Comprehensive AAP and Powerpoint slide.
WWTC Security Policies Guide
Contents WWTC Acceptable Use 2 Connections to Remote Network 4 Network Users and Customer Data Privacy 5 Approved Devices 7 WWTC Physical Security 8 Network Security 15 Server/Workstation Security Policies 18 Vulnerability Management 22
WWTC Acceptable Use
1. Policy
1.1 While WWTC’s network administration desires to provide a reasonable level of
privacy, users should be aware that the data they create on the corporate systems remains the property of WWTC. Because of the need to protect WWTC’s network, management cannot guarantee the confidentiality of information stored on any network device belonging to WWTC.
1.2. Employees are responsible for exercising good judgment regarding the reasonableness of personal use. Individual departments are responsible for creating guidelines concerning personal use of Internet/Intranet/Extranet systems. In the absence of such policies, employees should be guided by departmental policies on personal use, and if there is any uncertainty, employees should consult their supervisor or manager.
1.3. InfoSec recommends that any information that users consider sensitive or vulnerable be encrypted. For guidelines on information classification, see InfoSec’s Information Sensitivity Policy. For guidelines on encrypting email and documents, go to InfoSec’s Awareness Initiative.
1.4. For security and network maintenance purposes, authorized individuals within WWTC may monitor equipment, systems and network traffic at any time, per InfoSec’s Audit Policy.
1.5. WWTC reserves the right to audit networks and systems on a periodic basis to ensure compliance with this policy.
2. Security and Proprietary Information
2.1. The user interface for information contained on Internet/Intranet/Extranet-related systems should be classified as either confidential or not confidential, as defined by corporate confidentiality guidelines, details of which can be found in Human Resources policies. Examples of confidential information include but are not limited to: company private, corporate strategies, competitor sensitive, trade secrets, specifications, customer lists, and research data. Employees should take all necessary steps to prevent unauthorized access to this information.
2.2. Keep passwords secure and do not share accounts. Authorized users are responsible for the security of their passwords and accounts. System level passwords should be changed quarterly, user level passwords should be changed every six months.
2.3. All PCs, laptops and workstations should be secured with a password-protected screensaver with the automatic activation feature set at 10 minutes or less, or by logging-off (control-alt-delete for Win2K users) when the host will be unattended.
2.4. Use encryption of information in compliance with InfoSec’s Acceptable Encryption Use policy.
2.5. Because information contained on portable computers is especially vulnerable, special care should be exercised. Protect laptops in accordance with the .Laptop Security Tips.
2.6. Postings by employees from a WWTC email address to newsgroups should contain a
disclaimer stating that the opinions expressed are strictly their own and not necessarily those of WWTC, unless posting is in the course of business duties.
2.7. All hosts used by the employee that are connected to the WWTC Internet/Intranet/Extranet, whether owned by the employee or WWTC, shall be continually executing approved virus-scanning software with a current virus database. Unless overridden by departmental or group policy.
2.8. Employees must use extreme caution when opening e-mail attachments received from unknown senders, which may contain viruses, e-mail bombs, or Trojan horse code.).
3. Policy Compliance
3.1 Compliance Measurement
The Infosec team will verify compliance to this policy through various methods, including but not limited to, periodic walk-thrus, video monitoring, business tool reports, internal and external audits, and feedback to the policy owner.
3.2 Exceptions
Any exception to the policy must be approved by the Infosec team in advance.
3.3 Non-Compliance
An employee found to have violated this policy may be subject to disciplinary action, up to and including termination of employment.
Connections to Remote Network
1. Policy
It is the responsibility of WWTC employees, contractors, vendors and agents with remote access privileges to WWTC's corporate network to ensure that their remote access connection is given the same consideration as the user's on-site connection to WWTC.
General access to the Internet for recreational use through the WWTC network is strictly limited to WWTC employees, contractors, vendors and agents (hereafter referred to as “Authorized Users”). When accessing the WWTC network from a personal computer, Authorized Users are responsible for preventing access to any WWTC computer resources or data by non-Authorized Users. Performance of illegal activities through the WWTC network by any user (Authorized or otherwise) is prohibited. The Authorized User bears responsibility for and consequences of misuse of the Authorized User’s access. For further information and definitions, see the Acceptable Use Policy.
