VeriSign White Paper Sample
Checklist of Practices and Technologies
To recap, the following quick checklist of practices and technologies can be incorporated into your business-centric security strategy:
- Secure communications with SSL- Data in motion does not have the advantage of the access controls in place with data at rest; encryption provides added protection against a number of threats
- Use digital certificates to authenticate devices from servers to mobile devices- Rather than assume we can trust the device to which we are about the send confidential data, verify the device's identity first
- Protect against malicious content with anti-malware and content filtering on the network and on endpoint devices
-
- Use network security controls such as firewalls, IPSs, and network access controls
- Develop a patch management plan to ensure OSs and critical applications, such as databases, are patched against security vulnerabilities
- Monitor network and host activity- The volume of log data from devices can be substantial; data collection and reporting tools can help
-
- Train end users by focusing on delivering information from a business-centric, not a technical, perspective
- Think in terms of defense in depth and use multiple security controls to protect against a single threat- Fortunately many security controls protect against multiple threats as well