RE: Handling new vulnerabilities like WebDav - SUMMARY

Mike Alexander <[email protected]> Thu, 27 Mar 2003 10:20:24 -0000
Newsgroups gmane.comp.security.incident-handling
Message-ID <[email protected]>
Patrik,

I agree entirely with what you say.  IDSs are but one link in the chain that
forms the security defences that a company can build, but like firewalls
they should not be seen as the be all and end all of a corporate security
system.

Good systems management and awareness of the risks are what is required, not
a blind faith in technology.  IDSs are useful in alerting the
network/security/systems manager to unusual activity, but I share your view
about the "proactive IDS" and the potential for carrying out a DoS attack
through what could be nothing more than a port scan.

However these sorts of "active IDS" products appeal to a level of management
who don't understand the real risks and seem to think that security is
something that you can buy in and is delivered in a large box - the "silver
bullet" that you refer to.  It's not.  I believe that this notion arises
from some senior managers having an inability to understand that security
should be a layered approach, with integration between a number of
difference products/areas.

But now I am also preaching to the converted! ;-)

Regards,

Mike
___________________________________________________________
Mike Alexander      Email: [email protected]
ICT Project Leader    Tel: 01343 563445   Fax: 01343 563221
The Moray Council     Web: http://www.moray.gov.uk
___________________________________________________________
"He is your friend, your partner, your defender, your dog.
You are his life, his love, his leader. He will be yours, 
faithful and true, to the last beat of his heart. You owe
it to him to be worthy of such devotion."   -Anon.


********  The Moray Council: Internet E-mail Notice  ********

The contents of this e-mail and any attachments ('this e-mail')
are confidential and intended solely for the addressee.
If this e-mail has been sent to you by mistake, please notify
[email protected] as soon as possible; you should then
delete this e-mail from your computer.