Authorized Users will not use WWTC networks to access the Internet for outside business interests.
2. Requirements
2.1 Secure remote access must be strictly controlled with encryption (i.e., Virtual Private Networks (VPNs)) and strong pass-phrases. For further information see the Acceptable Encryption Policy and the Password Policy.
2.2 Authorized Users shall protect their login and password, even from family members.
2.3 While using a WWTC-owned computer to remotely connect to WWTC's corporate network, Authorized Users shall ensure the remote host is not connected to any other network at the same time, with the exception of personal networks that are under their complete control or under the complete control of an Authorized User or Third Party.
2.4 Use of external resources to conduct WWTC business must be approved in advance by InfoSec and the appropriate business unit manager.
2.5 All hosts that are connected to WWTC internal networks via remote access technologies must use the most up-to-date anti-virus software (place url to corporate software site here), this includes personal computers. Third party connections must comply with requirements as stated in the Third Party Agreement.
2.6 Personal equipment used to connect to WWTC's networks must meet the requirements of WWTC-owned equipment for remote access as stated in the Hardware and Software Configuration Standards for Remote Access to WWTC Networks
3. Policy Compliance
3.1 Compliance Measurement
The Infosec Team will verify compliance to this policy through various methods, including but not limited to, periodic walk-thrus, video monitoring, business tool reports, internal and external audits, and inspection, and will provide feedback to the policy owner and appropriate business unit manager.
3.2 Exceptions
Any exception to the policy must be approved by Remote Access Services and the Infosec Team in advance.
3.3 Non-Compliance
An employee found to have violated this policy may be subject to disciplinary action, up to and including termination of employment.
Network Users and Customer Data Privacy
1 .Policy
1.1 Employees are required to ensure that all sensitive/confidential information in hardcopy or electronic form is secure in their work area at the end of the day and when they are expected to be gone for an extended period.
1.2 Computer workstations must be locked when workspace is unoccupied.
1.3 Users must log out of the computer workstations at the end of the work day
1.4 Any Restricted or Sensitive information must be removed from the desk and locked in a drawer when the desk is unoccupied and at the end of the work day.
1.5 File cabinets containing Restricted or Sensitive information must be kept closed and locked when not in use or when not attended.
1.6 Keys used for access to Restricted or Sensitive information must not be left at an unattended desk.
1.7 Laptops must be either locked with a locking cable or locked away in a drawer.
1.8 Passwords may not be left on sticky notes posted on or under a computer, nor may they be left written down in an accessible location.
1.9 Printouts containing Restricted or Sensitive information should be immediately removed from the printer.
1.10 Upon disposal Restricted and/or Sensitive documents should be shredded in the official shredder bins or placed in the lock confidential disposal bins.
1.11 Whiteboards containing Restricted and/or Sensitive information should be erased.
1.12 Lock away portable computing devices such as laptops and tablets.
1.13 Treat mass storage devices such as CDROM, DVD or USB drives as sensitive and secure them in a locked drawer . All printers and fax machines should be cleared of papers as soon as they are printed; this helps ensure that sensitive documents are not left in printer trays for the wrong person to pick up.
2. Policy Compliance
2.1 Compliance Measurement
The Infosec team will verify compliance to this policy through various methods, including but not limited to, periodic walk-thrus, video monitoring, business tool reports, internal and external audits, and feedback to the policy owner.
2.2 Exceptions
Any exception to the policy must be approved by the Infosec team in advance.
2.3 Non-Compliance
An employee found to have violated this policy may be subject to disciplinary action, up to and including termination of employment.
Approved Devices
1. Policy
WWTC staff may only use WWTC removable media in their work computers. WWTC removable media may not be connected to or used in computers that are not owned or leased by the WWTC without explicit permission of the WWTC InfoSec staff. Sensitive information should be stored on removable media only when required in the performance of your assigned duties or when providing information required by other state or federal agencies. When sensitive information is stored on removable media, it must be encrypted in accordance with the WWTC Acceptable Encryption Policy.
Exceptions to this policy may be requested on a case-by-case basis by WWTC-exception procedures.
