Keep your information system up to date #CyberSecMonth

by | Nov 15, 2018 | CyberSecMonth, News & Events

Although we are only a few days away from the end of the 2018 edition of CyberSecMonth, there is still time to learn and share our best practices on digital security. This is our ambition with our new infographics on the maintenance of the information system. This CyberTip is particularly close to our hearts. Indeed, we have developed a solution that perfectly meets the challenges of computer maintenance. We’ll tell you more just below!

An up-to-date information system for a secure IT park

In this day and age, digital transformation is becoming increasingly important. Information systems as well as software are constantly evolving and therefore often updated. The main reasons for this are the additions of new functionalities or corrections. All these changes generate a certain “instability” with regard to software. It is therefore not surprising that security flaws are regularly discovered.

Infographie "Maintenir le système d'information à jour"
From the point of view of cyber attackers, these security breaches are very good opportunities to penetrate the information system and reach sensitive data or contaminate the network. It is obviously impossible to prevent software from evolving. However, it is possible to limit the risks represented by frequent updates of the solutions used within an organization.

How to limit the risk of infection on your information system ?

Update the components of the information system:

The only way to prevent this risk is to be informed when new vulnerabilities are discovered so that you can act quickly. The CERT-FR is the government centre for monitoring, alerting and responding to computer attacks and acts as the French government’s CERT (Computer Emergency Response Team). It carries out technological monitoring and communicates on the state of the art of systems and software. This organization therefore makes it possible to keep informed of the various security vulnerabilities discovered. Thereafter, it is important to apply the security patches to all components of the information system within a maximum period of one month after the publisher’s publication. It is also advisable to define and implement an update policy specifying:

  • The way in which the inventory of the components of the information system is carried out.
  • Sources of information related to the publication of updates.
  • Tools to deploy patches on the fleet.
  • The possible qualification of patches and their progressive deployment on the fleet.

Obsolete components no longer supported by manufacturers must be isolated from the rest of the system. This measure also concerns the network (strict filtering of flows) but also authentication secrets (dedicated to these systems).

Monitor the obsolescence of the software used:

Using an obsolete system or software represents an additional risk of being cyber attacked. As soon as patches are no longer made to a system, it becomes vulnerable. Many malicious tools available on the web exploit this lack of security correction on the part of the publisher. There are still precautions to avoid the obsolescence of these systems:

  • Create and maintain an inventory of information system systems and applications.
  • Prefer solutions whose support function is guaranteed at least for the duration of use.
  • Ensure a follow-up of updates and end dates of software support.
  • Maintaining the homogeneity of the IT equipment, the accumulation of several versions of a software can lead to problems and complicate the monitoring of the equipment.
  • Limit the operating dependencies of one software to another (software adhesions), in fact the support time of these solutions is not equivalent.
  • Include clauses in contracts with service providers and suppliers to monitor security patches and manage obsolescence.
  • Identify the time and resources required to migrate each software in the decline phase (non-regression test, backup and data migration procedure, etc.).

Facilitate the implementation of these good practices to maintain an up to date information system :

Ensure software compliance:

SUMo (for Software Update Monitor) is a tool that is easy to use and yet very useful. It automatically detects, through an analysis of the hard disk, new versions of software installed on the computer in question. The little something extra about this really practical solution is that it is free and available in French. During an analysis, if SUMo discovers a new version of a software, the console displays the version currently installed on the computer and the new version of the software as well as a link to download it. There is also a paid version that allows you to download updates directly from developers’ websites.

WAPT for simplified fleet management:

WAPT, our open source software deployment solution for Windows, was designed to simplify IT asset management by centralizing administration actions in a single console. WAPT allows you to quickly create, test, install, update and uninstall software packages or configurations across an entire fleet. The information goes directly to the console and it is therefore possible to know the progress of the actions carried out on the fleet in real time. It is also possible to remotely program the deployment of software so as not to disturb users. The simplicity of the software allows you to be more responsive and quickly correct security vulnerabilities by en Keeping your fleet up to date with just a few clicks.

Regarding the deployment of software packages, you have three options. First, it is possible to download the secure packages from our store (with more than 1000 packages available). Alternatively, you can create your own packages via the WAPT console. We use the wizard package and PyScripter environment to really simplify package creation, as you can see just below. If all this seems complex to you, it is still possible to ask us to develop your packages for you.

The National Agency for Information Systems Security has recognized the security and robustness of the software by awarding version 1.5 of WAPT Enterprise the ANSSI qualification. This version offers more flexibility in managing the largest fleets, whether through AD authentication, separation of user roles or simplified management of remote sites or individual depots.
Do you need to keep your fleet up to date?

Benefit from our expertise

As the creators of WAPT, we are best able to answer your questions and solve your problems. We have implemented support tickets and qualiopi certified training on our software. Our DevSecOps working methodologies and our 15 years of expertise in securing the local network make us trusted partners to act effectively on a computer fleet.

Cybersecurity: Visualize, understand, decide

This week, Cigref, a network of major French companies and public administrations focused on digital technology, published a report on Cybersecurity. The purpose of this report is to help organizations to understand the challenges of cybersecurity. Thus, the Cigref working group identified and structured the strategic information and indicators needed to provide a dashboard on cybersecurity. This document, mainly intended for CIOs, includes several sections (information system, company vulnerability, etc.) and is based on current data, risk analyses, cost elements and aggregated quantitative indicators.

Articles not to be missed:

Find all our recommendations on Twitter and LinkedIn and on hashtag: #TousSecNum, #CyberSecMonth, #ECSM2018 et #ECSM. Also follow our hashtag #CyberConseil to follow Tranquil IT’s advice and discover the following graphics.

FAQ WAPT 2.5 : Answers to your questions

FAQ WAPT 2.5 : Answers to your questions

It's now been several months since the release of WAPT 2.5. Let's take a look at the 10 most frequently asked questions and answers.For more answers, don't hesitate to :- Consult our discord: https://discord.com/invite/BSqGacB  - Read our technical documentation:...

read more
Demonstration

Group demo

18/04/2024 : 10h30 - 11h30

Let's go !