
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 32
n PolicyObjective7: Allinternalusers,aswellasallserversfrom the
Internal_Serverssegment, areallowedtosafelyaccesstheinternetviaproxying.
Intrusionviathisinternetlinkmustbeblocked.Therelevantpoliciesare
enforcedatISA_Cache,withadditionalprotectionsuchasJava/ActiveX
blockingprovidedbyNorton1_IDS,Norton2_IDSandNorton3_IDS.
WhydoweblockJavaandActiveXfortheusers?
JavaandActiveXmainlyrunontheusers’computers. Theyareclientside
Whydoweallowtheinternal serverstoaccesstheinternetviaproxying?
InGIAC,thereisnorealneedforserversintheInternal_Serverssegmentto
reachtheinternet.However,manyserversdorelyontheinternetasanupdate
medium(forexample,MicrosoftWindowsUpdate).Givingthemthecapability
toconnectallowscertaindegreeofflexibilityandproductivitygain.
WhydowedisallowtheRASuserstoaccessCritical_Resources?
InGIAC,theCritical_Resourcessegmentcontainsserverwithcriticaldatabase
records.Sincetheserecordscontaincriticalandsensitiveinformation,access
andupdatesmustbehandledseriously,andshouldbeconductedonlyinthe
office.Wedefinitelydonotwanttheserecordsto“leak”totheoutsideworldvia
thischannel.
WhydowedisallowtheRASuserstoaccesstheirowndesktops?
InGIAC,allresourcesaresupposedtobestoredintheservers.Byrestrictingthe
RASuserstoaccessonlytheservers,weareeffectivelyencouragingthemto
savefilesintheserversratherthantokeeplocalcopies.
Comentarios a estos manuales