Thursday, August 6, 2015

Tabula Rosa Systems Twenty Greatest Security Risks


The following list is one I recently came across which describes the ranking of security dangers. For those who have a say in their own or their organization's security decision making. I have always wondered what order these issues should have. Here is one very plausible answer!
==========================================================
(Adapted from www.sans.org/critical-security-controls/winter-2012-poster.pdf.)

Most security practitioners are familiar with the 20CSC. The controls are designed to counter an adversary’s actions of conducting reconnaissance, gaining access, keeping access and exploiting target systems by stopping attacks early, stopping multiple attacks, and mitigating the impact of any attacks that are implemented. The controls, listed in Figure 1, are prioritized by their capability to provide a direct defense against attacks. The first four controls have a very high effect on attack mitigation, while the last two are rated as having a low effect (but still important enough to be implemented.)    
Critical Control Effect on Attack Mitigation    
1. Inventory of Authorized and Unauthorized Devices    
2.     Inventory of Authorized and Unauthorized Software    
3.     Secure Configurations for Hardware and Software on Laptops, Workstations, and Servers    
4.     Continuous Vulnerability Assessment and Remediation    
5.     Malware Defenses    
6.     Application Software Security    
7.     Wireless Device Control    
8.     Data Recovery Capability    
9.     Security Skills Assessment and Appropriate Training to Fill Gaps    
10.     Secure Configurations for Network Devices such as Firewalls, Routers, and Switches    
11.     Limitation and Control of Network Ports, Protocols, and Services    
12.     Controlled Use of Administrative Privileges    
13.     Boundary Defense    
14.     Maintenance, Monitoring, and Analysis of Security Audit Logs    
15.     Controlled Access Based on the Need to Know    
16.     Account Monitoring and Control    
17.     Data Loss Prevention    
18.     Incident Response Capability    
19.     Secure Network Engineering    
20.     Penetration Tests and Red Team Exercises    
    VERY HIGH HIGH MODERATE LOW    
   Figure 1: The 20 Critical Security Controls (Version 3.1) and Their Effect on Attack Mitigation  
SANS Analyst Program 4 Reducing Federal Systems Risk with the SANS 20 Critical Controls.
     ======================================================
Tabula Rosa Systems features a rich suite of "best of breed" products and services for network, security and systems management.  You can follow our Twitter page or our website at:

www.tabularosa.net or call us at (609) 818 1802. 

=======================================
 I am the founder and president of  a sister company, Netiquette IQ. It has a website with great assets which are being added to on a regular basis as well as a new Twitter site. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:


 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Tuesday, August 4, 2015

Tabula Rosa Systems Blog For 8/4/2015 - Netiquette IQ Blog Of 8/4/2015 - Email Can Be Indefinitely Recoverable With Office 365









Email can be indefinitely recoverable with Office 365
·         By Kurt Mackie
·         Feb 23, 2015 gcn.com

