Client-based Systems Vulnerabilities and Mitigations

End users in most cases physically control these devices. This allows for end user modification or removal from enterprise control of the system. They may be more susceptible to loss or theft for this reason.

4 slides · 1 min read · Domain 3

Slide 1

Since the devices are typically under user control, monitoring and updating the systems may be difficult as the location and power status (e.g., on/off) may be indeterminate.

Text on this slide

Physically under user control

Monitoring may be difficult

Susceptible to user misuse (intentional or accidental)

100 percent update may be difficult

May be lost/stolen

The following mitigations are the basic mitigations to apply to a general-purpose computer. While these mitigations seem basic in nature, they are difficult to do well across a large installation base of client devices.

  • Patch/update:* Continuous action
  • General network protections: e.g., network segmentation, firewall devices, network intrusion prevention or detection
  • Host protections:* Antivirus, host intrusion prevention system (IPS), host firewall, disk encryption
  • Monitor:* Logs, alerts, track location
  • Educate users: Anti-phishing campaign, detecting attacks
  • These mitigations should be applied to all general-purpose computing platforms to support software (e.g., database/ application) or functional roles.
Test this domain