Re: [fw-wiz] What challenges are security admins facing?

From: Paul Robertson (proberts_at_patriot.net)
Date: 05/28/03

  • Next message: Monkman, Brian: "RE: [fw-wiz] Benefit of firewall over NAT-only 'protected' networ k"
    To: ark@eltex.net
    Date: Wed, 28 May 2003 12:33:44 -0400 (EDT)
    

    On Wed, 28 May 2003 ark@eltex.net wrote:

    > Being a bit offtopic on firewall security audit discussion, i'd like
    > to remember a paper i wrote on security management problems. Unfortunately
    > the paper is in Russian thus having no value for the mailing list
    > subscribers, but i can recite key point here: the major problem is
    > responsibility and serious gap between de jure and de facto computers and
    > network usage policy. People DO use computers at their workplace for
    > personal needs and its OKAY. There are some cases when it is not

    Sometimes it's okay, and sometimes it's not- that's highly dependent on
    what that personal usage is (playing pirated copyrighted content would not
    be ok in most places, nor would browsing porn sites, and certainly handing
    out administrative accounts for your friends to use would be frowned
    upon.)

    > Enforcing a fascist set of restrictions just makes users extremely
    > creative to avoid it. Keeping restrictions reasonable makes it possible

    Getting rid of the creative ones tends to work like natural selection.

    [snip]

    > gets fscked really bad - but to make things work this way the administrator
    > should allow him to do it if it is really innocent. Otherwise he

    How does the admin kno wif it's "really innocent?"

    > Another problem is, again, management. Ever seen a big boss that
    > says "i need this videoconferencing software working today from my
    > desktop, so please poke a hole in firewall to make it work - it
    > is IMPORTANT! no, we do not have time for security analisys, we need
    > it NOW! No, i do not want to do it from dedicated notebook machine".
    > The point is obvious. Why designing and implementing
    > crafty security policy just to have it ruined this way?

    My standard answer of "No." worked for everyone from the person in the
    mail room to the CEO of a multibillion dollar company when I was running
    firewalls daily. Perhaps this too is part of the responsibility?

    Paul
    -----------------------------------------------------------------------------
    Paul D. Robertson "My statements in this message are personal opinions
    proberts@patriot.net which may have no basis whatsoever in fact."
    probertson@trusecure.com Director of Risk Assessment TruSecure Corporation

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Monkman, Brian: "RE: [fw-wiz] Benefit of firewall over NAT-only 'protected' networ k"

    Relevant Pages

    • [fw-wiz] UNSUBSCRIBE
      ... (Paul D. Robertson) ... > fixup protocol icmp error ... >> isn't about the security properties of the control, ... errors in the firewall, configuration errors, and it then takes physical ...
      (Firewall-Wizards)
    • [REVS] Bypassing Client Application Protection Techniques
      ... Get your security news from a reliable source. ... protection programs. ... * Kerio Personal Firewall 4.0 ... And we got actually nothing in the field of client application ...
      (Securiteam)
    • Re: Recycler security issues on IIS server
      ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...
      (microsoft.public.inetserver.iis.security)
    • Why hasnt Symantec addressed nastier Messenger spoofs
      ... Norton / Symantec has been silent on whether Norton Internet Security ... DSL firewall will stop these kinds of pop-ups. ... major ISPs and broadband systems. ...
      (comp.security.misc)
    • Re:RE : suggestions on a good firewall
      ... Subject: RE: suggestions on a good firewall ... CheckPoint does! ... with a url-filtering server. ... IT Technical Security Officer ...
      (Security-Basics)