layered security solutions - simplified 303-232-9070 © 2008 monte robertson - ceo layered security...

26
Layered Security Solutions - Simplified www.SoftwareSecuritySolutions.com 303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Upload: sydni-webb

Post on 13-Dec-2015

216 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Layered Security Solutions - Simplified

www.SoftwareSecuritySolutions.com

303-232-9070

© 2008

Monte Robertson - CEO

Layered Security Solutions – Simplified!

Page 2: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

The Layered Security Solution for Small Businesses

Goals and Outcomes:

• Begin to understand layered security.

• Put information to immediate use, at home and at work.

• Use this to help others with awareness.

Page 3: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

The Small Business Situation

• SMB does not have the knowledge or skills to address this complex issue.

Small Business Information Security Act of 2008 (Senator Olympia J. Snowe, R-Maine)

As Mentors - You can help!

Page 4: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Identification of Risk

• What data could cause them harm if lost, changed or compromised?

• What do they need to protect?

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

1. Financial Data2. Customer Data3. Vendor Data4. Employee Data5. Health Care, Investments6. Corporate Intellectual Property7. Investors

Page 5: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Identification of Risk• What is the value of each category?

• Where is this information kept?

• What regulations apply to the business’ data?

– PCI, SOX, GLB, HIPAA– E-Discovery requirements for pertinent data

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 6: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Data Back-up

• All categories of Data1. Critical\Non Critical

2. Email – Archiving, new legal requirements

3. Data Shares

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 7: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Data Back-up

• Local – on site, DAS, NAS, Appliances

• Tape vs. new technology

• Off site, Online

• Redundancy & DR

• Standards & Regulations

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 8: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Data Back-up Research

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

• Are all areas identified & backed up? Both on & off site?

• What type do they use & is it efficient?

• Time & resources required to maintain?

• Time & resources required to restore?

• Have backups been tested?

• Comfort & Consequences!

Page 9: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Disaster Recovery Plan

• Identify and assign resources

• Business Continuity

• Insurance

• Tools to help

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 10: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Disaster Recovery Research

• Disaster Recovery Journalhttp://www.drj.com/

• Gartner http://www.gartner.com/5_about/news/disaster_recovery.html

• SBA http://www.sba.gov/services/disasterassistance/index.html

• Plans are a work in progress as business changes.• Less than 10% survive without a plan

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 11: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Anti Malware

• Client machines – laptop, desktop, mobile• Servers• Gateways

1. Internet, Email

• Changes in technology• New Threats

– Mashups & Web 2.0

• $100 additional cost per user

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 12: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Anti Malware Research

• Virus Bulletinhttp://www.virusbtn.com

• Anti Virus Comparativeshttp://www.av-comparatives.org

• AV Testhttp://www.av-test.org

– Times have changed & so have solutions• www.SoftwareSecuritySolutions.com/anti-virus-cost-

calculator.php

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 13: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Firewalls

• Gateway• Inspection types• Additional layers

1. Anti Malware

2. Anti Spam

3. Content Filtering

4. Intrusion prevention

• Personal Firewalls

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 14: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Firewall Research

• ICSA

http://www.icsa.net/icsa/icsahome.php

• West Coast Labs

http://www.westcoastlabs.com

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 15: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Email Security & Filtering

• All user devices• Email Technology

• Spam1. Volume, Cost

• Malware• Phishing• Social Engineering• Archiving, Legal

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 16: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Email Security Research

• How critical is Email to their business?

• Associated cost?

• POP3 vs. SMTP

• Conduct CBA on Service vs. Appliances & Software

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 17: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Wireless Security

• Mobile Devices1. Anti malware

2. Backup & theft recovery

• Wireless Networks

• Authentication

• Encryption

• WEP\WPA

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 18: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Web Security & Filtering

• All user devices\Servers

• Shift in threat

• Web applications– PCI compliance

• Searching\Surfing

• Liabilities

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 19: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

User Education & Application updates

• Weakest link

• Threat Surface

• Future attacks

• Updates1. OS

2. Office

3. Common apps

4. Checked regularly?

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 20: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

User Education Resources

Employee Awareness:http://www.gocsi.com/awareness/awareness_peer_group.jhtml

Security Video:http://i.cmpnet.com/gocsi/wsc/video.html

World Security Challenge:http://www.gocsi.com/WSC/

Customizable Awareness Newsletter:http://www.gocsi.com/awareness/front.jhtml

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 21: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Security Policy

• Definitions– All Layers– Acceptable Use– Consequences

• Resources– What to use– Who supports

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 22: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Security Policy Resources

• Policies, Standards and Guidelines: https://www2.sans.org/resources/policies/

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 23: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

What they can (and should) do right now

• Network Configuration (P2P vs. Domain)

• Updates – 3rd party

• Office machines – (all in one)

• Laptop encryption, theft tracking

• User rights

• File Access

• Physical Access

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 24: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Implementing a Layered Security Solution

• Create a Security Policy

• Formulate an adoption plan

• Budget

• Start with most critical areas

• Set & forget not an option

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 25: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Questions and Answers

If your data isn’t secure, it isn’t your data.®

www.SoftwareSecuritySolutions.com

Page 26: Layered Security Solutions - Simplified  303-232-9070 © 2008 Monte Robertson - CEO Layered Security Solutions – Simplified!

Layered Security Solutions - Simplified

www.SoftwareSecuritySolutions.com

303-232-9070

© 2008

Monte Robertson – CEO

Layered Security Solutions – Simplified!