE-2018-8406
PUBLISHED: 2018-08-15
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique...
CVE-2018-8412
PUBLISHED: 2018-08-15
An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing them, aka "Microsoft (MAU) Office Elevation of Privilege Vulnerability." This affects Microsoft Office.
CVE-2018-8414
PUBLISHED: 2018-08-15
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.
CVE-2018-8398
PUBLISHED: 2018-08-15
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, W...