
Message to readers
Security was one of my main concerns since I started working almost 15 years ago.
In the mean time I gained some experience in this field which I would like to share with others tech and non tech professionals.
Following capabilities should be protected and assured by security in my opinion:
- The capability of a system to continuously deliver services which depends on the availability of hardware, software and services.
- The capability of a system to prevent unauthorized individuals and processes from accessing data. This concerns the preservation of data confidentiality and integrity.
- The capability of a system to ensure that specific actions and transactions have actually taken place.
- The capability of a system to carry out actions and provide the expected services throughout its life span.
All these capabilities will make a stronger and more secure environment and that's why I'm addressing at least following categories:
Access restrictions
Centralized logging systems
DDoS
Digital Certificates
Nmap, OpenSSL and Tcpdump use cases
Second factor authentication