Ever hear from users who cleaned out their email only to discover later they’ve deleted something important? Not to worry. IT managers will soon have the option to make email and calendar items recoverable, no matter when they were deleted. 
Currently Outlook 365 administrators can recover emails 30 days after they get deleted by an end user. After that time, the email becomes unrecoverable.  Microsoft’s new policy makes email in the Deleted Items folder accessible indefinitely, or for as long as determined by the email administrator.
If an end user takes the effort to empty the Deleted Items folder, though, those items will still be unrecoverable, Redmond clarified.
This policy change will arrive "over the next month" as an update for Office 365 subscribers, according to the company's announcement. Microsoft will write over the current default Messaging Records Management (MRM) policy for Office 365 account holders to reflect the new policy.
Organizations retaining a "Default MRM Policy" setting will get the new policy change. However, if organizations don’t want it, they can rename the setting and create a custom policy, specifying the email retention time period that's wanted from a drop-down list. Modifications to the Default MRM Policy can be performed by using the Exchange Admin Console or PowerShell.
Microsoft describes the shell path to modify the policy setting as follows: "Office 365 Admin > Exchange admin center > compliance management > retention policies." IT pros can then access the Default MRM Policy and modify it.
If an organization already has a custom MRM policy, the change Microsoft plans to push down in a month won't affect it, as long as it has been renamed from the "Default MRM Policy" name, according to Microsoft.
The policy change will only affect the "Deleted Items" folder. It won't affect the "Recoverable Items" folder, Microsoft's announcement clarified. Both primary and archive mailboxes will be affected by the new policy change. The "Litigation Hold" and "In-Place Hold" spaces won't be affected.
Microsoft's announcement didn't explain why the policy change was being made. However, Microsoft MVP Tony Redmond, in an article at Windows IT Pro, said that deleted emails that pass beyond the 30-day retention period currently become unrecoverable in Microsoft's Office 365 service under the current policy, and possibly that circumstance may have led to some customer complaints.
Redmond noted some scenarios where organizations may want to alter the Default MRM Policy to avoid Microsoft's new policy change. Some organizations may find the permanent retention of deleted emails to be problematic from a compliance perspective. Possibly, offline storage .OST performance could be affected if deleted emails pile up, he suggested, especially when using older Outlook clients.

For a great email parody, view the following link:

https://www.youtube.com/watch?v=HTgYHHKs0Zw&__scoop_post=bcaa0440-2548-11e5-c1bd-90b11c3d2b20&__scoop_topic=2455618



==============================================
**Important note** - contact our company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================

Tabula Rosa Systems Technical Term For 8/4/2015 - E2EE (encryption)




From whatis.com posted by Margaret Rouse
In E2EE, the data is encrypted on the sender's system or device and only the recipient is able to decrypt it. Nobody in between, be they an Internet service provider, application service provider or hacker, can read it or tamper with it.
The cryptographic keys used to encrypt and decrypt the messages are stored exclusively on the endpoints, a trick made possible through the use of public key encryption. Although the key exchange in this scenario is considered unbreakable using known algorithms and currently obtainable computing power, there are at least two potential weaknesses that exist outside of the mathematics. First, each endpoint must obtain the public key of the other endpoint, but a would-be attacker who could provide one or both endpoints with the attacker's public key could execute a man-in-the-middle attack. Additionally, all bets are off if either endpoint has been compromised such that the attacker can see messages before and after they have been encrypted or decrypted.
The generally employed method for ensuring that a public key is in fact the legitimate key created by the intended recipient is to embed the public key in a certificate that has been digitally signed by a well-recognized certificate authority (CA). Because the CA's public key is widely distributed and generally known, its veracity can be counted on, and a certificate signed by that public key can be presumed authentic. Since the certificate associates the recipient's name and public key, the CA would presumably not sign a certificate that associated a different public key with the same name.
The first widely used E2EE messaging software was Pretty Good Privacy, which secured email and stored files, as well as securing digital signatures. Text messaging applications frequently utilize end-to-end encryption, including Jabber, TextSecure and Apple's iMessage






================================================================
Good Netiquette to all!
================================================================

For a great email parody, view the following link:

https://www.youtube.com/watch?v=HTgYHHKs0Zw&__scoop_post=bcaa0440-2548-11e5-c1bd-90b11c3d2b20&__scoop_topic=2455618



==============================================
**Important note** - contact our company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================

Monday, August 3, 2015

Top Ten Principles For Job Seekers




Netiquette, as most of you readers know, extends to any electronic communications. One of the most critical forms of business email is that of the employment candidate. Below is a list of Netiquette essential for the job seeker. If you have any to add, your thoughts are welcome might be cited in my soon to be published book, noted below.

