SlideShare ist ein Scribd-Unternehmen logo
1 von 33
Downloaden Sie, um offline zu lesen
Outsourcing SEPM
   Tony Asher
Agenda
• Goal: Successfully manage endpoint security for
  outsourced clients, while minimizing time and resources.

• Requirements / Challenges

• Solutions
   – 3 Unique ‘features’ we leveraged.

• Issues
Requirements
1. Single point of:
      •   Management
      •   Visibility
      •   Alerts
      •   Reporting


2.
2 Neutral from client environments

3. Automatic ticket generation
3 A t    ti ti k t        ti
Challenges – 1) Independent secure
network, allow client communication
Challenges – 1) Independent secure
network, allow client communication
Challenges – 2) Updates to enclave
without Internet connection
Challenges – 2) Updates to enclave
without Internet connection
Challenges – 3) Clients ability 'go-away'
Challenges – 4) Ticket generation
Steps Towards Solutions
Solutions – 1) Replication
• Choices: Site Replication vs. GUPs
   – GUPs: Can’t manage independent client
     admins, won’t centrally collect logs, open
     ports.
   – Domains vs Groups
              vs.
Replication Process
Replication Process (cont.)
Replication Process (cont.)
Steps:
1. Verify ‘Additional Site’ in SEPM

2. Edit Properties of Replication

3. Replicate Now

4. Check Log

5. Setup ‘Limited Admin’
       p
Edit Replication Properties
Issues:
1.
1 SEPM = Same Version
         S    V i

2. Shut down replication during
   upgrade
    pg

3. Remember to turn back on

4.
4 Easily ‘Deleted’
          Deleted
Solutions – 2) Live Update Server
• C
  Challenge:
   – Couldn't communicate with Internet.



• Solution:
    – Live Update Server on Tier 3 with
      Internet connectivity
    – Pushes out to 'Distribution share'
      on a server within the Secure
      Enclave (use for 4th box!).
LUA = Def Pusher
Live Update Server
Live Update Server (cont.)
Live Update Server (cont.)
Live Update Server (cont.)
LUA Issues

1. Postgres.exe 100%

2. Troubleshooting def’s (3-4
2 T bl h ti d f’ (3 4
   spots)

3. Patch s
3 Patch’s more difficult

4. 12/31 disaster

5. No ‘delta’ benefit
Solutions – 3) Ticket Automation
• Challenge:
   – No ‘flip switch’ options to escalate alerts.
   – L
     Laughed at for not having SEM/SIM solution.
           h d tf       th i                 l ti
• Solution:
   – Syslog server
   – Remedy server reads Syslog
Steps:
1. Configure ‘External Logging’

2. Point to Syslog server IP/port
    o t Sys og se e         /po t

3. SLOWLY turn on Log Filters

4.
4 Request tickets be pulled

5. Verified ticket generation

6. Solid Security Incident Response
   Process in place.
External Logging - Config
External Logging   Ticket
Other Issues
 •   Firewall Change Requests = > 80% of time

 •   Client P k
     Cli t Packages sometimes h ld ‘
                         ti     held ‘master’ SEPM
                                          t ’
     in Sylink.xml file.
      • Opened ticket – Due to TS installation.

 •   Use CD Package with custom Sylink
Sylink Issue
Sylink Issue
Resources: Exclusion Process
Resources: Exclusion Form

Weitere ähnliche Inhalte

Andere mochten auch

如何提升产品体验与设计品质,兼谈价值体现与个人成长
如何提升产品体验与设计品质,兼谈价值体现与个人成长 如何提升产品体验与设计品质,兼谈价值体现与个人成长
如何提升产品体验与设计品质,兼谈价值体现与个人成长
Lavi
 
English astronomie21
English astronomie21English astronomie21
English astronomie21
filipj2000
 
Chapter 1 market & marketing
Chapter 1 market & marketingChapter 1 market & marketing
Chapter 1 market & marketing
Ho Cao Viet
 
Data-driven modeling: Lecture 01
Data-driven modeling: Lecture 01Data-driven modeling: Lecture 01
Data-driven modeling: Lecture 01
jakehofman
 
Ubuntu žaliems
Ubuntu žaliemsUbuntu žaliems
Ubuntu žaliems
sirexas
 
Perpres12 1961 tugas belajar
Perpres12 1961 tugas belajarPerpres12 1961 tugas belajar
Perpres12 1961 tugas belajar
Rubby Anzela
 
