7MS #285: The Quest for Critical Security Controls - Part 2




7 Minute Security show

Summary: <p>Nothing to do with security, but I've heard <a href="https://www.youtube.com/watch?v=iKzRIweSBLA" rel="nofollow noreferrer noopener" target="_blank">this song</a> way too much this week.</p> <p>I love the <a href="https://www.cisecurity.org/controls/" rel="nofollow noreferrer noopener" target="_blank">CIS Controls</a> but it seems like there isn't a real good hands-on implementation guide out there. Hrmm...maybe it's time to create one? Speaking of that, check out the <a href="https://github.com/hackern0v1c3/MacMon" rel="nofollow noreferrer noopener" target="_blank">MacMon</a> project and chat with us about it via <a href="https://7ms.us/slack" rel="nofollow noreferrer noopener" target="_blank">Slack</a>.</p> <p>After hearing rave reviews about <a href="https://www.indiegogo.com/projects/fingbox-network-security-wi-fi-troubleshooting" rel="nofollow noreferrer noopener" target="_blank">Fingbox</a> (<em>not a sponsor</em>), I picked one up (~$120) and wow, I'm impressed! It's got a lot of neat features that home users and SMBs would like as it related to mapping to CSC #1:</p> <ul> <li>Ability to map network devices to users to create an inventory</li> <li>Email alerts for new devices that pop up on the network</li> <li>Block unwanted users from the app, even when not directly connected to the LAN</li> <li>Nice set of troubleshooting tools, such as wifi throughput test, Internet speed test, and port scanning of LAN/WAN devices</li> </ul><p>More on today's show...</p>