ISACARuSec – Telegram
ISACARuSec
2.27K subscribers
1.77K photos
13 videos
303 files
5.63K links
Канал направления ИБ Московского отделения ISACA

Направление канала новости ISACA, новости в области управления ИБ в России и мире, обмен лучшими практиками.

https://engage.isaca.org/moscow/home

Связь с администрацией
@popepiusXIII
Download Telegram
Отличный отчет ФБР по киберпреступлениям в 2018 году.
8 Мая вебинар от Tenable и Siemens на тему: "Adapting Asset and Vulnerability Management Processes for Operational Technology". Обсудят:

- Breaking down silos between OT and IT
- Which OT asset attributes must be tracked
- Practical tips for effective OT asset management
- Adapting vulnerability remediation processes for OT

https://www.tenable.com/webinars/adapting-asset-and-vulnerability-management-for-ot
Forwarded from SecurityLab.ru
Национальный институт стандартов и технологий США (The National Institute of Standards and Technology, NIST) выпустил обновление исследовательского набора инструментов (Automated Combinatorial Testing for Software, ACTS), призванное помочь разработчикам сложных критически важных с точки зрения безопасности приложений выявлять потенциально опасные ошибки в своем ПО.
NIST обновил инструмент для поиска ошибок в критически важном ПО
Пример того насколько надежна современная атрибуция кибер атак.

"...When we used to put out anonymised, non-attributable attacks, we'd say we'd seen something somewhere and this is how you can fix it, you can get a certain response. When you say this is Russia, you get a bigger response and that does matter," he said..."
5 советов, от которых зависит успешность вашего SOC (презентация) https://t.co/o1jWWnzFBD
— Alexey Lukatsky (@alukatsky) April 29, 2019
Vulnerability Management vendors and Vulnerability Remediation problems

It’s not a secret, that #VulnerabilityManagement vendors don’t pay much attention to the actual process of fixing vulnerabilities, that they detect in the infrastructure (Vulnerability Remediation).

In fact, most of VM vendors see their job in finding a potential problem and providing a link to the Software Vendor’s website page with the #remediation denoscription. How exactly the #remediation will be done is not their business.

Remediation is a painful topic and it’s difficult to sell it as a ready-made solution. And even when Vulnerability Vendors try to sell it this way, it turns out pretty ugly and does not really work. Mainly because the Remediation feature is sold to the Security Team, and the IT Team will have to use it.

#Windows #remediation #patch #Linux #VulnerabilityManagement

Read more: https://avleonov.com/2019/04/29/vulnerability-management-vendors-and-vulnerability-remediation-problems/