===================================================


1.     Be mindful of core Netiquette and email etiquette practices
2.     Keywords, keywords and more keywords
3.     Note specific accomplishments rather than day to day tasks
4.     Include links to positive on-line presence
5.     Provide a section for additional accomplishments, not “references available”
6.     Make use of all available tools for creating, editing and validating
7.     Omit personal opinions
8.     Eliminate overused phrases such as “Basic Objectives” or “Career Goals”
9.     Embrace polite persistence and include processes for follow-up and maintain a consistent tone
10.     Research the competition – how can you beat them









==============================================


For a great email parody, view the following link:

https://www.youtube.com/watch?v=HTgYHHKs0Zw&__scoop_post=bcaa0440-2548-11e5-c1bd-90b11c3d2b20&__scoop_topic=2455618



==============================================
**Important note** - contact our company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================

Tabula Rosa Systems Security Alert - SB15-215: Vulnerability Summary for the Week of July 27, 2015


============================================================
National Cyber Awareness System:
08/03/2015 06:25 AM EDT

Original release date: August 03, 2015
The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cybersecurity and Communications Integration Center (NCCIC) / United States Computer Emergency Readiness Team (US-CERT). For modified or updated entries, please visit the NVD, which contains historical vulnerability information.






================================================================

Good Netiquette to all!
================================================================

For a great email parody, view the following link:

https://www.youtube.com/watch?v=HTgYHHKs0Zw&__scoop_post=bcaa0440-2548-11e5-c1bd-90b11c3d2b20&__scoop_topic=2455618



==============================================
**Important note** - contact our company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================

Sunday, August 2, 2015

Tabula Rosa Systems - Overview Of Self Destructing Email Products


===========================================================
Many products and services have made reference or offered services to hide their identity, guarantee the safe message delivery and have even created self-destruct email.

Is this good Netiquette? it is an interesting question. There is a hint of deceptiveness being a reason for utilizing these methods.

But, in light of the lack of Internet security combined with eroding privacy lead me to conclude this is acceptable when done for good purposes.

Notwithstanding, there are now more of these products than ever. Below is a good article referencing these. I will leave it to you, the reader, to make your own conclusion. Whatever you do, it remains an interesting topic.

Good Netiquette to all! This blog will not self-destruct!
====================================================

This Email Will Self-Destruct In Five Seconds
A raft of new companies aim to deliver the dream of the secure, easy-to-use and ephemeral email.

