42
Safe Mac, Happy Mac https://goo.gl/bCGJHU Resources and links:

Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

  • Upload
    others

  • View
    2

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Safe Mac, Happy Mac

https://goo.gl/bCGJHUResources and links:

Page 2: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Chris MillerAsst. Director Technology Services Eanes ISD

@EdTechChris EdTechChris.com

Shout out to my Apple SE:

Page 3: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

How can macOS keep our teachers and our kids safer?

Page 4: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Security is a ProcessIt’s about the journey

Privacy & Usability v. Security

Shifting Paradigms

Page 5: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Traditional ApproachWide open, standard OS architecture

Extensive “add-on” solutions for security

Increase security by disabling functionality

Page 6: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Modern Security ApproachDesigned for mobility

Security built in, not bolted on

Optimal user experience

Page 7: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

System Security

Data Security

App Security

Page 8: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

System Security

Page 9: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

System Security

Integrated hardware and software

Services off by default

Access permissions

System integrity protection

X Protect

Data Path Randomization

Page 10: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

User Types

Admin UsersOS X macOS

Page 11: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

User Types

Admin Users Standard Users

Page 12: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Software UpdatesOne of the most important practices for security on any OS

Updates are provided for all supported devices for free

Organizations can prompt a device to download and install updates through MDM*

Supports multiple generations

3

Page 13: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

System Integrity Protection

Includes protection for these parts of the system:

• /System• /usr• /bin• /sbin• Apps that are pre-installed with

OS X

Page 14: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

X Protect

• Virus & Malware Detection

• File Quarantine Aware

• Checks content against a plist of known vulnerabilities

Page 15: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Mobile Device Management

Secure device configuration

Configuration profiles can be locked, signed and encrypted

XML based configuration profiles covering security and network policies

Page 16: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Configuration Profiles

Page 17: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Device Enrollment Program

Page 18: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

MDM Server

How Device Enrollment Works

Apple School Manager

DEP Customer Account

Purchased from Apple

K-12

Purchased from Reseller

(higher ed only)

Page 19: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

EFI Firmware Password

Page 20: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Asset ProtectionNow being integrated into MDM

MDM + DEP + EFI = better asset protection

iOS allows some GPS location - will we see this with macOS?

Page 21: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

JAMF Pro MDM

Page 22: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Data Security

Page 23: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Keychain

Database for passwords, certificates, and encryption keys

Safe, Encrypted

Recover Lost Passwords

Page 24: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Passwords

Page 25: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

1231231234567890000000abc1231234adobe1macromediaazertyiloveyouaaaaaa654321

1231231234567890000000abc1231234adobe1macromediaazertyiloveyouaaaaaa654321

Page 26: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

• Go to HaveIBeenPwned.com

• Check to see if any of your user names or emails have been compromised.

Page 27: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud
Page 28: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

2 Factor Authentication

Page 29: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Filevault

Encrypted Disk Image

Pre-boot authenticationEFI Firmware based

Policy management through MDM

Recovery key management

Page 30: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Managed Apple IDs

Page 31: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

iCloud Backup

Secure transport to iCloud

Files backed up in their original, encrypted state

Backups taken when connected to power and on Wi-Fi

Device settings, app data, Photos, iMessage conversations, Desktop, Documents & more

Page 32: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Application Security

Page 33: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Cryptography

Page 34: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Certificates

Cryptographic Validation (FIPS 140-2)

Common Criteria Certification (ISO 15408)

Commercial Solutions for Classified (CSfC)

Security Configuration Guides

Page 35: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Privacy

Data Randomization

Obscured, Random Unique Identifiers

API’s designed to protect user identity

Page 36: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

App Security

Identity of developers verified for the apps available through App Store

Code signing

Keychain architecture

Runtime security

Page 37: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Gatekeeper

Security feature that helps prevent users from installing malicious apps.

Page 38: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Code Signing

Mandatory application signing*

Ensures app integrity and authenticity

Verified during app launch and runtime

Page 39: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Just Do 3 Things

• Update your junk

• Good password management

• Listen to your Mac (a.k.a. don’t do anything stupid.)

Page 40: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

MacAdmins Slack

Page 41: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

We’ve Finished!!!!

Page 42: Safe Mac, Happy Mac - ISTE Standards · 2017-06-27 · X Protect Data Path Randomization. User Types Admin Users OS X macOS. User Types ... iCloud Backup Secure transport to iCloud

Questions?

Contact Info:

Chris Miller Tw: @EdTechChris [email protected]