Wednesday, September 9, 2020

ESET Secure Authentication overview: how to keep sensitive data safe

Nowadays, every web service that cares about user security offers multi-factor authentication (MFA), also known as two-factor authentication (2FA). It requires two independent pieces of information to verify a user's identity. This authentication is much more secure than a regular password. You can find two-factor authentication in online banking, accounting software, and even Google services. Today in our review we will get acquainted with the ESET Secure Authentication two-factor authentication system, which can be easily integrated into the corporate network of an organization.

ESET Secure Authentication is a two-factor authentication tool that provides access to sensitive or confidential company information.

Why is this relevant for companies?

In many companies, employees are often the “weak link”. They often use the same passwords for all corporate systems. And sometimes they just share them with their colleagues or relatives. Because of this, information leaks can occur. Two-factor authentication allows you to close this vulnerability in the system. Another threat in the company is bots, Trojans and phishing. They can intercept passwords from company systems and pass them on to attackers. That being said, if an additional factor of authentication is used, it will be much more difficult to access your files.

In addition, in the context of remote work (now more and more companies use it), ESET Secure Authentication is becoming very relevant.

System requirements:

Server : Windows Server 2008/2008 R2 / 2012/2012 R2 / 2012 Essentials / 2012 R2 Essentials / 2016/2016 Essentials / 2019/2019 Essentials and Windows Small Business Server 2008/2011

Client : Windows 7/8 / 8.1 / 10 (including Fall Creators or Redstone 3 update)

Mobile OS: iOS 9 and above, Android 4.1 and above, Windows Phone 8.1 and above

Supported web applications:

Microsoft Exchange 2007 (Outlook Web Access - Exchange Client Access Server), 2010 (Outlook Web App - Exchange Mailbox Server Role, Exchange Control Panel), 2013 (Outlook Web App - Exchange Mailbox Server Role, Exchange Admin Center), 2016 (Outlook Web App - Exchange Mailbox Server Role, Exchange admin center)

Microsoft Dynamics CRM 2011, 2013, 2015, 2016

Microsoft SharePoint 2010, 2013, 2016

Microsoft SharePoint Foundation 2010, 2013

Microsoft Remote Desktop Web Access

Microsoft Terminal Services Web Access

Microsoft Remote Web Access

Software version during testing

License

By the number of users (from 5 devices)

Term - from 1 to 3 years

Why ESET Secure Authentication?

ESET Secure Authentication is a simple system that does not require special training and a lot of time to implement in a large company. It reliably protects all popular systems in the organization. It is not only logging into a computer (supported by Microsoft Windows, Linux or Mac OS X), but also protecting web applications (Microsoft Outlook Web App, Microsoft Exchange, Microsoft SharePoint, Microsoft Dynamics CRM), cloud services, VPN and VDI systems.

An additional password (second factor) comes to the user in the form of an SMS on the phone, or in a special application on the smartphone (PUSH messages). OTP password can also be delivered to e-mail. There is support for hardware tokens (operating according to OATN, NOTP and TOTP standards) and the FIDO2 standard. Recently there was support for embedded biometrics in Android and iOS apps.

Installation

ESET Secure Authentication was tested in edition and turned out to be really easy to set up, we did not need any special skills. First you need to download the distribution and install.

The installer is in English, but everything is clear in it. You can get the trial key here.

There are 2 types of installation - for those who want to integrate it into Active Directory, and standalone on machines that do not use a domain. We chose type 2 - Standalone. Next, select the necessary components for installation.

The installer itself checks if your system meets the ESET Secure Authentication requirements and shows which libraries may be missing for correct installation.

At a certain stage, a username and password are set to access the ESET Secure Authentication web administrator console.


Electrical engineering vs computer engineering

After successful completion of the installation, you need to go to the web console through any popular browser and enter the login and password that were previously set.

After that, we get to the main console window, where we see information about the license status, the number of active users, the product version and the modules that have been installed. The console interface is also in English. In the Users section, we see the categories of security modules (we only have Windows Login activated) and users for which you can configure two-factor authentication.

Next, select the user account that you want to protect, and enter the phone number, as well as specify other parameters.

Authentication confirmation methods:

SMS-based OTPs - SMS notifications

Mobile Application OTP - one-time password, pin-code generated in the mobile application:

Event-based (HOTP) - when the password has no expiration date, i.e. it will be generated every time it is requested.

Time-based (TOTP) - a new one is generated every time (every 30 seconds).

Mobile Application Push - notification in the mobile application. A specific action is requested and you can choose to accept or reject it. The user can now see where the request is coming from (IP address).

Hard Token - physical keys. The latest versions of ESET Secure Authentication have expanded the list of available authentication methods. This product now supports authenticators (such as dongles) that meet the FIDO2 standards. This improves security as well as user-friendliness - devices register quickly and easily without additional drivers.

We have installed the mobile app and selected the settings to receive Push notifications when logging into Windows. In order to link the mobile application to your user in ESET Secure Authentication, all you need to do is scan the QR code.  

The mobile app is very simple and intuitive. You can set a PIN to enter it. If this is inconvenient, you can use a fingerprint or face recognition system. Everything works quickly and accurately.

At the same time, it is impossible to make a screenshot of the code in the mobile application for security reasons. This is to prevent the user from forwarding it to others.

Next, we rebooted the computer and tried to log in. They entered the password and then an ESA (ESET Secure Authentication) window appeared asking for the code. We opened the app on a smartphone and entered it. Success! Everything is working.

ESET Secure Authentication has a detailed reporting system where you can see when SMS was sent, who logged in and when, and much more.

There are also "fine" settings in which you can configure a list of white IP-addresses from which an additional password will not be requested, your company name in the application and other options.

Simple, understandable, convenient. Setting up ESET Secure Authentication on our Windows 10 computer went smoothly. Push notifications are working, SMS received.

It's worth noting that two-factor authentication will only work on machines with ESET Secure Authentication client installed. Integration with Active Directory allows you to quickly deploy ESA on computers, even in a large company. ESET Secure Authentication 3.0 brings significant performance improvements to large projects. The solution is easy to deploy on any network scale.

API source code packages (for systems connected to Active Directory) and SDKs based on Java, PHP and Microsoft .NET are available for implementation in their own authentication systems and systems for additional confirmation of user actions. This is a big plus for those who want to customize ESA for their company.

Another feature of the ESA system is easy integration into RADIUS systems, including: Microsoft Forefront Threat Management Gateway, Barracuda, F5 FirePass, Cisco ASA, Fortinet FortiGate, Citrix Access Gateway, Juniper, Citrix NetScaler, Palo Alto, Check Point Software, SonicWall, VMware Horizon View and Citrix XenApp.

Tuesday, September 8, 2020

How to create a development plan for a developer

For any IT specialist there is an opportunity to facilitate and accelerate his professional and career growth. A personal development plan is an effective help in this difficult task. How to compose it and apply it in practice - this material will tell.

Avoid procrastination 

A personal plan for self-development allows you to clarify the goal and see a transparent, measurable and visual way to achieve it. The main objective of the plan is to prevent procrastination of the specialist's development. This behavior involves the postponement of important tasks and tasks leading to the achievement of growth. The reason is the illusion of the goal and the steps leading to its achievement. These factors hinder self-development and eliminate the career plan.

Consider obstacles 

It is difficult to engage in self-development if you do not see a clear goal for your growth. And even if you understand what level you want to achieve, without planning and real actions in this direction, this may remain a pipe dream. And even if you start moving towards your goal, you will encounter many obstacles on your way:

Loss of motivation. Faced with obstacles and not noticing his progress, the developer forgets why he wants to achieve the goal. As a result, he may refuse to make efforts to overcome difficulties and stop developing.

Lack of time. Often a programmer is so busy with work that he does not have enough strength and energy to engage in self-development. Realizing this, the developers abandon their development, reassuring themselves that for growth it is enough to solve the daily tasks set by the management.

The actual milestone is different from the target. Instead of making adjustments to his plan, the specialist continues to move along a previously conceived path that is no longer relevant.

Define a goal

To develop a development plan, you need to clearly understand the goal that you intend to achieve. The more accurately the goal is determined, the less will be its discrepancy with the actual result. For convenience and efficiency, the plan for achieving the goal is broken down into tasks, subtasks, and simple steps. All elements are tied to the time of their implementation. This is the way to achieve the goal is proposed by Maxim Dorofeev in his bestseller "Jedi Techniques".

Following the algorithm, first you need to decide on the goal of your development. To understand in which direction to move, study the available information about specialties and positions in the IT industry: computer engineering major

Range of tasks;

Salary level;

Area of ​​responsibility;

Competence and knowledge.

Specialized resources such as Technology Online Courses can serve as a source of information . Study the forecasts of which IT trends will be promising this year, in 5-10 years. Analyze the collected information based on your desires, dispositions, competencies, knowledge, talents and resources. Choose the goal you want to achieve as you grow.

