Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 55 guests and 2 members online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Other
Company Wide InfoSec....
EH-Net
May 22, 2013, 04:44:48 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Other
(Moderator:
don
) >
Company Wide InfoSec....
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Company Wide InfoSec.... (Read 2742 times)
0 Members and 1 Guest are viewing this topic.
SecurityMonkey
Jr. Member
Offline
Posts: 89
Company Wide InfoSec....
«
on:
August 20, 2012, 07:54:34 PM »
I have worked for a number of large companies and have found that different ones treat InfoSec differently.
One in particular were very keen to make sure IP was not leaked out of the company, they made sure all users were aware of the Green, Yellow , Red designations of data. Anything that was above Green was NOT to go to people outside of the company and Red and Yellow print outs were to be shredded.
But when it came to the security of the network and data on the network it was different. Users were allowed to copy files to USB keys with no encryption. Never once did they employ a company to test the security of the network, relying 100% on the automated scanning tool!
Do you guys find this is often the case with companies? They do a great job in some parts of InfoSec and not others?
Logged
www.securitymonkey.net
cd1zz
Hero Member
Offline
Posts: 561
Re: Company Wide InfoSec....
«
Reply #1 on:
August 20, 2012, 08:52:54 PM »
Yes. I've found that most companies are pretty bad in general and the exceptions to the rule only do
some
of it well, like you said.
Infosec is hard to do right, really hard. I'm so glad I am on the offensive side of things now because its expensive, difficult to manage and hard to get budget approval for. I think that a lot of companies struggle to find that balance between functionality and security. I also think that a lof companies dont understand that there are ways to mitigate a lot of the risk and problem areas that they face, that might be much less expensive.
I would say 2% of the companies we deal with are proactive about security. It's clear that they have a solid enterprise security program, but we still can usually get in. It's just to hard to do well!!
my 2 cents
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
ajohnson
Recruiters
Hero Member
Offline
Posts: 1057
aka dynamik
Re: Company Wide InfoSec....
«
Reply #2 on:
August 21, 2012, 06:36:47 AM »
Quote from: cd1zz on August 20, 2012, 08:52:54 PM
I would say 2% of the companies we deal with are proactive about security.
This. When overall security is poor, but there are a few tasks done really well, those are usually a direct result of audit findings and/or historic incidents (or someone with some pull saw a really convincing piece on CNN).
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
m0wgli
Full Member
Offline
Posts: 248
Re: Company Wide InfoSec....
«
Reply #3 on:
August 21, 2012, 08:04:14 AM »
Quote from: SecurityMonkey on August 20, 2012, 07:54:34 PM
One in particular were very keen to make sure IP was not leaked out of the company, they made sure all users were aware of the Green, Yellow , Red designations of data. Anything that was above Green was NOT to go to people outside of the company and Red and Yellow print outs were to be shredded.
But when it came to the security of the network and data on the network it was different. Users were allowed to copy files to USB keys with no encryption. Never once did they employ a company to test the security of the network, relying 100% on the automated scanning tool!
You could argue they weren’t even doing the first part very well if anyone was capable of walking out the door, with the data on an unencrypted USB stick.
Logged
Security + | OSWP | eCPPT | CSTA
Jamie.R
Sr. Member
Offline
Posts: 429
Re: Company Wide InfoSec....
«
Reply #4 on:
August 21, 2012, 08:51:23 AM »
I have seen the same in my time where companies just do so many things wrong. I have even seen security companies that have made mistakes and have sql and XSS on their site.
«
Last Edit: August 22, 2012, 08:07:51 AM by Jamie.R
»
Logged
OSWP | Hackingdojo Nidan | eCPPT
3xban
Hero Member
Offline
Posts: 608
Re: Company Wide InfoSec....
«
Reply #5 on:
August 21, 2012, 01:26:43 PM »
I am currently in a similar position. I've spent most of my time in the SMB realm as a consultant. Most of the SMBs that I have worked with are much better off security wise than the big enterprises. I think what makes this work is for one, their risk of data loss is much greater than that of a large organization. It could be the difference between closing the doors or keeping them open for another couple years. They simply don't make the revenue to afford any major fines or have their IP stolen and their business fly out the door to the competitors. For those that realize this, security means everything.
Now back to the large enterprises. At this time many I think are in a reactive state due to some breach or major incident. They are in clean-up mode and looking for the "magic bullet" to help them protect their data from "APTs." My problem with their approach to remediate these issues, is the fact they are not even practicing security 101. How could you take a 501 course when you haven't met the pre-reqs??? You can't even understand the basics but you want to jump right into the advanced skills. Ok you have the firewalls, the IDS/IPS in place and a switched network with a solid core. Lets ensure we are using those devices to the fullest extent before buying more crap that no one knows how to use.
Don't even get me started on outsourcing. My feeling is that, depending on the size of the environment, you should have at least one FTE per area. That FTE should be an expert level for that system. They should send the tasks to the outsourcing company to complete but at the same time they also understand and can perform the duties required. They are available on the higher level engineering side. They can focus on improving the architecture and allow the outsourced company to perform the day-to-day operational tasks.
Logged
Certs: GCWN
(@)Dewser
SecurityMonkey
Jr. Member
Offline
Posts: 89
Re: Company Wide InfoSec....
«
Reply #6 on:
August 21, 2012, 05:17:37 PM »
To contrast that I have worked for a company that did things almost right… The only users with internet access were the office admin team (HR, Front Desk). The Developers and Analysts had no internet, no external email, no USB access and could not print!
Logged
www.securitymonkey.net
jjwinter
Jr. Member
Offline
Posts: 76
Re: Company Wide InfoSec....
«
Reply #7 on:
August 22, 2012, 09:03:20 PM »
I too deal primarily with SMB's, well mostly SB. The major issue I've seen recently is how poorly they deal with employee termination. I got a call from one THREE WEEKS after they let someone go for check stealing. She still had remote access and a working company email. I found out during a routine checkup. They said "Oh, don't bother with her computer, she doesn't work here anymore..."
She had been given significant access to many areas. My head spins at the harm that
could
have been wrought. I had a chat with the boss and hopefully enlightened him. At the very, very least, call me first before firing anyone so I can cut access and lock their account.
I know many larger companies with real HR departments handle this more professionally. Have any of you needed to step in and fix employee termination processes as part of an evaluation?
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Burberry UK,2013 Burberry Safety-valve Online Available in London
(4) by
BeecyGorror
Greetings
: but the desperate effort that comes from being hopeful Nike Blazers Uk
(0) by
Loyatoitada
ChicagoCon 2007
: waterfall Cheap Air Max Sale
(0) by
Loyatoitada
News Items and General Discussion About EH-Net
: The advent of the web happened slowly Nike Blazer Uk
(0) by
Loyatoitada
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.