<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1 - it-operations</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/tags/it-operations/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2015-06-01T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/tags/it-operations/atom.xml</id>
    <entry xml:lang="en">
        <title>Taking Control of IT Operations through the Critical Security Controls</title>
        <published>2015-06-01T00:00:00+00:00</published>
        <updated>2015-06-01T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/taking-control-with-critical-security-controls-csooutlook/"/>
        <id>https://blog.itys.net/vol1/posts/taking-control-with-critical-security-controls-csooutlook/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/taking-control-with-critical-security-controls-csooutlook/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The CSO Outlook article Taking Control of IT Operations through the Critical
Security Controls by Matthew J. Harmon explains how embedding the first five of
the SANS&#x2F;CIS 20 Critical Security Controls into everyday IT processes can
transform security from a reactive cost center into a proactive, measurable
discipline.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;starting-easy&quot;&gt;Starting Easy&lt;&#x2F;h2&gt;
&lt;p&gt;First, Harmon shows that many breaches start with unknown or low-priority
systems, devices and software not inventoried or patched. Controls 1 (Inventory
of Authorized and Unauthorized Devices) and 2 (Inventory of Authorized and
Unauthorized Software) create visibility by correlating DHCP, ARP, and DHCP
assignments for hardware and using WMIC, RPM&#x2F;APT, or SCCM to catalog installed
applications. This foundational inventory maps assets to owners, enables
application whitelisting, and allows organizations to detect unauthorized
additions before attackers can pivot.&lt;&#x2F;p&gt;
&lt;p&gt;Next, the article tackles Controls 3 through 5: secure configurations,
continuous vulnerability assessment and remediation, and malware defenses.
Harmon advocates applying vendor and CIS hardening guidelines via Group Policy
Objects or configuration-management tools (Puppet, Chef), enforcing a 48-hour
patch window for critical flaws through tiered testing and deployment, and
layering defenses beyond antivirus, such as host firewalls, DNS filtering (e.g.,
OpenDNS), and threat-intelligence driven proxies. He concludes by recommending a
gap assessment against the remaining controls and a phased implementation
roadmap to embed these practices into routine IT operations and gauge their
impact over time .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;57174_2015-06-01_Taking_Control_with_Critical_Security_Controls-CSOOutlook.pdf&quot;&gt;CSO Outlook: Taking Control of IT Operations Through the Critical Secuity
Controls&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
