Entries Tagged as 'Beyond Anti-Virus'
by Neil MacDonald | August 22, 2011 | 3 Comments
I’ve had two discussions with clients today already on the role of full drive encryption ( FDE technologies such as Microsoft’s BitLocker, McAfee Total Protection, Sophos/Utimaco, Symantec PGP, Check Point, Trend/Mobile Armor etc) for fixed desktops. Full drive encryption should be considered mandatory for laptops and most organizations have implemented this – either with Windows [...]
Category: Beyond Anti-Virus Endpoint Protection Platform Information Security Windows 7 Tags: Beyond Anti-Virus, Defense-in-Depth, Endpoint Protection Platform, Microsoft Security, Windows
by Neil MacDonald | July 11, 2011 | Comments Off
I’ve been absent from blogging for 2 weeks – first we had the Gartner Information Security Summit in DC and then I took some time off for a much-needed vacation. We spent some time at Hilton Head Island in South Carolina. They’ve got a pretty amazing flat beach where the difference between high tide and [...]
Category: Beyond Anti-Virus Information Security Next-generation Security Infrastructure Tags: APTs, Beyond Anti-Virus, Defense-in-Depth, Information Security, Next-generation Security Infrastructure, Security-Summit-NA, Systematic Workload Reprovisioning
by Neil MacDonald | June 23, 2011 | Comments Off
I’m here at the Gartner Information Security summit on the fourth and final day. We had a record number of attendees – at least 1700 by my estimate. Attendees have the ability to book one on one conversations with the analysts and my schedule was completely full. One of the conversations with a client was [...]
Category: Information Security Next-generation Security Infrastructure Virtualization Tags: Adaptive Security Infrastucture, Beyond Anti-Virus, Endpoint Protection Platform, Information Security, Next-generation Security Infrastructure, Security-Summit-NA, Systematic Workload Reprovisioning, Virtualization Security
by Neil MacDonald | June 17, 2011 | 3 Comments
One of the toughest problems in information security is addressing advanced intrusions that have bypassed traditional security controls and now reside undetected on enterprise systems. With financially motivated attacks and state-sponsored “advanced persistent threats” both on the rise, intrusions can remain undetectable for extended periods of time. We have reached a point where our systems [...]
Category: Beyond Anti-Virus Next-generation Security Infrastructure Virtualization Virtualization Security Tags: Adaptive Security Infrastucture, APTs, Beyond Anti-Virus, Defense-in-Depth, Next-generation Security Infrastructure, Security-Summit-NA, Virtualization, Virtualization Security, Windows
by Neil MacDonald | June 16, 2011 | Comments Off
It sounds counterintuitive, but today’s advanced threat environment requires new approaches to the ongoing security and management of server and desktop workloads. The trouble with Advanced Persistent Threats is that, by definition, they have evaded our traditional network and endpoint security controls and now reside undetected in our IT Systems. How many advanced intrusions will [...]
Category: Beyond Anti-Virus Next-generation Security Infrastructure Virtualization Virtualization Security Tags: Adaptive Security Infrastucture, APTs, Beyond Anti-Virus, Defense-in-Depth, Next-generation Security Infrastructure, Security-Summit-NA, Virtualization, Virtualization Security
by Neil MacDonald | May 17, 2011 | 1 Comment
I’m having lots of discussions with clients on Microsoft’s new Forefront Endpoint Protection offering that was released in December of 2010. In addition to recent licensing changes, the biggest change over the pervious release (formerly called Forefront Client Security) is the change out of the management, policy and reporting infrastructure underneath to be based on [...]
Category: Beyond Anti-Virus Endpoint Protection Platform Information Security Tags: Beyond Anti-Virus, Endpoint Protection Platform, Information Security, Microsoft Security, Reducing Complexity, Reducing Cost, Security-Summit-NA, Windows
by Neil MacDonald | May 13, 2011 | Comments Off
I saw this article recently describing an attack against one or more zero day vulnerabilities in Google’s Chrome browser. Worse, the attack reportedly is able to break outside of the “sandbox” (created by the use of mandatory integrity controls within Windows) and execute code at a different trust level. The attack is reportedly not stopped [...]
Category: Application Security Information Security Windows 7 Tags: Apple, Application Security, Beyond Anti-Virus, Browser Security, Security-Summit-NA, Windows
by Neil MacDonald | May 4, 2011 | Comments Off
In discussions with clients, I still run into some confusion on whether or not removal of administrator rights constitutes “lockdown”. Perhaps this was the case a few years ago with older Windows applications and Windows XP, but this is not the case today with Windows 7. For example: Standard users can install and execute well-written [...]
Category: Beyond Anti-Virus Endpoint Protection Platform Microsoft Security Windows 7 Tags: Apple, Beyond Anti-Virus, Endpoint Protection Platform, Lockdown, Microsoft Security, Security-Summit-NA, Whitelisting, Windows
by Neil MacDonald | May 2, 2011 | 3 Comments
Rapid adoption rates, three hundred and fifty thousand apps, but not much malware. What gives? 1) The power of whitelisting. Call it what you may, but having Apple act as the steward of all applications via its App Store is a form of whitelisting (where the list of approved applications [whitelist] is defined by those [...]
Category: Beyond Anti-Virus Endpoint Protection Platform Information Security Microsoft Security Windows 7 Tags: Apple, Beyond Anti-Virus, Defense-in-Depth, Endpoint Protection Platform, Lockdown, Security-Summit-NA, Windows
by Neil MacDonald | April 14, 2011 | 4 Comments
Whether or not you agree with the use of the term “Advanced Persistent Threat” (APT), we can agree that there is a very real threat from advanced intrusions which persist undetected in our systems. By definition, these intrusions are advanced so our traditional (and increasingly ineffective) protection mechanisms such as firewalls and antivirus don’t catch [...]
Category: Beyond Anti-Virus Information Security Next-generation Security Infrastructure Tags: Beyond Anti-Virus, Defense-in-Depth, Endpoint Protection Platform, Information Security, Security-Summit-NA, Whitelisting