<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Risk Management and Compliance&#187; Operating system</title>
	<atom:link href="http://blog.kraasecurity.com/tag/operating-system/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kraasecurity.com</link>
	<description>Risk Assessment, Vulnerabilities, Website Security</description>
	<lastBuildDate>Tue, 07 Sep 2010 01:35:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>What are the features you need a Windows Security Host Diagnostic tool?</title>
		<link>http://blog.kraasecurity.com/2010/04/01/what-are-the-features-you-need-a-windows-security-host-diagnostic-tool/</link>
		<comments>http://blog.kraasecurity.com/2010/04/01/what-are-the-features-you-need-a-windows-security-host-diagnostic-tool/#comments</comments>
		<pubDate>Fri, 02 Apr 2010 00:56:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Could Computing]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Managed Security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Federal Information Security Management Act of 2002]]></category>
		<category><![CDATA[Health Insurance Portability and Accountability Act]]></category>
		<category><![CDATA[Operating system]]></category>
		<category><![CDATA[Policy]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=207</guid>
		<description><![CDATA[Image via Wikipedia There is a lot of focus on network security and application security today. Years ago it was operating system security that was all the rage. But with the advent of the strict requirements of some of the regulations such as HIPAA, PCI, SOX, and FISMA, more attention needs to be paid to [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 83px; height: 29px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:Windows_7.png"><img title="Windows 7 is the latest stable Windows operati..." src="http://upload.wikimedia.org/wikipedia/en/thumb/b/bd/Windows_7.png/300px-Windows_7.png" alt="Windows 7 is the latest stable Windows operati..." width="79" height="51" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:Windows_7.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>There is a lot of focus on network security and application security today. Years ago it was <strong><a title="host security assessment" href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">operating system security</a></strong> that was all the rage. But with the advent of the strict requirements of some of the regulations such as <strong><a title="Hipaa security" href="http://www.kraasecurity.com/compliance/hipaa-assessment">HIPAA</a></strong>, <strong><a title="PCI security" href="http://www.kraasecurity.com/compliance/PCI-Assessment">PCI</a></strong>, SOX, and <a class="zem_slink freebase/en/federal_information_security_management_act_of_2002" title="Federal Information Security Management Act of 2002" rel="wikipedia" href="http://en.wikipedia.org/wiki/Federal_Information_Security_Management_Act_of_2002">FISMA</a>, more attention needs to be paid to the operating system. As <a class="zem_slink freebase/en/microsoft_windows" title="Windows" rel="homepage" href="http://www.microsoft.com/WINDOWS">Windows</a> is still dominant, what are some of the features you need to be concerned with in an application?</p>
<p>Some key feature of a <a title="windows security assessment" href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment"><strong>host security assessment</strong> </a>tool are: </p>
<ol>
<li>Ability to quickly audit</li>
<li>Ability to inventory</li>
<li>Structure for classification of components</li>
<li><strong><a title="patch management" href="http://www.kraasecurity.com/consulting-services/network-solutions/security-architecture-analysis">Patch management</a></strong> of course</li>
<li>Ability to baseline and report against the baseline</li>
<li>Templates of the regulatory requirements</li>
<li>Templates of different levels of security configurations</li>
<li><a title="threat assessment" href="http://www.kraasecurity.com/consulting-services/network-solutions/vulnerability-assessment"><strong>Threat identification</strong> </a>and classification</li>
<li>User management</li>
<li>Port security assessment and management</li>
<li>Service and process analysis</li>
</ol>
<p>A baseline configuration for <strong><a title="operating system security" href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">operating system security</a></strong>, cover things such as patch levels, ports, services, processes, logging, policy settings and user configuration, should be the first step for any company in host security assessment and diagnostics. If you build from scratch, or don’t use a secure template, you will always be in trouble. Timely updates and reconfiguration of your baseline is necessary.</p>
<p>Your operating system like your <strong><a title="Network security" href="http://www.kraasecurity.com/consulting-services/network-solutions/vulnerability-assessment">network security</a></strong> should match your corporate business practices and procedures. <strong><a title="policy development" href="http://www.kraasecurity.com/consulting-services/network-solutions/policy-development">Policies</a></strong> should be in place for this of course.  Over time you should be able to benchmark your <strong>host security</strong> problems, solutions and changes.</p>
