Security Policy: The Next Generation
by Peter Hesse on Oct 18, 2010
- 584 views
Presentation delivered by Peter Hesse at Security BSides Atlanta, October 8, 2010
Presentation delivered by Peter Hesse at Security BSides Atlanta, October 8, 2010
Accessibility
Categories
Tags
More...Upload Details
Uploaded via SlideShare as Apple Keynote
Usage Rights
© All Rights Reserved
Statistics
- Favorites
- 1
- Downloads
- 0
- Comments
- 0
- Embed Views
- Views on SlideShare
- 584
- Total Views
- 584
Policies are written to counter known or notional risk.
Helps set the rules of the game – guidance -- not that they can’t be changed later
Then they have to follow some more frameworks.
And some more. And more and more.
You end up with something you didn’t really expect. Kind of reminds me of a platypus, webbed feet, duck bill, thick fur, mostly aquatic, lays eggs…
Then they have to follow some more frameworks.
And some more. And more and more.
You end up with something you didn’t really expect. Kind of reminds me of a platypus, webbed feet, duck bill, thick fur, mostly aquatic, lays eggs…
Then they have to follow some more frameworks.
And some more. And more and more.
You end up with something you didn’t really expect. Kind of reminds me of a platypus, webbed feet, duck bill, thick fur, mostly aquatic, lays eggs…
Then they have to follow some more frameworks.
And some more. And more and more.
You end up with something you didn’t really expect. Kind of reminds me of a platypus, webbed feet, duck bill, thick fur, mostly aquatic, lays eggs…
Then they have to follow some more frameworks.
And some more. And more and more.
You end up with something you didn’t really expect. Kind of reminds me of a platypus, webbed feet, duck bill, thick fur, mostly aquatic, lays eggs…
Then they have to follow some more frameworks.
And some more. And more and more.
You end up with something you didn’t really expect. Kind of reminds me of a platypus, webbed feet, duck bill, thick fur, mostly aquatic, lays eggs…
Then they have to follow some more frameworks.
And some more. And more and more.
You end up with something you didn’t really expect. Kind of reminds me of a platypus, webbed feet, duck bill, thick fur, mostly aquatic, lays eggs…
Then they have to follow some more frameworks.
And some more. And more and more.
You end up with something you didn’t really expect. Kind of reminds me of a platypus, webbed feet, duck bill, thick fur, mostly aquatic, lays eggs…
Then they have to follow some more frameworks.
And some more. And more and more.
You end up with something you didn’t really expect. Kind of reminds me of a platypus, webbed feet, duck bill, thick fur, mostly aquatic, lays eggs…
Then they have to follow some more frameworks.
And some more. And more and more.
You end up with something you didn’t really expect. Kind of reminds me of a platypus, webbed feet, duck bill, thick fur, mostly aquatic, lays eggs…
Then they have to follow some more frameworks.
And some more. And more and more.
You end up with something you didn’t really expect. Kind of reminds me of a platypus, webbed feet, duck bill, thick fur, mostly aquatic, lays eggs…
Then they have to follow some more frameworks.
And some more. And more and more.
You end up with something you didn’t really expect. Kind of reminds me of a platypus, webbed feet, duck bill, thick fur, mostly aquatic, lays eggs…
Then they have to follow some more frameworks.
And some more. And more and more.
You end up with something you didn’t really expect. Kind of reminds me of a platypus, webbed feet, duck bill, thick fur, mostly aquatic, lays eggs…
Then they have to follow some more frameworks.
And some more. And more and more.
You end up with something you didn’t really expect. Kind of reminds me of a platypus, webbed feet, duck bill, thick fur, mostly aquatic, lays eggs…
Length of policy also a huge problem.
Like making sausage
However, they distill the guide down to 5 main points, care to guess what they are?
-Patching
-Running as limited user
-Anti-malware
-Personal firewall
-Perform backups
Do they need the rest of the document?
Do these statements apply to the average user? (No, 1 is for IT only, 2 is for people doing downloads, and management to know that they need to approve – but how do they determine if they should?)
What do you do when one of these policies is met, but the other isn’t?
- Not getting into the metrics / qualitative/ quantitative holy war, but policies related to greater risks should have greater importance; those that relate to lower risks should be waived, deemed less important, or excised entirely
- The heat map could automatically filter based on the perspective of the audience
- Not getting into the metrics / qualitative/ quantitative holy war, but policies related to greater risks should have greater importance; those that relate to lower risks should be waived, deemed less important, or excised entirely
- The heat map could automatically filter based on the perspective of the audience
- Not getting into the metrics / qualitative/ quantitative holy war, but policies related to greater risks should have greater importance; those that relate to lower risks should be waived, deemed less important, or excised entirely
- The heat map could automatically filter based on the perspective of the audience