Re: [fw-wiz] httport 3snf

From: Al Potter (apotter@icsalabs.com)
Date: 10/22/02


To: "Robert E. Martin" <rmartin@fishburne.org>
From: Al Potter <apotter@icsalabs.com>
Date: Tue Oct 22 12:14:01 2002


Robert:

rmartin@fishburne.org said:
> This is a military School for 8-12 graders.. The key here is
> disipline.

I've been lurking quietly on this thread for a few days, waiting for you
to weigh back in as you have here. I strongly suspected what you say
above to be the case.

You have a policy / discipline / supervision issue. The firewall (or
other security device) can never enforce compliance with this type of
policy 100% (there's always a smarter hacker), but it can make deviation
more difficult, and provide an audit trail to assist the supervisor in
detecting and documenting policy violations. This brings the problem out
of IT and back into its proper realm, personnel supervision. People set
policy, have the discipline (or not) to follow policy, and supervise /
enforce compliance with policy.

Being in a military environment (and I have 9 years of active duty Army in
my past), you may have the luxury of what would be (viewed in many
corporate environments as) a draconian policy and enforcement environment.
 "$FOO is verboten. First time offenders will be counseled in writing.
Second time offenders will loose privileges for X days. Third time
offenders will be...."

Being in an educational environment, you have a challenge and IMHO
responsibility to educate these young people as to WHY the policy is there
(there IS a reason, right?). I'd recommend you take a look at Winn
Schwartau's book: Internet_&_Computer_Ethics_for_Kids_(and_Their_Parents_&_
Teachers_Who_Haven't_Got_a_Clue). It's designed to teach exactly these
kinds of lessons to exactly your target audience, and does a decent job of
discussing the issues.

In short:

        - Write a policy
        - Brief and educate your users on the issues, ethics and the policy
        - Empower the supervisors to monitor compliance and enforce the policy

The Firewall only helps with the last one.

Hope this helps....

AL

-- 
+------------------------------------------------------------------------+
| Al Potter                                                              |
| Manager, Network Security Labs                                         |
| ICSA Labs                                         apotter@icsalabs.com |
| www.icsalabs.com                                PGP Key ID: 0x58c95451 |
+------------------------------------------------------------------------+




Relevant Pages

  • Re: Planning A Group Policy Deployment
    ... construct for admin/mgmt of the computing environment (i.e. ... In a more ideal world one gets to factor policy settings so ... network functionality and domain wide network access issues. ... I am prejudiced when it comes to the guides you mention (as ...
    (microsoft.public.windows.group_policy)
  • RE: Ensuring Disabling/Uninstalation of Windows XP Firewall in LA N enviro.
    ... Since the Group Policy editor is really just a fancy GUI for making registry ... Ensuring Disabling/Uninstalation of Windows XP Firewall in LAN ... Since this is not an AD environment as yet, ...
    (Focus-Microsoft)
  • Re: Corporate Humour
    ... There is a third environment: ... Enron/Andersen thing to petty crap where some overling can "change" the policy, use vague phrases in memos and letters, and then after whatever has happened, "change back" the policy and if the higher-ups back the guy up, then he gets away with it. ... If there is a market for Y, and sales says "There is a market for Y" then the orders were passed on. ... IBM was very much like a military organization with dress codes, behavior codes, process codes/regulations/policies/etc. ...
    (sci.research.careers)
  • Re: Corporate Humour
    ... There is a third environment: ... Enron/Andersen thing to petty crap where some overling can "change" the policy, use vague phrases in memos and letters, and then after whatever has happened, "change back" the policy and if the higher-ups back the guy up, then he gets away with it. ... In academia, its a bunch of fiefdoms, within bigger fiefdoms, that are within even bigger fiefdoms (and if the chair doesn't get along with the dean? ... In industry, particularly in corporations, there's a tendency to dictate every aspect of one's existence, almost to the point of deciding what will served for breakfast or the colour of one's socks. ...
    (sci.research.careers)
  • Need "lessons learned" on using GPMC to migrate OUs, GPOs
    ... I need your thoughts / experiences with using Group Policy Managment Console ... to migrate OUs and GPOs created in a test lab environment. ... I created a BDC in our lab environment and synced the BDCs ...
    (microsoft.public.windows.server.active_directory)