On a day-to-day basis, the security team will come across some of the following issues; we will look at how the team can mitigate them:
- Unencrypted credentials/clear text: Unencrypted credentials/clear text are a security risk as they can be intercepted by a packet sniffer or protocol analyzer. We should be using an authentication protocol, such as Kerberos, that is encrypted and encrypts data in transit.
- Logs and events anomalies: There are many logs in a company (such as firewall logs, antivirus logs, and event viewers on computers and servers), showing attempts to log into the network. The best way to prevent duplications of events and get real-time monitoring would be to install an SIEM system.
- Permission issues: Permissions that are incorrectly set can give users more permissions than they need to do their jobs, but someone with more...