Eicon Networks S92 Manual de usuario Pagina 32

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 209
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 31
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 32
n PolicyObjective7: Allinternalusers,aswellasallserversfrom the
Internal_Serverssegment, areallowedtosafelyaccesstheinternetviaproxying.
Intrusionviathisinternetlinkmustbeblocked.Therelevantpoliciesare
enforcedatISA_Cache,withadditionalprotectionsuchasJava/ActiveX
blockingprovidedbyNorton1_IDS,Norton2_IDSandNorton3_IDS.
WhydoweblockJavaandActiveXfortheusers?
JavaandActiveXmainlyrunontheusers’computers. Theyareclientside
Whydoweallowtheinternal serverstoaccesstheinternetviaproxying?
InGIAC,thereisnorealneedforserversintheInternal_Serverssegmentto
reachtheinternet.However,manyserversdorelyontheinternetasanupdate
medium(forexample,MicrosoftWindowsUpdate).Givingthemthecapability
toconnectallowscertaindegreeofflexibilityandproductivitygain.
WhydowedisallowtheRASuserstoaccessCritical_Resources?
InGIAC,theCritical_Resourcessegmentcontainsserverwithcriticaldatabase
records.Sincetheserecordscontaincriticalandsensitiveinformation,access
andupdatesmustbehandledseriously,andshouldbeconductedonlyinthe
office.Wedefinitelydonotwanttheserecordsto“leak”totheoutsideworldvia
thischannel.
WhydowedisallowtheRASuserstoaccesstheirowndesktops?
InGIAC,allresourcesaresupposedtobestoredintheservers.Byrestrictingthe
RASuserstoaccessonlytheservers,weareeffectivelyencouragingthemto
savefilesintheserversratherthantokeeplocalcopies.
Vista de pagina 31
1 2 ... 27 28 29 30 31 32 33 34 35 36 37 ... 208 209

Comentarios a estos manuales

Sin comentarios