Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
System Compliance on a Budget
Search
Sponsored
·
SiteGround - Reliable hosting with speed, security, and support you can count on.
→
paulh
June 04, 2012
Technology
55
0
Share
System Compliance on a Budget
AUCTC, Saint Mary's University. 2012
paulh
June 04, 2012
More Decks by paulh
See All by paulh
Beginners Guide to OSINT
paulh
1
420
squert – an open source UI for NSM data
paulh
0
67
squert - an open source UI for NSM data
paulh
0
350
Internet Safety
paulh
0
120
Situational Awareness with Open Source Tools
paulh
0
100
Network Security Monitoring with Open Source Tools
paulh
0
190
Other Decks in Technology
See All in Technology
Contract One Engineering Unit 紹介資料
sansan33
PRO
0
16k
システムは「動く」だけでは足りない 実装編 - 非機能要件・分散システム・トレードオフをコードで見る
nwiizo
3
390
え!?初参加で 300冊以上 も頒布!? これは大成功!そのはずなのに わいの財布は 赤字 の件
hellohazime
0
140
DIPS2.0データに基づく森林管理における無人航空機の利用状況
naokimuroki
1
210
昔はシンプルだった_AmazonS3
kawaji_scratch
0
230
CloudSec JP #005 後締め ~ソフトウェアサプライチェーン攻撃から開発者のシークレットを守る~
lhazy
0
190
60分で学ぶ最新Webフロントエンド
mizdra
PRO
33
16k
Master Dataグループ紹介資料
sansan33
PRO
1
4.6k
研究開発部メンバーの働き⽅ / Sansan R&D Profile
sansan33
PRO
4
23k
数案件を同時に進行するためのコンテキスト整理術
sutetotanuki
2
240
自分のハンドルは自分で握れ! ― 自分のケイパビリティを増やし、メンバーのケイパビリティ獲得を支援する ― / Take the wheel yourself
takaking22
1
430
GitHub Copilotを極める会 - 開発者のための活用術
findy_eventslides
7
4.3k
Featured
See All Featured
Save Time (by Creating Custom Rails Generators)
garrettdimon
PRO
32
2.7k
The Impact of AI in SEO - AI Overviews June 2024 Edition
aleyda
5
790
4 Signs Your Business is Dying
shpigford
187
22k
The Illustrated Children's Guide to Kubernetes
chrisshort
51
52k
Beyond borders and beyond the search box: How to win the global "messy middle" with AI-driven SEO
davidcarrasco
3
110
What the history of the web can teach us about the future of AI
inesmontani
PRO
1
520
The Anti-SEO Checklist Checklist. Pubcon Cyber Week
ryanjones
0
120
AI: The stuff that nobody shows you
jnunemaker
PRO
5
540
Impact Scores and Hybrid Strategies: The future of link building
tamaranovitovic
0
260
Leveraging Curiosity to Care for An Aging Population
cassininazir
1
220
CSS Pre-Processors: Stylus, Less & Sass
bermonpainter
360
30k
DBのスキルで生き残る技術 - AI時代におけるテーブル設計の勘所
soudai
PRO
64
53k
Transcript
None
the question: what is the security posture of our devices?
what we used to try and get the answer: McAfee
ePO Nessus Build something
our Experience
McAfee ePO
problems with McAfee ePO complex inaccuracies cumbersome reports blackbox (customizations,
waiting)
Nessus
problems with Nessus tedious overkill inconsistent results hosts accounted for:
76%
our problems in general timing transient devices deepfreeze
our kick at the can
None
what we collect (currently) antivirus windows updates asset info
None
None
None
None
None
the backend host host antivirus antivirus windows updates windows updates
asset info asset info active directory active directory …? …? …? …? other.. other..
the backend host host antivirus antivirus windows updates windows updates
asset info asset info active directory active directory compliance history compliance history problem frequency problem frequency other.. other.. SHAZAM! SHAZAM!
the script (patch_status.vbs) what it does how it evolved where
it’s headed
what it does deployment scheduled task information gathering transport
how it evolved primarily driven by trial and error a
lot of: “wouldn’t this be neat” what works? what doesn’t? dealing with problems
what it has changed Managed AV Microsoft update Maintenance window
where it’s headed deployment strategy refne/improve installer target other OS’s
where it’s headed additional metrics ids alert data device usage
java version flash version
where it’s headed helpdesk integration automated ticket generation
thoughts?