03.12.2021 Views

Cyber Defense eMagazine December Edition for 2021

Will you stay one step ahead of Cyber Scrooge this year? Learn new ways to protect your family, job, company & data. December Cyber Defense eMagazine: Cyber Deception Month is here...Defeat Cyber Scrooge! Cyber Defense Magazine December Edition for 2021 in online format #CDM #CYBERDEFENSEMAG @CyberDefenseMag by @Miliefsky a world-renowned cyber security expert and the Publisher of Cyber Defense Magazine as part of the Cyber Defense Media Group as well as Yan Ross, US Editor-in-Chief, Pieruligi Paganini, International Editor-in-Chief and many more writers, partners and supporters who make this an awesome publication! Thank you all and to our readers! OSINT ROCKS! #CDM #CDMG #OSINT #CYBERSECURITY #INFOSEC #BEST #PRACTICES #TIPS #TECHNIQUES See you at RSA Conference 2022 - Our 10th Year Anniversary - Our 10th Year @RSAC #RSACONFERENCE #USA - Thank you so much!!! - Team CDMG CDMG is a Carbon Negative and Inclusive Media Group.

Will you stay one step ahead of Cyber Scrooge this year? Learn new ways to protect your family, job, company & data. December Cyber Defense eMagazine: Cyber Deception Month is here...Defeat Cyber Scrooge!

Cyber Defense Magazine December Edition for 2021 in online format #CDM #CYBERDEFENSEMAG @CyberDefenseMag by @Miliefsky a world-renowned cyber security expert and the Publisher of Cyber Defense Magazine as part of the Cyber Defense Media Group as well as Yan Ross, US Editor-in-Chief, Pieruligi Paganini, International Editor-in-Chief and many more writers, partners and supporters who make this an awesome publication! Thank you all and to our readers! OSINT ROCKS! #CDM #CDMG #OSINT #CYBERSECURITY #INFOSEC #BEST #PRACTICES #TIPS #TECHNIQUES

See you at RSA Conference 2022 - Our 10th Year Anniversary - Our 10th Year @RSAC #RSACONFERENCE #USA - Thank you so much!!! - Team CDMG

CDMG is a Carbon Negative and Inclusive Media Group.

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Step Four: Develop Actionable Remediations<br />

The final piece of the puzzle is to create clear remediation guidance that all teams can understand. AD<br />

administrators or IAM team members will likely implement any changes to AD. They have different<br />

priorities than the security team, and they’re under extreme pressure to maintain the backbone of the<br />

enterprise. There<strong>for</strong>e, they need to consider how any changes to AD will affect the user's ability to do<br />

their jobs.<br />

That means any remediation recommendations need to clearly explain what the AD admins should do,<br />

the side effects of the change, and how the fix will affect overall risk exposure. This lets AD admins,<br />

executives, and management make in<strong>for</strong>med decisions about executing the change. For example,<br />

remediation could break legacy application functionality. As a result, the change may need to be logged<br />

<strong>for</strong> a substantial amount of time be<strong>for</strong>e the organization feels confident that it won’t cripple a critical<br />

business function.<br />

Active Directory has existed <strong>for</strong> over 20 years. Un<strong>for</strong>tunately, 20 years without visibility into how privileges<br />

are applied leads to seemingly insurmountable challenges. To make real progress, teams must use other<br />

methods to evaluate their AD environment, measure risk, and give practical, actionable guidance <strong>for</strong><br />

fixing problems. Any plan that can account <strong>for</strong> all these elements will be a massive step towards a more<br />

secure AD environment <strong>for</strong> everyone.<br />

About the Author<br />

Justin Kohler is the director <strong>for</strong> the BloodHound Enterprise<br />

product line at security consulting company SpecterOps.<br />

He is an operations expert who has over a decade of<br />

experience in project and program development. After<br />

beginning his career in the US Air Force, he worked <strong>for</strong><br />

several consulting firms focused on process and workflow<br />

optimization and held positions at Microsoft and Gigamon.<br />

He enjoys building and leading teams focused on customer<br />

delivery at Fortune 500 companies.<br />

Justin can be reached online at @JustinKohler10 and at our company website https://specterops.io/<br />

<strong>Cyber</strong> <strong>Defense</strong> <strong>eMagazine</strong> – <strong>December</strong> <strong>2021</strong> <strong>Edition</strong> 132<br />

Copyright © <strong>2021</strong>, <strong>Cyber</strong> <strong>Defense</strong> Magazine. All rights reserved worldwide.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!