Top Banner
How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets Courtesy of FPA Technology Services, Inc. http:// www.TechGuideforLADistributors.com
31

How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Aug 07, 2015

Download

Technology

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

How LA Manufacturers and Distributors

Use Vulnerability Testing

to Protect Company Assets

Courtesy of FPA Technology Services, Inc.

http://www.TechGuideforLADistributors.com

Page 2: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

The right vulnerability testing,

security assessment, and

ongoing management

of your IT resources

Page 3: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

can help bring your

stress level down and

ensure your company

will have many more

working days ahead

Page 4: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

Vulnerability

Compared to Risk

Page 5: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

Vulnerability can be defined

as a weakness or openness

to attack or damage

Page 6: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

Testing is often done together

with a vulnerability assessment

Page 7: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

This may sound similar

to a risk assessment,

but there are differences:

Page 8: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

• Risk focuses on the

likelihood of a cause and

its impact (i.e. cost) on an

item or resource.

Page 9: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

Risk can also be positive

or negative

Page 10: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

• Vulnerability is focused on

the opportunity or specific

exposure points or resources

and its implication on other

resources.

Page 11: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

Vulnerability is only negative

Page 12: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

Following up on possible

chains of events is therefore

an important part of

vulnerability testing

Page 13: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

What Should Be Tested

for Vulnerability?

Page 14: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

Although every major

resource needed to keep

a manufacturer, distributor,

or wholesaler operational

should be checked,

Page 15: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

IT resources get the lion’s

share of the testing

Page 16: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

Sometimes companies

fall short and only think of

vulnerability of IT equipment

and its immediate impact

on operations

Page 17: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

rather than the valuable

information it contains and

the overall value impacted

Page 18: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

How Should the Testing

Be Done?

Page 19: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

Tools exist to automate testing

to identify vulnerabilities

at a technical level

Page 20: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

They should however be

supplemented with checks

on IT staff and employee

security procedures

Page 21: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

Chains and Fuzzing

Page 22: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

The following two aspects

of vulnerability testing

of IT resources are of

particular interest:

Page 23: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

1. Identifying chains of effects

Page 24: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

A user login for a print server

might not seem like a big

deal, but that print server

might also be connected

to a network

Page 25: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

that also links to a database

with SQL injection vulnerability

and potential exposure of

administrator login credentials

Page 26: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

2. Fuzzing

Page 27: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

The idea is to stumble upon

unknown vulnerabilities by

using random input,

Page 28: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

rather than continually

retesting the standard paths

through a system that have

already been shown to be

well-protected

Page 29: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

Is your LA manufacturing

or distribution company

using vulnerability testing?

Page 30: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Sponsored by http://www.TechGuideforLADistributors.com

Craig PollackFounder & CEO

Give us your point of view

in the Comments box below

Page 31: How LA Manufacturers and Distributors Use Vulnerability Testing to Protect Company Assets (SlideShare)

Copyright © FPA Technology Services, Inc.

Learn How to Boost Your Company’s

Productivity with the Right Technology

Download Your Free Guide

How COOs at Los Angeles Distributors

and Manufacturers Get More Done

Now at http://www.TechGuideforLADistributors.com