Can You Recommend a Checklist for a Network Security Policy?
Posted on: Tuesday, 11 April 2006, 06:00 CDT
There are many threats that today's growing small businesses need to be concerned with. Paramount among these concerns are content-related and physical-access threats.
Content-related threats generally refer to access of content from the Internet by internal users of the network in violation of company policies. But a new type of content-related threat is an infected file that combines several stand-alone viruses or attack methods in one package. For example, the myDoom virus, using e-mail as its carrier, set up an SMTP e-mail relay engine on each computer it infected to propagate the virus throughout the network. These so-called blended threats are complex and often avoid detection entirely.
Unauthorized access to corporate network resources can occur in many forms. The most common example is an external hacker trying to gain access to equipment and information on a corporate network. Internal users represent a risk as well, either purposely or accidentally, by using restricted resources of the network. An internal user may even hide his or her identity by "spoofing" an IP address of a resource that already exists on the network.
Only a thorough, companywide security policy can protect your network equipment and information. It must be comprehensive enough to address both internal and external users of wired and wireless connections while ensuring that all access points of the network are properly defended.
A detailed security policy is the foundation for maintaining a secure enterprise network. Here are some of the key elements to consider when developing a security policy:
1. Lock up and monitor physical access to all core network resources.
2. Lock and password-protect all physical and logical ports of your network.
3. Lock network services such as FTP, SMTP, Telnet and Web. Additional network services should be allowed on an as-needed basis.
4. Install firewalls to protect all entry and exit points of the network.
5. Block external access to all internal resources, offering access on an exception basis only. This excludes public servers, which should be isolated from the rest of the network by placing them in a protected demilitarized zone (DMZ).
6. Secure all servers with a dedicated firewall to provide granular security and to enforce access privileges.
7. Connect remote sites to the main campus by secure VPN communication links with attack protection, strong user authentication, and data encryption.
8. Incorporate fail-over or redundant elements to protect pathways into and around the network.
9. Define and implement clear maintenance and update policies for keeping current all scanning and filtering software and hardware.
10. Inspect the broader context of supplier, partner and independent contractor connections to block blended threats at all access points.
___
(AllBusiness.com is a leading online resource offering advice and solutions for growing businesses. AllBusiness.com includes how-to articles, forms and agreements, directory listings, product comparisons and more. Send questions to experts@allbusiness.com.)
___
(c) 2006, Knight Ridder/Tribune Information Services.
For information on republishing this content, contact us at (800) 661-2511 (U.S.), (213) 237-4914 (worldwide), fax (213) 237-6515, or e-mail reprints@krtinfo.com.
Source: Knight Ridder/Tribune
Related Articles
- Novell Expands Endpoint Security Management With Network Access Control
- Celestix Is First to Announce Appliance Based on Microsoft Network Access Protection Platform
- Cisco and Microsoft Unveil Joint Architecture for NAC-NAP Interoperability; Security Architecture to Enable Customers and Partners to Deploy Interoperable Cisco Network Admission Control and Microsoft Network Access Protection
- Enterasys Networks Introduces Enterasys Sentinel, Industry's First Federated Solution for Secure Network Access Control
- A10 Networks Joins Microsoft's Network Access Protection Program to Accelerate Adoption of Secure, Identity-Aware Network Solutions
- Wincor Nixdorf Introduces ProTect/Enterprise Security Server Software Solution
- ConSentry Networks Joins Microsoft's Network Access Protection Program; ConSentry's Secure LAN Controller(TM) Enforces NAP Policies With In-Line, Secure Networking System
- American Security Resources Enters Discussions to Acquire Proprietary Hydrogen Fuel Cell Technology Company
- ENDFORCE Releases New Version of Its Network Access Control Software for Enterprises Seeking Protection From Non-Compliant Endpoints
- Extreme Networks to Develop Switch-Based Security Enhancements for Network Access Protection Technology From Microsoft
User Comments (0)


RSS Feeds