People soft. Computers hard.

People soft. Computers hard.

People are advised to be soft and vulnerable in order to be able to communicate and build trust between each other. Please do remember that with computers this is not the case.

One of the classic situations that we face with clients is a phenomena where hardening the systems or limiting traffic between trust zones or network is seen as "burdensome useless waste of time that is done merely to please the compliance". Clients sometimes seem to race on how little is counted as "hardening done" tick-box on the audit report.

MS just updated their CVE-2020-16898 ICMPv6 RCE vulnerability to "just" 8.8 from 9.8 on CVSS score due exploitability index changes. They realized that building an exploit for this is a bit harder than initially expected. A working exploit would still make it possible to spread the foothold of the initial attack to every non-hardened latest version Windows server or Win10 computer in the network.

How many of you have IPv6 stateless address auto-configuration as primary source of routing information in your network? If not, why then keep it enabled and running on the background? If you don't support printers on every server, why then let the print spooler service run and communicate on every host? Why allow insecure SMB versions to exist? Or SQL server to communicate to whole internal network and not just the application server that actually uses it?

Hardening is hard but that's why it's called hardening. When looking it from a very Finnish perspective, you simply cannot keep your house warm in the freezing winter times if you use single layered window glasses, poor insulation on walls and if you leave the backyard door open just in case you might want to visit the garden tomorrow.

Ask for advice if you need some. Winter is coming.

Good place to start. https://www.cisecurity.org/cis-benchmarks/

Hannes Saarinen

Privacy Director at RELEX Solutions

4 年

"you simply cannot keep your house warm... if you use single layered window glasses," -> excellent comparison.

It helps to fire up saunas and hot tubs during the winter ;)

Joonas Heimonen

#CISOlife | CISM | CISA

4 年

"Winter is coming" ????

要查看或添加评论,请登录

Antti Laatikainen的更多文章

  • PCI Tips'n'Tricks, part 2 - "PCI DSS March 31st requirements for service providers"

    PCI Tips'n'Tricks, part 2 - "PCI DSS March 31st requirements for service providers"

    As PCI DSS (and the payment ecosystem altogether) is so heavily leaning towards service providers, there were so many…

  • Insights into NIS2 compliance

    Insights into NIS2 compliance

    NIS2 requires companies to identify their critical dependencies on IT systems and recognize the associated risks. These…

    3 条评论
  • Vendor management, PCI style.

    Vendor management, PCI style.

    We have lately been running into multiple clients that have challenges on sketching out what PCI DSS requirement 12.8.

    2 条评论
  • Customize your PCI in version 4.0

    Customize your PCI in version 4.0

    There's a lot happening in the PCI world right now, with new version of the Point-to-Point-Encryption standard rolling…

  • OPSman Auditing

    OPSman Auditing

    After doing audits and assessment for more than 5 years now, I've had a pleasure and privilege to visit, and not only…

    1 条评论
  • "Safe Harbor 2.0" = EU-US Privacy Shield

    "Safe Harbor 2.0" = EU-US Privacy Shield

    New umbrella agreement between EU and US is born, at least on paper. Just in time, since the old one was canceled at…

  • Time is running out on Safe Harbor 2.0

    Time is running out on Safe Harbor 2.0

    With end of January closing in and nothing concrete coming out from EU’s Article 29 Working Party, it seems more and…

  • EU-US Safe Harbour framework has been dismantled

    EU-US Safe Harbour framework has been dismantled

    So this was the day when the highly anticipated decision was made - EU highest court ruled that U.S.

    4 条评论
  • GDPR,TTIP ja ISDS, mik? n?ist? m??r?? yksityisyydensuojan tason EU:ssa?

    GDPR,TTIP ja ISDS, mik? n?ist? m??r?? yksityisyydensuojan tason EU:ssa?

    T?m? on k??nn?s aiemmin Englanniksi kirjoittamastani artikkelista (this is a translation of my previous…

    1 条评论
  • GDPR,TTIP and ISDS, which one will set the bar for EU privacy law?

    GDPR,TTIP and ISDS, which one will set the bar for EU privacy law?

    From the beginning, I want to make it 100% clear that I’m not a lawyer or in any way a professional in international…

    5 条评论

社区洞察

其他会员也浏览了