2. Policy Compliance
2.1 Compliance Measurement
The Infosec team will verify compliance to this policy through various methods, including but not limited to, periodic walk-thrus, video monitoring, business tool reports, internal and external audits, and feedback to the policy owner.
2.2 Exceptions
Any exception to the policy must be approved by the Infosec team in advance.
2.3 Non-Compliance
An employee found to have violated this policy may be subject to disciplinary action, up to and including termination of employment.
WWTC Physical Security
1. Physical Security Policies
1.1. Office Exterior
1.1.1. Outside hallway & elevator area must be kept clean and without any large decorations to prevent obstructions or block line of site.
1.2. Lobby
1.2.1. All non-employees must enter through lobby
1.2.2. All employees must check in with security for badge and escort to enter the office area.
1.2.3. Guest bathroom is located in lobby to prevent the need for guests to enter the office area.
1.3. Security System
1.3.1. Security Staff is responsible for maintaining security monitoring using cameras, walkthroughs, and other techniques 24/7.
1.3.2. Motion detectors must be used after hours in key areas.
1.3.3. Emergency buttons will be located at all security stations.
1.4. Security Cameras
1.4.1. Security cameras will be used for safety and security purposes.
1.4.2. Security camera footage will have one month retention. Recorded footage may only be accessed by security personnel for official purposes.
1.4.3. Live feed monitoring of all non-classified cameras will be done in the security office located off the lobby.
1.4.4. External
1.4.4.1. Cameras will be located in the external hallway and elevator lobby.
1.4.4.2. Camera footage will be recorded 24/7.
1.4.4.3. Live monitoring of camera feed will be performed by security staff.
1.4.5. Internal
1.4.5.1. Cameras will be located in the lobby, hallways, and all key areas.
1.4.5.2. Cameras will be used on the server room door and external door to the classified area to monitor access.
1.4.5.3. Camera footage will be recorded 24/7.
1.4.5.4. Live monitoring of camera feed will be performed by security staff.
1.4.6. Classified network area & classified security check point
1.4.6.1. Closed circuit cameras will monitor and record footage on a on a separate DVR located inside the classified area.
1.4.6.2. Camera footage will be recorded 24/7.
1.4.6.3. Live monitoring of camera feed will be performed by security staff.
1.5. Security Staff
1.5.1. Security Manager
1.5.1.1. Security Manager is responsible for managing all security staff.
1.5.1.2. Security Manager is responsible for issuing all WWTC smart cards.
1.5.2. Security staff
1.5.2.1. Responsible for checking for physical media/drives or other banned items when entering/exiting classified network area
1.5.2.2. Must complete organization training, including incident response
1.5.2.3. One staff member at all times at security office(off of lobby) and classified security check point
1.5.3. Security office
1.5.3.1. Responsible for monitoring all live camera footage.
1.5.3.2. Responsible for issuing guest passes to all authorized contractors, clients, and guests.
1.5.3.3. Arrange escorts for all authorized contractors, clients, and guests.
1.6. Smart Cards
1.6.1. Smart cards will be used to validate individual access to all WWTC office areas beyond the lobby
1.6.2. Smart cards must be used to control building access.
1.6.3. Smart cards must be used to control network access. Cards must be tied to user’s network account.
1.6.4. All employees must complete required documentation to be issued a smart card. Documentation must have the signature of the employee’s supervisor, department head & security manager to be valid.
1.6.5. Smart cards will be used as employee ID cards. All cards must have individual photos.
1.6.6. All employees are required to display smart cards at all times when away from their workstation. This prevents users from leaving their card in computer smart card readers when away from their workstation. It also identifies them as employees to security staff
1.6.6.1. Badge holders will be issued to all employees when the smart card is issued.
1.6.6.2. Smart cards must be removed when leaving the office area.
1.6.7. Only Security Manager & CTO are authorized to have admin access to smart card system
1.7.1. Card reader locks will be used to read all WWTC smart cards, which are used to control employee access rights.
1.7.2. Card readers will be used to provide an audit trail for all entry points
1.7.3. Card Readers will be located at
1.7.3.1. All lobby entrances to office space
1.7.3.2. Classified network area outside door
1.7.3.3. Server Room
1.7.3.4. All offices and shared work spaces
1.8. Classified Material Area
1.8.1. The classified area can only be access through the security check point. This area is accessible through an external door by employees who have authorized smart cards.
