Skip to content
NGTEdu Logo

NGTEdu

A PRODUCT OF NGTECH.CO.IN

NGTEdu Logo

NGTEdu

  • Home
  • Cyber Attacks
  • Malware
  • Vulnerabilities
  • Data Breach
  • Home
  • Data Breach
  • Tripwire & FoxGuard: Patching for compliance and security
  • Critical Vulnerability
  • Data Breach

Tripwire & FoxGuard: Patching for compliance and security

4 years ago David Bruce
Tripwire & FoxGuard: Patching for compliance and security

There’s a saying in the cybersecurity community which states that just because you are compliant doesn’t mean that you are secure. Over the years, many images have been used to illustrate the point. One memorable image is that of a nude bicyclist wearing a helmet. By all standards, that is the epitome of “compliant, but not secure”. 

Many organizations have shifted the focus away from merely achieving compliance, to being both compliant and secure. Security is often more difficult to achieve than compliance, so the higher standard of security often fills in all the compliance details as well. This mindset is highlighted in organizations that are part of critical infrastructure, where adherence to very strict rules go far beyond compliance.

Electrical companies are tasked with the burden of providing uninterrupted power across the nation. In an effort to assist in this goal, the North American Electrical Reliability Corporation (NERC), was founded as an advisory body, making recommendations to increase the fidelity of the North American power grid. Over time, NERC took on a more regulatory role, creating the Critical Infrastructure Protection (CIP) standards, which govern the operation of electrical companies. One important aspect of the CIP standards is security.

When it comes to security, one of the most deceptively simple protective measures is to apply security patches to all the systems in the environment. Even in a small organization, this can be a challenge, as number of devices, coupled with the number of patches can quickly overwhelm even the most diligent security practitioner. When it comes to an electrical company, not only do the systems exceeds hundreds, or thousands of patchable components, but the patches themselves can be just as numerous—this creates millions of patch/server combinations that must be measured every month, all requiring specific audit justification to be documented.

Tripwire and FoxGuard Solutions

To add to the specificity of guaranteeing electrical reliability, all patches must be approved before being deployed in an electrical company. The requirement of constant up-time, coupled with the need for security sounds unmanageable, however, there are methods to simplify this process. One way that patching is made more manageable in electrical companies is through a patch control system, such as that offered by FoxGuard Solutions, which helps to validate and advise which patches are critical or confirmed to be necessary each month.

FoxGuard can process the inventory of an electrical organization to discover and prioritize the available patches for all of the assets. FoxGuard also has the ability to determine if a patch is known to cause problems and will remove it from the list.

Tripwire has partnered with FoxGuard to integrate their systems with the Tripwire State Analyzer (TSA) software released last year. TSA already helped to by showing the users what the operating state is of the servers in an environment. Leveraging FoxGuard’s data into TSA allows this process to become more efficient as the operational needs change over time for electrical operators and other industries.

When it comes to NERC, an audit baseline is the intended operational state of their servers. Auditors require an organization to not only to be compliant, but to prove that compliance and whenever it deviates against the baseline. Part of that proof includes showing that the operational state is also secure. It’s not just good enough to modify the configuration to make the server theoretically secure. An electrical organization must prove that it’s actually secure as it is operating by monitoring open ports, installed software, users, and other critical data points.

Another part of security as it works in tandem with compliance is through the ability to prove that the approved patches were actually installed. Without a tool such as TSA it can be a very tedious job to examine all that detail, and TSA helps make this process more efficient. TSA allows the users to quickly compare all of the installed software on thousands of machines against the defined baseline state to identify any deviations. The integration with FoxGuard further aids this time savings by taking the hundreds (or thousands) of monthly updates to the baseline and builds a workflow into TSA allowing for effortless updates to the Allowlist (which represents the baseline).

Future releases of TSA are planned, and integrations with other patch control systems are anticipated, making patch management more workable for all industries. This can help organizations fulfill compliance, while achieving new heights of security.

The post ” Tripwire & FoxGuard: Patching for compliance and security” appeared first on TripWire

Source:TripWire – David Bruce

Tags: Critical Severity, TripWire

Continue Reading

Previous FBI, Europol Seize RaidForums Hacker Forum and Arrest Admin
Next How to Use NIST’s Cybersecurity Framework to Protect against Integrity-Themed Threats

More Stories

  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery

17 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

CISA Orders Removal of Unsupported Edge Devices to Reduce Federal Network Risk

18 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities

20 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach

How Samsung Knox Helps Stop Your Network Security Breach

21 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware

23 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Data Breach
  • Vulnerabilities

Claude Opus 4.6 Finds 500+ High-Severity Flaws Across Major Open-Source Libraries

1 day ago [email protected] (The Hacker News)

Recent Posts

  • China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery
  • CISA Orders Removal of Unsupported Edge Devices to Reduce Federal Network Risk
  • Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities
  • How Samsung Knox Helps Stop Your Network Security Breach
  • Compromised dYdX npm and PyPI Packages Deliver Wallet Stealers and RAT Malware

Tags

Android APT Bug CERT Cloud Compliance Coronavirus COVID-19 Critical Severity Encryption Exploit Facebook Finance Google Google Chrome Goverment Hacker Hacker News High Severity Instagram iPhone Java Linux Low Severity Malware Medium Severity Microsoft Moderate Severity Mozzila Firefox Oracle Patch Tuesday Phishing Privacy QuickHeal Ransomware RAT Sim The Hacker News Threatpost TikTok TripWire VMWARE Vulnerability Whatsapp Zoom
Copyright © 2020 All rights reserved | NGTEdu.com
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More here.Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT