19
1 Secure Online Presence Savio Fernandes [email protected]

1 Secure Online Presence Savio Fernandes [email protected]

Embed Size (px)

Citation preview

Page 1: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

1

Secure Online Presence

Savio Fernandes

[email protected]

Page 2: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

2

Rule #1: Determine the value of Information that you want to secure

• Then decide on the investments that you need to make.

• The cost of the security solution should not exceed the value of the information

Image taken from http://dailycupoftech.com/10-ways-to-protect-your-home-network/

Page 3: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

3

Rule #2: Classify your information

• Also determine who is authorized to access the informationImage taken from http://searchsecurity.techtarget.com/tip/0,289483,sid14_gci995767,00.html

Page 4: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

4

Rule #3: Different level of sensitivity will require different security levels.

Image taken from http://www.accessandprivacy.gov.on.ca/english/pub/iaa.html

Page 5: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

5

Endpoint Security Management

Image taken from http://www.networkd.co.uk/securitysuite.html

Page 6: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

6

Patch Management Apply patches but test before deploying on production servers.

Image taken from http://www.microsoft.com/technet/security/guidance/patchmanagement/secmod193.mspx

Page 7: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

7

Windows Patches

Visit http://windowsupdate.microsoft.com for patches. All Critical (Express) patches should be applied

Page 8: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

8

Microsoft Update

Get all Microsoft updates in one place: http://www.update.microsoft.com/microsoftupdate

Page 9: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

9

Ensure that the anti-virus software is configured to receive the latest updates automatically

Image taken from http://www.secured-networking.com/email_security.htm

Page 10: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

10

Host Based Intrusion Detection System (IDS) should be deployed on servers in addition to the network IDS

Image taken from http://www.secureworks.com/services/managed/host_intrusion_prevention.html

Page 11: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

11

Protect your Application and database severs via additional firewalls.

• Internet users should not be able to reach the application and database servers directly.

• Only the webserver should be able to access the application servers.

• You should also have another firewall in front of the webserver preferably of a different make than the other firewalls.

Image taken from http://www.dmreview.com/editorial/dmreview/200209/200209_014_1.gif

Page 12: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

12

Security Audit - Nessus• You should conduct a weekly audit of your infrastructure

with tools such as Nessus (Freeware)

Snapshot of Nessus product – downloaded from http://www.nessus.org/nessus/

Page 13: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

13

Beware of Zero-day Attacks

Image taken from http://www.guardsite.com/ZeroDayProtection.asp

Page 14: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

14

Install the Free McAfee SiteAdvisor

Snapshot of page taken from http://us.mcafee.com/root/product.asp?productid=sa&cid=26044

Page 15: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

15

Heed the advise given by McAfee SiteAdvisor when downloading software

Google search output - http://www.google.co.in when a search was made for “free networking tools”

Page 16: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

16

Subscribe to Security Newsletters

Snapshot of page at http://www.computerworld.com/action/member.do?command=registerNewsletters&intsrc=hm_nav_nl

Page 17: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

17

Incident ResponseReport the computer incidents to the National Computer Incident response team. e.g. In India log the incident at http://www.cert-in.org.in/

Snapshot of US-CERT home page at http://www.us-cert.gov/

Page 18: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

18

Thank You• T

Image taken from: http://www.shepherd-wireless.com/freequote.html

Page 19: 1 Secure Online Presence Savio Fernandes Savio.CISSP@gmail.com

19

Disclaimer

"The images presented and products referenced are the intellectual property of their respective owners.  The use of such images is for non-commercial educational purposes only and no claim otherwise is made regarding the said images."