n ui ux design - new york state office of information ... · n n ui|ux design strategy pac dev ops...

16
UI | UX DESIGN n Privileged Access Control & Security Strategy 1 n Security Program

Upload: others

Post on 28-Jan-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: n UI UX DESIGN - New York State Office of Information ... · n n UI|UX DESIGN Strategy PAC Dev OPS Automation 2. n Security strategy with Novacoast Regulations, Standards, Policy,

UI|UX DESIGNn

Privileged Access Control

& Security Strategy

1

nSecurity Program

Page 2: n UI UX DESIGN - New York State Office of Information ... · n n UI|UX DESIGN Strategy PAC Dev OPS Automation 2. n Security strategy with Novacoast Regulations, Standards, Policy,

UI|UX DESIGNnn

Strategy PAC Dev OPS Automation

2

Page 3: n UI UX DESIGN - New York State Office of Information ... · n n UI|UX DESIGN Strategy PAC Dev OPS Automation 2. n Security strategy with Novacoast Regulations, Standards, Policy,

n

Security strategy with Novacoast

Regulations, Standards, Policy, Measurement

What are the typical issues?

What are compliance, standards, and regulations?

3

Novacoast Security

Page 4: n UI UX DESIGN - New York State Office of Information ... · n n UI|UX DESIGN Strategy PAC Dev OPS Automation 2. n Security strategy with Novacoast Regulations, Standards, Policy,

n

Tailored security services

Complete solution and coverage

Agile approach focused on specific needs

4

What we do

Page 5: n UI UX DESIGN - New York State Office of Information ... · n n UI|UX DESIGN Strategy PAC Dev OPS Automation 2. n Security strategy with Novacoast Regulations, Standards, Policy,

n

Regulations

Standards

Policy

Measurement

5

Security Strategyn

Page 6: n UI UX DESIGN - New York State Office of Information ... · n n UI|UX DESIGN Strategy PAC Dev OPS Automation 2. n Security strategy with Novacoast Regulations, Standards, Policy,

UI|UX DESIGNnOverview

6

n

Page 7: n UI UX DESIGN - New York State Office of Information ... · n n UI|UX DESIGN Strategy PAC Dev OPS Automation 2. n Security strategy with Novacoast Regulations, Standards, Policy,

n

PAC

7

Currently root access not controlled

Changes are not tracked

Limited Automation

Recording reviews is spot checked at best

Manual intervention is required for tickets

Page 8: n UI UX DESIGN - New York State Office of Information ... · n n UI|UX DESIGN Strategy PAC Dev OPS Automation 2. n Security strategy with Novacoast Regulations, Standards, Policy,

n

PAC

8

How do you gain control

Version control systems?

What about the data?

Change control?

no more root access?

Page 9: n UI UX DESIGN - New York State Office of Information ... · n n UI|UX DESIGN Strategy PAC Dev OPS Automation 2. n Security strategy with Novacoast Regulations, Standards, Policy,

n

PAC

9

Automation can provide access

Track full changes not just access

all commands can be audited

build complete visibility

!

Page 10: n UI UX DESIGN - New York State Office of Information ... · n n UI|UX DESIGN Strategy PAC Dev OPS Automation 2. n Security strategy with Novacoast Regulations, Standards, Policy,

n

Dev OPS

10

What

Why

How

Page 11: n UI UX DESIGN - New York State Office of Information ... · n n UI|UX DESIGN Strategy PAC Dev OPS Automation 2. n Security strategy with Novacoast Regulations, Standards, Policy,

n

Dev OPS

11

Automation should be built on DevOps

Tools exist to provide control

Must be used with lockdown tools

Deploy new systems instead of patches

Do no make local changes

Page 12: n UI UX DESIGN - New York State Office of Information ... · n n UI|UX DESIGN Strategy PAC Dev OPS Automation 2. n Security strategy with Novacoast Regulations, Standards, Policy,

UI|UX DESIGNn

Reporting

12

n

Page 13: n UI UX DESIGN - New York State Office of Information ... · n n UI|UX DESIGN Strategy PAC Dev OPS Automation 2. n Security strategy with Novacoast Regulations, Standards, Policy,

UI|UX DESIGNn

Trends & Considerations

13

n

Page 14: n UI UX DESIGN - New York State Office of Information ... · n n UI|UX DESIGN Strategy PAC Dev OPS Automation 2. n Security strategy with Novacoast Regulations, Standards, Policy,

n

OpenVswitch

Docker (LXC) OpenStack Vagrant and Chef

Trending

14

Page 15: n UI UX DESIGN - New York State Office of Information ... · n n UI|UX DESIGN Strategy PAC Dev OPS Automation 2. n Security strategy with Novacoast Regulations, Standards, Policy,

n 15

Finding the Point

What is next?

Page 16: n UI UX DESIGN - New York State Office of Information ... · n n UI|UX DESIGN Strategy PAC Dev OPS Automation 2. n Security strategy with Novacoast Regulations, Standards, Policy,

UI|UX DESIGNnn

16

Q &A