Top Banner
How to Take the Fire Drill out of Making Firewall Changes
29
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Taking the fire drill out of making firewall changes

How to Take the Fire Drill out of Making Firewall Changes

Page 2: Taking the fire drill out of making firewall changes

“Complexity is the worst enemy of security” - Bruce Schneier

Page 3: Taking the fire drill out of making firewall changes

• Application Connectivity

• Data Center Migration/Consolidation

• Decommissioned Applications

• M&A

• Next-Generation Policies • (External) Applications

• Users

• Devices

• New Threats

Page 4: Taking the fire drill out of making firewall changes

This is Not a Formal Policy

Page 5: Taking the fire drill out of making firewall changes
Page 6: Taking the fire drill out of making firewall changes

Source: The State of Network Security 2013

20.2% 22.1%

54.5%

43.6%

25.8%

16.6%

23.0% 25.2%

32.5%

0%

10%

20%

30%

40%

50%

60%

70%

80%

In your organization, an out-of-process change has resulted in...

2012

2013

Application Outage

Network Outage

Data Breach System Outage Failing an Audit None of the above

Page 8: Taking the fire drill out of making firewall changes

30%

of Changes

Made are Unneeded

Page 9: Taking the fire drill out of making firewall changes

“The best way to manage network

security operations is to

link security and operations

through change management and

change control, and to supplement

and accelerate automation.”

Page 10: Taking the fire drill out of making firewall changes

Dissecting the Security

Change Workflow

Page 11: Taking the fire drill out of making firewall changes

The Security Change Workflow

Request Analysis

Approval Implementation

Design Execution/ Verification

Audit the Change Process

Recertify Rules

Measure SLAs Security Operations

Compliance Executive

Operations

11

Page 12: Taking the fire drill out of making firewall changes

Request Analysis

• Who can make a request?

• Avoiding miscommunication

• What can be requested? • Add access

• Remove access

• Recertify access

• Change/Remove objects

• Prioritization

• Eliminating “already works”

• Discovering relevant devices

12

Page 13: Taking the fire drill out of making firewall changes

Approval

• Risk analysis

• Compliance analysis

• Legal analysis

• Serial vs. Parallel

• Escalation

• Documentation!

13

Page 14: Taking the fire drill out of making firewall changes

Implementation/Design

• Create new vs. edit existing

• Reusing objects

• Testing the new rule

• Pushing the new rule

14

Page 15: Taking the fire drill out of making firewall changes

Execution/Verification

• Verify correct execution

• Notify requestor

• Request/Change reconciliation

15

Page 16: Taking the fire drill out of making firewall changes

Tips to Take

the Fire Drill out of

Firewall Changes!

Page 17: Taking the fire drill out of making firewall changes

“It is especially critical for people to

document the rules they add or change

so that other administrators know the

purpose of each rule and who to contact

about them. Good documentation can

make troubleshooting easy and reduces

the risk of service disruptions that can be

caused when an administrator deletes or

changes a rule they do not understand.”

- Todd, InfoSec Architect, United States

17

Tip 1: Document, Document, Document

Page 18: Taking the fire drill out of making firewall changes

“Perform reconciliation between change requests and actual performed changes – looking at the unaccounted changes will always surprise you. Ensuring every change is accounted for will greatly simplify your next audit and help in day-to-day troubleshooting.”

- Ron, Manager, Australia

18

Tip 2: Ensure Accountability

Page 19: Taking the fire drill out of making firewall changes

19

Tip 3: Ensure an Application-Centric View

• Provide centralized visibility of

application connectivity needs

• Understand the impact of application

changes on the network and vice-versa

• Understand firewall rule and

application interdependency to safely

decommission applications

Page 20: Taking the fire drill out of making firewall changes

Your Security Change Management Solution Must:

1. Be firewall-aware

2. Support all firewalls and routers in your network

3. Be topology-aware

4. Integrate with your existing CMS

5. Provide application-level visibility and change impact analysis

6. Easily customize to your business processes

20

Look for these Key Capabilities

Page 21: Taking the fire drill out of making firewall changes

Security Change Automation

with the

AlgoSec Security

Management Suite

Page 22: Taking the fire drill out of making firewall changes

Security Infrastructure

Business Applications

Managing Security at the Speed of Business

22

Application Owners Security Network Operations

Faster Security Provisioning for Business Applications

Align Teams for Improved Agility and Accountability

ROI in less than 1 Year!

Gain Total Visibility and Control of your Security Policy

AlgoSec Security Management Suite

Page 23: Taking the fire drill out of making firewall changes

Security Infrastructure

Business Applications

The AlgoSec Suite - BusinessFlow

23

Application Owners Security Network Operations

AlgoSec Security Management Suite

BusinessFlow

Application-Centric Policy Management

• Easily provision connectivity for business applications

• Improve visibility and application availability

• Securely decommission applications

• Translate business requirements to underlying policy

Page 24: Taking the fire drill out of making firewall changes

Business Applications

Security Infrastructure

The AlgoSec Suite – Firewall Analyzer

24

Application Owners Security Network Operations

AlgoSec Security Management Suite

BusinessFlow Firewall Analyzer

Security Policy Analysis

• Automate and streamline firewall operations

• Ensure a secure and optimized policy

• Conduct audits in hours instead of weeks

Page 25: Taking the fire drill out of making firewall changes

Business Applications

Security Infrastructure

The AlgoSec Suite – FireFlow

25

Application Owners

AlgoSec Security Management Suite

BusinessFlow FireFlow Firewall Analyzer

Security Policy Change Automation

• Process changes 2x-4x faster

• Improve accuracy and accountability

• Ensure continuous compliance and security

Security Network Operations

Page 26: Taking the fire drill out of making firewall changes

Business Impact

26

Annual Savings

Reduction in Auditing Expenses $192,000

Reduction in Change Request Processing Time $180,000

Reduction in Troubleshooting Resolution Time $90,000

Extended Lifespan of Hardware $47,500

Total Annual Savings $509,500

3 Year Savings $1,528,500

Sample Organization

• 50 Network Firewalls

• Loaded IT cost - $60/hour

• 2 changes per firewall per month

Generate your own ROI report at AlgoSec.com/ROI

Page 27: Taking the fire drill out of making firewall changes

A Real Life,

Automated, Firewall

Change Workflow

Page 28: Taking the fire drill out of making firewall changes

Q&A and Next Steps

Download the Security Change Management ebook @ www.algosec.com/securitychanges_ebook

Calculate your potential ROI @ www.algosec.com/ROI

Evaluate the AlgoSec Security Management Suite @ www.algosec.com/eval

28