<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>eIQviews &#187; configuration audit</title>
	<atom:link href="http://blog.eiqnetworks.com/tag/configuration-audit/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.eiqnetworks.com</link>
	<description>Perspectives on Security and Compliance Management from eIQnetworks</description>
	<lastBuildDate>Mon, 14 Dec 2009 13:04:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.eiqnetworks.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/9a3baa02baa3289d9a8c9a6a0eb652a5?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>eIQviews &#187; configuration audit</title>
		<link>http://blog.eiqnetworks.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.eiqnetworks.com/osd.xml" title="eIQviews" />
	<atom:link rel='hub' href='http://blog.eiqnetworks.com/?pushpress=hub'/>
		<item>
		<title>Ten Reasons Log Data is Not Enough: #3. What&#8217;s the Configuration, Kenneth?</title>
		<link>http://blog.eiqnetworks.com/2009/09/10/ten-reasons-log-data-is-not-enough-3-whats-the-configuration-kenneth/</link>
		<comments>http://blog.eiqnetworks.com/2009/09/10/ten-reasons-log-data-is-not-enough-3-whats-the-configuration-kenneth/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 18:54:39 +0000</pubDate>
		<dc:creator>Mike Rothman</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Log Management Series]]></category>
		<category><![CDATA[configuration audit]]></category>
		<category><![CDATA[Log Data is Not Enough]]></category>
		<category><![CDATA[log management]]></category>

		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=273</guid>
		<description><![CDATA[As we resume our series on why Log Data is Not Enough, the 3rd reason we have underscores the importance of configuration data as part of the security analysis. As we&#8217;ve repeatedly mentioned, log management systems are driven by log data. And as we showed in Reason #1, logging can (and usually is) turned off [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=273&subd=eiqviews&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>As we resume our series on why <a href="http://en.wordpress.com/tag/log-data-is-not-enough/" target="_blank">Log Data is Not Enough</a>, the 3rd reason we have underscores the importance of configuration data as part of the security analysis. As we&#8217;ve repeatedly mentioned, <a href="http://www.eiqnetworks.com/solutions/log_management.shtml" target="_blank">log management</a> systems are driven by log data. And as we showed in <a href="http://blog.eiqnetworks.com/2009/09/03/ten-reasons-log-data-is-not-enough-1-logging-can-be-turned-off/" target="_blank">Reason #1</a>, logging can (and usually is) turned off &#8211; by savvy attackers anyway.</p>
<p>So how do you detect an attack, if you have no log data to analyze? Basically you need other data sources to figure out what&#8217;s happening and that is where configuration data comes in. Every device (whether it&#8217;s a firewall, switch, Windows Server, Linux Server, desktops, etc.) has a configuration and you can poll that configuration (with proper authorization) to figure out what&#8217;s going on.</p>
<p>Note you have to PULL the config data out of the device. It&#8217;s not going to just send it to you (like with log data), so this is actually a big deal to have in a security management platform. It&#8217;s a totally different way to gather data and is very hard to do in a scalable fashion with the reliability enterprises demand.</p>
<p>Once you have the configuration baseline, then you can compare new versions of the config to the baseline at a user defined interval. If something changes (like logging is turned off, a new service is turned on, or a registry change happens, for example), it will create an event in the system that can then be used with other data types to determine if it&#8217;s really an attack.</p>
<p>Remember systems relying just on log data can&#8217;t do this level of analysis. And those vendors that say they do require customers to buy a totally different product with a totally different management interface. Many of these other folks ONLY track network device configuration as well.</p>
<p>So this is another reason that Log Data is Not Enough, and those folks that know they need to go beyond compliance know they need to go beyond log management.</p>
<br />Posted in Compliance, Log Management Series Tagged: configuration audit, Log Data is Not Enough, log management <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eiqviews.wordpress.com/273/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eiqviews.wordpress.com/273/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eiqviews.wordpress.com/273/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eiqviews.wordpress.com/273/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eiqviews.wordpress.com/273/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eiqviews.wordpress.com/273/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eiqviews.wordpress.com/273/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eiqviews.wordpress.com/273/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eiqviews.wordpress.com/273/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eiqviews.wordpress.com/273/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=273&subd=eiqviews&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.eiqnetworks.com/2009/09/10/ten-reasons-log-data-is-not-enough-3-whats-the-configuration-kenneth/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike</media:title>
		</media:content>
	</item>
		<item>
		<title>Controlling the browser, if you can</title>
		<link>http://blog.eiqnetworks.com/2009/02/05/controlling-the-browser-if-you-can/</link>
		<comments>http://blog.eiqnetworks.com/2009/02/05/controlling-the-browser-if-you-can/#comments</comments>
		<pubDate>Thu, 05 Feb 2009 17:07:39 +0000</pubDate>
		<dc:creator>Mike Rothman</dc:creator>
				<category><![CDATA[User Issues]]></category>
		<category><![CDATA[asset management]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[configuration audit]]></category>
		<category><![CDATA[Firefox]]></category>

