Multiple Layers of Defense
by Carol Woodbury
President, SkyView Partners, Inc.
I f you've read my articles or been in a class with me you've probably heard me talk about implementing 'multiple layers of defense. I had this conversation with a client recently so I thought I'd share the discussion of the layers of defense that are available on the i. - Object Level Security - The first layer of defense and the foundation of your security scheme must be object level security.
- Exit Programs - Unfortunately, some exit point vendors have made the claim that you must have exit point programs in place to secure a system or be in compliance with certain laws and regulations. This is simply not true.
- Auditing - Using the audit features of i5/OS is a layer of defense I recommend everyone use.
- Packet Filtering and Port Restrictions - Most organizations put this function in their routers and/or firewalls but you can also add a layer of defense by configuring packet filtering or port restrictions on the i.
- Limiting iNavigator and iSeries Access - Using Application Administration, you can limit users' access to parts of iNavigator and iSeries Access for Windows.
- Perform a Risk Assessment - While you may not have thought about a vulnerability or assessment as a 'layer of defense' ... basically, when done right, a risk assessment is a second set of eyes used to examine the security configuration of your system.
|
Automating IBM AIX Security Compliance Reporting (with SkyView Policy Minder for IBM AIX)
presented by Carol Woodbury
Compliance and reporting requirements span all operating systems. Now the reporting features that are available for IBM i are available on IBM AIX. You can gather and compare the information on user accounts, directory and file permissions and global settings using hand-written scripts run on each of your partitions. Or... you can use Policy Minder for AIX to automate the process of gathering and reporting on the information simply and concisely, consolidating information from each AIX server being examined. During this webinar you'll see the features of Policy Minder for AIX and see how you save time on your compliance reporting needs and see how to set up a consistent, accurate and efficient process that can span multiple partitions from a single console.
When: Wednesday, October 26, 2011 8:00 AM - 9:00 AM PDT.
|
|
The Hidden Cost of Compliance
by John Vanderwall
CEO, SkyView Partners, Inc.
"Automating your security compliance process cuts the hidden cost associated with manual processes. No more "scrambling" to answer requests for data. No more time spent documenting your processes and continually reviewing that documentation. No more time spent reproducing information because a "manual error" was found. By examining compliance, automating what can be automated, you end up with several very positive results for your company. First you free up time for IT to focus on bottom-line projects."
|