One of the first steps in security design is developing a security plan. A security plan isa high-level document that proposes what an organization is going to do to meet securityrequirements. The plan specifies the time, people, and other resources that will berequired to develop a security policy and achieve technical implementation of the policy.As the network designer, you can help your customer develop a plan that is practical andpertinent. The plan should be based on the customer’s goals and the analysis of networkassets and risks.A security plan should reference the network topology and include a list of network servicesthat will be provided (for example, FTP, web, email, and so on). This list should specifywho provides the services, who has access to the services, how access is provided, andwho administers the services.As the network designer, you can help the customer evaluate which services are definitelyneeded, based on the customer’s business and technical goals. Sometimes new servicesare added unnecessarily, simply because they are the latest trend. Adding services mightrequire new packet filters on routers and firewalls to protect the services, or additionaluser-authentication processes to limit access to the services, adding complexity to thesecurity strategy. Overly complex security strategies should be avoided because they canbe self-defeating. Complicated security strategies are hard to implement correctly withoutintroducing unexpected security holes.One of the most important aspects of the security plan is a specification of the peoplewho must be involved in implementing network security:■ Will specialized security administrators be hired?■ How will end users and their managers get involved?■ How will end users, managers, and technical staff be trained on security policies andprocedures?For a security plan to be useful, it needs to have the support of all levels of employeeswithin the organization. It is especially important that corporate management fully supportthe security plan. Technical staff at headquarters and remote sites should buy intothe plan, as should end users.
đang được dịch, vui lòng đợi..
