dslreports logo
site
 
    All Forums Hot Topics Gallery
spc

spacer




how-to block ads


Search Topic:
uniqs
389
share rss forum feed

avze

join:2013-08-19

HIPS/firewall protection

i was speaking to one ISO (information security officer) and he tells me that running an enterprise level HIPS with a properly configured firewall rules means we do not have to patch our Windows OS with secuity updates.
Is this just BS or what????



ashrc4
Premium
join:2009-02-06
australia

1 edit

He said "we" and I believe they could. The rest of the configs and practices more than likely won't suit most if any.


avze

join:2013-08-19

do not quite understand your reply.
So if one has an enterprise grade HIPS/firewall does that mean they will not need those OS security patches because the HIPS will protect them anyway?


HELLFIRE
Premium
join:2009-11-25
kudos:8
reply to avze

said by avze:

Is this just BS or what????

Tell said ISO to start rewriting their resume... if not the press release explaining why they think patching is NOT necessary. Sure the hackers of the world will LOVE to prove said ISO wrong.

To me, that just smacks of stupidity to the Nth degree... not to mention a failure of good practices when doing a "corporate security policy" -- namely "monitor and respond," "test," and "manage and improve."

...or as I got drilled into me in Corporate InfoSec 101 -- "security is a process, NOT a product."

Regards

TheMG
Premium
join:2007-09-04
Canada
kudos:2
reply to avze

Security is NOT a one-layer approach. There are many layers to a good security approach and one of those layers is keeping OS and applications up to date with security patches.

There are many methods by which malware can infect a system/network without being detected/stopped by the very best of firewalls.


Mele20
Premium
join:2001-06-05
Hilo, HI
kudos:4

HIPS is NOT a firewall. A great HIPS is all you need. You would NOT need to keep up with security patches. BUT there are no great HIPS since ProcessGuard that does not work beyond XP. You can thank Microsoft for that. (Plus, it should go without saying that the user must fully understand how to use the HIPS or all bets are off. Most HIPS are difficult to use).
--
When governments fear people, there is liberty. When the people fear the government, there is tyranny. Thomas Jefferson


avze

join:2013-08-19

I think the ISO meant, was if you have an enterprise grade HIPS along with a properly configured software firewall and router firewall, it will only just keep the ZERO Day bugs to a stop until things get patched up to the OS level.
So until the OS security patches are being testing or unable to be pushed out on time, then the HIPS/firewall will at least stop or monitor all zero day exploits.



jimkyle
Btrieve Guy
Premium
join:2002-10-20
Oklahoma City, OK
kudos:2
Reviews:
·AT&T Southwest
reply to Mele20

said by Mele20:

A great HIPS is all you need.

Unfortunately, Murphy's first law of software remains true of even that "great HIPS" -- Every program is too long and contains at least one bug; this remains the case after shortening it and removing the bug.

You don't have to be paranoid to be secure, but it helps. And the only truly secure system is one that has no input or output capability, and is powered off.
--
Jim Kyle