
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 184
AdministrativeSecurityAssessment
Foreveryfirewallandrouterinuse,determinethefollowing:
n Aretheyphysicallysecured?
n Doeslocalloginaccessrequire(asalways)validcredentialstobesupplied?
n Arethedefaultloginnames(suchasadministrator)removed?
n Whatistheminimumrequiredlengthoftheloginpassword?
n Whenthelocalconsoleisidlefor1minute,willanypasswordprotected
screensavercomeup?
n Howmanydifferentadministratorsareallowedtologin?Dotheyhaveseparate
setsofcredentials?
n Isthereanyestablishedprocedureforcontrollingthechangesofrulesorother
settingsonthefirewall?
n Whohaveaccesstothelocalfilesystemswherethefirewallproducts/logfiles
reside? Arethesecuritypolicyfiles/logfilesadequatelyprotectedbythefile
systemACLs?
FaultToleranceAssessment
Foreveryfirewallandrouterinuse,determinethefollowing:
n Arethelogfilesbackedupregularly?(Checkthebackuplogsheet)
n Arethebackuptapesthatholdthelogsprobablystored?
n Is theUPSrunning?DoesitconnectwellwiththecorrespondingOSservice?
Howaboutthebatterylevel?
n Isdiskmirroringfullyfunctional?
n Whatisthecurrentdiskspaceutilization?(Outofdiskspaceistheprimary
reasonforWindowsbasedmachinetocrash)
n Arethereanydifferenceinsettingsbetweentheproductionsystemandthe
standbysystem?(Anychangeinsettingsmadetotheproductionsystemmustbe
replicatedtothestandbysystemandtothebackupdiskimage)
Comentarios a estos manuales