		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=96</guid>
		<description><![CDATA[Andreas makes a number of good points in his weekly NetworkWorld column about Firefox add-ins. His general point is that software extensibility is good, but it must be controlled lest you introduce significant new risks to your environment. I couldn&#8217;t agree more. That&#8217;s why a lot of the work we at eIQ do with configuration [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=96&subd=eiqviews&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Andreas makes a number of good points in <a href="http://www.networkworld.com/columnists/2009/020309antonopoulos.html" target="_blank">his weekly NetworkWorld column about Firefox add-ins</a>. His general point is that software extensibility is good, but it must be controlled lest you introduce significant new risks to your environment. I couldn&#8217;t agree more. That&#8217;s why a lot of the work we at eIQ do with configuration auditing is such an important part of maintaining a secure environment.</p>
<p>Most security organizations don&#8217;t have the pull to really lock-down desktops. Sure they can mandate a standard build, but in most cases users can install software that they want, and sometimes that software becomes a problem. The reality is you can&#8217;t avoid these issues, but you need to figure out how to react faster and appropriately when an issue crops up.</p>
<p>The first step is to know what&#8217;s out there. A lot of organizations rely on asset management tools to assemble information on who is using what. You can also figure out what software is out of policy and decide whether to do anything about it. Sometimes it&#8217;s the better answer to turn the other cheek, in terms of getting rid of unauthorized software. But it&#8217;s not OK to not know it&#8217;s there.</p>
<p>Just as important as understanding what&#8217;s out there, you need to understand what&#8217;s changing. That&#8217;s why constantly revisiting the asset base and the device configurations are critical. And just doing one or the other isn&#8217;t enough. New software can (and usually does) change configurations and that can create security exposures.</p>
<p>To bring the point home, it&#8217;s probably unreasonable to expect that your users will allow you to totally control what software they are running. But you CAN and SHOULD know what they are running and be able to pinpoint when something changes to evaluate the security risk to your environment. That&#8217;s just good security practice.</p>
<br />Posted in User Issues Tagged: asset management, browser, configuration audit, Firefox <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eiqviews.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eiqviews.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eiqviews.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eiqviews.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eiqviews.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eiqviews.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eiqviews.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eiqviews.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eiqviews.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eiqviews.wordpress.com/96/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=96&subd=eiqviews&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.eiqnetworks.com/2009/02/05/controlling-the-browser-if-you-can/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike</media:title>
		</media:content>
	</item>
		<item>
		<title>eIQcast Episode 6: All about Configuration</title>
		<link>http://blog.eiqnetworks.com/2009/02/04/eiqcast-episode-6-all-about-configuration/</link>
		<comments>http://blog.eiqnetworks.com/2009/02/04/eiqcast-episode-6-all-about-configuration/#comments</comments>
		<pubDate>Wed, 04 Feb 2009 15:27:22 +0000</pubDate>
		<dc:creator>Mike Rothman</dc:creator>
				<category><![CDATA[eIQcast]]></category>
		<category><![CDATA[CIS]]></category>
		<category><![CDATA[configuration audit]]></category>
		<category><![CDATA[FDCC]]></category>
		<category><![CDATA[SCAP]]></category>

