Operating System Security
Goals
- Define operating system security, including operating system hardening, malware protection, software firewalls, and host intrusion detection
- Identify the steps to harden an operating system
- Identify operating system security tools, including scanners, vulnerability assessment tools, and exploit frameworks
- Align account permissions configurations for operating systems, applications, and databases with the principle of least privilege
- Identify elements of risk management in policies and procedures
- Identify the layers of a defense-in-depth strategy
- compare the abilities of physical, logical, and administrative controls, and combinations of same, to protect resources
- Categorize cybersecurity principles and defense concepts according to area of impact
- Classify security principles and actions according to the types of attacks they mitigate or eliminate
- Identify the key information or critical fields to be analyzed, using a range of cybersecurity tools to determine vulnerabilities or possible attacks
- Classify cybersecurity tools according to the type of vulnerability they find/identify
- Classify attacks according to the cybersecurity concept or principle that was violated
- Identify cybersecurity concepts and principles that protect IT infrastructure
- Identify cybersecurity concepts and principles that protect critical information (e.g., intellectual property, files)
An operating system is the software that supports the basic functionality of the device.
Operating system security is the process of securing the operating system to prevent unauthorized access and reduce vulnerabilities.
Ways to Secure an Operating System
- Operating System Hardening
- Protecting Operating Systems Against Malware
- Operating System Security Tools
Protecting Operating Systems Against Malware
- Anti-Malware Applications
- Executable Space Protection
- Software Firewalls
- Host Intrusion Detection Systems
Operating System Security Tools
- Scanners
- Vulnerability assessment tools
- more comprehensive version of a vulnerability scanner
- OpenVAS
- Exploit Frameworks