Title :
Automated security configuration checklist for a cisco IPsec VPN router using SCAP 1.2
Author :
Gabriel Biedima Peterside;Pavol Zavarsky;Sergey Butakov
Author_Institution :
Information Systems Security Management, Concordia University of Edmonton, Edmonton, Alberta, Canada
Abstract :
For large enterprises running many different operating systems, applications, and multi-vendor devices, the task of reviewing the security state of a broad range of devices and business areas in order to either comply with security requirements from regulations or detect risks such as misconfigured devices, out-of-date software, etc., is time-consuming, error-prone, and expensive. Although humans are important in the security assessment process, they are unable to keep up with the task, and may introduce inconsistencies which could further make organizations vulnerable to security breaches. Security automation provides a solution to this challenges. In this paper, a common security automation protocol, Security Content Automation Protocol (SCAP) version 1.2, was leveraged to develop an automated secure configuration checklist which can be used by security professionals to rapidly and consistently audit network edge devices such as a Cisco IPsec VPN router to ensure secure configuration per the baseline.
Keywords :
"Security","Automation","Virtual private networks","NIST","Operating systems"
Conference_Titel :
Internet Technology and Secured Transactions (ICITST), 2015 10th International Conference for
DOI :
10.1109/ICITST.2015.7412120