Network Security Assessment Checklist
This network assessment checklist is taken from Managing a Network Vulnerability Assessment by Thomas R. Peltier, Justin Peltier and John A. Blackley. What do you think? To much or?
- Unique user ID and confidential password required
- Additional identification required for remote access
- "Help" screen access available to logged-on users only
- Last session date and time message back to user at sign-on time
- Exception reports for disruptions in either input or output
- Session numbers for users/processors that are not constantly logged in
- Notification to users of possible duplicate messages
- Threshold of errors and consequential retransmission on the network related to management via automatic alarms
- Encryption requirements
- Encryption key management controls
- Message Authentication Code requirements for nonencrypted sensitive data transmission
- System authentication at session start-up (wiretap controls)
- Confirmation of host log-off to prevent line grabbing
- Downloading controls for connected intelligent workstations
- User priority designation process
- Transaction handling for classified communications
- Trace and snapshot facilities requirements
- Log requirements for sensitive messages
- Alternate path requirements between nodes
- Contingency plans for hardware as well as all usual system requirements
- Storage of critical messages in redundant locations
- Packet recovery requirements
- Physical access for workstations when units are not in use
- Control units, hubs, routers, cabinets secured
- Environmental control critical requirements
- Segregation for sections of the network that are deemed "untrustworthy"
- Gateway identification for authorized nodes
- Automatic disable of a user/account, line or port if evidence an attack is underway
- Naming convention to distinguish test messages from production
- User switching application controls
- Time-out reauthorization requirements
- Password changes (time/length/history) requirements
- Encryption requirements for passwords, security parameters, encryption keys, tables, etc.
- Shielding requirements for fiber-optic lines
- Controls to prevent wiretapping
- Reporting procedures for all interrupted telecommunication sessions
- Identification requirements for station/ terminal access connection to network
- Printer control requirements for classified information
- Appropriate "welcome" connection screens
- Dial-up access control procedures
- Anti-daemon dialer controls
- Standards for equipment, applications, protocols, operating environment
- Help desk procedures and telephone numbers
- Protocol converters and access method converters dynamic change control requirements
- LAN administrator responsibilities
- Control requirements to add nodes to the network
- Telephone number change requirements
- Automatic sign-on controls
- Telephone trace requirements
- FTP access controlled
- Are patches tested and applied?
- Software distribution current
- Employee policy awareness
- Emergency incident response plan/procedure
- Internal applications control
- Proper control of the development environment
- Software licensing compliance review
- Portable device (laptop/notebook/PDA) handling procedures
- Storage and disposal of sensitive data/information
- Default password controls and settings
- Review of off-site storage for disaster recovery resources
- Unnecessary services disabled
- Client server data transfer analyzed and secured
- Restrict telnet and r-commands (rlogin, rsh, etc.)
- Configuration management procedures
- Tracking port scans
- Review monitoring responsibilities
- Separation between test and production environment
- Strong dial-in authentication
- System administrator training
- Voice system protection procedures
- Tunneling for all remote access (inbound or outbound)
- Encryption of laptops
- Management awareness
- Program and system change control procedures
- Open "inbound" modem access for vendor support
- Modem usage policy
- Incident event coordination (procedures)
- Intrusion detection system (IDS) implementation and monitoring
- Monitoring Web site from attack (internal and external)
- Domain Name Server monitoring
- Hardware maintenance requirements
- Hard drive repair, maintenance, and disposal procedures
- BIOS (Basic Input/Output System) boot order
- E-mail content policy and monitoring
- E-mail forwarding policy (hopping)
- Spamming controls and testing procedures
- Employee termination and credential disablement
- After-hours sign-in logs
- Network sniffer policy, procedures, and monitoring
- Validity of e-mail accounts
- Background checks before hiring
- Administrator accounts and password controls
- Time synchronization procedures
- Establishment of a Security Committee
- Testing process for LAN applications
- Business unit security person designated
- Log and review of all Administrator changes
- Review and resolution of past audit comments
- Audit logs secured.
Trackback URL for this post:
http://www.securityprocedure.com/trackback/118
- Add new comment
- 13146 reads













That is one hell of a long
That is one hell of a long checklist. Anyways, I too can't find the link. Where is it?
offsite backup
Where is the link to
Where is the link to download?
I can´t see it.
Thanks.