Episode 63 — A.8.19–8.20 — Software installation on operational systems; Network security

Episode 63 — A.8.19–8.20 — Software installation on operational systems; Network security

A.8.19 restricts software installation on operational systems to prevent drift, reduce attack surface, and maintain license and support compliance. For the exam, distinguish between development/test flexibility and production control: in operational environments, only authorized, vetted software from approved repositories may be installed, with changes governed by documented requests, peer review, and rollback plans. Baselines should define permissible packages, versions, and configurations, enforced by configuration management or MDM. Evidence includes deployment manifests, signed artifacts, and change records tied to assets and owners. Common pitfalls are local admin rights that allow shadow installs, emergency fixes that bypass approval and remain, and unmanaged plugins or browser extensions that introduce risk. Strong practices quarantine or rebuild noncompliant systems, integrate SBOM tracking, and verify that installed software aligns with vulnerability management scopes and patch cadences so that coverage is real, not assumed.

A.8.20 addresses network security, requiring designs and controls that protect information in transit and manage exposure. Candidates should cover segmentation by trust level and function, least-privilege routing and firewall rules, use of secure protocols, and protective services like DNS security, email authentication, and web application firewalls where appropriate. Zero-trust patterns emphasize identity-aware access and continuous verification rather than implicit trust based on location. Monitoring complements prevention through flow logs, intrusion detection, and anomaly detection tuned to expected behaviors. Pitfalls include flat networks that enable lateral movement, legacy cleartext protocols, and complex rules without ownership or recertification. Effective implementations maintain rule life cycles with justification and expiry, test egress controls to prevent data exfiltration, and document provider-managed boundaries in cloud environments, including shared responsibility delineations. Candidates should be ready to explain how installation discipline reduces exploitable code paths while network security constrains blast radius, and how both depend on accurate inventories, change control, and continuous validation to satisfy auditors and real-world resilience goals. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(71)

Welcome to Framework - ISO 27001

Welcome to Framework - ISO 27001

Dive into a fast, no-fluff overview of what this podcast delivers, who it’s for, and how each episode helps you level up with practical, real-world takeaways. In this trailer, you’ll hear the show’s p...

14 Okt 20251min

Episode 70 — A.8.33–8.34 — Test information; Protecting systems during audit testing

Episode 70 — A.8.33–8.34 — Test information; Protecting systems during audit testing

A.8.33 governs test information—data and artifacts used to verify functionality and security—so that confidentiality, integrity, and legality are preserved. For the exam, distinguish data sources and ...

14 Okt 202513min

Episode 69 — A.8.31–8.32 — Separation of dev/test/prod; Change management

Episode 69 — A.8.31–8.32 — Separation of dev/test/prod; Change management

A.8.31 enforces separation between development, test, and production to prevent inadvertent changes, data leakage, and unauthorized access. For the exam, stress environment isolation, distinct identit...

14 Okt 202511min

Episode 68 — A.8.29–8.30 — Security testing in development & acceptance; Outsourced development

Episode 68 — A.8.29–8.30 — Security testing in development & acceptance; Outsourced development

A.8.29 requires structured security testing throughout development and acceptance, proving that controls operate as intended before release. For the exam, differentiate testing modalities and purposes...

14 Okt 202513min

Episode 67 — A.8.27–8.28 — Secure system architecture & engineering; Secure coding

Episode 67 — A.8.27–8.28 — Secure system architecture & engineering; Secure coding

A.8.27 focuses on secure system architecture and engineering, requiring designs that partition trust, minimize attack surface, and enforce least privilege at every layer. For the exam, emphasize archi...

14 Okt 202514min

Episode 66 — A.8.25–8.26 — Secure development lifecycle; Application security requirements

Episode 66 — A.8.25–8.26 — Secure development lifecycle; Application security requirements

A.8.25 requires a secure development lifecycle (SDLC) that embeds security from concept to retirement, not as a late-stage gate. For the exam, describe SDLC phases with explicit security tasks: threat...

14 Okt 202514min

Episode 65 — A.8.23–8.24 — Web filtering; Use of cryptography

Episode 65 — A.8.23–8.24 — Web filtering; Use of cryptography

A.8.23 establishes web filtering to manage risk from browsing and outbound HTTP/S traffic, acknowledging that the browser is a primary threat vector. For the exam, emphasize policy-aligned controls th...

14 Okt 202515min

Episode 64 — A.8.21–8.22 — Security of network services; Segregation of networks

Episode 64 — A.8.21–8.22 — Security of network services; Segregation of networks

A.8.21 requires that network services—whether internal or provided by third parties—be specified and secured to meet business and security requirements. For the exam, think beyond raw connectivity: se...

14 Okt 202513min

Populært innen Fakta

fastlegen
dine-penger-pengeradet
relasjonspodden-med-dora-thorhallsdottir-kjersti-idem
foreldreradet
treningspodden
jakt-og-fiskepodden
rss-kunsten-a-leve
rss-kull
takk-og-lov-med-anine-kierulf
mikkels-paskenotter
sinnsyn
rss-strid-de-norske-borgerkrigene
tomprat-med-gunnar-tjomlid
hverdagspsyken
gravid-uke-for-uke
rss-sarbar-med-lotte-erik
hagespiren-podcast
smart-forklart
fryktlos
rss-bisarr-historie