By Kevin Lincoln - fastcompany.com
In early September, Bruce Levenson, owner of the NBA’s Atlanta Hawks, announced that he would sell the team after self-reporting a racist email he had sent in 2012.
The Hawks are valued at over $400 million. That’s a strong tribute to the power of the written word.
Wouldn’t be nice if, in classic Mission Impossible fashion, emails could actually self-destruct?
Or take the case of the missent email. This past July, a Goldman Sachs employee accidentally typed “gmail” instead of “gs” into address bar and sent confidential information to a Gmail random account. The brokerage house then sued to have that email deleted, which Google said it would only do with a court order.
It seems fair that a racist email from a powerful sports figure should be disclosed or maybe even that misspent emails stay where they land. But after Snowden’s revelations, it also seems likely that even innocent text communications can be stored and sifted. Wouldn’t be nice if, in classic Mission Impossible fashion, emails could actually self-destruct?
A handful of companies are trying to fleeting email a reality.
Normal email accounts—Gmail, Yahoo!, etc.—can’t add this feature because of the way Simple Mail Transfer Protocol (SMTP) works. (In 2009, Gmail debuted an “undo send” feature but it doesn’t actually yank email back—it just adds five seconds before it sends.) To create truly disposable messaging, you need to build it from the ground up. “We decided we wanted to make crypto that people would use 100 times a day, and crypto that exceeds the NSA’s top-secret encryption technology,” says Nico Sell, the CEO of a company called Wickr.
Sell is a DefCon vet and white-hat hacker notorious for her secrecy—she refuses to be photographed on camera without sunglasses, which mess with facial-recognition software, and most details of her life are a mystery, from where she lives to the names of her husband and daughters to whether her “Nico Sell” is even her real name. She founded Wickr in 2011 after 10 years of trying to get other companies to use her encryption technology. Now, she provides an app that uses “seamless key management” to allow the anonymous sending and receiving of messages that are timed to self-destruct and, because they are stored exclusively on devices, cannot be accessed from a cloud or server.
“Wickr is processing millions of messages a day, which is more top-secret messages than the Internet has ever seen,” she says. “Which is really great too, because a lot of what we’re doing is working with human rights activists, and you’ve got tons of great cover traffic—I’m pushing people to encrypt as much as they can, it helps to control the surveillance state and give power to the people.”
Matching her background, Sell’s rhetoric and behavior is couched in the philosophies of activists—she famously refused to allow the FBI a backdoor into Wickr. But she also believes that Wickr is the best messaging app, period, and she sees Facebook, Skype, Whatsapp, and Snapchat as its competition. Eventually, the company will move beyond even that: Sell wants to use Wickr’s tech to facilitate financial-industry and peer-to-peer transactions securely and secretly. With a business model built on these trades, as well as premium content and licensing, Wickr also has no need for ads, which means no need for any user data.
While Wickr might be the most ambitious and well-known of the secure messaging apps, it’s far from the only one. Telegram, an Android-only app that originated out of Russia, is a fast-growing service that also provides encryption and self-destruct options, though, unlike Wickr’s, those features aren’t always activated. And Gliph combines messaging with completely secure bitcoin payments, making it an attractive service for a certain kind of user—the kind that cares enough to use bitcoin.
If you delete a message in Gliph, it will delete it on the other side as well. It’s a complete deletion, no backup.
Gliph allows users to send messages across platforms, including the web browser and desktops. This flexibility comes with a caveat—instead of local encryption, like Wickr and Telegram, Gliph uses server-side encryption—but founder and CEO Rob Banagale believes that the trade-off is more than worth it in terms of improving the user experience.
“We host the conversations, so you can lose your phone and still pick up the conversation on the web and on somebody else’s phone by logging in,” Banagale says. “Another key aspect of what we have is you can delete messages. If you delete a message in Gliph, it will delete it on the other side as well. It’s a complete deletion, no backup.”
Like Wickr, Gliph is ad-free, and it protects user details via messaging as well as a service called cloaked email, which hides email addresses behind a pseudonym. Regardless of which app you opt for—and there are others—their rise is both a reaction to current events as well as a curious harbinger of what’s to come in communication. Sell says that Wickr is a tool, and like all tools, it can be used by both good people and bad people. But in her eyes, that doesn’t change the need for the tool itself.
“We believe in power to the people,” Sell says. “We really think that no matter the frontier, if we can get freedom of communications and freedom of information to everyone around the world, then we can have significant change, in a good way.”
It also means that, if  Levenson’s email had self-destructed, he’d still be the owner of the Hawks. Or maybe the next time an intern decides to accidentally reply instead of forward an email—maybe the whole office won't get it.






================================================================
Good Netiquette to all!
================================================================

For a great email parody, view the following link:

https://www.youtube.com/watch?v=HTgYHHKs0Zw&__scoop_post=bcaa0440-2548-11e5-c1bd-90b11c3d2b20&__scoop_topic=2455618



==============================================
**Important note** - contact our company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================

Tabula Rosa Systems Security Alert 8/2/2015 - US CERT - Phishing Bulletins


============================================================


Original release date: August 01, 2015

Systems Affected

Microsoft Windows Systems, Adobe Flash Player, and Linux

Overview

Between June and July 2015, the United States Computer Emergency Readiness Team (US-CERT) received reports of multiple, ongoing and likely evolving, email-based phishing campaigns targeting U.S. Government agencies and private sector organizations. This alert provides general and phishing-specific mitigation strategies and countermeasures.