<p>Gary Bahadur</p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p><em><strong>Address</strong></em><em>: 200 Se 1st St #601 Miami FL 33131</em></p>
<p>*Managed Security Services</p>
<p>*Vulnerability Management</p>
<p>*Compliance &amp; Policy Development</p>
<p>*<strong><a title="PGP " href="http://www.kraasecurity.com/products/PGP-Enterprise-Products">PGP Security</a></strong></p>
<p>*FREE Website Security Test </p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.prweb.com/releases/fisma/compliance/prweb3558694.htm">Lumension Highlights Six Critical Elements To Ensure Painless FISMA Compliance</a> (prweb.com)</li>
<li class="zemanta-article-ul-li"><a href="http://web2.sys-con.com/node/1261691">Security vs. Compliance in the Cloud</a> (web2.sys-con.com)</li>
<li class="zemanta-article-ul-li"><a href="http://blogs.technet.com/keithcombs/archive/2010/02/11/security-compliance-manager-beta-signup-now-available.aspx">Security Compliance Manager &#8211; beta signup now available</a> (blogs.technet.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/7e3a67f9-0b1f-4428-8b45-7f4634faec56/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=7e3a67f9-0b1f-4428-8b45-7f4634faec56" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/04/01/what-are-the-features-you-need-a-windows-security-host-diagnostic-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When will Vendors provide Risk Assessments of their products?</title>
		<link>http://blog.kraasecurity.com/2010/02/17/when-will-vendors-provide-risk-assessments-of-their-products/</link>
		<comments>http://blog.kraasecurity.com/2010/02/17/when-will-vendors-provide-risk-assessments-of-their-products/#comments</comments>
		<pubDate>Thu, 18 Feb 2010 04:22:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Hacking News]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[Supplier Security]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Adobe Systems]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[CIO.com]]></category>
		<category><![CDATA[Cross-site scripting]]></category>
		<category><![CDATA[Flash]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Operating system]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=185</guid>
		<description><![CDATA[Image via Wikipedia Vendor risk assessment are not part of everyday corporate managememnt but it should be. If you drive a car and every week you have to get something fixed it would prove pretty annoying, disgusting, outrageous and you probably you would never buy that model again and probably wouldn&#8217;t by from that manufacturer [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 92px; height: 52px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:AdobeSystems.svg"><img title="Adobe Systems Incorporated" src="http://upload.wikimedia.org/wikipedia/en/thumb/d/dd/AdobeSystems.svg/300px-AdobeSystems.svg.png" alt="Adobe Systems Incorporated" width="97" height="65" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:AdobeSystems.svg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p><a title="vendor risk assessment" href="http://www.kraasecurity.com/consulting-services/network-solutions/supplier-security-assessment"><strong>Vendor risk assessment</strong></a> are not part of everyday corporate managememnt but it should be. If you drive a car and every week you have to get something fixed it would prove pretty annoying, disgusting, outrageous and you probably you would never buy that model again and probably wouldn&#8217;t by from that manufacturer either. So why do we accepts buggy <a class="zem_slink freebase/en/computer_software" title="Computer software" rel="wikipedia" href="http://en.wikipedia.org/wiki/Computer_software">software</a> that is vulnerable to things like cross site scripting attacks, buffer overflows, malware and such? But we do that everyday.</p>
<p>Everything from vulnerable <a class="zem_slink freebase/en/operating_system" title="Operating system security" href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">operating systems</a> such as Windows to vulnerable applications such as <a class="zem_slink freebase/en/adobe_creative_team" title="Adobe Systems" rel="homepage" href="http://www.adobe.com/">Adobe</a> and weak website such as Facebook. As stated by <a class="zem_slink" title="CIO.com" rel="homepage" href="http://www.cio.com">CIO.com</a>, &#8220;SANS and Mitre, a Bedford, Mass.-based <a class="zem_slink freebase/en/non-profit_organization" title="Non-profit organization" rel="wikipedia" href="http://en.wikipedia.org/wiki/Non-profit_organization">non-profit</a>, federally funded technology <a class="zem_slink freebase/en/research_and_development" title="Research and development" rel="wikipedia" href="http://en.wikipedia.org/wiki/Research_and_development">research and development</a> organization, today is also releasing its second annual CWE/SANS Top 25 list of the most common programming errors currently being made by software <a class="zem_slink freebase/en/software_developer" title="Software developer" rel="wikipedia" href="http://en.wikipedia.org/wiki/Software_developer">developers</a>. The authors say the errors on the list are responsible nearly every major type of cyber attack, including the recent intrusions at Google (<a class="zem_slink freebase/en/google" title="NASDAQ: GOOG" rel="stockexchange" href="http://finance.yahoo.com/q?s=GOOG">GOOG</a>), and numerous utilities and government agencies.&#8221;  The biggest companies are culprits.</p>
