Re: General security issues

From: Chuck (none_at_example.com)
Date: 12/06/03


Date: 5 Dec 2003 17:24:09 -0600

On Fri, 5 Dec 2003 12:12:28 -0800, "Doug"
<anonymous@discussions.microsoft.com> wrote:

>>Thanks for the info. We are county government. I will
>not be the person responsible to implement/manage the
>server. We have an IT person on staff that will manage
>the server. My questions come because I will be
>helping/support the financial/pr applications. One of my
>main concerns is response and security on the server.

OK, Doug,

You're application support, and you'll be supporting an application
running on a server provided and maintained by IT.

Concerns off the top of my head (amended):
1) Server patch management. Will you be involved in server patch
management? Microsoft patches have been known to break applications
running on servers. Will there be a patch testing, approval, and
rollback process?
2) Application security. Will you use Active Directory, will the
application be AD aware, or will it have its own authentication /
authorisation mechanism?
3) Data backup. Will you depend upon backup support from IT, or will
you be responsible for that?
4) Application Support. Is the application being developed in-house,
is it a custom job by an outside firm, or is it "shrinkwrap" off the
shelf?
5) Server Resources. You'll be sharing a server with email and file
sharing (internet eventually?). Application, email, and file sharing
each place a different load and instability risk on a server. Does
your government agency have a good security policy to deal with
internal and external technological threats? If your application gets
trashed by a file sharing or internet originated virus or worm, will
you be responsible?
6) Server Access - Physical and Logical. The server will be owned
and supported by IT. Will there be good controls re physical and
logical access to a) Identify past access in case of a problem, b)
Limit future access to prevent problems. Will you have the access
needed to do your job?
7) Desktop Support Needs. You'll be supporting an application which
will have desktop involvement. Will you support the application on
the desktop, if not, how will the support responsibility (desktop /
server) be delineated? How easily will the desktop portion of your
application integrate with the desktop platform as a whole?

Cheers,

Chuck
I hate spam - PLEASE get rid of the spam before emailing me!
Paranoia comes from experience - and is not necessarily a bad thing.



Relevant Pages

  • NFS locking
    ... We have a NFS server here with a fairly high load. ... lockd: server xxx.xxx.xxx.xxx not responding, ... # ACPI Support ... # CD-ROM/DVD Filesystems ...
    (Linux-Kernel)
  • RE: Non-negative number required. Parameter name: byteCount
    ... Is your ASP.NET server service built on ASP.NET 1.1 or 2.0? ... The problem however is that the content (or error message) returned from ... InvalidOperationException with the message text of client found response ... Microsoft MSDN Online Support Lead ...
    (microsoft.public.dotnet.framework.aspnet.webservices)
  • NFS problems with through 2.5.x to 2.6.0-test9
    ... When the server is running the ... kernel, as a client the 2.6 series seem to work perfectly, excluding ... Interesting problem arose when I attempted switch the server's kernel to ... with and without nfsv4 support compiled in (was considering testing it at ...
    (Linux-Kernel)
  • RE: Backups, VSS and SBS2003 HELP NEEDED!!!
    ... 2K3 server currently, also, I understand that it is better to have a backup ... Support Professional can assist with your request. ... Microsoft CSS Online Newsgroup Support ... >> suggest customers Only install Windows Server 2003 SP1 on their server. ...
    (microsoft.public.windows.server.sbs)
  • Re: about image rotating
    ... Thanks to everyone's response and informaton. ... on GDI+ image transformation: ... Microsoft MSDN Online Support Lead ... how could I rotate a server side image in asp.net and show it ...
    (microsoft.public.dotnet.framework.aspnet)