Codeasaurus Rex

September 7, 2008

Privileged user monitoring in the enterprise

Filed under: Security — Codeasaurus Rex @ 12:09 pm

I just listened to the Tuesday, May 09 2006 webcast entitled “Ask The Expert Webcast: Who’s Guarding the Guards? Employing a Privileged User Monitoring Strategy” on the SANS webcast archive page at

https://www.sans.org/webcasts/archive.php

Too much ground was covered and it could have been better organized, but I’m still recommending this webcast because there were some valuable nuggets of information that I was able to pick out of the torrent of exposition.

I was not aware, for example, that behavioral analysis of database usage is being deployed to identify potential insider abuse like credit card data collection. The webcast also asserted that the majority of serious breaches were committed by employees with five to ten years of service: long enough to gain the requisite levels of experience, trust and privileged access to sensitive–and saleable–data.

What amazed me was the scope of the problem: 300 to 400 billion dollars per year. Now I understand why drug tests and credit checks are becoming part of the IT employee vetting process, though I do not approve. In the final analysis, only the Lord beholds the soul and recourse is had to imperfect substitutes due to the Deity’s lamentable absence from the hiring process

Insider threats to information security

Filed under: Security — Codeasaurus Rex @ 10:24 am

Although most of the information security business seems centered on detecting and intercepting external attacks, dishonest insiders pose a more subtle threat.

A valuable introduction to this topic is the May 3, 2006 webcast entitled “Wednesday Webcast: Web Application Security” on the SANS webcast archive page at

https://www.sans.org/webcasts/archive.php

September 6, 2008

Securing Mobile Access

Filed under: Security — Codeasaurus Rex @ 11:58 am

Exposing a subset of enterprise data and applications anytime, anywhere is a requirement of doing business these days. There are, however, technical challenges to limiting that exposure to authorized parties and protecting against compromised systems they may be using.

This post is to call attention to an interesting presentation by SAN on the implications of mobile access for enterprise security. It is listed as the April 20, 2006 webcast entitled “Part 1: The Mobile User – Secure Access from Anywhere (even the Home PC!)” on the SANS webcast archive page at

https://www.sans.org/webcasts/archive.php

As the first part of a three-part series, it doesn’t provide solutions. It does, however, provide a good summary of the issues that mobile access introduces.

Powered by WordPress