<p>So what are we do to about buggy software? How do you force a <strong>vendor risk assessment</strong> on all yoru vendors? Maybe scream &#8220;I&#8217;m mad as hell and I am not going to take it anymore!&#8221;  Might feel good for a second or two, but not going to solve the almost daily patch process we have to go through for our software. <strong><a title="patch management" href="http://www.kraasecurity.com/consulting-services/network-solutions/host-security-assessment">Patch management</a></strong> is a thriving sector!</p>
<p>As I see it, some theoretical things the end user can do to change the deadly cycle of poor software:</p>
<ol>
<li>Sue! I don&#8217;t know if that&#8217;s possible, but if you bought a car with bad acceleration problems (ahem Toyota) you might just sue the manufacturer if you got into an accident. What can we do that if some hacker breaks in through buggy software?</li>
<li>Stop buying from that vendor! <a class="zem_slink" title="Apple Inc." rel="geolocation" href="http://maps.google.com/maps?ll=37.33187,-122.029669&amp;spn=1.0,1.0&amp;q=37.33187,-122.029669%20%28Apple%20Inc.%29&amp;t=h">Apple</a> seems to be taking this tactic by not allowing Flash on the IPad. But can we all move away from <a class="zem_slink freebase/en/microsoft" title="Microsoft" rel="homepage" href="http://www.microsoft.com">Microsoft</a> tomorrow? Probably not.</li>
<li>Make the vendors conduct <strong><a title="application security assessment" href="http://www.kraasecurity.com/consulting-services/application-solutions/application-security-assessment">Risk Assessments</a></strong> of their products prior to release. A third party risk assessment is probably a good idea. Something with more teeth than a SAS70 type review.</li>
</ol>
<p>Gary Bahadur</p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a onclick="javascript:pageTracker._trackPageview('/outbound/article/twitter.com');" href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p><strong><em>Address</em></strong><em>: 200 Se 1st St #601 Miami FL 33131</em></p>
<p> *Managed Security Services</p>
<p>*Vulnerability Management</p>
<p>*Compliance &amp; Policy Development</p>
<p>*PGP Security</p>
<p> *FREE Website Security Test </p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://seekingalpha.com/article/188591-apple-vs-microsoft-making-platform-enemies-and-friends?source=feed">Apple vs. Microsoft: Making Platform Enemies and Friends</a> (seekingalpha.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.ghacks.net/2010/02/17/adobe-reader-and-acrobat-get-yet-another-security-update/">Adobe Reader And Acrobat Get Yet Another Security Update</a> (ghacks.net)</li>
<li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-13860_3-10447081-56.html?part=rss&amp;subj=BeyondBinary">Microsoft investigates new Internet Explorer flaw</a> (news.cnet.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.infoworld.com/d/developer-world/adobe-air-20-full-featured-flash-player-coming-smartphones-253&amp;a=13137035&amp;rid=5940a61e-7193-4971-a98b-6547400ef860&amp;e=5d602d8d9add939e9717afe63232605d">Google readies Flash for Android devices</a> (infoworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.computerworld.com/s/article/9162258/IBM_Vulnerabilities_fell_in_09_but_other_risks_abound?source=rss_security">IBM: Vulnerabilities fell in &#8217;09, but other risks abound</a> (computerworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.computerworld.com/s/article/9157558/Update_Adobe_issues_emergency_PDF_patches?source=rss_security">Update: Adobe issues emergency PDF patches</a> (computerworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.theregister.co.uk/2009/12/22/mass_flash_file_vulnerability/">Serious web vuln found in 8 million Flash files</a> (theregister.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://www.computerworld.com/s/article/347250/Hold_Vendors_Liable_for_Buggy_Software?source=rss_dev">Hold vendors liable for buggy software, group says</a> (computerworld.com)</li>
</ul>
<p>Gary Bahadur</p>
<p><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></p>
<p><a href="../">http://blog.kraasecurity.com</a></p>
<p><a onclick="pageTracker._trackPageview('/outbound/article/twitter.com');" href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a><br />
<a href="http://www.kraasecurity.com/managed-services/intrusion-defense/firewall" target="_blank">Managed Firewall</a><br />
<a href="http://www.kraasecurity.com/managed-services/vulnerability-defense/internal-external-scanning" target="_blank">Managed Vulnerability Scanning</a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/5940a61e-7193-4971-a98b-6547400ef860/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=5940a61e-7193-4971-a98b-6547400ef860" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/02/17/when-will-vendors-provide-risk-assessments-of-their-products/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
