St. Bernard Software v7.01 manual SecurityEXPERT Overview

Page 27

St. Bernard Software, Inc. ­ Protecting Your Network Investment

SecurityEXPERT Overview

Settings Management (Services, Registry, File, and Security Policy settings) is provided by downloading one or more security templates from the UpdateEXPERT Security Templates Tab, and using the settings management information to:

·Create Policies, i.e., research and select security points of interest

·Test Compliance, i.e., assess the status of machines

·Enforce Policy, i.e., implement settings changes to enhance security

Important: The actual enforcement of settings policy can change registry items, file­system permissions, and services settings. Settings changes can negatively impact applications and users. It is strongly recommended that you completely research and understand your chosen security points when creating policy, and that you first test enforcement on appropriate test platforms. You must test the effects of enforcement on applications & users. In general, understand what you are doing and why, and be conservative. Deployed settings changes cannot be easily reversed or undone.

Related to the point above, is that file­system permission enforcements currently replace permissions that currently exist on the target file(s). SecurityEXPERT will apply the specified permissions for the accounts listed and will remove any other account or permission. Again, test how the permission replacement may impact applications/users.

Note: SecurityEXPERT settings that affect remote access are displayed with a warning icon. Losing remote access will prevent patch management and settings management.

Assuming you included SecurityEXPERT during installation, using SecurityEXPERT requires the following:

·Downloading SecurityEXPERT Templates

·Researching Security Points and Creating Policy

·Assigning Machines to a Policy

·Assessing Machines by Policy

·Policy Enforcement

The example that follows creates a policy starting with an “expert” recommendation for a “desktop” XP machine. For the sake of simplicity, you will clear all the security points, and create a simple policy for two services. This allows rapid familiarization with the SecurityEXPERT workflow. Using expert recommendations would be appropriate for setting a security “baseline” for newly installed or imaged machines. For existing machines, careful construction of your own policy, adding specific items over time, may work best. The intention of this Evaluation is to get you started on using basic SecurityEXPERT features and workflow. See the UpdateEXPERT User Guide for more information on SecurityEXPERT.

June 19th, 2006

UpdateEXPERT Premium v7.01 Evaluation Guide

25

Image 27
Contents UpdateEXPERT Premium V7.01 Evaluation Guide St. Bernard Software Europe, Asia, Africa Table of Contents June 19th UpdateEXPERT Premium v7.01 Evaluation Guide Purpose UpdateEXPERT Premium OverviewInstall UpdateEXPERT Premium June 19th UpdateEXPERT Premium v7.01 Evaluation Guide Click Install June 19th UpdateEXPERT Premium v7.01 Evaluation Guide Launch UpdateEXPERT ... click Finish June 19th UpdateEXPERT Premium v7.01 Evaluation Guide Identify the Web Proxy if applicable Http//ueupdates.stbernard.comEnumerate Discover Machines Download the Latest UpdateEXPERT DatabaseQuery your UpdateEXPERT Machine Agentless Query Requirements Download Patches Install Patches Named Policies Install Required command Conformance Reporting Other Reports Installing Master or Leaf­Agents Remote Local Command­Line Active Directory Agent Settings Leaf­Agent ConfigurationValidation Scheduling Queries Logging What’s Next?Validating Patches Logging Scheduling QueriesSecurityEXPERT Overview Configure SecurityEXPERT Web Proxy Download SecurityEXPERT Templates Creating a SecurityEXPERT Policy June 19th UpdateEXPERT Premium v7.01 Evaluation Guide June 19th UpdateEXPERT Premium v7.01 Evaluation Guide Assigning the SecurityEXPERT Policy Testing SecurityEXPERT ComplianceJune 19th UpdateEXPERT Premium v7.01 Evaluation Guide Enforcing the SecurityEXPERT Policy Modifying the SecurityEXPERT PolicyJune 19th UpdateEXPERT Premium v7.01 Evaluation Guide Using Profiles with SecurityEXPERT June 19th UpdateEXPERT Premium v7.01 Evaluation Guide Thank You GlossaryServer Master­Agent and Agent­ Installer Appendix a Custom Install OptionsAppendix a Custom Install Options …