Description

US-CERT is aware of three phishing campaigns targeting U.S. Government agencies and private organizations across multiple sectors. All three campaigns leveraged website links contained in emails; two sites exploited a recent Adobe Flash vulnerability (CVE-2015-5119) while the third involved the download of a compressed (i.e., ZIP) file containing a malicious executable file. Most of the websites involved are legitimate corporate or organizational sites that were compromised and are hosting malicious content.

 

Impact

Systems infected through targeted phishing campaigns act as an entry point for attackers to spread throughout an organization’s entire enterprise, steal sensitive business or personal information, or disrupt business operations.

Solution

Phishing Mitigation and Response Recommendations
  • Implement perimeter blocks for known threat indicators:
    • Email server or email security gateway filters for email indicators
    • Web proxy and firewall filters for websites or Internet Protocol (IP) addresses linked in the emails or used by related malware
    • DNS server blocks (blackhole) or redirects (sinkhole) for known related domains and hostnames
  • Remove malicious emails from targeted user mailboxes based on email indicators (e.g., using Microsoft ExMerge).
  • Identify recipients and possible infected systems:
    • Search email server logs for applicable sender, subject, attachments, etc. (to identify users that may have deleted the email and were not identified in purge of mailboxes)
    • Search applicable web proxy, DNS, firewall or IDS logs for activity the malicious link clicked.
    • Search applicable web proxy, DNS, firewall or IDS logs for activity to any associated command and control (C2) domains or IP addresses associated with the malware.
    • Review anti-virus (AV) logs for alerts associated with the malware.  AV products should be configured to be in quarantine mode. It is important to note that the absence of AV alerts or a clean AV scan should not be taken as conclusive evidence a system is not infected.
    • Scan systems for host-level indicators of the related malware (e.g., YARA signatures)
  • For systems that may be infected:
    • Capture live memory of potentially infected systems for analysis
    • Take forensic images of potentially infected systems for analysis
    • Isolate systems to a virtual local area network (VLAN) segmented form the production agency network (e.g., an Internet-only segment)
  • Report incidents, with as much detail as possible, to the NCCIC.
Educate Your Users
Organizations should remind users that they play a critical role in protecting their organizations form cyber threats. Users should:
  • Exercise caution when opening email attachments, even if the attachment is expected and the sender appears to be known.  Be particularly wary of compressed or ZIP file attachments.
  • Avoid clicking directly on website links in emails; attempts to verify web addresses independently (e.g., contact your organization’s helpdesk or sear the Internet for the main website of the organization or topic mentioned in the email).
  • Report any suspicious emails to the information technology (IT) helpdesk or security office immediately.
Basic Cyber Hygiene
Practicing basic cyber hygiene would address or mitigate the vast majority of security breaches handled by today’s security practitioners:
  • Privilege control (i.e., minimize administrative or superuser privileges)
  • Application whitelisting / software execution control (by file or location)
  • System application patching (e.g., operating system vulnerabilities, third-party vendor applications)
  • Security software updating (e.g., AV definitions, IDS/IPS signatures and filters)
  • Network segmentation (e.g., separate administrative networks from business-critical networks with physical controls and virtual local area networks)
  • Multi-factor authentication (e.g., one-time password tokens, personal identity verification (PIV cards)
Further Information
For more information on cybersecurity best practices, users and administrators are encouraged to review US-CERT Security Tip: Handling Destructive Malware to evaluate their capabilities encompassing planning, preparation, detection, and response. Another resource is ICS-CERT Recommended Practice: Improving Industrial Control Systems Cybersecurity with Defense-In-Depth Strategies.






================================================================

Good Netiquette to all!
================================================================

For a great email parody, view the following link:

https://www.youtube.com/watch?v=HTgYHHKs0Zw&__scoop_post=bcaa0440-2548-11e5-c1bd-90b11c3d2b20&__scoop_topic=2455618



==============================================
**Important note** - contact our company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================