workstation security ted wallerstedt, cisa, cia principal information systems auditor university of...

10
Workstation Security Ted Wallerstedt, CISA, CIA Principal Information Systems Auditor University of Minnesota

Upload: myles-davidson

Post on 02-Jan-2016

219 views

Category:

Documents


1 download

TRANSCRIPT

Workstation Security

Ted Wallerstedt, CISA, CIAPrincipal Information Systems

AuditorUniversity of Minnesota

Workstation Basics

• Input

• Processing

• Output

• Storage

SECURING INPUT• Don’t leave you PC unsecured

• Don’t accept non trusted disks

• Don’t let people shoulder surf

• Don’t leave a mic and camera attached

• Don’t leave you PC unsecured

SECURING PROCESSING

• Physical Security

• Antivirus

• Don’t run as Admin

SECURING OUTPUT

SECURING STORAGE• Secure passwords• Encryption• Don’t store sensitive data• Secure deletion• Secure removable storage

What’s missing?

NETWORK INTERFACE

SECURING THE NETWORK INTERFACE

• University Policies

• Quick Start

• Group Policies

SUMMARY• Maintain Physical Security

• Use Quickstart Basic and Level-2

• Use current Antivirus

• Run as a standard user

• Stop shoulder surfing

• Don’t open non trusted files/disks

• Secure your output

• Encrypt sensitive data