Home > Midmarket CIO Tips > Security for the midmarket > Open source security: Five best practices
CIO Midmarket Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY FOR THE MIDMARKET

Open source security: Five best practices


Joel Dubin, CISSP, Contributor
09.10.2007
Rating: -4.75- (out of 5)


Technology news and tips for midmarket CIOs
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


On the surface, open source software seems like a great deal for small and medium-sized businesses (SMBs). It's free and freely available on the Web -- which is always in the budget. But best of all, it's supposedly more secure than off-the-shelf commercial software.

But does open source software live up to its touted security credentials?

Open source software, just like its commercial counterpart, still needs to be hardened, patched and locked down before it's deployed in the enterprise.
True, its source code is open and gets picked apart, played with, hacked and tweaked over and over by developers and software gurus worldwide. But open source software, just like its commercial counterpart, still needs to be hardened, patched and locked down before it's deployed.

Here are five best practices SMBs should employ to keep open source applications safe and secure.

Software inventory. If you haven't done a software inventory, do one. An inventory provides a measure of control over what's installed in-house. Even in a small company, the number of software applications -- open source or otherwise -- can get out of hand. And while purchased commercial software leaves a paper trail of invoices for record-keeping, open source software can be downloaded right off the Web without leaving a trace.

Not only should logs with download dates and times be kept, but all open source software should also be checked for integrity before being installed. Open source software comes with MD5 hashes or GNU Privacy Guard signatures to verify that what was downloaded is whole and complete. If the software doesn't pass an integrity check and needs to be downloaded again, this should be noted in a log, too.

Patch management. Patch management for open source software can be tricky, but it's crucial. Release cycles and update schedules often aren't in sync, making patch planning difficult, but it can be done.

For SMBs with a small open source software base, manual patching may be the cheapest, if not only, option. You'll need to manually check and apply open source patches for technologies like Apache and Jakarta, products that have regular release cycles for patches but lack automated updates like Linux systems.

Another option for smaller SMBs is to regularly check open source Web sites and automatically install updates via scripts. Scripts can be written by most system administrators and set to run in off hours -- weekends or in the middle of the night -- at regular intervals.

But as an SMB grows, manual updating and scripts become unrealistic, and patch management tools are the next step. Unfortunately, most patch management tools are geared toward Windows updates. But a few products also update open source software, including PatchLink Update and Shavlik Technologies LLC's NetChk Protect.

Network and firewall compatibility. Open source software, like all software, may require the opening of specific TCP ports for Internet access. But be sure when doing so to not open other security holes in your network.

Also, it's important that open source software is compatible with your existing network security architecture. If adopting a given open source application or software requires radical changes to your architecture that could compromise network's security, you might want to reconsider whether it's right for your company and look for alternatives.

Access management. You should change all default security settings as soon as any open source software is installed to keep out hackers, who often keep lists of common user IDs and passwords.

More on open source
CIOs struggle with open source governance, cite lack of tools

Open source tools: SMB Buying Decisions 
Also, where possible, upgrade the built-in access management systems that come with open source software. Apache, for example, employs basic and digest authentication -- weak systems that can be easily broken by hackers -- and uses a file called "htaccess" to provide password protection to restrict access to certain Web site directories. Don't rely solely on these, as there are many better ways to restrict access using Apache's configuration files and security modules or to lock down access on the server itself using the operating system.

Test and scan. Tools from Fortify Software Inc. and Ounce Labs Inc. can scan for software vulnerabilities, while WebInspect from SPI Dynamics and AppScan from Watchfire Corp. can check for vulnerabilities in Web sites running Apache or other open source Web servers.

Ultimately, open source software is more secure than its commercial counterparts, but care should still be taken to ensure that it's installed, configured and patched securely. SMBs, which have less money and resources to play with, may have to be more creative than larger companies to do so, but they still can and should do it, too.

Joel Dubin, CISSP, is an independent computer security consultant. He is a Microsoft MVP specializing in Web and application security, and is the author of The Little Black Book of Computer Security available from Amazon. He has a radio show on computer security on WIIT and runs The IT Security Guy blog at www.theitsecurityguy.com.


Rate this Tip
To rate tips, you must be a member of SearchCIO-Midmarket.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Information security management for the midmarket
Droid does, but will IT support it?
Information security program revamp adds outsourcer oversight and more
From data breaches to risk management frameworks: Test your knowledge
The challenge of managing risk when IT budgets tighten
Why cybersecurity awareness is everyone's responsibility
Information technology management e-book downloads for midmarket CIOs
10 must-have steps for an effective SMB information security program
Your IT security budget: How to get more bang for the buck
Using key risk indicators to sell your information security program
IT security spending a bright spot in '09, with more growth predicted

Security for the midmarket
Information security program revamp adds outsourcer oversight and more
Your IT security budget: How to get more bang for the buck
Locking down security in the move to electronic medical records
A CIO's advice for implementing single sign-on solutions
Options for outsourcing security grow, offer IT budget savings
Network access control: Pointers for getting the knack of NAC
Stopping malware viruses from attacking Web 2.0 technology
Virtual servers no escape from IT security management concerns
Unified communications: Securing access to OCS
Unified communications security: How safe is it?

Open source midmarket software
Business software guides for the midmarket: CRM, ERP, Web 2.0 and more
Open source solutions vs. SaaS applications: Weigh the options
Microsoft releases code to the Linux community -- and?
Key IT software solutions: Making smart choices in tough times
Information systems management for the midmarket
How to choose the right open source solution for your business
Open source applications sit at IT strategy table during recession
OpenOffice takes on Microsoft Office at SMBs
Open source and SMBs: Open your mind
Open source and SMBs: Answers

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Mid-market CIO Business Solutions on Data Integrity, Unified Communications, and Virtualization
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2007 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts