<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Reaching for the high hanging fruit</title>
	<atom:link href="http://www.greebo.net/2007/12/21/reaching-for-the-high-hanging-fruit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.greebo.net/2007/12/21/reaching-for-the-high-hanging-fruit/</link>
	<description>mostly useless crap from me</description>
	<pubDate>Wed, 19 Nov 2008 22:58:45 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Augusto P Barros</title>
		<link>http://www.greebo.net/2007/12/21/reaching-for-the-high-hanging-fruit/#comment-16520</link>
		<dc:creator>Augusto P Barros</dc:creator>
		<pubDate>Thu, 07 Feb 2008 18:10:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.greebo.net/2007/12/21/reaching-for-the-high-hanging-fruit/#comment-16520</guid>
		<description>Hi,

just blogged about your blog. I'm also doing some research about mainframe security, specially on cases where legacy applications are being used by new apps on other platforms. I have seen some huge security holes on how people are doing that integration, like screen scraping systems, direct CICS Sockets access and so on. Good to see more people talking about it.

Regards,

Augusto</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>just blogged about your blog. I&#8217;m also doing some research about mainframe security, specially on cases where legacy applications are being used by new apps on other platforms. I have seen some huge security holes on how people are doing that integration, like screen scraping systems, direct CICS Sockets access and so on. Good to see more people talking about it.</p>
<p>Regards,</p>
<p>Augusto</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Nadir</title>
		<link>http://www.greebo.net/2007/12/21/reaching-for-the-high-hanging-fruit/#comment-16262</link>
		<dc:creator>Mark Nadir</dc:creator>
		<pubDate>Wed, 09 Jan 2008 17:59:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.greebo.net/2007/12/21/reaching-for-the-high-hanging-fruit/#comment-16262</guid>
		<description>ACF2 and RACF are both excellent facilities for securing access control as well as the auditing of said access control to resources residing on mainframes. As with everything else, the trick is the proper configuration and use of these facilities. 

However, these facilities don't address the other concerns you mentioned in this article, especially in the areas of batch data transfers that may use cleartext protocols, batches with no integrity and no accountability controls, and so on.

Having conducted a few security and compliance initiatives for two large retailers in North America, this is a key area for improvement. Not only that, but the auditors are also taking note, especially for PCI.

I've seen cases where FTP was used to transfer critical information for a few reasons: either it was the only protocol available, or it was the easiest way to do things. Added to that was the skill sets and experience levels of the mainframe administrators who may or may not know how to secure said transfers.

This is a fascinating field. 

Some things that environments can do to immediately help with this are:

1. Understand what data is sensitive to their mainframe environments. A true understanding of this data can help companies decide on what measures they can deploy that can provide the best value to mitigate risk and balance operational efficiencies;

2. Isolate the mainframe environment from the actual web processing environment, ensuring that only the bare minimum of information flow happens between the two. If possible, use a data abstraction layer between the two separated environments;

3. Understand how to secure protocols, including the clear text protocols such as FTP. Easy ways of securing FTP are Secure FTP (FTP/s) and SSH FTP (SFTP). Use FTP servers that fully audit activities;

4. Consolidate the logs of all these different systems, processes and subsystems into a centralized log management solution such as a SIEM. Utilize any correlation and analysis capabilities of said solution. I've had great success with the RSA enVision solution for this.

These are some of the things companies can do, that can realize immediate benefits to them.</description>
		<content:encoded><![CDATA[<p>ACF2 and RACF are both excellent facilities for securing access control as well as the auditing of said access control to resources residing on mainframes. As with everything else, the trick is the proper configuration and use of these facilities. </p>
<p>However, these facilities don&#8217;t address the other concerns you mentioned in this article, especially in the areas of batch data transfers that may use cleartext protocols, batches with no integrity and no accountability controls, and so on.</p>
<p>Having conducted a few security and compliance initiatives for two large retailers in North America, this is a key area for improvement. Not only that, but the auditors are also taking note, especially for PCI.</p>
<p>I&#8217;ve seen cases where FTP was used to transfer critical information for a few reasons: either it was the only protocol available, or it was the easiest way to do things. Added to that was the skill sets and experience levels of the mainframe administrators who may or may not know how to secure said transfers.</p>
<p>This is a fascinating field. </p>
<p>Some things that environments can do to immediately help with this are:</p>
<p>1. Understand what data is sensitive to their mainframe environments. A true understanding of this data can help companies decide on what measures they can deploy that can provide the best value to mitigate risk and balance operational efficiencies;</p>
<p>2. Isolate the mainframe environment from the actual web processing environment, ensuring that only the bare minimum of information flow happens between the two. If possible, use a data abstraction layer between the two separated environments;</p>
<p>3. Understand how to secure protocols, including the clear text protocols such as <a href="http://FTP" rel="nofollow">http://FTP</a>. Easy ways of securing FTP are Secure FTP (FTP/s) and SSH FTP (SFTP). Use FTP servers that fully audit activities;</p>
<p>4. Consolidate the logs of all these different systems, processes and subsystems into a centralized log management solution such as a SIEM. Utilize any correlation and analysis capabilities of said solution. I&#8217;ve had great success with the RSA enVision solution for this.</p>
<p>These are some of the things companies can do, that can realize immediate benefits to them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dre</title>
		<link>http://www.greebo.net/2007/12/21/reaching-for-the-high-hanging-fruit/#comment-16052</link>
		<dc:creator>dre</dc:creator>
		<pubDate>Mon, 24 Dec 2007 02:57:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.greebo.net/2007/12/21/reaching-for-the-high-hanging-fruit/#comment-16052</guid>
		<description>http://isbn.nu/0131738569/</description>
		<content:encoded><![CDATA[<p><a href="http://isbn.nu/0131738569/" rel="nofollow">http://isbn.nu/0131738569/</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
