[aklug] Re: Information Systems Audit

From: Marc Grober <marc@interak.com>
Date: Wed Feb 06 2013 - 12:36:08 AKST

On Feb 6, 2013, at 11:21 AM, Tom Simes <simestd@netexpress.com> wrote:
> Don't forget those sneaky individuals that roll their own distros, no
> telling WHAT they are stuffing in the folds ;)

Virtually anything can be hidden in plain sight in a *x system. As an SA do you run a regular report on changed time stamps? Clock anomalies? Reboots? sudo and su? How do you sort and address alarms and warnings? If you can't stop whatever, can you detect & remediate quickly enough? Bottom like is one of your worst enemies is your user demand for speed. Get rid of the users and life would be much more secure ;-)

---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.
Received on Wed Feb 6 12:36:19 2013

This archive was generated by hypermail 2.1.8 : Wed Feb 06 2013 - 12:36:19 AKST