Herding Happy Sheep - Securing an Open Environment

No ratings

Presented at BSidesDFW 2018 by

It has been proven time and again that humans can't be trusted. So, we lock them down by removing permissions. Not only does this tend to upset users, but it inevitably creates more work for admins, such as having to intervene to install applications or making exceptions to policy for legacy applications. But what happens when the user finds a loophole? What happens when the admin is the bad guy? Or when someone disables that one little control, just for testing(tm), but forgets to turn it back on? This talk will provide a high level, theoretical overview (backed up by some real world examples) of methods organizations can use to take a different approach to securing sensitive data. Using guide rails and automation, it will explore methods of giving freedom back to users and developers while your admins work on more important things. Your CISO will finally be able to get a good night's sleep knowing that his data is as safe as it could be, even if a compromise occurs.