<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Practical Issues in InfoSec &#187; Operations</title>
	<atom:link href="http://www.dlstrom.com/tag/operations/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dlstrom.com</link>
	<description>... putting information security within reach of everyone!</description>
	<lastBuildDate>Tue, 20 Dec 2011 17:00:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>The Operations Element</title>
		<link>http://www.dlstrom.com/2009/06/17/the-operations-element/</link>
		<comments>http://www.dlstrom.com/2009/06/17/the-operations-element/#comments</comments>
		<pubDate>Wed, 17 Jun 2009 20:14:07 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[Awareness]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Operations]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=246</guid>
		<description><![CDATA[The final commonly held element of good Defense in Depth is Operations. I say &#8220;commonly held&#8221; because various authors make additions to the list of People, Technology and Operations. For a functioning description, consider Operations to be the tasks required to maintain a desired level of security. It is easy to get bogged down thinking [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2009/06/17/the-operations-element/" data-text="The Operations Element" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2009/06/17/the-operations-element/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>The final commonly held element of good <a href="http://www.dlstrom.com/2009/04/16/defense-in-depth/">Defense in Depth</a> is <strong>Operations</strong>. I say &#8220;commonly held&#8221; because various authors make additions to the list of <a href="http://www.dlstrom.com/2009/05/19/the-people-element/">People</a>, <a href="http://www.dlstrom.com/2009/06/10/the-technology-element/">Technology</a> and <strong>Operations</strong>.</p>
<p>For a functioning description, consider Operations to be the tasks required to maintain a desired level of security. It is easy to get bogged down thinking about the security posture and auditing to make sure that we are maintaining that posture.</p>
<p>Regardless of what level of security you want, the following are some ideas to get you started thinking about InfoSec Operations&#8230;</p>
<p>Good InfoSec operations will be <strong>driven by policy</strong>.</p>
<ul>
<li>
<strong>Acceptable Use Policy</strong> &#8211; The AUP clearly lays out what the organizations resources can or can not be used for. Check out some <a href="http://www.dlstrom.com/2007/10/25/do-i-need-an-acceptable-use-policy/">reasons you need an Acceptable Use Policy.</a></li>
<li>
<strong>Configuration Change Policy</strong> &#8211; Even the smallest of businesses needs to have guidelines and policies of who can make and when changes can be made to computer, software and infrastructure. Chaos ensues without this.</li>
</ul>
<p>Good InfoSec operations will work to <strong>minimize the risk from malware</strong>.</p>
<ul>
<li>
<strong>Operation system patches</strong> &#8211; Whether you are running Unix, Linux, Windows or OS X as you operating system, there are frequent patches that should be applied. Depending upon your business, you may even need to test patches on test servers and workstations prior to general deployment.</li>
<li>
<strong>Anti-virus updated and scanning</strong> &#8211; Malware is a significant attack vector. Viruses, worms or spyware are often used to gather personal information from the infected host. A major step in minimizing the risk if to keep the anti-virus software updated and scanning.</li>
</ul>
<p>Good InfoSec operations will be <strong>aware of threats</strong>.</p>
<ul>
<li>
<strong>Know what the risks are to your organization</strong> &#8211; The risks to a small bank are different than the risks for the fitness club. Awareness of the risks to your specific industry will enable you to establish sound defenses.</li>
<li>
<strong>Know what has been done to remediate specific threats</strong> &#8211; I keep a &#8220;risk register&#8221; of the various risks, threats, problems that I encounter. It includes the date found, a brief description of the risk, what I have done to address the risk, and the date that was done. Not only does it help me remember, but it is good to periodically review it to make sure the remediation is still valid.</li>
</ul>
<p>Good InfoSec operations will <strong>be ready to recover from an incident</strong>.</p>
<ul>
<li>
<strong>Backups</strong> &#8211; Having good backups can make you look like a genius! (and they can be the difference between an inconvenience and the organization shutting the doors&#8230;)</li>
<li>
<strong>Disaster Recover Planning</strong> &#8211; Even the smallest of businesses needs a DRP. <a href="http://www.ready.gov">Ready.gov</a> can be a good starting place. </li>
</ul>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2009/06/17/the-operations-element/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Defense in Depth</title>
		<link>http://www.dlstrom.com/2009/04/16/defense-in-depth/</link>
		<comments>http://www.dlstrom.com/2009/04/16/defense-in-depth/#comments</comments>
		<pubDate>Thu, 16 Apr 2009 21:44:03 +0000</pubDate>
		<dc:creator>Dan Strom</dc:creator>
				<category><![CDATA[Awareness]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Operations]]></category>
		<category><![CDATA[People]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=170</guid>
		<description><![CDATA[Can a small or medium sized business do Defense in Depth? How about the home user? The phrase &#8220;defense in depth&#8221; is tossed around in the Information Security field as if everyone knows what is being talked about. Just what is Defense in Depth? The National Security Agency has put out a short paper which [...]]]></description>
			<content:encoded><![CDATA[<p></p><div class="socialize-in-content" style="float:right;"><div class="socialize-in-button socialize-in-button-right"><a href="http://twitter.com/share" class="twitter-share-button" data-url="http://www.dlstrom.com/2009/04/16/defense-in-depth/" data-text="Defense in Depth" data-count="none" data-via="danstrom" data-related="danstrom"><!--Tweetter--></a></div><div class="socialize-in-button socialize-in-button-right"><iframe src="http://www.facebook.com/plugins/like.php?href=http://www.dlstrom.com/2009/04/16/defense-in-depth/&amp;layout=standard&amp;show_faces=false&amp;width=50&amp;action=like&amp;font=arial&amp;colorscheme=light&amp;height=65" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:50px !important; height:65px;" allowTransparency="true"></iframe></div></div><p>Can a small or medium sized business do Defense in Depth?</p>
<p>How about the home user?</p>
<p>The phrase &#8220;defense in depth&#8221; is tossed around in the Information Security field as if everyone knows what is being talked about.</p>
<p>Just what is <strong>Defense in Depth</strong>?</p>
<p>The National Security Agency has put out a short <a href="http://www.nsa.gov/ia/_files/support/defenseindepth.pdf">paper</a> which discusses a strategy for defense in depth.</p>
<p>I certainly encourage you to take a look at that paper.</p>
<p>The defense in depth strategy focuses on three important elements as we work toward information assurance. These elements are:</p>
<ul>
<li>People</li>
<li>Technology</li>
<li>Operations</li>
</ul>
<p>We will soon begin looking at each of these elements as it related to Information Security and the small business or home user.</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2009/04/16/defense-in-depth/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

