Home > Commonly overlooked security hazards
Tech Article:
EMAIL THIS

Commonly overlooked security hazards

18 May 2005 | by Dave Piscitello

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Security expert Dave Piscitello offers tried-and-true practices for identifying and alleviating security risks, and implementing guidelines that will protect your company from the next nasty threat. Here, Dave covers the ten most commonly overlooked security hazards and easy ways to prevent them from placing your network at risk.

  1. Lax policy definition and enforcement – You cannot determine compliance to, enforce, or demand accountability to a policy if you don't have and maintain one.
  2. Overly permissive access policies – Access is one example where more is not better.
  3. Single line of defense - Does your security resemble a soft-boiled egg?
  4. Default installations of software - These are among the most common flaws, and often lead to escalated privilege attacks.
  5. Default and vulnerable configurations - Under most default conditions, devices join networks, even when this is not good for security.
  6. Weak authentication methods - You must apply two or more credentialing criteria.
  7. Inadequate auditing, logging, analysis - Auditing is not an in- depth activity in most organizations, but it should be.
  8. Flawed security processes, unsecured workflows - Mis-configurations commonly expose assets to attack.
  9. Weak security testing and auditing methodologies - Testing and policy changes are related events.
  10. Weak incident response and business continuity plans - Chicken Little is not a role model for a CSO.

Check out Dave's full-length presentation here.


Dave Piscitello is an authority on network security with more than 30 years experience in data networking and telecommunications. Dave is President of Core Competence Inc., founder and program manager of The Internet Security Conference, and chairman of Networld+Interop's Security Conference. Dave has authored books on internetworking and remote access, and regularly publishes articles on a variety of subjects including switched internetworking, ATM and Gigabit Ethernet, Internet security, and virtual private networking.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Network Security Monitoring and Analysis
Where can I find a sample security audit report? How can I run my own?
The firewall remains the network traffic cop, but its role is changing
Troubleshooting VLANs: How to monitor 802.1q tagged traffic
Poor data-loss prevention practices almost cost Intel a billion
How can I block my competitor's IP address range from my website?
Hospital gains network visibility by convincing vendors to collaborate
What software monitors and locks users from accessing my router?
Data leak prevention starts with trusting your users
NagVis -- 'Nagios: System and Network Monitoring, Second Edition,' Chapter 18
What is a genetic algorithm and where can I learn more about them online?

Network Security Best Practices and Products
Ethical hacking and countermeasures: Network penetration testing intro
Are you on a domain name system (DNS) blacklist database?
Rogue access points: Preventing, detecting and handling best practices
Network security threats solved by risk management: John Pironti explains
How to evaluate and manage UTM for network security
Profiling -- and protecting against -- network problem users: The Internet Novice
How does a firewall work?
Physical network security key to fighting low-tech threats
Why are TCP/IP networks considered unsecured?
Troubleshooting networks: Can vendor software self-install firewalls?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
deep packet inspection (DPI)  (SearchNetworking.com)
FCAPS  (SearchNetworking.com)
Nessus  (SearchNetworking.com)
netstat  (SearchNetworking.com)
port mirroring  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Network Management features current networking news and in-depth network white papers.
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts