ATLANTA -
That’s why Terrence Griffin, vp-information services (IS) at the $1.5-billion credit union, is currently shopping solutions that will automate these critical pieces of the vulnerability management process.
“We’re looking for new ways to mitigate vulnerabilities,” he said.
The tools will cost a pretty penny, continued Griffin. “We’ll make a significant IS investment, and it’ll be worth it to protect member data.” APCU spent $250,000 on data security in 2007 and will rack up a similar figure this year.
Griffin plans to beta-test the VAM vulnerability management platform, provided by Superior, Colo.-based StillSecure.
The solution will search the network for weak points and verify that every program has up-to-the-minute patches.
“I can sleep well knowing that a system administrator has applied new patches, and that the vulnerability is no longer there,” Griffin explained.
The platform will generate verification reports that Griffin can show to internal auditors and supervisory committee members, as well.
Otherwise, the IS team has to complete a full network scan and manually record the results in a spreadsheet to prove to auditors and committees that everything is copasetic.
Sometimes, patches released by one company will break previously applied patches from another company, he added. “Then we have to scan again to check to make sure all patches are good. It takes employees in IS and other departments at least four days per month to patch and validate.”
VAM will not only keep all patches current but will also reduce human error, Griffin said. With a minimum of 15 patches per month on 182 workstations at the credit union, plus monthly patches for 50 servers, it’s easy for “administrators to get confused as to what they’ve patched.”
Griffin warned against using vulnerability management freeware. “It’s not easy to use, and you have to supplement them with a lot of custom development.”
Whereas APCU will monitor patching with VAM, which can also demonstrate regulatory compliance via Web-based reporting tools, the CU will run a disparate system to tame the mountain of network logs.
“After we beta-test the VAM, our next phase will be to manage the logs from our firewalls, routers and switches,” said Griffin.
APCU plans to deploy the Cisco Security Monitoring, Analysis and Response System (MARS) to “alert us of people who are getting into the network who aren’t supposed to,” he said.
“We spend too much time going through and validating all the logs and checking for false positives and vulnerabilities”–in fact, it’s a full-time task for one Atlanta Postal CU employee, said Griffin.
The MARS intrusion prevention appliance patrols the network, delivering a complete visual of all applications and security devices. MARS can eliminate false positives by automatically checking each point along an attack path to see whether a threat has already been thwarted.
MORE
Read more about vulnerability management at cujournal.com and search the following bolded terms in the archive:
Go (con)Figure!
Patching A Problem: 1 CU’s Strategy For Handling Updates
Boosting Security Through Snapshots
For info on this story:
* www.apcu.com
* www.cisco.com
* www.stillsecure.com










