Eicon Networks S92 Manuel d'utilisateur Page 32

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 209
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 31
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 32
n PolicyObjective7: Allinternalusers,aswellasallserversfrom the
Internal_Serverssegment, areallowedtosafelyaccesstheinternetviaproxying.
Intrusionviathisinternetlinkmustbeblocked.Therelevantpoliciesare
enforcedatISA_Cache,withadditionalprotectionsuchasJava/ActiveX
blockingprovidedbyNorton1_IDS,Norton2_IDSandNorton3_IDS.
WhydoweblockJavaandActiveXfortheusers?
JavaandActiveXmainlyrunontheusers’computers. Theyareclientside
Whydoweallowtheinternal serverstoaccesstheinternetviaproxying?
InGIAC,thereisnorealneedforserversintheInternal_Serverssegmentto
reachtheinternet.However,manyserversdorelyontheinternetasanupdate
medium(forexample,MicrosoftWindowsUpdate).Givingthemthecapability
toconnectallowscertaindegreeofflexibilityandproductivitygain.
WhydowedisallowtheRASuserstoaccessCritical_Resources?
InGIAC,theCritical_Resourcessegmentcontainsserverwithcriticaldatabase
records.Sincetheserecordscontaincriticalandsensitiveinformation,access
andupdatesmustbehandledseriously,andshouldbeconductedonlyinthe
office.Wedefinitelydonotwanttheserecordsto“leak”totheoutsideworldvia
thischannel.
WhydowedisallowtheRASuserstoaccesstheirowndesktops?
InGIAC,allresourcesaresupposedtobestoredintheservers.Byrestrictingthe
RASuserstoaccessonlytheservers,weareeffectivelyencouragingthemto
savefilesintheserversratherthantokeeplocalcopies.
Vue de la page 31
1 2 ... 27 28 29 30 31 32 33 34 35 36 37 ... 208 209

Commentaires sur ces manuels

Pas de commentaire