Wednesday, December 25, 2024

Just a thought 🤔

What Vulnerabilities are to Vulnerability Management,

Threats are to Threat Management,

Risks are to Risk Management,

Patches are to Patch Management,

Use Cases are to Detection Engineering,

Malwares are to AV,

Controls are to Compliance,

Incidents are to Incident Response,

Identities are to Identity Management,

Certificates are to PKI,

Rules are to Firewalls/IPS/IDS,

Test Cases are to Penetration Testing,

Clauses are to Framework,

Policies are to Governance.

Happy Learning !!
hashtagVulnerabilityManagement hashtagCybersecurity

Vulnerability Management - Understanding vulnerability posture

Understanding the vulnerability posture of an organization at a basic level helps you drive remediation efforts.


So, I don't know what to call this information but I have decided to call it 'Vulnerability Posture' 😄

Let's consider an organization 'ORG' which manages infrastructure security for a 'CLIENT' and let us assume the 'CLIENT' has a total of 700 vulnerabilities.

So, here is how one can split the vulnerability data:

1. Total - 700 (ORG Managed - 500, ORG Unmanaged - 200)

2. ORG Managed - 500 (Non-EOL - 400, EOL - 100)

3. Non-EOL ORG Managed - 400 (OS - 250, Non-OS - 150)

4. Non-EOL ORG Managed OS - 250 (Server - 50, Network Devices - 25, Network Security - 25, Workstation - 150)

5. Non-EOL ORG Managed OS Server - 50 (CLIENT independent - 40, CLIENT dependent - 10)

Now, you should understand the split of 40 by the type of OS i.e. whether Linux or Windows, similarly for Workstation.

6. Non-EOL ORG Managed non-OS - 150 (CLIENT independent - 100, CLIENT dependent - 50)

Similarly for non-OS, the split of 100 by type of applications i.e. Browsers, PDF Readers, Microsoft Office, File Compression Apps, Java/.NET framework (at least top 5).

Points to ponder 🤔

1. Why does ORG has unmanaged assets?
2. What is the action plan for EOL assets?
3. In CLIENT's environment, how many new vulnerabilities appear and how many are remediated every month?
4. Are there vulnerabilities/assets which are part of any exception?
5. What is the patching cadence for CLIENT? Is it monthly or quarterly?
6. Why do some vulnerabilities have dependencies on CLIENT?
7. Is there a formal agreement on dependencies between ORG and CLIENT?

Outcome:
Once ORG understands the vulnerability posture of CLIENT, ORG will be able to identify key challenges in remediation efforts.

Once the challenges are identified I don't need to tell what needs to be done.

Happy Learning !!
hashtagVulnerabilityManagement hashtagCyberSecurity

Sunday, October 20, 2024

Vulnerability Management - Deprecated vs End of Support

The terms deprecated and end of support are related but have distinct meanings:

--> Deprecated:
When a protocol, software feature, or technology is deprecated, it means it is no longer recommended for use and may be phased out in the future. It is a warning that the technology is outdated, may have security vulnerabilities, or there are better alternatives available. However, the deprecated protocol or feature can still be used, and it may still receive security updates or limited support for a certain period.
Deprecated protocols or features are typically marked to discourage new usage, and developers or administrators are advised to transition to more secure or up-to-date alternatives.

--> End of Support (EoS):
End of support means that the protocol, software, or system will no longer receive any updates, including security patches and technical support from the vendor. This is a more critical stage than deprecation. Continuing to use systems or protocols that have reached end of support can expose them to security risks since vulnerabilities may no longer be addressed.
At this point, the vendor has officially stopped supporting the product, and users are strongly encouraged to migrate to newer versions or alternative solutions to avoid security risks.

--> Key Differences:
Deprecated: Still supported but not recommended for new use.
End of Support: No longer supported, no updates or security patches are provided.

The reason for this post was specifically one famous protocol .. Yes .. I am talking about NTLM.

Per Microsoft:
All versions of NTLM, including LANMAN, NTLMv1, and NTLMv2, are no longer under active feature development and are deprecated. Use of NTLM will continue to work in the next release of Windows Server and the next annual release of Windows. Calls to NTLM should be replaced by calls to Negotiate, which will try to authenticate with Kerberos and only fall back to NTLM when necessary.

Please find the below URL for more details:
https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features

In cybersecurity, using deprecated protocols poses increasing risks over time, but using software that is at the end of support is much riskier, as it will not receive any security fixes.

Happy Learning !!
hashtagVulnerabilityManagement hashtagCyberSecurity

Vulnerability Management - Understanding vulnerability posture

Understanding the vulnerability posture of an organisation at a basic level helps you drive remediation efforts. So, I don't know what t...