您好,欢迎访问三七文档
当前位置:首页 > 商业/管理/HR > 市场营销 > 安徽省商品住宅销售Title
Copyright2001Marchany1BuildingYourITSecurityChecklistSamplechecklist/auditplansforUnix,NTandWindows2000ActiveDirectory销售信TheTop20threatsmeetourriskcriteria:•Haveahighprobabilityofoccurring•Resultinthelossofacriticalservice•Beextremelyexpensivetofixlater•Resultinheavy,negativepublicityCopyright2001Marchany3ApplyingTBStotherealworld!TBS=TimeBasedSecurityTopTenVulnerabilities,thevulnerabilitiesresponsibleformosthacksApplyTBSasanapproachtoaneffectiveunderstandablesecuritypolicyBasicsPerimeterUnixNTWindows2000Copyright2001Marchany4TheTBSAuditLayersAcompleteITaudit/securitychecklistisasetofcomponentaudits/checklists.YoushouldbeabletomeasureE,DandRtimesforeachlayerofthesecurityarchitecture.ComponentsProcedural:E=D+RPerimeter(Firewall):E=D+RUNIX:E=D+RNT/Windows2000:E=D+RCopyright2001Marchany5CISRulersRulerslistasetofminimalactionsthatneedtobedoneonahostsystem.ThisisaconsensuslistderivedfromsecuritychecklistsprovidedbyCISchartermembers(VISA,IIA,ISACA,FirstUnion,PitneyBowes,AllstateInsurance,DOJ,Chevron,ShellOil,VATech,Stanford,Catepillar,PacificGas&Electric,RCMP,DODCIRT,Lucent,EduTestingServicesandothers)Can’tdevelopyourownset?Usethese!Level1MandatoryActionsrequiredregardlessofthehost’slocationorfunction.Level2DependentonyournetworktopologyDifferentforswitchednetsvs.sharednetsvs.wirelessnets,etc.Copyright2001Marchany7CISRulers:SecurityChecklist&AuditPlanLevel3ApplicationSpecific()ProceduralExaminesthepoliciesinplace.Thisisthepolicyreviewchecklist.FTPGeneralAdministrationPoliciesKeysecuritytoolinstalledUserAccountsandenvironmentSystemLogsNetworkFilesharingGeneralEmailIssuesThisreviewisdoneduringtheAuditPlanningPhaseoftheauditprocessCopyright2001Marchany9CISRuler:ProceduralGeneralAdministrationPoliciesAcceptableUsePolicyBackupPolicySecurityAdministratordutiesWhoisContactInformation(Tech/Admin)Systemchangelogs(SourceRevisionControl)IncidentResponseMinimumsoftwarerequirementsUser,temp,systemaccountpoliciesPatchesCopyright2001Marchany10CISRulerExample:Backups·Doesabackuppolicyexist?·Dobackuplogsexist?·Whatdataisbackedup·Howoftendataisbackedup·Typeofbackup(full,differential,etc.)·Howthebackupsarescheduledandverified·Howthebackupmediaishandledandlabeled·Howthebackupmediaisstored·Howlongthebackupmediaisretained·Howbackupmediaisrotatedandexpired·HowbackupdataisrecoveredCopyright2001Marchany11CISRuler:ProceduralKeysecuritytoolsinstalledNetworkroutersimplementminimumfilteringrequirementsVerifynetworkroutersareproperlyconfiguredandmonitoredforin/outtrafficAreallfirewallsproperlyconfiguredandmonitoredforin/outtrafficTheaboverulespreventDDOSattacksfromaffectingothernets.Copyright2001Marchany12CISRuler:ProceduralUserAccountsandEnvironmentRemoveobsoleteuserentriesfromsystemSystemLogsHowlongaretheykept?Aretheysecured?NetworkfilesharingReviewwhatfilesystemsthissystemcanaccessReviewwhatfilesystemsthissystemexportsEmailPolicyAbusePolicy?Copyright2001Marchany13CISRuler:WrittenDocumentation,PoliciesWhereisit?Isitavailabletoanyonethatneedsit?Isituptodate?Isanythingmajormissing(SGIpolicies,butnoHPpolicies)?Copyright2001Marchany14CISRulerExample:SecurityPolicyPurpose-thereasonforthepolicy.Relateddocuments–listsanydocuments(orotherpolicy)thataffectthecontentsofthispolicy.Cancellation-identifiesanyexistingpolicythatiscancelledwhenthispolicybecomeseffective.Background-providesamplifyinginformationontheneedforthepolicy.Copyright2001Marchany15CISRuler:Scope-statestherangeofcoverageforthepolicy(towhomorwhatdoesthepolicyapply?).Policystatement-identifiestheactualguidingprinciplesorwhatistobedone.Thestatementsaredesignedtoinfluenceanddeterminedecisionsandactionswithinthescopeofcoverage.Thestatementsshouldbeprudent,expedient,and/oradvantageoustotheorganization.Action-specifieswhatactionsarenecessaryandwhentheyaretobeaccomplished.Responsibility-stateswhoisresponsibleforwhat.Subsectionsmightidentifywhowilldevelopadditionaldetailedguidanceandwhenthepolicywillbereviewedandupdated.Copyright2001Marchany16Procedural:IncidentResponsePlanArethesixIncidentResponsestepscovered?PreparationIdentificationContainmentEradicationRecoveryLessonsLearned(iftherearenolessonslearneddocumentseithertheplanisn’tfollowedornoincidentshaveoccurred).Copyright2001Marchany17Procedural:Training&EducationDotechnicalpeoplehavethetrainingtodotheirjobcompetently?Aretherestandardstheirskillscanbemeasuredagainst?Aretherestandardsofcompliancethatensuretheyareusingtheirtraininginaccordancewithpolicy?Copyright2001Marchany18Procedural:PhysicalSecurityConsolesinphysicallysecureareas?Firesuppression?Backups?Offsitebackups?Networkcomponentssecured?Phonewiringsecured?Copyright2001Marchany19Procedural:Windows2000ThesearebasedontheSANS“SecuringWindows2000”
本文标题:安徽省商品住宅销售Title
链接地址:https://www.777doc.com/doc-1704870 .html