58 Developing a pre-installation security plan
Educating users
policies, implementing them carefully, and confirming that they work as
intended.
Educating users
Your overall site policy involves a numbers of tasks. Of these, user education is
paramount
.
Publish your company’s security policy. Make sure your users are
informed of the determination of would-be invaders and the sophistication of
available password guessing programs. Make sure they understand how
common security breaches are and how costly they can be. These facts alone
dictate that users should be encouraged to select passwords that are difficult to
crack and to change passwords regularly.
Involving the user community
When developing the details of your security plan, you should solicit the input
of group managers or leaders on what services they require, for what users, and
so on. Explain to users the need for network security to protect private
information, intellectual property, and your business plans.
Notifying affected users
Before implementing policies, notify the user community of your proposed
policies. Doing so in advance can prevent unnecessary frustration on the part of
your users.
For instance, if you plan to limit Web services to a single server during specific
hours, let this be known to the affected groups and users. If you plan to pass all
email through a dedicated server, or if external users will be disallowed from
accessing certain systems by Telnet, consider passing these changes along
before implementation. Consulting users prior to implementation may save you
the time needed to fine-tune those policies later.
Taking a pro-active stance
Again, keep in mind that configuring a set of authorization rules on the security
gateway is just one piece of your overall security plan. To be effective, this plan
should also include:
■
Physical security of key systems (especially the security gateway)
■
Security risk training for users
■
Guidelines on passwords
■
Proprietary information policies
Содержание 4400 Series
Страница 20: ...16 Installing the appliance About model 4460 ...
Страница 58: ...54 License setup About Symantec Clientless VPN Gateway 4400 Series licenses ...
Страница 74: ...70 Developing a pre installation security plan Filling out worksheets ...
Страница 96: ...92 Specifications and safety Product certifications ...
Страница 100: ...4 Index ...