Password creation policies are the enemy of secure... » Commenting on reports that a security developer has concluded that password-creation policies are th... Thousands of Young Adventurers kept safe with M2M ... » Thousands of teenagers taking part in the annual two-day Ten Tors Challenge across Dartmoor in Devon... avast! Free Antivirus for Mac tops CNET’s download... » PRAGUE, Czech Republic: Three days after its release avast! Free Antivirus for Mac shot to first pos... USB-Tischmikrofone von Imtradex gewährleisten schn... » TM2-LS und TM3 verbinden innovative Technik mit einfacher Handhabung Dreieich: Schnelle und einfach... Opengear wins Information Technology Industry’s 20... » Opengear ACM5504-5-G-I Remote Infrastructure Management Gateway Honored at Interop Interop, Las Veg... ISACA Speaker urges IT candidates to shift career ... » In-depth discussion to be held at INSIGHTS 2012 London, UK: Recruiting in the technology sector is ... Venafi hails FBI’s hotel-network security warning ... » London: “Everyone with an Internet connection has a stake in understanding the critical links in the... Is loaphobia causing workers to fear losing their ... » 19% missed a critical deadline because they couldn’t access the right applications, 14% lost a job a... Whoopee! £38 billion blackhole in Defence budget e... » Vigilance can report that the MoD’s budget deficit has been wiped out for the first time in a genera... Media Alert: DDoS tool (LOIC) downloads increasing... » Imperva's Application Defense Centre has been tracking the Anonymous DDoS tool, LOIC, and the number...

Advertise with Vigilance

Got News?

Got news for Vigilance?

Have you got news/articles for us? We welcome news stories and articles from security experts, intelligence analysts, industry players, security correspondents in the main stream media and our numerous readers across the globe.

READ MORE

Subscribe to our Newsletter

Information Security Header

Manchester (UK) and Boston (MA): Reacting to a report from Trustwave claiming that antivirus (AV) software is powerless to stop data breaches, Avecto says the study’s conclusion is similar to that of a Best Buy Guide to Chocolate Fireguards - the end result is always going to be a negative one.

 

“This report conclusion made me smile, as the reality is that, if a system compromise has occurred, then the security surrounding IT has obviously failed. Never mind that 99.9 per cent of the other times the IT defences have worked - what this study really proves is that a multi-layered security defence strategy is the only way to go,” said Paul Kenyon, chief operating officer with the Windows privilege management specialist.

“In taking a multi-layered security approach, he says, IT security systems can help defend against today’s hybridised and multi-vectored technology aggression – ranging from a simple piece of virus malware, all the way through to a man-in-the-browser blitzkrieg,” he added.

And, he went on to say, while the primary aim of today’s attacks is to monetise a cybercriminal fraud - or simply embarrass an organisation, as illustrated by the latest politically-motivated hacktivist attacks – defending against these technology barrages requires a well-planned strategy.

That strategy, he explained, goes way beyond the simple use of AV software and needs to involve advanced technologies that include security privilege management – controlling who can use which software assets, as well as from what location and at what time.

Although taking this approach may sound complex, says Kenyon, the fundamental principle is one of breaking the security process into a series of simple stages and the building the defences up from there.

“In the case of our own Windows privilege management approach - which seeks to reduce the security risk profile of the Windows desktop - you manage the endpoint through the use of admin domains; UAC - user account control; software hardening; application whitelisting; and assigning privileges to each user,” he said.

Limiting admin privileges to true administrators only, engenders advancement towards the least risk Windows 7 desktop. By ensuring all other users log on with standard user rights, and only elevating applications, a new option previously unavailable to organizations is introduced.

Put simply, Kenyon says, this means that if a hacker gains access to a general user account – which are in the majority - they have no admin privileges. Coupled with the aforementioned endpoint management controls, you then end up with the aim of a highly effective IT security strategy: a least risk environment:

Source: Gartner Making the Most of Windows 7 Security, dated 24th August 2010 – Dan Blum

“This is the heart of our Windows privilege management approach to security and is designed to augment the basic AV software and firewall systems that many organisations still rely upon – and whose systems almost certainly feature in the 300 instances of data breaches identified in this report,” he said.

“In my opinion, the takeout from this report is that AV technology should no longer be the solus security system that companies rely upon to defend the integrity of their data and allied IT platforms. Better security in today’s electronic space means tapping the power of technologies such as privilege management as an integral part of your defences,” he concluded.

Add comment


Security code
Refresh