Network Security Assessment Checklist
This network assessment checklist is taken from Managing a Network Vulnerability Assessment by Thomas R. Peltier, Justin Peltier and John A. Blackley. What do you think? To much or?
- Unique user ID and confidential password required
- Additional identification required for remote access
- "Help" screen access available to logged-on users only
- Last session date and time message back to user at sign-on time
- Exception reports for disruptions in either input or output
- Session numbers for users/processors that are not constantly logged in
- Notification to users of possible duplicate messages
- Threshold of errors and consequential retransmission on the network related to management via automatic alarms
- Encryption requirements
- Encryption key management controls
- Message Authentication Code requirements for nonencrypted sensitive data transmission
- System authentication at session start-up (wiretap controls)
- Confirmation of host log-off to prevent line grabbing
- Downloading controls for connected intelligent workstations
- User priority designation process
- Transaction handling for classified communications
- Trace and snapshot facilities requirements
- Log requirements for sensitive messages
- Alternate path requirements between nodes
- Contingency plans for hardware as well as all usual system requirements
- Storage of critical messages in redundant locations
- Packet recovery requirements
- Physical access for workstations when units are not in use
- Control units, hubs, routers, cabinets secured
- Environmental control critical requirements
- Segregation for sections of the network that are deemed "untrustworthy"
- Gateway identification for authorized nodes
- Automatic disable of a user/account, line or port if evidence an attack is underway
- Naming convention to distinguish test messages from production
- User switching application controls
- Time-out reauthorization requirements
- Password changes (time/length/history) requirements
- Encryption requirements for passwords, security parameters, encryption keys, tables, etc.
- Shielding requirements for fiber-optic lines
- Controls to prevent wiretapping
- Reporting procedures for all interrupted telecommunication sessions
- Identification requirements for station/ terminal access connection to network
- Printer control requirements for classified information
- Appropriate "welcome" connection screens
- Dial-up access control procedures
- Anti-daemon dialer controls
- Standards for equipment, applications, protocols, operating environment
- Help desk procedures and telephone numbers
- Protocol converters and access method converters dynamic change control requirements
- LAN administrator responsibilities
- Control requirements to add nodes to the network
- Telephone number change requirements
- Automatic sign-on controls
- Telephone trace requirements
- FTP access controlled
- Are patches tested and applied?
- Software distribution current
- Employee policy awareness
- Emergency incident response plan/procedure
- Internal applications control
- Proper control of the development environment
- Software licensing compliance review
- Portable device (laptop/notebook/PDA) handling procedures
- Storage and disposal of sensitive data/information
- Default password controls and settings
- Review of off-site storage for disaster recovery resources
- Unnecessary services disabled
- Client server data transfer analyzed and secured
- Restrict telnet and r-commands (rlogin, rsh, etc.)
- Configuration management procedures
- Tracking port scans
- Review monitoring responsibilities
- Separation between test and production environment
- Strong dial-in authentication
- System administrator training
- Voice system protection procedures
- Tunneling for all remote access (inbound or outbound)
- Encryption of laptops
- Management awareness
- Program and system change control procedures
- Open "inbound" modem access for vendor support
- Modem usage policy
- Incident event coordination (procedures)
- Intrusion detection system (IDS) implementation and monitoring
- Monitoring Web site from attack (internal and external)
- Domain Name Server monitoring
- Hardware maintenance requirements
- Hard drive repair, maintenance, and disposal procedures
- BIOS (Basic Input/Output System) boot order
- E-mail content policy and monitoring
- E-mail forwarding policy (hopping)
- Spamming controls and testing procedures
- Employee termination and credential disablement
- After-hours sign-in logs
- Network sniffer policy, procedures, and monitoring
- Validity of e-mail accounts
- Background checks before hiring
- Administrator accounts and password controls
- Time synchronization procedures
- Establishment of a Security Committee
- Testing process for LAN applications
- Business unit security person designated
- Log and review of all Administrator changes
- Review and resolution of past audit comments
- Audit logs secured.
Trackback URL for this post:
http://www.securityprocedure.com/trackback/118
- Add new comment
- 24486 reads













That is one hell of a long
That is one hell of a long checklist. Anyways, I too can't find the link. Where is it?
offsite backup
Where is the link to
Where is the link to download?
I can´t see it.
Thanks.
Attitude is always pleasant
Attitude is always pleasant to enjoy the fruits of our labours, of course. Sometimes, however, it seems that whatever we do, it's just not enough to be able to afford that new car or that foreign holiday. So, what do we usually do then? We work harder, longer; we increase the stress on our minds and bodies; we spend less time with our families and friends; we become more irascible and less likeable people.
========================================
Testking E20-329// Testking HP0-M36// Testking HP0-Y30// Testking 646-223// Testking 640-801// Testking 646-671// Testking JN0-343// Testking 9L0-407//