Aiguilledu midiengelseversie
Aiguilledu midiengelseversieAiguilledu midiengelseversie
Aiguilledu midiengelseversie
filipj2000
 
Abctest
AbctestAbctest
Abctest
rupamb
 
Fascinating....... mother russia
Fascinating....... mother russiaFascinating....... mother russia
Fascinating....... mother russia
filipj2000
 
賽後心得分享
賽後心得分享賽後心得分享
賽後心得分享
jenyjeny
 
Proceeding aciar beefcattle_ias team_jan_2014
Proceeding aciar beefcattle_ias team_jan_2014Proceeding aciar beefcattle_ias team_jan_2014
Proceeding aciar beefcattle_ias team_jan_2014
Ho Cao Viet
 

Andere mochten auch (20)

Learning from Web Activity
Learning from Web ActivityLearning from Web Activity
Learning from Web Activity
 
如何提升产品体验与设计品质,兼谈价值体现与个人成长
如何提升产品体验与设计品质,兼谈价值体现与个人成长 如何提升产品体验与设计品质,兼谈价值体现与个人成长
如何提升产品体验与设计品质,兼谈价值体现与个人成长
 
11강 기업교육론 20110518
11강 기업교육론 2011051811강 기업교육론 20110518
11강 기업교육론 20110518
 
Market research process
Market research processMarket research process
Market research process
 
English astronomie21
English astronomie21English astronomie21
English astronomie21
 
Chapter 1 market & marketing
Chapter 1 market & marketingChapter 1 market & marketing
Chapter 1 market & marketing
 
Data-driven modeling: Lecture 01
Data-driven modeling: Lecture 01Data-driven modeling: Lecture 01
Data-driven modeling: Lecture 01
 
Death
DeathDeath
Death
 
Ubuntu žaliems
Ubuntu žaliemsUbuntu žaliems
Ubuntu žaliems
 
Introduction to Steens Furniture
Introduction to Steens FurnitureIntroduction to Steens Furniture
Introduction to Steens Furniture
 
Perpres12 1961 tugas belajar
Perpres12 1961 tugas belajarPerpres12 1961 tugas belajar
Perpres12 1961 tugas belajar
 
Aiguilledu midiengelseversie
Aiguilledu midiengelseversieAiguilledu midiengelseversie
Aiguilledu midiengelseversie
 
1강 기업교육론 20110302
1강 기업교육론 201103021강 기업교육론 20110302
1강 기업교육론 20110302
 
Abctest
AbctestAbctest
Abctest
 
Gen Y and Connected Consumers – A Study of their Opinion Management in Social...
Gen Y and Connected Consumers – A Study of their Opinion Management in Social...Gen Y and Connected Consumers – A Study of their Opinion Management in Social...
Gen Y and Connected Consumers – A Study of their Opinion Management in Social...
 
Fascinating....... mother russia
Fascinating....... mother russiaFascinating....... mother russia
Fascinating....... mother russia
 
CFA presentation
CFA presentationCFA presentation
CFA presentation
 
賽後心得分享
賽後心得分享賽後心得分享
賽後心得分享
 
A New Wave of Tobacco Products, April 2011 Update
A New Wave of Tobacco Products, April 2011 UpdateA New Wave of Tobacco Products, April 2011 Update
A New Wave of Tobacco Products, April 2011 Update
 
Proceeding aciar beefcattle_ias team_jan_2014
Proceeding aciar beefcattle_ias team_jan_2014Proceeding aciar beefcattle_ias team_jan_2014
Proceeding aciar beefcattle_ias team_jan_2014
 

Ähnlich wie SEPM Outsourcing

ISACA Scholarship Competition.pptx
ISACA Scholarship Competition.pptxISACA Scholarship Competition.pptx
ISACA Scholarship Competition.pptx
Junho Lee
 
Case Study of the Unexplained
Case Study of the UnexplainedCase Study of the Unexplained
Case Study of the Unexplained
shannomc
 

Ähnlich wie SEPM Outsourcing (20)

ISACA Scholarship Competition.pptx
ISACA Scholarship Competition.pptxISACA Scholarship Competition.pptx
ISACA Scholarship Competition.pptx
 
Free OpManager training Part 4 - Fault Management and IT automation
Free OpManager training Part 4 - Fault Management and IT automationFree OpManager training Part 4 - Fault Management and IT automation
Free OpManager training Part 4 - Fault Management and IT automation
 
Free OpManager training Part 4 - Monitoring Network Performance and Network Maps
Free OpManager training Part 4 - Monitoring Network Performance and Network MapsFree OpManager training Part 4 - Monitoring Network Performance and Network Maps
Free OpManager training Part 4 - Monitoring Network Performance and Network Maps
 
JavaOne 2010: Top 10 Causes for Java Issues in Production and What to Do When...
JavaOne 2010: Top 10 Causes for Java Issues in Production and What to Do When...JavaOne 2010: Top 10 Causes for Java Issues in Production and What to Do When...
JavaOne 2010: Top 10 Causes for Java Issues in Production and What to Do When...
 