Choose a mentor  

Once you have decided on the direction of your development goal, enlist the support of a mentor. An experienced specialist will act as a driver of your development, provided that he is periodically interested in success and corrects your development.

To successfully interact with a mentor, it is important to show that you are interested in your development and are ready to make efforts to achieve your goal. In this case, he will be much more willing to help you, devote more time and often give valuable recommendations.

It does not have to be a specialist who is moving in the same direction as you, he may well have an alternative vector of development.

In a situation where you cannot regularly interact with the teacher, take his model of behavior as a model. Gather information about how he achieved his success, find out about his life hacks, sources of development. Analyze the information gathered and apply it to yourself.

If the company has a shortage of specialists, you can refer to chats by directions in Telegram, as well as to specialized forums. Various events in the IT field: conferences, meetups, gather a huge number of experts from various fields and specializations, where you can also meet the future curator.

Use software

You can use any planning tool. The free Grow app is an excellent tool for creating a development plan for an IT specialist .

Using the program, select the level of development that you want to achieve. For example, you are middle and want to move up to senior level. The application will form for you a matrix of skills required to reach the senior level:

literature to read;

skills to be possessed;

what courses to attend.

The next step is to divide the plan into tasks linked by dates. Some companies require a promotion recommendation to advance to senior level. To do this, you need to pass an assessment (the process of assessing the developer's compliance with the requirements of the Global Competency Framework).

Turning to Grow , you can see that to complete the assessment you need:

study courses on new technologies;

improve team skills;

improve communication skills with the customer;

get a recommendation from fellow developers.

Using the Agile design method, we break these tasks into elementary subtasks and tie them to specific dates. At the next stage, we divide them into even smaller elements - time-bound iterations.

This approach makes it possible to realistically assess how much effort and time it will take to achieve the goal. This increases the chances of getting the desired result, as you realize how much time and effort it will take you to grow up to senior level.

Often times have to be set based on external circumstances. For example, earlier in the EPAM assessment it was possible to complete only a certain period of time. Setting a specific date allows you to get away from procrastination. If you do not complete the task on time, then there is a factor that distracts you and should be promptly eliminated. \

Keep motivated

A well-developed development plan allows you to see the progress of your development. This can help maintain your enthusiasm when a temporary setback stops you. She is not able to break, because you see the whole picture and observe your successful progress.

You will also be able to avoid creating overly optimistic plans that are not able to be completed by the selected date. If you are unable to achieve your goal every day, it makes sense to adjust the plan so that you can monitor progress once a week or even a month.

Feedback from peers is also a great tool to stay motivated. From the outside, mistakes that are made or opportunities that are missed are always better visible.

Unload time for development

It is also important to find the time that you have set aside for your development. To do this, you can contact the manager or find solutions to do it yourself. Situations can be different, but long-term work overloads will not allow you to develop and threaten professional burnout.

Update plan

The plan should be flexible and easily adapt to new data obtained during its implementation. This is due to the fact that the planned intermediate achievements will differ from the actual ones. Based on the results obtained, it is worth revising your plan and adapting your further development.

Complex security solutions

With the development of computer companies, the question of the high-quality organization of the  IT infrastructure becomes inevitable. We are engaged in complex security of computer networks based on two solutions: terminal access and information encryption. This guarantees reliable data protection without limiting the capabilities of popular network technologies at all.

Terminal access

Terminal access is an arrangement that makes it possible to store a large amount of information on the server. At the workplaces of workers, there are no longer ordinary computers, but terminals that provide access to all programs and information on the server, and all calculations are also performed by the server. This makes it possible to achieve significant benefits in the networking process.

If your software is configured on a server, then there is no need to install programs on each computer separately.


What does a computer engineer do

Remote administration is possible. In this case, the administrator has the ability to perform all the necessary work over the Internet.

It takes only 10-20 minutes to organize a workplace. All you need to do is connect the necessary equipment, set up an account on the server and set the path to the required programs.

All data processing and calculations are carried out on the server, the conditions for thin clients are the least.

You get savings on software. Licensed programs that are not always used may be purchased in smaller quantities. On the server, you can see the number of simultaneous connections to the program, which will help you get rid of the need to purchase expensive software for each computer.

You can freely arrange workplaces for workers who are on business trips, are absent from the office for various reasons and for those who work outside the office.

The terminals are much quieter than computers and consume less electricity.

When using computers under normal conditions, the owners retain a lot of important materials, including those that contain trade secrets. When using thin clients, all employees are required to use server technology. This allows you to combine the entire scale of information in one place, which makes it easier to protect.

