Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!

Securing PC Users, In Spite of Themselves

By Alan Ross
September 1, 2007
With risk more complicated and diverse, security measures for the enterprise network and its many devices become more important.


An increasingly mobile workforce, device proliferation, greater legal responsibilities and the rising value of corporate data assets all impact security for today’s enterprise client environment. Add to that the fact that more physical security systems, including video, are working through the enterprise network.

PC users can exacerbate the already challenging situation by intentionally or unintentionally disabling a security program or ignoring a recommended security patch download. As risk factors become more complicated and diverse, security measures for the enterprise network and its many devices become more important, and need to become capable, than ever before.

While the industry is at the earliest stages of moving to the next generation of client security, with more advanced security tools that are built in and readily available, fundamental measures remain the foundation.

Secure Configuration Management is essential for Intel, where security must support 34,000 desktops, more than 70,000 notebooks and more than 5,000 wireless access points.

DON’T FORGET SECURE CONFIGURATION MANAGEMENT

Chief security officers and their colleague chief information officers all too frequently discuss protecting the client environment in terms of attack prevention. But secure configuration management is equally, if not more, important to protecting corporate assets. While not a cure-all for PC security, secure configuration management is an integrated and pragmatic approach to protecting devices and the network despite user mischief and other factors. Intel’s IT group supports 34,000 desktops, more than 70,000 notebooks and more than 5,000 wireless access points. Secure configuration management is central to our internal security strategy.

How to proceed with secure configuration management depends on the company, the risks it faces, the desktop and mobile composition of the client fleet and the time and funds available. For a smaller company with limited IT resources, improving fundamentals such as system builds and asset tracking is a good start. Hardening clients before giving them to users and putting processes in place to monitor PCs and other devices throughout their lifecycle are key. Best practices for hardening builds are readily available in the public domain, while many security news groups offer freeware and shareware versions of threat and vulnerability management solutions. Check the accompanying chart for fundamental elements as well as some advanced features of the secure configuration management domain.

BUILDING AND PROVISIONING

Regardless of the environment, the building and provisioning of clients is the first element in the secure configuration management domain. It includes receiving and imaging the client with its operating system and applications, and giving the system its identity as it joins the active directory and repository. At this stage, the client initially ties into the identity and access management system, and other authentication and authorization services, registers its owner and hardware information with asset management and the audit trail for the device begins. The inventory tracking these elements will be completely automated in next generation clients. Proper build and provisioning ensure the client is as resistant as possible to attacks and that only authorized devices connect to the corporate network.

The next element in secure configuration management is threat and vulnerability management, which serves as an early warning system to publicly disclosed dangers. It informs IT professionals of emerging threats and enables them to assess how exposed the network and clients may be to a particular vulnerability. The pragmatic, holistic approach is to use this information to gauge the potential impact of a threat and determine how hard and fast to move. If, for example, threat and vulnerability management receives a warning regarding a particular operating system, the right person can be called in to assess the number of devices and people at risk and determine whether standard or emergency procedures are in order. Monitoring the threat and vulnerability landscape not only feeds into our vulnerability scanning and compliance monitoring capabilities, but combined with internal monitoring of different channels also enables us to create and enforce new security policies.

“DOWN THE WIRE” SCANNING

Vulnerability scanning follows in our secure configuration management process, which is a “down the wire” scanning capability that provides us with a macro view of the security posture of the network and its devices. While deeper scanning requires an agent or permission, our initial vulnerability scanning does not require discreet interaction with the client or the installation of permissions. It gives us a broad, preliminary look at all the devices and services on the network to see if any are vulnerable to known exploits. We can discover and monitor the whole environment, even with thousands of devices, switches, IP addresses, applications and operating systems on the network. Vulnerability scanning precedes compliance monitoring.

In compliance monitoring, the agent does have authority to scan on a deeper level to give us a detailed, per-device view of the environment. With certain threats, assessing them and taking appropriate action requires information, such as the particular application version or the date the software was created. Based on the results of the compliance monitoring utility, a client may be referred to remediation services that can make registry modifications and enable us to remotely modify the client when needed. Essentially, the compliance monitoring tool consumes the data from the threat and vulnerability management and vulnerability scans to do intense scanning. Where there are gaps between the two, remediation services brings the client up to date.

HOLISTIC UNDERSTANDING OF RISK

The goal is to gain a holistic understanding of risk exposure and to ensure that the security tools in place are both working and in use. As we move to the next generation of clients, automatic update capabilities will reduce the sometimes heroic efforts security and IT departments undertake just to stay current on threat protection. Automatic updates will not only eliminate the need for the user to accept a new security tool, but also will occur invisibly in the background, remotely and regardless of the system state. Automated compliance monitoring further assures that patches are applied when required, giving a higher degree of confidence in rapid compliance as the user no longer determines if and when it happens. It is a faster path to goal of 95 percent confidence, particularly around immediate or code red concerns.

In our secure configuration management domain two highly advanced elements give us added protection.

On-connect authentication is a utility that requires devices to prove their identity before becoming a part of the production network, which protects the production network from rogue devices.

On-connect enforcement ensures that the device is known and has the correct security updates and patches in place. If a device is deficient, it is referred to remediation services, which first correct and then connect the device to the production network. Both on-connect utilities are emerging capabilities that play an important role in the proactive protection of the network and its devices.

Throughout the secure configuration management domain there are a number of interactions and dependencies. Among these dependencies is the reliance of the on-connect authentication and on-connect enforcement utilities on the identity and access management for both authorization and policy data. Both vulnerability scanning and compliance monitoring also depend heavily on the information provided threat and vulnerability management system. On-connect enforcement relies on the processes of the on-connect authentication and compliance monitoring utilities to properly enforce its policies.

Finally, the system and security event management depends on all elements of the secure configuration management to properly collect, aggregate, correlate, report and archive the lifecycle of the network and devices, and the threats they encounter.

Regardless of the size and complexity of the network in question, we are all challenged to keep each PC, user and the network as a whole safe from a growing number of threats and vulnerabilities. This includes physical security systems now part of the IT infrastructure. The mobility of the workforce, legal responsibilities and the value of corporate data assets will undoubtedly continue to grow, and PC users will continue to make mistakes that are potentially dangerous to the network. At its most fundamental and advanced, secure configuration management is a key to addressing these challenges.

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Alan Ross is a principal engineer and lead enterprise security architect at Intel Corp. He has over 10 years of IT security experience in various arenas, from policy and training to engineering and architecture. He has 17 patents pending related to security and manageability.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Top Cybersecurity Leaders
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Columns
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    New Security Technology
    By: Charles Denyer
Subscribe For Free!
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

White post office truck

Department of Labor Sues USPS Over Texas Whistleblower Termination

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Person holding large ball of twine

Preventing Burnout in The Security Industry

Harrods

Harrods’ Cyberattack: Cybersecurity Leaders Weigh In

Coding

AI Emerges as the Top Concern for Security Leaders

2025 Security Benchmark banner

Events

September 29, 2025

Global Security Exchange (GSX)

 

November 17, 2025

SECURITY 500 Conference

This event is designed to provide security executives, government officials and leaders of industry with vital information on how to elevate their programs while allowing attendees to share their strategies and solutions with other security industry executives.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!