|
|||||||||||
|
RE: Handling new vulnerabilities like WebDav - SUMMARY
From: Harlan Carvey <keydet89(at)yahoo.com>
Date: Tue Mar 25 2003 - 16:15:50 EST
> Minus the vendor plugs, here is a summary of the
Thanks for providing a summary. > 1. Maintain an accurate inventory of your assets to
I work in an all-MS shop, and we've opted to go with RippleTech's PatchWorks for patch management. It's extremely helpful in not only rolling the patches out, but also keeping track of what's installed where. > 2. Use a preventative IDS solution to prevent the
"preventative IDS" is almost a contradiction in terms. Something that detects does not necessarily protect. As far as prevention, or "intrusion prevention" goes, there are a number of ways to go about it, ranging from system hardening to installing third party products such as Okena's suite of products. Other products, such as Nokia + ISS RealSecure, bill or market themselves as "intrusion prevention", but they really aren't. > 3. Run an immediate scan of your environment to
This is pretty high-level, but completely accurate. "Scan", "determine your risk", and "mitigating controls" are all very general terms that rely on a lot of political and monetary factors within each organization. HTH, Harlan Do you Yahoo!? Yahoo! Platinum - Watch CBS' NCAA March Madness, live on your desktop! http://platinum.yahoo.com Received on Tue Mar 25 16:35:09 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:18 EDT |
||||||||||
|
|||||||||||