Originally posted by: Ameesh
Originally posted by: Jzero
Originally posted by: Ameesh
dont you find it boring, installing patches all day, every day?
I rarely install patches. I have automated tools to do that for me.
then what do you do all day? tell your tools which patches to push out?
No, in between posts on ATOT, I flip burgers and take out the garbage, too.
Let's see...
Today my team:
-Wrote an automated script to analyze our production system and make sure that all the systems are configured properly, patched, and antivirused.
-Drafted a proposal to modify the AD structure of the domain and implement new GPOs to give us better control over international offices.
-Drafted responses to three different clients and prospects requesting information on my company's security, backup and disaster recovery practices.
-Continued remediation activities on a comprehensive 3rd-party audit that was recently conducted.
-Met with in-house counsel to ensure that proposed new security policy documents are legally sound.
-Began piloting a remote access solution that ensures that VPN/Dialup users have firewall and AV software running BEFORE they connect
-Checked IDS logs for signs of suspicious activity.
-Reviewed parts of the year-old disaster recovery plan and updated as necessary.
-Executed a monthly audit of user accounts
Oh, yes. And at some point someone clicked a few checkboxes on the SUS server.
As I said - take a look at the SSCP CBK at
www.isc2.org and you'll pretty much know what I'm up to:
Access Controls
Administration
Audit and Monitoring
Risk, Response and Recovery
Cryptography
Data Communications
Malicious Code/Malware