IT:Network:Apps
Security Options Group Policy AppLocker ACL
Defense in depth ◦ Physical ◦ File level Folder/File permissions Minimalist mentality ◦ Object level Object permissions
Desktop ◦ Physical ◦ Group Policy ◦ Access/Authentication Server ◦ Physical ◦ Group Policy ◦ Access/Authentication
Perimeter ◦ NAT ◦ Firewall ◦ Security Appliances Mail/Spam Gateway VPN concentrator ◦ Network Access Protection
Antivirus solutions rise-antivirus-software.aspx rise-antivirus-software.aspx ◦ Network based Antivirus Centrally managed Centrally deployed Engines for both server and client Agents for server based applications Exchange filtering Central point for updates Engines Definitions
Antivirus solutions Centralized reporting Reports on activities, updates and policies
Antivirus solutions ◦ Client based Antivirus Updates done individually at client directly to Internet Reporting local to client Typically has engine for desktops and not server
Group Policy Objects (GPO) can be used to secure both server and desktop machines Security Configuration Wizard (SCW) ◦ us/library/cc771492(WS.10).aspx us/library/cc771492(WS.10).aspx
What does SCW do? ◦ Guides you through the process of creating, editing, applying, or rolling back a security policy. ◦ It provides a way to create or modify a security policy for your server based on its role. ◦ Use Group Policy to apply the security policy to multiple target servers that perform the same role ◦ You can compare a server's security settings with a desired security policy to check for vulnerable configurations in the system.
Security Configuration Wizard Start Programs Administrative Tools
SCW will create/edit or roll back security settings based on your selections Creates role based policy settings ◦ Detects what roles are installed on server
Controlling applications ◦ Application Control Policies ◦ Software Restriction Policies
Applocker requirements ◦ Works on Windows 7 and newer ◦ Only available on 7 Enterprise and Ultimate…not Pro ◦ Application Identity service must be running. ◦ Add default rules to prevent stepping on “required” services
Applocker ◦ Add default rules ◦ Create new rule
Software Restriction Polices ◦ Similar to Applocker, works on XP and later
Security can be controlled from the file level to the Active Directory Object level NTFS permissions Share permissions ADO permissions Out of sight, out of mind approach Minimalist approach