Data protection

Terminal access only half solves the issue of information protection. There is still a danger of unauthorized access, i.e. stealing the server with all its files. In order to ensure reliable security, you must use a file encryption system.

Limitation of rights. Restriction of rights sets the prohibition of access of other people's users to the personal information that they do not particularly need for work. Since all information is located remotely, it is possible to monitor, i.e. You can determine when, what time and from which computer there was a request for this or that information. In addition, you can prohibit the use of flash cards, CDs and DVDs. Storing all e-mails on the server allows you to track whether personal information is being sent by e-mail.

Encryption . All information is protected by encryption. This is done using reliable open algorithms, crypto resistance, which are proven by scientific methods. Either individual parts of hard drives or the entire drive are encrypted. The whole process takes place with encrypted files. Encoding and decoding takes place "in an instant". With the help of the "red button" you can block access to files at any time. This button is most often found at the company's management. If the files were stolen along with the hard drive, then the offenders simply will not be able to decrypt the data that is recorded on it. Each owner can have their own key that allows access to specific servers.

Backup . Theft of a server can be scary not only by the loss of information, but also by the fact that the process of work in the office will be suspended. Periodic copying of information helps to avoid such problems. The most efficient way is to back up to a server that will be located outside the company premises. Even if all of the equipment is suddenly stolen, it is very easy to resume work in the office by connecting existing thin clients or computers to a remote server.

If you have any problems with computer equipment, please contact us and choose the service " Integrated security solutions ". Specialists of our computer engineering center "Miass Center" with the help of new equipment will carry out " Integrated security solutions " in compliance with all technological standards. Relying on the broad technical base of our company, we significantly reduce the total repair time.

Friday, September 4, 2020

Scrum, BPM CBOK, TOGAF

Scrum is a flexible project management standard that helps businesses acquire project-specific specifics and thus stay afloat and grow. The standard allows an organization to build a Developer Operation and make always controlled changes to the business and its infrastructure. To understand the essence of the standard, the most important Scrum principles are formulated.

People and interactions are more important than processes and tools.

The work is done in small teams.

Performance is assessed at the team level, not the individual.

Self improvement.

Iterations. After each iteration or sprint, a working "product" should appear.

The Scrum standard is chosen when you need a simple, straightforward, logical, transparently manageable tool.

Scrum approaches to project implementation are extremely popular in companies that develop computer applications. Scrum courses are taught in IT training centers and specialized educational organizations.

The Business Process Management Common Body of Knowledge (BPM CBOK) is changing the way businesses view process management and the role of automation in managing processes and workflows within and between enterprises. This evolving standard, coupled with automation, has revolutionized rapid change management. BPM CBOK provides an innovative opportunity to optimize interactions with customers, suppliers and employees. The following BPM CBOK principles are formulated.

Transform, not just improve processes aws jobs.

Give leverage to clients.

Make processes global, standardized and human.

Leverage big data.

Doubling the focus on process competencies.

BPM CBOK uses a unified conceptual base of terms and provides a holistic approach to creating and managing business processes. Benchmarks for the implementation of BPM CBOK were developed and logically justified.

BPM CBOK courses are taught in business schools and education centers that develop project management curricula.

The Open Group Architecture Framework (TOGAF) allows you to assess the need to build an enterprise infrastructure and control changes in it. The main principle of TOGAF, any activity and changes in the infrastructure should create either new business opportunities or optimize existing activities. The main goal of TOGAF approaches should be the creation of the Value Chain. It is an architecturally holistic tool for building and maintaining infrastructure that is capable of addressing current and future business needs. 

TOGAF is necessary to create a long-term development plan for the company, for example, with the aim of obtaining investments or entering an IPO. It is a powerful tool for building a stable IT infrastructure for enterprises and organizations that will work reliably in the face of major changes. This ensures business continuity. TOGAF approaches help stabilize or increase business capitalization. It has tremendous benefits in the long run.

Thursday, September 3, 2020

Free Linux for work and creativity

Operating systems and applications of the Linux family are created by the world community of programmers and are freely distributed. Users can install and use, distribute and modify the software free of charge, and use it for commercial purposes.

For several decades, Linux distributions have been developed, supported and successfully used, targeting different users and different technical capabilities of computer technology. Distributions for beginners and home users, musicians and computer artists, cybersecurity specialists and hackers, system administrators and application developers have been created. There are lightweight distributions for legacy but working computers. There are specialized distributions that provide anonymity on the Internet, high performance, or, for example, optimized for scientific calculations. Enterprise distributions can be distributed commercially or free of charge.

