Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 47 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Compliance, Regulations & Standardsarrow Security Dashboard
EH-Net
May 22, 2013, 12:36:54 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1] 2   Go Down
  Print  
Author Topic: Security Dashboard  (Read 19639 times)
0 Members and 1 Guest are viewing this topic.
Dengar13
Sr. Member
****
Offline Offline

Posts: 380



View Profile
« on: April 05, 2010, 06:12:58 AM »

Has anyone ever had to do one of these?

Essentially, I am tasked with:  creating a snapshot that shows all aspects of security health that can be easily understood at the Exec level.

If anyone knows of any examples, ideas or suggestions I would greatly appreciate it.
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
ziggy_567
Sr. Member
****
Offline Offline

Posts: 361


View Profile
« Reply #1 on: April 05, 2010, 08:40:26 AM »

Have you taken a look at:

http://www.sans.org/security-resources/top5_logreports.pdf?ref=3766

Also, if your collecting network traffic, its always nice to see things like workstations/endpoints creating the highest traffic volume, workstations that are utilizing banned protocols, etc. etc.


--
Ziggy
Logged

--
Ziggy


eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
Dengar13
Sr. Member
****
Offline Offline

Posts: 380



View Profile
« Reply #2 on: April 05, 2010, 09:55:21 AM »

Thanks, Ziggy.  I think I will include charts, graphs and pictures since execs seem to like those better and can be a better point of reference than wording.  But, I will have captions as well so it has substance. 
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #3 on: April 05, 2010, 10:09:41 AM »

In my experience, execs like to see security related to dollars.   They react better when you are prepared to tell them:

a.  how much is it going to cost us?
b.  what is the potential cost if we don't do this?

I think that if you put security in the terms of risk analysis, they will respond better to your presentation.   

I think that charts and graphs are an excellent idea, especially if they rating the security issues in terms of cost, risk, and impact.

These are just my two cents.
Logged

~~~~~~~~~~~~~~
Ketchup
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« Reply #4 on: April 05, 2010, 08:01:55 PM »

Have you tried Splunk? I guess it would depend on the size of your organization if it would remain free, but here's a link that may help:

http://www.splunk.com/base/Documentation/latest/Developer/DashboardIntro

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Dengar13
Sr. Member
****
Offline Offline

Posts: 380



View Profile
« Reply #5 on: April 06, 2010, 07:38:41 AM »

Downloading now, Don.  I put your site and you as the person who referred me to this solution.

Thanks to you as well, Ketchup!  Good ideas to go off of.  I am going to start this today and see how it goes.
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #6 on: April 06, 2010, 10:43:22 AM »

Dengar13,

Please let us know what you think of Splunk. I had it at work, but the company wouldn't pay for the full version, thus usage was limited. Mainly it was used as a syslog tool for the NAS.

I didn't care for it, based on the limited function of it. When I took over the senior role, I dropped it and went with a proper syslog server in it's place.

I have heard other people speak good of it, require it for security related jobs, and I wonder what a full version would provide.
Logged

OSWP, Sec+
ziggy_567
Sr. Member
****
Offline Offline

Posts: 361


View Profile
« Reply #7 on: April 06, 2010, 11:47:29 AM »

I can't believe I didn't think of Splunk. I use the free version of Splunk as well, but I love it!

We use it with syslog-ng on our Solaris/RedHat servers for our log server. We've also incorporated all our Cisco logging, and a few of our Windows servers (with Snare). We are soon to start incorporating Apache and Weblogic logs to our implementation.

Splunk is awesome!!! Its not so intuitive to configure, but its VERY intuitive to use through the GUI once setup. The commercial version is not that expensive (depending on how much throughput you need) to boot...

--
Ziggy
Logged

--
Ziggy


eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
Dengar13
Sr. Member
****
Offline Offline

Posts: 380



View Profile
« Reply #8 on: April 06, 2010, 11:55:32 AM »

Roger that, chrisj.  I will be sure to do so when I have it set up and tuned the way I need it for my environment.
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
Dengar13
Sr. Member
****
Offline Offline

Posts: 380



View Profile
« Reply #9 on: April 16, 2010, 02:27:11 PM »

Well, Splunk has been scrapped.  The cost is too high for us to use and I will have to find a clever way to do this and am thinking I may leverage what I already have internally.  Thanks for the help as always!
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #10 on: April 16, 2010, 02:34:52 PM »

What about one of the ManageEngine products? I just happened to see an ad here on EH-Net for their helpdesk product (I actually implemented this in a prior position, price was very reasonable, much cheaper than competing products). They had a lot of different products, and I thought one or two was for overall network status that may have included security. Their stuff is very graphical and pretty Smiley and easy to use. I'll have to take a look at their products again, but I know they had a couple of security-related things.
Logged
Dengar13
Sr. Member
****
Offline Offline

Posts: 380



View Profile
« Reply #11 on: April 16, 2010, 02:35:57 PM »

Sweet....I will take a gander at that.  I appreciate that.
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #12 on: April 16, 2010, 02:36:11 PM »

http://www.manageengine.com/it-compliance-suite.html

Any of these do what you need?

No problem Smiley
Logged
Dengar13
Sr. Member
****
Offline Offline

Posts: 380



View Profile
« Reply #13 on: April 16, 2010, 02:40:57 PM »

WOW!  I'd say a couple of them would do the trick.  I will have to demo it and see what pricing is like.
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #14 on: April 16, 2010, 04:29:21 PM »

Cool, let us know how that works out. They were very accommodating of licensing for testing purposes when I worked with them.
Logged
Pages: [1] 2   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.591 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.