Top Banner
Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-
17

Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-

Feb 24, 2016

Download

Documents

gus

Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-. Incident. 80 Laptops lost 67 were stolen 13 Found missing when audited All Laptops lost offsite. How it Happened. No audits No Check-in or check-out procedures There were, but were not followed - PowerPoint PPT Presentation
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-

Analysis of Laptop Security Incident at Los Alamos Laboratory

-Ciscop Consulting-

Page 2: Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-

Incident

• 80 Laptops lost• 67 were stolen• 13 Found missing when audited

• All Laptops lost offsite

Page 3: Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-

How it Happened

• No audits• No Check-in or check-out procedures

There were, but were not followedFailure to know where laptops were

Page 4: Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-

Recommendation

• Establish two security levels• Low Risk Classification

• Desktop or on-campus devices• Non classified data

• High Risk Classification• Mobile or laptop devices• Sensitive or classified data

Page 5: Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-

• Spiceworks• Check-in and out procedures• Physically locking machines down• More regularly scheduled and formal audits

Low Risk Classification

Page 6: Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-

SpiceWorks

• Separate Spiceworks servers high risk/low risk• Additional servers

• Spiceworks audits daily electronically• Only if computer doesn’t check in for the day

Monday-Friday

Page 7: Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-
Page 8: Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-

Lock Down Machines

• Non mobile devices locked down• Laptop Lockdowns• $10

• Desktop lockdowns• $10/15ft of cable• Covers 3 computers

• $3 per lock

Page 9: Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-

High Risk Classification

• Beacons• RFID• Encrypted hard drives

Page 10: Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-

Beacons

• Constantly sends a location packet to the server

• Wipes the hard dive upon server request• Built into the BIOS• Can be used as an auditing tool

Page 11: Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-

RFID’s

• Passive tags• Creates a log of when and

where a device leaves• High implementation costs• Low recurring costs

Page 12: Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-

RFID’s

• Estimated prices• Readers $500 - $2,000• Tags 7-15 cents each• Support software

Page 13: Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-

Encrypted Hard drives

• All Mobile devices• Full Disc Encryption (FDE)– Uses AES requires authentication before boot up will

occur• Password• Biometrics• Smart cards

– Hard ware encryption– Seagate Monentus 7200 rpm FDE.2 ST9250411AS 89.99

Page 14: Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-

Check-in/out Procedures

• RFID’s help to denote high and low risk• Low risk laptops• Basic Check-out procedures• Once weekly• Monitored by SpiceWorks

• SpiceWorks audits once weekly

• High risk laptops• Check-out Daily• Check-in Daily• Constantly Monitored by SpiceWorks

Page 15: Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-

References

Page 16: Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-

Questions?

Page 17: Analysis of Laptop Security Incident at Los Alamos Laboratory -Ciscop Consulting-

Thanks and have a great day!