nagios conference 2012 - jared bird - providing value throughout the organization

22
Jared Bird [email protected] Twitter: @jaredbird Nagios: Providing Value Throughout the Organization

Upload: nagios

Post on 25-May-2015

1.168 views

Category:

Technology


2 download

DESCRIPTION

Jared Bird's presentation on providing value with Nagios. The presentation was given during the Nagios World Conference North America held Sept 25-28th, 2012 in Saint Paul, MN. For more information on the conference (including photos and videos), visit: http://go.nagios.com/nwcna

TRANSCRIPT

Page 1: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

Jared [email protected]: @jaredbird

Nagios:Providing Value Throughout the

Organization

Page 2: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

Introduction

Who is Jared Bird?

Page 3: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

Nagios

Page 4: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

Providing Value

Provide knowledgeAssist other departmentsStrengthen inter-

department relationshipsAchieve company wide

goalsReduce costs

Page 5: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

Understanding

What are the goals of the other departments?

Page 6: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

Infrastructure

Network, Server, and Desktop Teams

Concerns include: Availability Capacity Utilization Functioning Properly

Page 7: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

Security

Prevent data theftDeter identity theftAvoid legal issuesProtect brand“CIA Triad”

Confidentiality Integrity Availability

Page 8: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

Threats

Default configurationsWebsite defacementMissing patchesDNS redirectionUnauthorized useMany, many more

Page 9: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization
Page 10: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

Default Configurations

Default passwordsblank sa account

Once password is set, monitor with new credentials

XI Auto-discovery check for insecure protocols

Scheduled scans and output to Nagios

Page 11: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

Website

Monitor for defacement check_http –H

www.yoursite.com –s “sekret” Checks for “sekret”

string

Check certificate check_http –H

www.mysite.com –C 21 Checks certificate for 21

days of validity

Page 12: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

Software Installed

Check url for content (version)Ex:

http://www.adobe.com/software/flash/about/ Check for string “11.4.102.265”

Page 13: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

DNS

Have DNS entries changed?

DNS hijackedHigh Impact

Page 14: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

Unauthorized Use

LDAP check for account creationSyslog output from infrastructureSNMP Alerts

Page 15: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

Audit & Compliance

PCISOXHIPPAAlmost every

regulation*

* Note: Speaker will not be held responsible if Nagios does not help achieve compliance with a specific regulation

Page 16: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

PCI

PCI DSSAny organization that

processes, stores, or transmits credit card data

Requirements 12 overall requirements 287 individual

requirements

Page 17: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

PCI

Reqs 1&2: Build and Maintain a Secure Network Auto-discovery to look for services Checks to verify that vendor defaults have been

changed

Reqs 3&4: Protect Cardholder Data Scan for insecure protocols Check for expiration of SSL certificates

Reqs 5&6: Maintain a Vulnerability Management Program Check the anti-virus process to ensure it is running

Page 18: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

PCI

Reqs 7,8,& 9: Implement Strong Access Control Measures LDAP checks to ensure LDAP server is functioning Web Transaction Monitoring can be used to check two factor

Reqs 10&11: Regularly Monitor and Test Networks Check NTP Event logs from servers

Req 12: Maintain an Information Security Program Use device listings as well as contact info (incident response

plan)

Page 19: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

SOX

Sarbanes-Oxley or Public Company Accounting Reform and Investors Protection Act

Section 404: Assessment of internal controlNagios can help management show that

controls for assuring the integrity of the financial reports are effective.

Page 20: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

HIPAA Headlines

Page 21: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

HIPAA

Technical Safeguards: Access Control Audit Control Integrity Controls Transmission Security

Page 22: Nagios Conference 2012 - Jared Bird - Providing Value Throughout the Organization

Questions?

Jared [email protected]: @jaredbird

Thank You