Security Compliance Manager (SCM) v2.0



Similar documents
Compliance series Guide to meeting requirements of USGCB

Course Syllabus. Deploying Microsoft Windows Server Key Data. Audience. At Course Completion

6419: Configuring, Managing, and Maintaining Server 2008

Outline SSS Microsoft Windows Server 2008 Hyper-V Virtualization

How To Use A Policy Auditor (Macafee) To Check For Security Issues

A Microsoft U.S. Public Sector White Paper by Ken Page and Shelly Bird. January government

411-Administering Windows Server 2012

(Exam ): Configuring

Configuring Managing and Maintaining Windows Server 2008 Servers (6419B)

safend a w a v e s y s t e m s c o m p a n y

MS 50292: Administering and Maintaining Windows 7

MOC 10324A: Implementing and Managing Microsoft Desktop Virtualization

Fundamentals, Security, and the Managed Desktop

Implementing and Managing Microsoft Server Virtualization

Implementing and Administering Windows Small Business Server 2008

M6419 Configuring, Managing and Maintaining Windows Server 2008 Servers

Configuring, Managing and Maintaining Windows Server 2008 Servers

MS-50255: Managing, Maintaining, and Securing Your Networks Through Group Policy. Course Objectives. Required Exam(s) Price.

Implementing and Managing Microsoft Server Virtualization

MS 50255B: Managing Windows Environments with Group Policy (4 Days)

To get started, you will need the following items Product Key Router with firewall capability Network cables

Planning and Designing Microsoft Virtualization Solutions

Course 6419A: Configuring, Managing and Maintaining Windows Server 2008 Servers

Course 50273B: Planning and Designing Microsoft Virtualization Solutions. Level: 300. About this Course

Configuring, Managing and Maintaining Windows Server 2008 Servers

Configuring, Managing and Maintaining Windows Server 2008 Servers

Exam Questions

Course Outline. ttttttt

Army Golden Master (AGM) Microsoft Products

6445A - Implementing and Administering Small Business Server 2008

Implementing and Managing Microsoft Server Virtualization

10215A Implementing and Managing Microsoft Server Virtualization

6445A - Implementing and Administering Windows Small Business Server 2008

Microsoft SQL Database Administrator Certification

MCSA/MCITP: Enterprise Windows Server 2008 Course 9952; 14 Days, Instructor-led

Egress Switch Client Deployment Guide V4.x

Windows" 7 Desktop Support

Microsoft Windows Server Update Services Questions & Answers About The Product

Planning and Managing Windows 7 Desktop Deployments and Environments


SurfProtect User Activity Reporting

Managing and Monitoring Windows 7 Performance Lesson 8

Implementing and Managing Windows Server 2008 Hyper-V

MS-10215: Implementing and Managing Microsoft Server Virtualization. Course Objectives. Required Exam(s) Price. Duration. Methods of Delivery

MS-50292: Administering and Maintaining Windows 7. Course Objectives. Required Exam(s) Price. Duration. Methods of Delivery.

Lumension Endpoint Management and Security Suite Patch and Remediation 7.0 Service Pack 1 Migration Guide

NetIQ Group Policy Administrator User Guide

Administering and Maintaining Windows 7 Course 50292C; 5 Days, Instructor-led

DriveLock and Windows 7

EXAM Configuring and Deploying a Private Cloud with System Center Buy Full Product.