Everyone wants to take advantage of Linux. Major IT companies create and maintain their Linux distributions, this helps them to better understand technology trends. Even Microsoft Windows 10 provides Windows Subsystem for Linux, a software compatibility layer for running Linux applications without virtualization. Note that the operating systems for iOS and Android mobile devices are also based on Linux technologies.

The Linux ecosystem is extremely diverse and therefore very resilient. It is admirable that the most complex software, which was created on a voluntary basis and distributed free of charge, is used all over the world on personal computers and servers, for the functioning of the Internet, in powerful data centers and even in supercomputers cloud architect job description.

The complexities of administration and work in operating systems of the Linux family are easily overcome thanks to the support of the world Linux community, as well as specialized courses of the Networking Technologies Training Center.

At our Learning Center, we love Linux very much, so we teach Linux courses in a comprehensive manner. Author's Linux courses have been developed for users, administrators and network specialists. There are courses on working with application containerization and databases. These are good, methodically verified study programs containing a large amount of theoretical material and, most importantly, practical training.

Take the Linux Professional Institute certification exams to prove your Linux expert knowledge. Several levels of certification are provided. You can prove your knowledge of the basics of the Linux operating system or become a certified professional who can administer the system, design and deploy small and medium-sized networks, and create a secure enterprise-scale IT infrastructure with the ability to virtualize and integrate Linux services. For experienced professionals, there is an opportunity to get certified as a DevOps engineer. Linux Professional Institute certification significantly increases the chances of an IT specialist to get a high-paying job and take part in interesting projects.

15% off VMware vSphere Course

TC "Network Technologies" invites you to the NT-VMware vSphere course "Deployment and management of VMware vSphere infrastructure" and provide a 15% discount to all students. Hurry up to take the opportunity!

The course will cover the most pressing issues: aws solution architect professional salary

Introduction to Virtualization and Cloud Technologies

ESXi hypervisor installation and basic configuration

Creating a virtual machine

Installing vCenter with vCenter Server Appliance (VCSA)

Hierarchy of vCenter infrastructure objects. Rights and roles

VCenter Server Maintenance

Configuring and managing virtual networks

Configuring and managing virtual storage

Virtual machine management

Backing up and restoring virtual machines

Resource allocation management

Increased Availability with vSphere HA and vSphere Fault Tolerance

vSphere Distributed Resource Scheduler (DRS)

vSphere Update Manager (VUM)

AutoDeploy

Troubleshooting Overview

The course will be useful for system administrators and engineers who have experience with Windows or Linux operating systems.

Tuesday, September 1, 2020

Cisco Collaboration Solution. UC 8.0

This event was held with the aim of introducing Cisco Systems products in the field of unified communications and with the aim of helping organizations to more closely integrate communication systems with business processes based on Cisco Systems products and technologies.

Attendees aws associate salary

Specialists with experience of working with traditional telephony, IT specialists, heads of departments.

Training level

Required experience of a PC user. Experience with Cisco technologies and knowledge of the principles of telephony is desirable.

Event plan

General information about IP telephony

General information about IP telephony

Benefits of switching to IP telephony

Building an IP telephony system based on Cisco Unified Communications Manager

Unified communication system

Presence technology

Audio, video, web conferencing

Gradual (smooth) transition from analog to IP telephony based on Cisco Unified - - Communications Manager and Cisco Unified Communications Manager Express

Telephone (landline, mobile)

Corporate telephony with you anywhere in the world

Voice messaging system

Integration with various systems

Integration with the email system

IM electronic messaging system

Integration with communication systems of other vendors

Video telephony

Laboratory works

Products and solutions reviewed

Cisco Unified Communications Manager 8.0

Cisco Unified Communications Manager Express 8.0

Cisco Unified Presence

Cisco Unity

Integration of Cisco Voicemail with MS Exchange

Active Directory and Cisco Unified Communications Manager 8.0

Integration of AD user database with UC Manager

Configuring Cisco IP Phones

Setting up mobile phones (Unified Mobility: Mobile Voice Access, Mobile Connect)

Connecting Remote Mobile Phones to Cisco Communications Manager

Cisco Meeting Place Express

Setting up and creating conferences

Connecting intra-office mobiles from Cisco and other manufacturers via wi-fi

Demonstration of Cisco Hardware Solutions to Improve Availability and Cost Savings

Building a video telephony system based on equipment and software Cisco Systems

Features of using the new series of Cisco phones

Cisco Unified Video Advantage

Integration of a video telephony system with products from Tandberg and other manufacturers