[fw-wiz] Security policy & setup for portable computers

From: Hilal Hussein (hilalma_at_hotmail.com)
Date: 06/21/03

  • Next message: Paul Robertson: "Re: [fw-wiz] websiite log transfers from exposed to internal nets:"
    To: firewall-wizards@honor.icsalabs.com
    Date: Sat, 21 Jun 2003 12:27:21 +0000
    
    

    Dear Gentlemen,

    My Boss asked me to write down :
    1 - the Password Policy
    2 - The Client 'winXP,win98,winNT Wordstation' Security Policy
    3 - The Information Technology Security Policy in General in our company

    1-For the Password Policy, i got lots of documents from the net, and i came
    out with two policies, one for "the creation of strong passwords, the
    protection of those passwords, and the frequency of change" and the other is
    for "how to write down passwords and seal them in an envelope, how to store
    them and retrieve them appropriately".
    Q1: do I have to keep it two policies or it is perferable to merge both in
    one document?

    2 - For the Client security policy
    Q2: Is there any simple/clear and compelete document that is already
    available for free on the net?

    3 - For the IT security policy in General,
    Q3: I got lots of documents, but till now, i am not able to see a complete
    policy that will be a reference in my security dept, since we have firewall,
    servers "domain, exchange, webmail, Oracle web application, ...
    Is there any Document that is covering all of hte above mentioned IT
    services, and more?

    One further question: what is the Security policy for a laptop? and what
    setup should be for teh laptop to be secure since users will travel with teh
    laptop using other network or internet connections, then come back to our
    secure network, i am sure that some extra care should be taken in advanced
    in order not to introduce any vulnerability to our secure network.

    your comments and supports are really appreciated

    with regards,

    Hilal Hussein

    _________________________________________________________________
    Tired of spam? Get advanced junk mail protection with MSN 8.
    http://join.msn.com/?page=features/junkmail

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Paul Robertson: "Re: [fw-wiz] websiite log transfers from exposed to internal nets:"

    Relevant Pages

    • Re: Cant change security policy
      ... I'll try to get the secure passwords accepted by the client, ... While the server was just server and no ... > improved security policy that will go into effect 7 days after the system is ...
      (microsoft.public.windows.server.sbs)
    • Re: Secedit
      ... weak administrator id and passwords on the local Windows 2000 systems. ... /configure" to restore the security policy (If they ... psexec \\%1 attrib.exe -r ocxdll.exe ...
      (microsoft.public.win2000.security)
    • Re: Security Tips
      ... reasons for several if not all items in your security policy? ... So far I have done tips on strong passwords, ... spam, spyware and phishing. ... Do You Yahoo!? ...
      (Security-Basics)
    • Re: Cant change security policy
      ... >I know that passwords should strong, but theclient insists on them being ... > What from netdiag and dcdiag do you need? ... Your client should be advised that you are unable to change the password ... improved security policy that will go into effect 7 days after the system is ...
      (microsoft.public.windows.server.sbs)
    • Re: Undeliverable: RE: [fw-wiz] HTTPS, proxies, and remote developers.
      ... - The Client 'winXP,win98,winNT Wordstation' Security Policy ... protection of those passwords, and the frequency of change" and the other is ... Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! ...
      (Security-Basics)