首页> 外文期刊>IEEE Software >Reducing Internet-based intrusions: Effective security patch management
【24h】

Reducing Internet-based intrusions: Effective security patch management

机译:减少基于Internet的入侵:有效的安全补丁管理

获取原文
获取原文并翻译 | 示例
       

摘要

The Software Productivity Consortium (the Consortium) has been investigating methods for improving and measuring four essential defenses against Internet-based threats: security patch management, system and application hardening, network reconnaissance and enumeration, and tools against malicious software. These defenses increasingly are critical to an organization's information security posture and should be implemented in an effective, systematic, and repeatable fashion. Senior-level managers or executives should review process measurement data regularly to ensure that these defenses are being performed properly and to provide an objective basis for organizational improvement. This article focuses on lessons learned implementing improvements in the first of these defenses, security patch management, and is derived largely from pilot projects conducted in collaboration with Consortium members. The need for improved security patch management figured prominently in the recent draft cyber security strategy issued by the White House. The practices examined in this article can assist organizations in substantially reducing the risk from Internet-based compromises.
机译:软件生产力联盟(The Consortium)一直在研究用于改进和衡量针对基于Internet的威胁的四种基本防御措施的方法:安全补丁管理,系统和应用程序强化,网络侦察和枚举以及针对恶意软件的工具。这些防御对组织的信息安全态势越来越重要,应以有效,系统和可重复的方式实施。高级管理人员或高管应定期检查过程度量数据,以确保正确执行这些防御措施并为组织改进提供客观依据。本文重点介绍在这些防御中的第一个改进(安全补丁管理)中实现改进的经验教训,并且该教训主要来自与财团成员合作进行的试点项目。白宫最近发布的网络安全策略草案中突出强调了对改进安全补丁管理的需求。本文研究的实践可以帮助组织从根本上减少基于Internet的破坏的风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号