 | HIPS/firewall protection i was speaking to one ISO (information security officer) and he tells me that running an enterprise level HIPS with a properly configured firewall rules means we do not have to patch our Windows OS with secuity updates. Is this just BS or what???? |
|
 ashrc4Premium join:2009-02-06 australia 1 edit | He said "we" and I believe they could. The rest of the configs and practices more than likely won't suit most if any. |
|
 | do not quite understand your reply. So if one has an enterprise grade HIPS/firewall does that mean they will not need those OS security patches because the HIPS will protect them anyway? |
|
|
|
 | reply to avze
said by avze:Is this just BS or what???? Tell said ISO to start rewriting their resume... if not the press release explaining why they think patching is NOT necessary. Sure the hackers of the world will LOVE to prove said ISO wrong.
To me, that just smacks of stupidity to the Nth degree... not to mention a failure of good practices when doing a "corporate security policy" -- namely "monitor and respond," "test," and "manage and improve."
...or as I got drilled into me in Corporate InfoSec 101 -- "security is a process, NOT a product."
Regards |
|
 TheMGPremium join:2007-09-04 Canada kudos:2 | reply to avze
Security is NOT a one-layer approach. There are many layers to a good security approach and one of those layers is keeping OS and applications up to date with security patches.
There are many methods by which malware can infect a system/network without being detected/stopped by the very best of firewalls. |
|
 Mele20Premium join:2001-06-05 Hilo, HI kudos:4 | HIPS is NOT a firewall. A great HIPS is all you need. You would NOT need to keep up with security patches. BUT there are no great HIPS since ProcessGuard that does not work beyond XP. You can thank Microsoft for that. (Plus, it should go without saying that the user must fully understand how to use the HIPS or all bets are off. Most HIPS are difficult to use). -- When governments fear people, there is liberty. When the people fear the government, there is tyranny. Thomas Jefferson |
|
 | I think the ISO meant, was if you have an enterprise grade HIPS along with a properly configured software firewall and router firewall, it will only just keep the ZERO Day bugs to a stop until things get patched up to the OS level. So until the OS security patches are being testing or unable to be pushed out on time, then the HIPS/firewall will at least stop or monitor all zero day exploits. |
|
 jimkyleBtrieve GuyPremium join:2002-10-20 Oklahoma City, OK kudos:2 Reviews:
·AT&T Southwest
| reply to Mele20
said by Mele20:A great HIPS is all you need. Unfortunately, Murphy's first law of software remains true of even that "great HIPS" -- Every program is too long and contains at least one bug; this remains the case after shortening it and removing the bug.
You don't have to be paranoid to be secure, but it helps. And the only truly secure system is one that has no input or output capability, and is powered off. -- Jim Kyle |
|