<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Internal Security Zones in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Internal-Security-Zones/m-p/14699#M454</link>
    <description>&lt;P&gt;I'm looking for&amp;nbsp;strategies to convince middle-management to invest in preventing lateral movement within our network,&amp;nbsp;starting within our data center(s) and IAAS providers, and eventually extending to our manufacturing and office facilities.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The&lt;SPAN&gt;&amp;nbsp;anecdotal stories&amp;nbsp; (&lt;A href="https://krebsonsecurity.com/2014/02/target-hackers-broke-in-via-hvac-company/comment-page-3/" target="_self"&gt;Target&lt;/A&gt;,&amp;nbsp;&lt;A href="https://www.wsj.com/articles/new-equifax-ciso-tightens-structure-post-breach-1521235788" target="_blank"&gt;Equifax&lt;/A&gt;, etc) resonate with the techies, but I am looking things that are a bit more management-ready.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;For example, best practice documents, comparative peer-surveys&lt;/SPAN&gt;&lt;SPAN&gt;, pending or existing legislative requirements, etc.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;My basic thought is to somehow demonstrate that&amp;nbsp;the ground has shifted such that isolated security zones are now the basic standard-of-care and must become a financial priority.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I could find something like the PCI and HIPPA requirements that applies to Manufacturing, I would be all set.&amp;nbsp; Alas, that&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Sep 2018 15:55:24 GMT</pubDate>
    <dc:creator>denbesten</dc:creator>
    <dc:date>2018-09-17T15:55:24Z</dc:date>
    <item>
      <title>Internal Security Zones</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Internal-Security-Zones/m-p/14699#M454</link>
      <description>&lt;P&gt;I'm looking for&amp;nbsp;strategies to convince middle-management to invest in preventing lateral movement within our network,&amp;nbsp;starting within our data center(s) and IAAS providers, and eventually extending to our manufacturing and office facilities.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The&lt;SPAN&gt;&amp;nbsp;anecdotal stories&amp;nbsp; (&lt;A href="https://krebsonsecurity.com/2014/02/target-hackers-broke-in-via-hvac-company/comment-page-3/" target="_self"&gt;Target&lt;/A&gt;,&amp;nbsp;&lt;A href="https://www.wsj.com/articles/new-equifax-ciso-tightens-structure-post-breach-1521235788" target="_blank"&gt;Equifax&lt;/A&gt;, etc) resonate with the techies, but I am looking things that are a bit more management-ready.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;For example, best practice documents, comparative peer-surveys&lt;/SPAN&gt;&lt;SPAN&gt;, pending or existing legislative requirements, etc.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;My basic thought is to somehow demonstrate that&amp;nbsp;the ground has shifted such that isolated security zones are now the basic standard-of-care and must become a financial priority.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I could find something like the PCI and HIPPA requirements that applies to Manufacturing, I would be all set.&amp;nbsp; Alas, that&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 15:55:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Internal-Security-Zones/m-p/14699#M454</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2018-09-17T15:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Security Zones</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Internal-Security-Zones/m-p/14713#M455</link>
      <description>&lt;P&gt;In my opinion, you cannot do better than &lt;A href="https://www.guardicore.com/workload-protection-hybrid-cloud/" target="_self"&gt;Guardicore&lt;/A&gt; for microsegmentation and common security policy enforcement across hybrid infrastructure.&lt;/P&gt;&lt;P&gt;You'll get the lateral threat protection and much more with their Centra product.&lt;/P&gt;&lt;P&gt;If you are strictly a Linux shop, &lt;A href="https://www.aporeto.com/" target="_self"&gt;Aporeto&lt;/A&gt; is another contender.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 00:46:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Internal-Security-Zones/m-p/14713#M455</guid>
      <dc:creator>vt100</dc:creator>
      <dc:date>2018-09-18T00:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Security Zones</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Internal-Security-Zones/m-p/14750#M457</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/311867713"&gt;@denbesten&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I'm looking for&amp;nbsp;strategies to convince middle-management to invest in preventing lateral movement within our network,&amp;nbsp;starting within our data center(s) and IAAS providers, and eventually extending to our manufacturing and office facilities.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Consider using physical world analogies as you tell your story. Ask if in the company's loading dock workers can wander into the HR and or Finance offices and rummage through the file drawers whenever they like. Ask if they have any work spaces for sensitive information that have locked doors or cabinets; if so, ask why.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Sep 2018 10:42:20 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Internal-Security-Zones/m-p/14750#M457</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2018-09-19T10:42:20Z</dc:date>
    </item>
  </channel>
</rss>