What s New Guide: Version 5.6

MS 6419 Configuring, Managing and Maintaining Windows Server 2008-based Servers

Forefront Endpoint Protection. Jack Cobben

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

NetWrix Logon Reporter V 2.0

Designing a Windows Server 2008 Applications Infrastructure

Administering Windows Server 2012

Course Description. Course Page - Page 1 of 9. Administering Windows Server 2012 M Length: 5 days Price: $2,795.00

Managing Windows Environments with Group Policy

Patriot Hardware and Systems Software Requirements

(TS: Windows 7, Configuring)

Microsoft. Jump Start. M11: Implementing Active Directory Domain Services

ManageEngine Desktop Central Training

Administering Windows Server 2012

Course Syllabus. Implementing and Managing Windows Server 2008 Hyper-V. Key Data. Audience. At Course Completion. Prerequisites

Step-by-Step Guide for Microsoft Advanced Group Policy Management 4.0

Administering Windows Server 2012

Group Policy 21/05/2013

MS MCITP: Windows 7 Enterprise Desktop Support Technician Boot Camp

System Requirements and Prerequisites

MOC 6436A: Designing Active Directory Infrastructure and Services in Windows Server 2008

PAf KTl enterprise^ Virtualization Advanced Guide. Microsoft Application. optimize your application virtualization p'atform.

How To Write A Gpmc Script For A Gpc (Windows 2003) On A Windows 2000 (Windows 2000) On Your Computer Or Your Computer (Windows 3) On An Ipad Or Ipad (Windows 2) On The Macbook

COMPLETE COMPUTING, INC.

Top 10 Most Popular Reports in Enterprise Reporter

Administering Windows Server 2012

Appendix F: Instructions for Downloading Microsoft Access Runtime

Configuring and Troubleshooting Windows 2008 Active Directory Domain Services

Administering Windows Server 2012

Viewfinity Privilege Management Integration with Microsoft System Center Configuration Manager. By Dwain Kinghorn

Torgeir Bergsvik Solution Specialist Security & Management Microsoft

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Data Sheets RMS infinity

Admin Report Kit for Active Directory

Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

MOC 20413C: Designing and Implementing a Server Infrastructure

MOC 6419: Configuring, Managing, and Maintaining Windows Server 2008

CMB-207-1I Citrix XenApp and XenDesktop Fast Track

Transcription:

Security Compliance Manager (SCM) v2.0 Vlad Pigin Sr. Program Manager Shelly Bird Architect November 2011

Session Objectives and Takeaways The past, present, and future of Security Guidance and Microsoft Baselines Customer challenges SCM 2 Overview o Key use scenarios o Key features and benefits o Baselines we ship today o Installation & configuration o Learn o Customize o Export o Verify Field experience and examples SCM related links Questions 2

Customer Challenges Lack of timely authoritative prescriptive security guidance Guidance released for different products at different times and comes from various sources Inconsistent customer experience Security guidance provided by Microsoft was delivered in many different formats Customers need to visit several websites, and download separate tools and documents to get guidance for all products Lack of automation tools Customizing and deploying security guidance is tedious and time consuming Multiple products involved GPO to set, DCM to check, etc. IT compliance is difficult to manage Determining if deployed security configurations are still in effect, and comply with an environments requirements is quite challenging 3

SCM Overview Learn Customize Export Verify SCM provides centralized security baseline management features, a baseline portfolio, customization capabilities, and security baseline export flexibility to accelerate your organization s ability to efficiently manage the security and compliance process for the most widely used Microsoft technologies. 4

SCM v2 Use Scenarios Securing Windows Client Locking Down Windows Server Roles Applying Security recommendations to Microsoft Office Creating Public Access or Kiosk Desktops Internet Disconnected Environment Tracking decision making for security audits 5

Baselines that ship inside SCM today Server Operating Systems: Windows Server 2008 R2 SP1 Windows Server 2008 SP2 Windows Server 2003 SP2 Client Operating Systems: Windows 7 Windows Vista SP2 Windows XP SP3 MS Consulting Services: USGCB (United States Government Configuration Baseline) http://usgcb.nist.gov Auto-update functionality in SCM alerts you of new baselines releases Applications: Office 2010 Office 2007 SP2 Internet Explorer 9 Internet Explorer 8 7

