Enabling firewalls
A firewall is a set of virtual rules that help prevent malicious applications from communicating with a device. They should be enabled on all compatible workplace devices.
Why is it important?
Firewalls control communication to and from a device. They're a set of rules which manage traffic. Without one, malicious programs can interact with the device and cause harm.
Priority Tier
Behaviours in SebDB are ranked by their impact on risk. Tier 1 behaviours have the biggest impact, Tier 4 behaviours the least.
Risk Mitigated
Malware Infection
Malware infections occur when malicious software makes its way on to a device or network.
Data Theft
Data theft is the intentional stealing of data.
Further reading
https://www.ncsc.gov.uk/collection/10-steps-to-cyber-security?curPage=/collection/10-steps-to-cyber-security/the-10-steps/network-security https://www.ncsc.gov.uk/whitepaper/security-architecture-anti-patterns#section_5 https://www.cisco.com/c/en_uk/products/security/firewalls/what-is-a-firewall.html https://www.us-cert.gov/ncas/tips/ST04-004