Managed Host Security – Patch Management   BigFix Deployment April-September 2004 Jay Stamps, ITSS Turing Auditorium, May 21, 2004.

Slides:



Advertisements
Similar presentations
This course is designed for system managers/administrators to better understand the SAAZ Desktop and Server Management components Students will learn.
Advertisements

Auditing Microsoft Active Directory
Network Redesign and Palette 2.0. The Mission of GCIS* Provide all of our users optimal access to GCC’s technology resources. *(GCC Information Services:
A Technical Overview of Microsoft Forefront Client Security (FCS) Howard Chow Microsoft MVP.
OAAIS Enterprise Information Security Security Awareness, Training & Education (SATE) Program or UCSF Campus VPN.
Defense-in-Depth Against Malicious Software Jeff Alexander IT Pro Evangelist Microsoft Australia
Network Redesign and Palette 2.0. The Mission of GCIS* Provide all of our users optimal access to GCC’s technology resources. *(GCC Information Services:
Microsoft Systems Management Server Implementation at SLAC Freddie Chow Freddie Chow Stanford Linear Accelerator.
Trend Micro Round Table May 19, Agenda Introduction – why switch? Timeline for implementation Related policies Trend Micro product descriptions.
Small Business Security By Donatas Sumyla. Content Introduction Tools Symantec Corp. Company Overview Symantec.com Microsoft Company Overview Small Business.
NETOP ONDEMAND What’s new in version 2.1? DECEMBER 09 NETOP ONDEMAND1.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 11 Managing and Monitoring a Windows Server 2008 Network.
How To Keep Up With Security Patches Eric Schultze Security Strategies Microsoft.
Tripwire Enterprise Server – Getting Started Doreen Meyer and Vincent Fox UC Davis, Information and Education Technology June 6, 2006.
Fermilab VPN Service What is a VPN ?.
Windows XP Professional Deployment and Support Microsoft IT Shares Its Experiences Published: May 2002 (Revised October 2004)
Windows Anti-virus and Security WNUG Meeting
VMware vCenter Server Module 4.
Group Policy in Microsoft Windows Active Directory.
Module 16: Software Maintenance Using Windows Server Update Services.
16.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 16: Examining Software Update.
IBM Endpoint Manager - Bigfix
Stanford’s Patch Management Project   Ced Bennett May 17, 2004 Copyright Cedric Bennett This work is the intellectual property of the author. Permission.
Getting Connected to NGS while on the Road… Donna V. Shaw, NGS Convocation.
Security Audit Tools Project. CT 395 IT Security I Professor Igbeare Summer Quarter 2009 August 25, 2009.
Task Scheduler Pro Managing scheduled tasks across the enterprise Joe Vachon Sales Engineer.
Hands-On Microsoft Windows Server 2008 Chapter 1 Introduction to Windows Server 2008.
BASIC NETWORK CONCEPTS (PART 6). Network Operating Systems NNow that you have a general idea of the network topologies, cable types, and network architectures,
Acceleratio Ltd. is a software development company based in Zagreb, Croatia, founded in We create innovative software solutions for SharePoint,
1 Objectives Windows Firewalls with Advanced Security Bit-Lock Update and maintain your clients using Windows Server Update Service Microsoft Baseline.
WINDOWS XP PROFESSIONAL Bilal Munir Mughal Chapter-1 1.
IT:Network:Microsoft Server 2 Chapter 27 WINDOWS SERVER UPDATE SERVICES.