Main view breakdown & filters 8

SCM Overview 9

Settings details view 10

Editing Baselines in Library 11

Importing security baselines / GPO s Create baselines from your production GPOs Import GPO Backups created using GPMC Import Third Party Baselines in.cab format GPO Backups created using LocalGPO Snapshot your golden master configuration from a reference computer Create baselines in SCM that match the configuration of your reference computers 12

Compare & Merge baselines SCM has the ability to compare & merge Baselines/GPOs Baselines/GPOs must be imported into SCM Highlight Baseline then select Compare/Merge in Actions pane Save Results in.excel report Use comparison to compare against Microsoft baseline recommendations To identify overlap To learn about settings unique to Microsoft baselines To review setting prescriptions specific to your baselines Merge wizard allows review settings with changing values; defined in both baselines, overwrite? 13

Export baselines to desired format GPO Backup (Set) Can be imported into Active Directory Can be applied to standalone computers using LocalGPO SCCM 2007 DCM Pack (Get) Can help verify deployed configurations SCAP data stream (Get) Product agnostic scanning method (http://scap.nist.gov) Excel (for documentation and analysis purposes) Includes all setting data visible in SCM SCM.CAB format Allows for baseline sharing between SCM installations 14

Apply GPO Backup to Local Policy Export Local Policy to GPO Backup 15

Lessons Learned Using SCM to Meet the USGCB Mandate Windows 7 Focus

Stick to the Standard Istockphoto.com/rtortoit@hotmail.com 17

Don t pull in old settings Istockphoto.com/rtortoit@hotmail.com 18

Contain the new systems Istockphoto.com/rtortoit@hotmail.com 19

Add a WMI Filter Istockphoto.com/rtortoit@hotmail.com 20

Study impact statements Istockphoto.com/rtortoit@hotmail.com 21

Veer when absolutely necessary Istockphoto.com/rtortoit@hotmail.com 22

Recap: Lessons Learned 1. Stick to the standard: US Govt Configuration Baseline 2. Don t pull in old settings from older operating systems 3. Contain the new Windows 7 systems in a carefully controlled set of OUs 4. Add a WMI filter to Group Policy to target Windows 7 5. Study impact statements in SCM and gather your own 6. Don t be afraid to veer from the standard when your situation calls for it; document why for auditors in SCM 23

How it works in the Real World 24

Real World Implementation: US Air Force History: Coming from Vista / XP Managed for 7 years Achievement: 386,000 desktops deployed in 12 months (~575,000 targeted) 253 management sites Averaging over 8,000 desktops per week Using: Configuration Manager 2007 OSD, SCM LGPO, Bitlocker, Network Access Protection (NAP) 25

Some History Largely unmanaged in 2004 Moved 525,000 to managed Windows XP in 18 months (FDCC) Moved 400,000 to Vista in 15 months Moved 386,000 to Windows 7 in 12 months When self-service offered, saw a 2:1 pickup (pull versus push) US Air Force is an active participant in early adopter programs (Technical Adoption Program) 26

Key Factors in Success Hardware Council, hardware buy each quarter Inclusive planning sessions, regular outreach Strategically placed technical resources Quarterly image (just one for all models) Simple installation, less than five steps from USB FOB or disk, or Zero Touch push of image Zero Touch Systems Center Configuration Manager Operating System Deployment 27

Some Surprising Facts Application compatibility: issues with security settings were and are far less than expected Controlled self-service is popular, and cheap Each deployment cycle accelerated, despite 3x larger images compared to XP Comply & Connect in monitoring mode works Going through Vista was worth it Zero Touch Systems Center Configuration Manager Operating System Deployment 28

From 1,000/week to 8,000 From 10Mbps Ethernet to 1 Gigabit (cut 30-40 min per install, 10-15 min download) From Network data transfer to in-disk transfer (cut 2 hrs per install, 3 to 5 minutes per 5GB) User State Migration Toolkit Hard Links Standardized procedures Task sequences Group Policy Objects Practice 29

Questions? 30