Re: [fw-wiz] Where do firewall Admins Sit in An Company

From: Tony Miedaner (miedaner_at_twcny.rr.com)
Date: 06/03/03

  • Next message: Paul Stewart: "RE: [fw-wiz] pix vs. ios firewall feature set"
    To: firewall-wizards@honor.icsalabs.com
    Date: Tue, 03 Jun 2003 06:37:51 -0400
    

    Thanks for the reply.

    OK. Security develops policy and does approval of changes but where is
    oversight?

    Since obviously the networking and server folks do not wear a security hat,
    at least that is not what they get pay raises for.

    TIA

    At 09:40 PM 6/2/2003 -0400, Bill Royds wrote:
    >You really have to differentiate between firewall administration and
    >firewall rule development, although often they will be the same in smaller
    >places.
    >Firewall administration is part of operations, often servers if you are
    >looking at an application gateway running on a server OS, or networking if
    >it is an appliance or stateful inspection like a PIX working more closely
    >with the network.
    >But the firewall policy and rule development should be part of security, so
    >that rules fit needs of security policy, rather than the needs of
    >operational efficiency. This is alos a good form of separation of duties by
    >having at least two independent reviews of the ruleset so both operational
    >needs (availability) and security needs are fulfilled.
    >
    >
    >----- Original Message -----
    >From: "Tony Miedaner" <miedaner@twcny.rr.com>
    >To: <firewall-wizards@honor.icsalabs.com>
    >Sent: Monday, June 02, 2003 7:38 AM
    >Subject: [fw-wiz] Where do firewall Admins Sit in An Company
    >
    >
    >: Hi All,
    >:
    >: A couple questions:
    >:
    >: 1. Typically what part of an organization do firewall administrators
    >belong
    >: to in a large Enterprise (Example Networking, Server, Security)?
    >:
    >: 2. If the firewall administrators sit in a non-security group what type of
    >: oversight is typically performed over them.
    >:
    >:
    >: 3. If firewall administrators sit in a security group what type of
    >: oversight is done on them?
    >:
    >: TIA.
    >:
    >: _______________________________________________
    >: firewall-wizards mailing list
    >: firewall-wizards@honor.icsalabs.com
    >: http://honor.icsalabs.com/mailman/listinfo/firewall-wizards

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Paul Stewart: "RE: [fw-wiz] pix vs. ios firewall feature set"

    Relevant Pages

    • Logon Locally problem.
      ... Since this mixes security and networking, I am posting this in both ... is setup to logon locally to each Non-DC server. ... Policy, I try to add my Domain Group, but the "effective check" never ...
      (microsoft.public.win2000.security)
    • Logon Locally and blocked ports
      ... Since this mixes security and networking, I am posting this in both ... is setup to logon locally to each Non-DC server. ... Policy, I try to add my Domain Group, but the "effective check" never ...
      (microsoft.public.win2000.networking)
    • Re: problem mapping local drives in remote desktop session
      ... Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net ... It is running Windows 2003 Server R2. ... change I made was to uninstall enhansed IE security. ...
      (microsoft.public.windows.server.networking)
    • security-basics Digest of: get.123_145
      ... VPN to ASP a security risk? ... Re: Multiple IPSec tunnels? ... Subject: Security NT Server ... VPN to ASP a security risk? ...
      (Security-Basics)
    • << SBS News of the week - Sept 26 >>
      ... And he points to the info you need to put the file on the server in the ... at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... by the firewall at risk. ...
      (microsoft.public.backoffice.smallbiz2000)