. Clearly define the areas of responsibility for the users, the administrators, and the managers . Be communicated to all once it is established . Be flexible to the changing environment of a computer network since it is a living document Operating Systems and Applications: Versions and Updates As much as possible, use the latest available and stable versions of the operating systems and the applications on all of the following computers on the network: clients, servers, switches, routers, firewalls and intrusion detection systems. Keep the operating systems and the applications current by installing the latest updates (e.g., patches, service packs, hotfixes), especially updates that correct vulnerabilities that could allow an attacker to execute code. Note that some updates may not be applied to the computer until a reboot occurs. The following applications should be given particular attention because they have been frequently targeted (e.g., by CodeRed, Melissa virus, Nimda): IIS, Outlook, Internet Explorer, BIND and Sendmail.
Know Your Network
Developing and maintaining a list of all hardware devices and installed software is important
|