Training on ManageEngine Desktop Central
Randy Diddel A+ Certified Technician Apple Certified Associate-Mac Integration OS X ITIL Foundations v3 Mac Team Technical Support Analyst II UNM IT Workstation.
Module 4: Add Client Computers and Devices to the Network.
1 Guide to Novell NetWare 6.0 Network Administration Chapter 13.
IMPLEMENTING F-SECURE POLICY MANAGER. Page 2 Agenda Main topics Pre-deployment phase Is the implementation possible? Implementation scenarios and examples.
Microsoft Active Directory(AD) A presentation by Robert, Jasmine, Val and Scott IMT546 December 11, 2004.
Raven Services Update December 2003 David Wallis Senior Systems Consultant Raven Computers Ltd.
Managing and Monitoring Windows 7 Performance Lesson 8.
User Manager Pro Suite Taking Control of Your Systems Joe Vachon Sales Engineer November 8, 2007.
Network Management Tool Amy Auburger. 2 Product Overview Made by Ipswitch Affordable alternative to expensive & complicated Network Management Systems.
The Microsoft Baseline Security Analyzer A practical look….
EMerge Browser Managed Security Platform Module 3: Startup eMerge Certification Course  Physical connection  TCP/IP Characteristics of PC  Initial connection.
EPolicy Orchestrator WNUG June Meeting 6/6/2002. Presentation Contents What is ePO? What are the requirements? ePO components Demo of ePO Where to get.
INSTALLATION HANDS-ON. Page 2 About the Hands-On This hands-on section is structured in a way, that it allows you to work independently, but still giving.
Windows 2003 Installation/Upgrade and Update. Checking Compatibility Supported Upgrade paths Using the MS Windows Upgrade Advisor HCL (Hardware Compatibility.
Course ILT Routine maintenance Unit objectives Discuss the necessity of applying software patches and fixes Discuss viruses and anti-virus strategy.
1 Objectives Windows Firewalls with Advanced Security Bit-Lock Update and maintain your clients using Windows Server Update Service Microsoft Baseline.
Technology Update TSAG Meeting 7/8/04. Announcements New Interim Director of User Support Services: Bill Hardy Outage on July 17 Udrive status Anyone.
Microsoft Management Seminar Series SMS 2003 Change Management.
Rob Davidson, Partner Technology Specialist Microsoft Management Servers: Using management to stay secure.
Hands-On Microsoft Windows Server 2003 Chapter 1 Introduction to Windows Server 2003, Standard Edition.
Virtualization Technology and Microsoft Virtual PC 2007 YOU ARE WELCOME By : Osama Tamimi.
IS493 INFORMATION SECURITY TUTORIAL # 1 (S ) ASHRAF YOUSSEF.
Windows SharePoint Services Installation and Configuration.
Microsoft NDA Material Adwait Joshi Sr. Technical Product Manager Microsoft Corporation.
Securing a Host Computer BY STEPHEN GOSNER. Definition of a Host  Host  In networking, a host is any device that has an IP address.  Hosts include.
GFI LANguard Matt Norris Dave Hone Chris Gould. GFI LANguard: Description Through the performances of the three (3) cornerstones of vulnerability management:
Planning Server Deployments Chapter 1. Server Deployment When planning a server deployment for a large enterprise network, the operating system edition.
ITMT 1371 – Window 7 Configuration 1 ITMT Windows 7 Configuration Chapter 8 – Managing and Monitoring Windows 7 Performance.
CACI Proprietary Information | Date 1 PD² v4.2 Increment 2 SR13 and FPDS Engine v3.5 Database Upgrade Name: Semarria Rosemond Title: Systems Analyst, Lead.
NETWORK SECURITY LAB 1170 REHAB ALFALLAJ CT1406. Introduction There are a number of technologies that exist for the sole purpose of ensuring that the.
Getting Connected to NGS while on the Road…
Network Services.
Getting Connected to NGS while on the Road…
Connecting Remotely Winter 2014.
Implementing Client Security on Windows 2000 and Windows XP Level 150
Presentation transcript:

Managed Host Security – Patch Management   BigFix Deployment April-September 2004 Jay Stamps, ITSS Turing Auditorium, May 21, 2004

Why Here? Why Now?  Because Stanford wants to protect its information resources and continue to enjoy an open, academic network  Three-pronged approach:  Patch Management  Configuration Management  Controlled Network Access  Clear that this approach requires active management of networked resources

Who’s Involved?  Executive Buy-In  Internal Audit  CFO  System Governance Group  C-ACIS  Academic Senate  President/Provost  Campus-Wide Working Group  Computer Science  Earth Sciences  Graduate School of Business  Internal Audit  ITSS  Medical School  Residential Computing

Patch Management  A tool / service designed to manage the application of patches to hosts  Components  An agent on each desktop and laptop computer  A server with all relevant patches & history  One or more consoles to manage / monitor the process  Relay servers to spread the patch distribution load  Basic process  Server provides new vulnerability information  Agent signals if its host needs remediation  Administrator releases patch to selected hosts

Patch Management (continued)  The BigFix Enterprise Suite (BES) Internet

Patching Procedures and Process  Routine: Non-security patch  Handled locally  As it is handled today or  Use patch management tool locally  Routine: Security patch No known exploits  Patch tested centrally and  Patch tested locally  Patch released after brief wait  High-risk security patch Exploits known to exist  CISO and CIO determine the rollout timeline

Centrally Tested Platforms  NT 4.0 Workstation SP 6a  Windows 2000 Professional SP 4  2003 Server, desktop configuration  Windows XP Home SP 1  Windows XP Pro, SP 1  Windows ME  Windows 98 SE  Newly available critical patches will be tested on these platforms with the latest Service Packs and ESS applications installed

Retrieved Properties  Computer Name  IP Address  MAC Address  OS  OS Language Version  CPU  Last Report Time  Subscription Time  Locked  Username  Blank Password Check  Free Space on System Drive  Lock Expiration  Total Size of System Drive  DNS Name  BES Relay Selection Method  Office Version  RAM  Norton AntiVirus Service Status  Norton AntiVirus DAT version  PC-Leland Version  Relay  Computer Type  PC-AFS Version  BES Relay Service Installed  BRIO Plug-in Installed  BIOS  Domain/Workgroup  Active Directory Path  Web Browser  Client Administrators  Client Settings  SU Group  SU Subgroup

Managing Patch Management  Top-down and hierarchical  To provide for testing of patches  To provide for managed patch deployment  Campus divided by groups  Groups may have management sub-groups  Administrators for each group can see and manage only PCs in their own group  Each group can lock individual machines  Self-managed machines  Not part of any group

Managing Patch Management continued)

Web Reports Total issues by Fixlet severity Issues remediated by Fixlet severity

Web Reports (cont) Computer vulnerability breakdown by severity Computers in the network with the BigFix agent, reported over time Top 10 Issues identified on the computers in the network

Web Report Progress Report Remediation progress report updates in near real-time as actions are being executed across the enterprise

Deployment Plan  Meeting with all organizations  Administrative contacts  Technical contacts  Discussing roll-out roadmaps  Selecting target date

Deployment Details  Local relays: ~ one per 500 – 1000 clients  SUGroup  Remote deployment tool  Wrapped agent installer   Ferret tool  Console Operators  Selection & training

What’s Next?  Questions?   Added to list  Follow up and meeting notes summary  Target date