		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=90</guid>
		<description><![CDATA[This week, John and Mike tackle the concept of configuration and why it&#8217;s important to ensure devices are configured correctly, both from a security and an operations standpoint. We also discuss some of the configuration &#8220;standards&#8221; out there, like Center for Internet Security and some suggestions from the US Federal Government. Running time: 12:23 Direct [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=90&subd=eiqviews&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-92" title="microphone1" src="http://eiqviews.files.wordpress.com/2009/02/microphone1.jpg?w=95&#038;h=100" alt="microphone1" width="95" height="100" />This week, John and Mike tackle the concept of configuration and why it&#8217;s important to ensure devices are configured correctly, both from a security and an operations standpoint. We also discuss some of the configuration &#8220;standards&#8221; out there, like Center for Internet Security and some suggestions from the US Federal Government.</p>
<p>Running time: 12:23</p>
<div style="margin-bottom:-5px;"></div>
<div><a href="http://eiqcast.podOmatic.com" target="eiqcast"><img src="http://www.podomatic.com/images/share/player_logo.jpg" border="0" alt="" /></a></div>
<p><a href="http://www.gigyamailbutton.com/wildfire/gigyamailbutton.ashx?url=aHR*cDovL3dpbGRmaXJlLmdpZ3lhLmNvbS93aWxkZmlyZS93ZnBvcC5hc3B4P21vZHVsZT1lbWFpbCZ1cmw9aHR*cCUzQSUyRiUyRnd3dyUyRXBvZG9tYXRpYyUyRWNvbSUyRnBvZGNhc3QlMkZlbWJlZCUyRmVpcWNhc3Q=" target="_blank"><img src="http://cdn.gigya.com/wildfire/i/includeShareButton.gif" border="0" alt="" width="60" height="20" /></a><img style="visibility:hidden;width:0;height:0;" src="http://counters.gigya.com/wildfire/IMP/CXNID=2000002.0NXC/bT*xJmx*PTEyMzM3NjA1OTIwNDcmcHQ9MTIzMzc2MDU5NTU2MSZwPTg*NjgxJmQ9Jmc9MSZ*PSZvPTg4MTkxNWRjNzQ1ODQzZWI5NzA3NDE5YjE4ZDU4YWM4.gif" border="0" alt="" width="0" height="0" /></p>
<p>Direct Link: <a href="http://eiqcast.podOmatic.com/entry/2009-02-04T07_15_13-08_00" target="_blank">http://eiqcast.podOmatic.com/entry/2009-02-04T07_15_13-08_00</a></p>
<p>Photo: &#8220;RCA 40A Ribbon Microphone&#8221; originally uploaded by <a href="http://www.flickr.com/photos/85941395@N00/1199679274/" target="_blank">jschneid</a></p>
<br />Posted in eIQcast Tagged: CIS, configuration audit, FDCC, SCAP <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eiqviews.wordpress.com/90/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eiqviews.wordpress.com/90/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eiqviews.wordpress.com/90/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eiqviews.wordpress.com/90/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eiqviews.wordpress.com/90/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eiqviews.wordpress.com/90/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eiqviews.wordpress.com/90/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eiqviews.wordpress.com/90/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eiqviews.wordpress.com/90/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eiqviews.wordpress.com/90/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=90&subd=eiqviews&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.eiqnetworks.com/2009/02/04/eiqcast-episode-6-all-about-configuration/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike</media:title>
		</media:content>

		<media:content url="http://eiqviews.files.wordpress.com/2009/02/microphone1.jpg" medium="image">
			<media:title type="html">microphone1</media:title>
		</media:content>

		<media:content url="http://www.podomatic.com/images/share/player_logo.jpg" medium="image" />

		<media:content url="http://cdn.gigya.com/wildfire/i/includeShareButton.gif" medium="image" />

		<media:content url="http://counters.gigya.com/wildfire/IMP/CXNID=2000002.0NXC/bT*xJmx*PTEyMzM3NjA1OTIwNDcmcHQ9MTIzMzc2MDU5NTU2MSZwPTg*NjgxJmQ9Jmc9MSZ*PSZvPTg4MTkxNWRjNzQ1ODQzZWI5NzA3NDE5YjE4ZDU4YWM4.gif" medium="image" />
	</item>
	</channel>
</rss>