NIST 800 standard on security states:
"CM-7(5), Least Functionality whitelisting, is not in the moderate security control baseline in accordance with NIST Special Publication 800-53. However, it is offered as an optional and stronger policy alternative to blacklisting."
Whitelisting is preferred. The Australian Information Security Manual requires it (in fact, it's required as part of their essential 8). Even for low security systems:
"Security Control: 0843; Revision: 7; Updated: Sep-18; Applicability: O, P, S, TS
An application whitelisting solution is implemented on all workstations to restrict the execution of executables, software
libraries, scripts and installers to an approved set"
PC Matic makes this easy and brings it to
...Показать большеthe consumer. Most consumers aren't installing bespoke software, so I think you have massively overstated the 'false positive' angle.
I'm surprised that as a security professional you'd rank it so low. I disagree with the core tenet of your report and your assessment.
I rank PC Matic at 5 stars.
Note: I have no relationship with PC Matic and don't know a single employee. This is my honest assessment.
Скрыть