measuring compliance with tenable security center

32
Measuring Compliance with Tenable Security Center Joe Zurba | HUIT IT Summit May 23, 2013

Upload: cade

Post on 24-Feb-2016

60 views

Category:

Documents


2 download

DESCRIPTION

Measuring Compliance with Tenable Security Center. Joe Zurba | HUIT IT Summit May 23, 2013. Agenda:. Introduction What is compliance and why is it important? What do we need to comply with? What can we measure? How is measurement accomplished? What are the first steps? - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Measuring Compliance with Tenable Security Center

Measuring Compliance with Tenable Security Center

Joe Zurba | HUIT IT SummitMay 23, 2013

Page 2: Measuring Compliance with Tenable Security Center

2

Agenda:

• Introduction

• What is compliance and why is it important?

• What do we need to comply with?

• What can we measure?

• How is measurement accomplished?

• What are the first steps?

• What are the next steps?

• Questions

Page 3: Measuring Compliance with Tenable Security Center

3

Introduction

Page 4: Measuring Compliance with Tenable Security Center

4

What is Compliance?

• com·pli·ance /kəmˈplīəns/Noun1. The action or fact of complying with a wish or command.

2. The state or fact of according with or meeting rules or standards.

Synonymsagreement - consent - accord - accordance - conformity

• Compliance means conforming to a rule, such as a specification, policy, standard or law.

Page 5: Measuring Compliance with Tenable Security Center

5

What is Compliance?

• com·pli·ance /kəmˈplīəns/Noun1. The action or fact of complying with a wish or command.

2. The state or fact of according with or meeting rules or standards.

Synonymsagreement - consent - accord - accordance - conformity

• Compliance means conforming to a rule, such as a specification, policy, standard or law.

Page 6: Measuring Compliance with Tenable Security Center

6

Why is Compliance Important?

• Compliance provides a baseline posture from which we can build more mature process and controls

• Compliance provides standards

• Compliance helps to lower risk

• Compliance helps to improve the quality of work

• Compliance helps to mitigate potential penalties

Page 7: Measuring Compliance with Tenable Security Center

7

What Do We Need To Comply With?

• Depending on where you are within Harvard, you may need to comply with one or several of the following policies/standards:

– HIPAA

– FERPA

– PCI

– Massachusetts 201 CMR 17

– Harvard Information Security Policy

– Harvard Research Data Security Policy

– Contractual Obligations

Page 8: Measuring Compliance with Tenable Security Center

8

What Can We Measure?

• Government Compliance– FISMA, NIST, DISA STIG, CERT

• Regulatory Compliance– HIPAA, Sarbanes-Oxley (SOX), FERPA

• Corporate (Institutional) Governance, Risk, and Compliance (GRC)

– Institutional Policy, PCI, ISO 27001

And…• Harvard Security Policy

Page 9: Measuring Compliance with Tenable Security Center

9

How Is Measurement Accomplished?

• Tenable Security Center Vulnerability Scanning– Used to measure systems for vulnerabilities in Operating Systems and

common applications

– Uses credentialed scans to unobtrusively log into systems to analyze patch status

• Tenable Security Center Compliance Scanning– Uses industry standard or custom audit files to measure system

configurations

– Uses credentialed scans to unobtrusively log into systems

Page 10: Measuring Compliance with Tenable Security Center

10

Audit Files

Page 11: Measuring Compliance with Tenable Security Center

11

Audit Files

Page 12: Measuring Compliance with Tenable Security Center

12

Audit Files

Page 13: Measuring Compliance with Tenable Security Center

13

Scan Policy

Page 14: Measuring Compliance with Tenable Security Center

14

Scan Policy

Page 15: Measuring Compliance with Tenable Security Center

15

Scan Policy

Page 16: Measuring Compliance with Tenable Security Center

16

Scan Policy

Page 17: Measuring Compliance with Tenable Security Center

17

Add a Compliance Scan

Page 18: Measuring Compliance with Tenable Security Center

18

Add a Compliance Scan

Page 19: Measuring Compliance with Tenable Security Center

19

Add a Compliance Scan

Page 20: Measuring Compliance with Tenable Security Center

20

Add a Compliance Scan

Page 21: Measuring Compliance with Tenable Security Center

21

Analyze The Results

Page 22: Measuring Compliance with Tenable Security Center

22

Analyze The Results

Page 23: Measuring Compliance with Tenable Security Center

23

Analyze The Results

Page 24: Measuring Compliance with Tenable Security Center

24

Analyze The Results

Page 25: Measuring Compliance with Tenable Security Center

25

Analyze The Results

Page 26: Measuring Compliance with Tenable Security Center

26

Analyze The Results

Page 27: Measuring Compliance with Tenable Security Center

27

Analyze The Results

Page 28: Measuring Compliance with Tenable Security Center

28

What Are The First Steps?• Measuring systems that store or process HRCI (PII) against 10 points of

the HEISP:– Private IP addressing

– Host-based firewall

– Vulnerability Scanning and Patching program

– External logging (Splunk)

– Active, up-to-date Anti-Virus software

– Unique credentials, default passwords changed, shared accounts disabled

– Password length and complexity

– Brute force credential lock-outs

– Logging of successful and unsuccessful login attempts

Page 29: Measuring Compliance with Tenable Security Center

29

What Are The Next Steps?

• Establish a process for ongoing compliance scanning, reporting and remediation

• Expand the service offering to comply with other regulatory standards

– HIPAA

– PCI

• Define standard build audit files to scan for deviation

Page 30: Measuring Compliance with Tenable Security Center

30

Where To Find More Information

• For this presentation – Harvard iSite HUIT IT Security - http://hvrd.me/13CFp4Z

[email protected]

• 617-495-7777

Page 31: Measuring Compliance with Tenable Security Center

31

Questions

Page 32: Measuring Compliance with Tenable Security Center

Joe Zurba | HUIT IT Summit

June 6, 2013

Thank you.