Client-based Systems Vulnerabilities and Mitigations
End users in most cases physically control these devices. This allows for end user modification or removal from enterprise control of the system. They may be more susceptible to loss or theft for this reason.
4 slides · 1 min read · Domain 3
Since the devices are typically under user control, monitoring and updating the systems may be difficult as the location and power status (e.g., on/off) may be indeterminate.
Text on this slide
Physically under user control
Monitoring may be difficult
Susceptible to user misuse (intentional or accidental)
100 percent update may be difficult
May be lost/stolen
The following mitigations are the basic mitigations to apply to a general-purpose computer. While these mitigations seem basic in nature, they are difficult to do well across a large installation base of client devices.
- Patch/update:* Continuous action
- General network protections: e.g., network segmentation, firewall devices, network intrusion prevention or detection
- Host protections:* Antivirus, host intrusion prevention system (IPS), host firewall, disk encryption
- Monitor:* Logs, alerts, track location
- Educate users: Anti-phishing campaign, detecting attacks
- These mitigations should be applied to all general-purpose computing platforms to support software (e.g., database/ application) or functional roles.
