C3 Security Consulting LLC
Confidentiality
Integrety
Availability
company banner
HomeSecurityServicesVistaInformationCompany
  
floating layer default test box
Security
FOREFRONT
Hardware
Networking
Patch Management
PKI
Web
Windows
Wireless
On this page:
Patch Management
Windows
Linux
Related Links
Security Lockdown: Utilizing Standard Microsoft Tools to Secure Your Network
Learn about tools that enable end users in your organization to lock down their own environment and help protect their desktops. Find webcasts and virtual labs that provide policy strategy, tips and tricks, and prescriptive guidance to help strengthen your organization's security, without sacrificing network performance and flexibility.
linux-wlan project
The goal of the linux-wlan project is to develop a complete, standards based, wireless LAN system using the GNU/Linux operating system.
Comprehensive personal security
Zone Alarm Internet Security Suite.
Linux Devices
To see a range of devices that run on Linux look at www.linuxdevices.com.
Securing your Pocket PC
This article discusses security for handheld computers running Pocket PC/Windows Mobile 2003 operating systems.

Patch Management

Print view

We would recommend you install a virus checker first, but the second thing you should do is ensure all your laptops, workstations and servers are running the latest operating system and application patches.

However, not all patches are created equally.

“There are some patches that are designed to fix specific issues and may be unrelated to security. The same patches may cause instability in other areas of the system. You should test all patches in your environment before deploying to the general population.”

That is great advice but a little unworldly. Firstly, do you have a representative environment to test all your patches? Secondly, do you have the ability to do interoperability testing? (i.e. does one patch interfere with another?) And thirdly, do you have the time?

C3SC will produce an environment to manage your patch deployment and we will structure the solution to;

  • allow you to maintain control
  • grade your patches in order of severity
  • respond rapidly for immediate/critical updates
  • deploy patches to control groups
  • view the current patch level of your environment

Windows

To meet the goals laid out in the previous section, C3SC will:

  • work with you to develop a list of requirements based on industry best practices and adjusted to your needs
  • develop an implementation plan
  • install, and configure, the necessary servers and software
  • automate your patch deployment
  • provide reporting solutions to display your current status
  • create a test environment for non-critical application or hardware specific patches
  • produce standard operating procedures
  • train administrators to monitor and maintain your environment

C3SC will, with appropriately scaled solutions, technology, and training, put control of patch deployment back into your hands.

If you don’t come to us, please seek assistance from someone. This is a fundamental requirement for a secure environment.

▲Top of page
Did you know?
Live CD
If you want to test a new/different version of Linux, there are many "live CD" distributions that allow you to boot into the operating system without needing to install it on the hard drive.
Many wireless access points, public and private, are open.
In a study of 2600 around Indianapolis, researchers from the University of Cambridge found 46% running with no encryption, and many were still using default settings.
Set up a firewall. Even if you just use dial-up or DSL you are fully exposed to the internet.
This is your primary defense and protects against outside attacks by screening and blocking all traffic between your network and the Internet that is not allowed. The firewall also hides computer addresses. Firewall hardware connects between the cable/ DSL modem and your computers. Windows operating systems have great built-in firewalls.
Only and estimated 25% of companies report computer intrusions to law enforcement.
They site bad publicity and loss of credibility as major concerns.
The easiest way to get someone's password - ask.
Make sure you have adequately trained you employees to expect and recognize "social engineering" attacks.