110 likes | 123 Views
A comprehensive overview of El Camino College's journey in improving cyber security measures and their plans for the future, including relevant trends and defenses.
E N D
Where we started – may, 2016 • Aging eol firewall/vpn • Aging eol switches • Aging eol server & workstation o.s. versions • Aging and underperforming email gateway • No dedicated security person • No spf/dmarc/dkimimplementation • No waf • No dns protection • No internal security procedures
Where we started – may, 2016 • No formal employee cyber security training program • No endpoint malware protection • No security website or newsletter • No penetration testing • No vulnerability testing • Out of date motd & web privacy statement • Only one administrative policy (out of date) • No firm understanding of cyber insurance coverage • No focus on ferpa/pci/ca compliance
Where we are now - 2019 • Hired CISO per plan-net • New Cisco 9000 firewall w/ vpn • New switches – more being replaced • Servers upgraded to newer os • Workstations being upgraded to win10 • Upgraded to barracuda 600 & cloud • spf/dmarc/dkim implementation • Cisco internal waf • Cisco umbrella dns • internal procedures for spam/phishing mitigation, ransomware, & formal breach response plan
Where we are now - 2019 • KnowB4 phishing simulator & training • Malwarebytes & Cisco amp endpoints • Cyber security website & monthly newsletter • penetration testing performed • vulnerability testing via tenable/nessus • New motd& web privacy statement • 12 new administrative policies & 2 new board policies • Complete understanding of cyber insurance coverage documented in breach-response plan • focus on ferpa/pci/gdpr compliance
Where we are now - 2019 • Splunk (log aggregation) • Re-wrote info security section in new technology master plan • Created 5 year cybersecurity strategic plan • Involvement in fbi-infragard, isaca, issa • FBI infragard daily intel briefings to ecc-pd • DHS cybersecurity intel briefings to its • Involvement in technology committee & aims committee • Representation at chancellor’s office events • Represented el camino at the 2018 mcafee cybersecurity leadership & innovation awards • Represented el camino at the 2019 cio ones to watch awards
Where we need to be – 2020 & beyond • New policies approved by board • Implement 2FA (at least its) • Another pen test • Threat-hunting s/w (Reveal-X) • Checkpoint sandblast now appliance • Address scada vulnerabilities • HP printer security • Look at logz.io (elk stack) • Finalize & implement br/dr plan • Look at spirion • Completion of data governance project (Vladimir)
Current trending threats • Cryptojacking (cryptomining) • File-less malware (powerghost) • Software Subversion – malware in opensource s/w • Attacks to cryptocurrency eco-system • Large-scale DNS attacks • Q1 2019 has seen a 967% increase so far on 100gbps+ attacks!!!
Current trending defenses • Threat emulation s/w (verodin, attackIQ, darklight, etc.) • IAM moving to the cloud • Authentication through mobile devices will explode (2FA) • The public will look beyond compliance for real trust • FedEx (notPetya) & Equifax (data breach)
Questions???https://www.elcamino.edu/about/depts/its/techservices/infosec.aspxQuestions???https://www.elcamino.edu/about/depts/its/techservices/infosec.aspx