Jump to content

Windows Anti-Virus etc. Security. Best Practice?


Recommended Posts

Posted

Hi folks,

 

As per my recent posts, we've had a virus outbreak that has potentially wrecked a lot of PCs, and could cause a lot of downtime on our network.

 

With zero day attacks being common, and other forms of security almost being more important than anti-virus, what do other schools do in terms of best practice?

 

For example, I have increased the number of file screens on our servers to prevent executable files from being in places where they are not needed. This would have probably helped a lot with our current outbreak, which was in part converting PDFs to EXEs (40,000 files were affected). Albeit we have to balance this with students who are programming – they are allowed EXE files, but only with a specific prefix.

 

Do other schools prevent use of USB memory sticks? We don’t currently.

 

What else do you do? Any suggestions/ideas welcomed!

 

TIA

Posted (edited)

Prevent downloading exe files on your web filter. Except from white listed accounts or websites

Have a mechanism for patching machines quickly which includes flash, Java and all web browsers.

Remove all admin account use for day to day use.

Have a seperate account for it admins which they only use to do admin tasks.

 

Review your anti virus, make sure it's updating promptly on all machines.this should be you final line of defence.

 

Review permissions on shares. Does everyone really need r/w to every folder?

 

 

Edit: what the above said :)

Edited by gaz350b
  • Thanks 1
  • 5 months later...
Posted

This might be of interest...

 

How to mitigate 85% of threats with only four strategies « SecureList

 

Through comprehensive, detailed analysis of local attacks and threats, the Australian Signals Directorate (ASD) has found that at least 85 per cent of the targeted cyber-intrusions it responds to could be mitigated by four basic strategies. Three of them are related to specialized security solutions. Kaspersky Lab products include technological solutions to cover these first three major strategies:

 

  • Use application whitelisting to help prevent malicious software and unapproved programs from running
  • Patch applications such as Java, PDF viewers, Flash, web browsers and Microsoft Office
  • Patch operating system vulnerabilities
  • Restrict administrative privileges to operating systems and applications, based on user duties.

 

http://vgy.me/2JLSlH.jpg

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...