About

This page contains a single entry from the blog posted on November 7, 2006 8:05 AM.

The previous post in this blog was Biometrics and US Department of Defense.

The next post in this blog is Oops...I accidentally sent out an infected email to 50,000 customers!.

Many more can be found on the main index page or by looking through the archives.

« Biometrics and US Department of Defense | Main | Oops...I accidentally sent out an infected email to 50,000 customers! »

Undisclosed flaws and a layered enterprise defense

While zero day exploits have been making headlines the last couple of years, what is slowly reaching the media are "less than zero day" flaws. For example, the story yesterday in Computerworld "Undisclosed flaws Undermine IT Defenses".

The story points out that there are many software and security holes that are unreported, to which enterprises are vulnerable to. Quoting a CTO of a telecommunications company, "Therefore, the emphasis has to be on detecting and containing the fallout from any attacks to the greatest extent possible, he added. That requires multiple layers of defenses not just at the network perimeter but behind it as well, according to Sullivan, who recommended the use of security measures such as strong user and device authentication, strict role-based access controls, network segmentation and data encryption."

The article is light on the many layers required. While it does mention perimeter security and authentication access control, it doesn't mention checking out workers before hiring, training users to not click on email links, multi-factor authentication and transaction authentication.

Guy
www.authenticationworld.com
guy.huntington@authenticationworld.com

TrackBack

TrackBack URL for this entry:
http://www.authenticationworld.com/cgi-bin/blog/mt-tb.cgi/39

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)