Download Hacking For Dummies

Transcript
Chapter 18: Plugging Security Holes
Beyond patching, if you follow the countermeasures I’ve documented in this
book, along with the other well-known security best practices that are freely
available on the Internet for such network systems (routers, servers, workstations, and so on), as well as perform ethical hacking tests on an ongoing
basis, you can rest assured that you’re doing your best to keep your organization’s information secure.
Assessing Your Security Infrastructure
A review of your overall security infrastructure can add oomph to your
systems.
Look at the big picture. How is your network actually designed? What about
your building? You should even consider organizational issues such as whether
policies are in place, maintained, or even taken seriously. Does upper management take information security seriously, or do they simply shrug it off as
another unnecessary expense?
Using the information you gathered by performing the ethical hacking tests
in this book, map your network. Update existing documentation — a major
necessity. Outline IP addresses, running services, and whatever else you’ve
found out. Although I prefer Visio or other, more-capable network diagramming tools, you could even draw out your map on a napkin! Just draw it out.
Network design and overall security issues are a whole lot easier to assess
when you can see them visually.
Are you focusing all your efforts on the perimeter and not on a layered security
approach? Think about how most convenience stores and banks are protected.
Their security cameras are focused on the cash registers, teller computers,
and surrounding areas — not just on the parking lot or entrance areas. Look
at security from a defense in-depth perspective. Make sure that several layers of
security are in place just in case one measure fails, so the malicious user must
go through various other barriers and jump through other hoops to carry out
a hack attack successfully.
Do the same thing with organizational issues as well. Document what security
policies and procedures are in place and how effective they are. Look at the
overall security culture within your company, and see what it looks like from
an outsider’s perspective. What would customers or business partners think
about how your organization is treating their confidential information?
Looking at your security from a high-level and nontechnical perspective will
give you a new outlook on what else still needs to be done. It takes some time
and effort at first, but after you establish a baseline of security, it will be much
easier to manage and keep a handle on moving forward as new threats and vulnerabilities emerge.
309