Automating some best-practice/common-sense [was: Keeping hosts updated]

Jaco <[email protected]> Sat, 26 Nov 2011 15:08:15 +1300
Newsgroups gmane.org.user-groups.linux.new-zealand.general
Organization Workshop Enterprises Ltd.
Message-ID <[email protected]>
> Ubuntu have a commercial service called landscape that does what you 
> want as well, and it looks like it's either run from the internet, or 
> you can have a local Landscape server installed.
A combination of Landscape & Puppet seems like the (long-term) ideal 
solution, but required some time & effort to get right.
I'll need to make a commitment to AppArmor/SELinux to deploy & maintain 
policy, such as application/process-whitelisting, etc.

What's spurned me to do this, beyond a very few systems, is this good 
report (posted before; might've been elsewhere):
Top 35 Mitigation Strategies
http://www.dsd.gov.au/infosec/top-mitigations/top35mitigationstrategies-list.htm

Quick summary of top points:
* Patch OS
* Patch apps
* Restrict privileges & scope
* Whilelist

I've been doing some of this for some time (to a greater & lesser 
extent), but I want to take the monotonous leg-work out of recurring 
repetitive tasks (i.e. automation).
Much of this seems like common sense, which really isn't all that common.

Thanks for the pointers & please keep them coming.

Cheers

- Jaco
_______________________________________________
NZLUG mailing list [email protected]
http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug