<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Binding Operational Directive 18-01: Enhance Email and Web Security in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Binding-Operational-Directive-18-01-Enhance-Email-and-Web/m-p/2041#M207</link>
    <description>&lt;P&gt;Correct recently all company are changing AES2 encryption for SSL/TLS offloading.&lt;/P&gt;&lt;P&gt;Narrow down&amp;nbsp; such e-mail security we may have industry best practices.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Harden SMTP gateway based on vulnerability assessment on top of it.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Time to time we should have phishing drill from Cyber team as a awareness initiative because series of ransomeware spread out across the globe.&lt;/LI&gt;&lt;LI&gt;enabled selinux who are still using sendmail or postscript.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thanks for highlighting this issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 29 Oct 2017 16:29:29 GMT</pubDate>
    <dc:creator>paul200310</dc:creator>
    <dc:date>2017-10-29T16:29:29Z</dc:date>
    <item>
      <title>Binding Operational Directive 18-01: Enhance Email and Web Security</title>
      <link>https://community.isc2.org/t5/Industry-News/Binding-Operational-Directive-18-01-Enhance-Email-and-Web/m-p/2012#M204</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Department of Homeland Security (DHS) published&amp;nbsp;&lt;STRONG&gt;&lt;A title="Enhance Email and Web Security" href="https://cyber.dhs.gov/assets/report/bod-18-01.pdf" target="_blank"&gt;Binding Operational Directive 18-01&lt;/A&gt;, &lt;EM&gt;Enhance Email and Web Security&lt;/EM&gt;&lt;/STRONG&gt;.&amp;nbsp; BOD-18-01 focuses on several elements including:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a.&amp;nbsp; Enhance Email Security&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Use of STARTTLS on internet-facing mail servers,&lt;/LI&gt;&lt;LI&gt;All second-level domains using SPF with a DMARC policy of "none" (initial 90 days),&lt;/LI&gt;&lt;LI&gt;Disable use of SSLv2 and SSLv3 on mail servers,&lt;/LI&gt;&lt;LI&gt;Disable use of RC4 and 3DES ciphers on mail servers.&lt;/LI&gt;&lt;LI&gt;Set a DMARC policy of "reject" (within 1 year)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;b.&amp;nbsp; Enhance Web Security&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;All public-facing websites must use Always-On HTTPS with HSTS&lt;/LI&gt;&lt;LI&gt;Disable use of SSLv2 and SSLv3 on web servers&lt;/LI&gt;&lt;LI&gt;Disable use of RC4 and 3DES cipheres on web servers&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The above is a summary of the memo and resources available at &lt;A href="https://cyber.dhs.gov/" target="_blank"&gt;https://cyber.dhs.gov&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question for the community is:&amp;nbsp; Does your organization leverage federal government requirements, beyond NIST guidance, to establish your policies and implementation guidance for cybersecurity and risk management?&amp;nbsp; &amp;nbsp;For example, minus the reporting requirements, the bullet list of email and web security parameters could be replicated for a company.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2017 16:03:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Binding-Operational-Directive-18-01-Enhance-Email-and-Web/m-p/2012#M204</guid>
      <dc:creator>djharrity</dc:creator>
      <dc:date>2017-10-29T16:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: Binding Operational Directive 18-01: Enhance Email and Web Security</title>
      <link>https://community.isc2.org/t5/Industry-News/Binding-Operational-Directive-18-01-Enhance-Email-and-Web/m-p/2041#M207</link>
      <description>&lt;P&gt;Correct recently all company are changing AES2 encryption for SSL/TLS offloading.&lt;/P&gt;&lt;P&gt;Narrow down&amp;nbsp; such e-mail security we may have industry best practices.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Harden SMTP gateway based on vulnerability assessment on top of it.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Time to time we should have phishing drill from Cyber team as a awareness initiative because series of ransomeware spread out across the globe.&lt;/LI&gt;&lt;LI&gt;enabled selinux who are still using sendmail or postscript.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thanks for highlighting this issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2017 16:29:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Binding-Operational-Directive-18-01-Enhance-Email-and-Web/m-p/2041#M207</guid>
      <dc:creator>paul200310</dc:creator>
      <dc:date>2017-10-29T16:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Binding Operational Directive 18-01: Enhance Email and Web Security</title>
      <link>https://community.isc2.org/t5/Industry-News/Binding-Operational-Directive-18-01-Enhance-Email-and-Web/m-p/2070#M211</link>
      <description>This really depends on the regulation or guidance to be adopted and/or the business benefit of it.&lt;BR /&gt;I know that some of the enterprises out there do adopt some federal regulations, majority however do it from a business perspective (bidding on contracts) rather than actual security concerns.</description>
      <pubDate>Sun, 29 Oct 2017 17:01:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Binding-Operational-Directive-18-01-Enhance-Email-and-Web/m-p/2070#M211</guid>
      <dc:creator>IliaTiv</dc:creator>
      <dc:date>2017-10-29T17:01:54Z</dc:date>
    </item>
  </channel>
</rss>

