Similar security controls.
I want to keep the story short and make less techie so that people like any level of background can understand. Let’s take a fridge lock system scenario where we put the controls to keep its safe from kiddos.
Likewise in the tech environment we put IDS, IPS,
firewall, etc to strengthen organization
security and to keep it in proper flow. What happens is the attacker gets curious and breaks
in and takes its bounty. Now security professionals found and fix the bug by
putting the same type of controls.
Yes it has slow down attacking rate and decrees
attack surface like from 100 to 70 % percent a decrement of 30% but we want to scale it down much lesser.
01001101 01101111 01110010 01100001 01101100 01001101 01101111 01110010 01100001 01101100
01001101 01101111 01110010 01100001 01101100 01001101 01101111 01110010 01100001 01101100
Moral: There can be many lessons from this story but what I want
to point out is
1:It can be the good but not best approach but yes it deteriorates
threat level attacker will find it bit difficult to break in comparison to
previous.
2. Don’t go with same kind of solution like which we already have. Just by replacing or adding new one doesn't make much difference to security posture. First we need to understand the problem and try to fix it. Below is
the example which represents what a different approach looks like in the context
of the above scenario.
Note: My intention was no to take you into technicalities of
info security field there are N number of sources and websites to go through. Just want to
bring up in market there are same solution with a different name it’s just marketing
gimmicks that’s the lure. So stay away don’t buy and implement similar controls which you already have in your stack or which you don’t require because poor decision leads
to compromised networks.
Comments
Post a Comment