Security Basics mailing list archives

RE: Antivirus- A Corrective Control?


From: "Mikesch, David A" <dave_mikesch () baxter com>
Date: Wed, 10 Aug 2011 12:52:21 -0500

Omar's last sentence makes the most sense and will likely get you the best results.

However to your question, it also depends on what is defined as AV - do they mean just AV or an entire AV suite like 
McAfee? If the latter, then it can certainly be argued that it's preventive due to the custom rules that can be 
created. For example, we created custom rules to prevent the creation of *.exe in certain folders because we saw that 
certain malware would create randomly named files in those folders. So in that example it's certainly preventive.

Dave

-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On Behalf Of Omar Salvador Alcalá Ruiz
Sent: Wednesday, August 10, 2011 10:37 AM
To: kartik.netsec () gmail com; security-basics () securityfocus com
Subject: RE: Antivirus- A Corrective Control?

Mmmhhh usually there are tricky questions like this. The objective of the preventive controls is to do that mainly: 
Prevent. Example a Firewall (in this case, access to a network). Look at the definition of the corrective controls: 
They look to alter the security by correcting deficiencies. I think it's a relative view, but if you stick to the 
corrective control definition, the antivirus is basically correcting mostly a flaw in your OS, or a lack of control for 
specific malware.

Remember for the CISSP two things: 1. Both answers can be good (I like your point of view, it's not bad), but 2. For 
the exam, what is the BEST option? Stick to that for the entire CISSP exam.

HTH

Omar


-----Mensaje original-----
De: listbounce () securityfocus com [mailto:listbounce () securityfocus com] En nombre de kartik.netsec () gmail com
Enviado el: miércoles, 10 de agosto de 2011 02:15 a.m.
Para: security-basics () securityfocus com
Asunto: Antivirus- A Corrective Control?

Hi, I have a confusion whether Antivirus is a Preventive control or a Corrective control? I am preparing for CISSP and 
somewhere I have read that AV is a corrective control. I somehow disagree with this point. 

I believe AV can only be a corrctive control if the machine (without AV) gets infected and then AV software is 
installed on it.

On the other hand, a machine already having an AV installed should be taken as a Preventive control.

Any inputs please?

Thanks,
Kartik

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------

The information transmitted is intended only for the person(s)or entity to which it is addressed and may contain 
confidential and/or legally privileged material. Delivery of this message to any person other than the intended 
recipient(s) is not intended in any way to waive privilege or confidentiality. Any review, retransmission, 
dissemination or other use of , or taking of any action in reliance upon, this information by entities other than the 
intended recipient is prohibited. If you receive this in error, please contact the sender and delete the material from 
any computer.

For Translation:

http://www.baxter.com/email_disclaimer


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: