Re: [fw-wiz] Security policy language



Hi Marco,

Marco Cremonini, 24 janvier 2007 09:51

The problem is: We would like to implement/adopt a high-level
specification language for the definition of a security
policy, something that should let to specify the policy at
organizational level. Such a policy should then be
translated into specific fw rules.

The problem is that the main part of a security policy is not technical but
organizationnal, and have to deal with human behavior!

Example: if your security policy tell that it is not allowed to surf non
professionnal website. You only need to check that there is no violation of this
rule (read web proxies log analysis). What you don't need is to use url
filtering system.

About the human part of the security policy:
1/ make people learn it and understand the whereabouts, [1]
2/ check if violations of the policy exist,
3/ have people explain why they don't respect the policy. [2]

Only the technical part of the policy have to be enforce by technical means
(example: designing DMZ to isolate IN and OUT networks).

[1] Yes... I know Marcus point of view: user education is one of the worst
security idea.
[2] User (and manager!) education is need, but is not enough. It's just a
beginning: telling users that doing that or that is bad is not enough, you have
to show them why, and spot them when they did bad things. User are like child
when you come to security: they have to be educated. The bad point is that users
are *adult*, and they don't want to be educated because they are convinced they
allready are!

JDG
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Fwd: Oh Dear, Where to start?!
    ... It seems to me you need two things: an organizational policy, ... finish college and break into the real world of computer security. ... experience in the field of network security and policy ... updates, driver updates, and recommended updates. ...
    (Security-Basics)
  • RE: [fw-wiz] PIX vs Checkpoint vs Sonicwall vs Netscreen - comme nts?
    ... All NetScreen appliances rely on custom-designed ASICs (Application ... Specific Integrated Circuits) for security policy enforcement. ... supports a finite number of "rules" or "policies". ...
    (Firewall-Wizards)
  • RE: Cant set Local Security policies. They fail to save
    ... predefined Security Template on SBS 2003 to restore security groups ... run "gpupdate.exe /force" under command prompt to force the policy ... reboot the Server to test. ... and then logon to client computer to test if user can save system logs. ...
    (microsoft.public.windows.server.sbs)
  • RE: [fw-wiz] PIX vs Checkpoint vs Sonicwall vs Netscreen - comme nts?
    ... The report you cite is CheckPoint originated and deals with older NetScreen ... All NetScreen appliances rely on custom-designed ASICs (Application ... Specific Integrated Circuits) for security policy enforcement. ...
    (Firewall-Wizards)
  • Re: No Shut Down or Restart for Domain Admins
    ... run rsop.msc from your DC and check which policy is responsible to this. ... I have created a group policy in a development network and imported it ... NT AUTHORITY\Authenticated Users Read (from Security Filtering) No ... Enforce user logon restrictions Enabled ...
    (microsoft.public.windows.server.active_directory)