La risorsa più importante nel paradigma della difesa in profondità è l'intelligenza umana : impiegare persone esperte della sicurezza responsabili della difesa continua e persistente.
Gli strumenti cambiano, le strutture delle app web cambiano, vengono scoperte nuove tecniche di exploit, cose che preludono a costruire una squadra umana strong per difendere.
Passare alla tattica, ma ancora ad alto livello:
secure coding (app layer) -> empowering teams to develop attacker-resilient applications -> OWASP
secure infrastructure -> empowering teams to deploy attacker-resilient servers and supporting equipment
http://cisecurity.org/
The Center for Internet Security (CIS) is a non-profit enterprise whose Benchmarking and Metrics Division helps organizations reduce the risk of business and e-commerce disruptions resulting from inadequate technical security controls. The Division provides enterprises with consensus best practice standards for security configurations, as well as resources for measuring information security status and for making rational decisions about security investments.
http://iase.disa.mil/stigs/checklist/
Defense Information Systems Agency (DISA)
http://web.nvd.nist.gov/view/ncp/repository
http://csrc.nist.gov/fdcc/faq-common_security_configurations.html
The National Checklist Program (NCP), defined by the NIST SP 800-70 Rev. 1, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.
capable incident detection and response -> empowering teams to detect, contain, respond, & fix
collection of incident response checklists: http://www.knowyourenemy.eu/checklists.php
Richard Bejtlich recently blogged:
"Resources for Building Incident Response Teams
Recently a colleague asked me for resources for building incident response teams. I promised I would provide a few ideas [...]
The CERT.org CSIRT Development site is probably the best place to start. From there you can find free documents, links to classes offered by SEI on building CIRTs, and so on. I don't think you can beat that site!
I don't think the resources at the FIRST site are as helpful, but the process of working toward membership is a great exercise for a new CIRT.
My TaoSecurity books page lists several books which CIRTs will likely find helpful."
Nel nome della brevità, forse quanto sopra è sufficiente?