SNMP Demystified Part-II
SNMP Demystified Part-IISNMP Demystified Part-II
SNMP Demystified Part-II
 
engage 2015 - IBM Notes Traveler Daily Business
engage 2015 - IBM Notes Traveler Daily Businessengage 2015 - IBM Notes Traveler Daily Business
engage 2015 - IBM Notes Traveler Daily Business
 
IBM Think 2018 - IBM Connections Troubleshooting
IBM Think 2018 -  IBM Connections TroubleshootingIBM Think 2018 -  IBM Connections Troubleshooting
IBM Think 2018 - IBM Connections Troubleshooting
 
Valgrind tutorial
Valgrind tutorialValgrind tutorial
Valgrind tutorial
 
Case Study of the Unexplained
Case Study of the UnexplainedCase Study of the Unexplained
Case Study of the Unexplained
 
CIRCUIT 2015 - Monitoring AEM
CIRCUIT 2015 - Monitoring AEMCIRCUIT 2015 - Monitoring AEM
CIRCUIT 2015 - Monitoring AEM
 
[Season - 3 OpManager Training] Monitoring Network Performance
[Season - 3 OpManager Training] Monitoring Network Performance [Season - 3 OpManager Training] Monitoring Network Performance
[Season - 3 OpManager Training] Monitoring Network Performance
 
BSides MCR 2016: From CSV to CMD to qwerty
BSides MCR 2016: From CSV to CMD to qwertyBSides MCR 2016: From CSV to CMD to qwerty
BSides MCR 2016: From CSV to CMD to qwerty
 
Common Pitfalls of Functional Programming and How to Avoid Them: A Mobile Gam...
Common Pitfalls of Functional Programming and How to Avoid Them: A Mobile Gam...Common Pitfalls of Functional Programming and How to Avoid Them: A Mobile Gam...
Common Pitfalls of Functional Programming and How to Avoid Them: A Mobile Gam...
 
Ch5 process synchronization
Ch5   process synchronizationCh5   process synchronization
Ch5 process synchronization
 
What the Heck Just Happened?
What the Heck Just Happened?What the Heck Just Happened?
What the Heck Just Happened?
 
DEVNET-1164 Using OpenDaylight for Notification Driven Workflows
DEVNET-1164	Using OpenDaylight for Notification Driven WorkflowsDEVNET-1164	Using OpenDaylight for Notification Driven Workflows
DEVNET-1164 Using OpenDaylight for Notification Driven Workflows
 
How to improve your Tizen native program
How to improve your Tizen native programHow to improve your Tizen native program
How to improve your Tizen native program
 
ISBG 2015 - Challenge accepted: IBM Cloud onboarding & Upgrades to IBM Notes ...
ISBG 2015 - Challenge accepted: IBM Cloud onboarding & Upgrades to IBM Notes ...ISBG 2015 - Challenge accepted: IBM Cloud onboarding & Upgrades to IBM Notes ...
ISBG 2015 - Challenge accepted: IBM Cloud onboarding & Upgrades to IBM Notes ...
 
Green Code Lab Challenge 2015 Subject Details
Green Code Lab Challenge 2015 Subject DetailsGreen Code Lab Challenge 2015 Subject Details
Green Code Lab Challenge 2015 Subject Details
 
Silicon Valley Code Camp 2015 - Advanced MongoDB - The Sequel
Silicon Valley Code Camp 2015 - Advanced MongoDB - The SequelSilicon Valley Code Camp 2015 - Advanced MongoDB - The Sequel
Silicon Valley Code Camp 2015 - Advanced MongoDB - The Sequel
 

Kürzlich hochgeladen

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Kürzlich hochgeladen (20)

Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontology
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptx
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​Elevate Developer Efficiency & build GenAI Application with Amazon Q​
Elevate Developer Efficiency & build GenAI Application with Amazon Q​
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 

SEPM Outsourcing