Eicon Networks S92 Uživatelský manuál Strana 32

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 209
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 31
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 32
n PolicyObjective7: Allinternalusers,aswellasallserversfrom the
Internal_Serverssegment, areallowedtosafelyaccesstheinternetviaproxying.
Intrusionviathisinternetlinkmustbeblocked.Therelevantpoliciesare
enforcedatISA_Cache,withadditionalprotectionsuchasJava/ActiveX
blockingprovidedbyNorton1_IDS,Norton2_IDSandNorton3_IDS.
WhydoweblockJavaandActiveXfortheusers?
JavaandActiveXmainlyrunontheusers’computers. Theyareclientside
Whydoweallowtheinternal serverstoaccesstheinternetviaproxying?
InGIAC,thereisnorealneedforserversintheInternal_Serverssegmentto
reachtheinternet.However,manyserversdorelyontheinternetasanupdate
medium(forexample,MicrosoftWindowsUpdate).Givingthemthecapability
toconnectallowscertaindegreeofflexibilityandproductivitygain.
WhydowedisallowtheRASuserstoaccessCritical_Resources?
InGIAC,theCritical_Resourcessegmentcontainsserverwithcriticaldatabase
records.Sincetheserecordscontaincriticalandsensitiveinformation,access
andupdatesmustbehandledseriously,andshouldbeconductedonlyinthe
office.Wedefinitelydonotwanttheserecordsto“leak”totheoutsideworldvia
thischannel.
WhydowedisallowtheRASuserstoaccesstheirowndesktops?
InGIAC,allresourcesaresupposedtobestoredintheservers.Byrestrictingthe
RASuserstoaccessonlytheservers,weareeffectivelyencouragingthemto
savefilesintheserversratherthantokeeplocalcopies.
Zobrazit stránku 31
1 2 ... 27 28 29 30 31 32 33 34 35 36 37 ... 208 209

Komentáře k této Příručce

Žádné komentáře