1.8.2. The security check point is a mantrap style security station designed to prevent unauthorized access. The checkpoint is also responsible for prevent employees bringing unauthorized materials, such as removable media.
1.8.2.1. Authorized personnel will use smart card to access security check point
1.8.2.2. Security staff will perform security check on entry and exit and employees buzz in/out of security check point.
1.8.3. Computer screens/classified equipment must not be directly viewable from the security cameras
1.8.4. No bags/briefcases are allowed in the classified area.
1.8.5. No data removal devices are allowed in the classified area. This includes removable media, AV recorders, pen and paper, and any form of printer
2. Network Equipment Physical Security
2.1. Server/Network Equipment
2.1.1. All Server and network equipment must be kept in the server room whenever possible to prevent theft and unauthorized access.
2.1.2. All Server and network equipment that must be located outside the server room must be kept in a locked network cabinet/closet that is bolted to the wall or floor to prevent theft and unauthorized access.
2.1.3. All unused network ports must be disabled to prevent unauthorized access.
2.1.4. All wall jacks not in use by WWTC equipment must be disabled to prevent unauthorized access.
2.2. Physical Network Access
2.2.1. All network infrastructure cables must be hardwired and plug into a network infrastructure device or terminate at a wall plate.
2.2.2. Users may not add routers, Wi-Fi access points, or any other network equipment to the WWTC network.
2.2.3. Requests for additional ports must be process through the IT department.
2.3. Unclassified & Classified Server Rooms
2.3.1. Only approved IT staff have access. Access rights must be approved by the employee’s supervisor, department head, and the security manager.
2.3.2. All non-IT staff must be escorted by approved IT/Security escort. This includes all maintenance or IT contractors
2.3.3. Server room door must be kept closed and locked at all times.
2.3.4. Server Racks
2.3.4.1. All server room equipment must be rack mounted
2.3.4.2. Server racks should be kept locked when not in immediate use.
2.3.4.2.1. Only authorized personnel may have access to the key(s)
2.3.4.3. All server racks must be bolted down to prevent theft and unauthorized access.
2.3.5. Classified and Unclassified equipment must maintain at least a 3 foot separation to prevent emanation crossover.
2.3.6. Classified and Unclassified equipment must use separate color cables to prevent accidental crossover contamination.
2.3.6.1. All unclassified equipment must use black cables.
2.3.6.2. All classified equipment must use red cables.
2.4. Backup Media
2.4.1. All unclassified backup media must be stored in a secure locked cabinet in the server room
2.4.2. Classified backup media must be stored in a secure locked cabinet in the classified network area
2.4.3. Backup media will be encrypted whenever possible.
3. Offices and Shared Work Space Security
3.1. All offices must be locked when unoccupied due to the confidential nature of WWTC business.
3.2. Workstation Physical security
3.2.1. Workstations must be removed from unoccupied desks/offices to prevent theft or unauthorized access
3.2.2. All hard drives must be locked in systems using case locks
3.2.2.1. Hard drive lock keys will be kept by IT staff and Security manager only.
3.2.3. Security seals must be placed on all cases to prevent unauthorized tampering
3.2.3.1. Any broken seals must be reported to the security manager
3.2.3.2. Seals broken by authorized IT staff for repairs or official business should be replaced before putting a system back into service
3.2.4. Classified and Unclassified workstations must use separate color cables to prevent accidental crossover contamination.
3.2.4.1. All unclassified equipment must use black cables.
3.2.4.2. All classified equipment must use red cables.
3.2.5. Laptops
3.2.5.1. Laptop cable locks will be provided to employees with approval of their department head.
3.2.5.1.1. Cable lock use is mandatory for any employee using a company laptop outside the office.
3.2.5.2. Laptops should also be equipped with “phone home” software
3.2.6. All floppy & USB drives must be disabled.
3.2.7. All workstations must have a card reader. Card reader can be built in to the system or the keyboard.
3.2.7.1. USB card readers will be provided to employees who need access from remote or personal systems.
3.2.8. Employees access WWTC resources while not on the corporate network must connect using DirectAccess.
3.3. Portable equipment
3.3.1. All authorized portable equipment must be stored in an secure locked cabinet when not in use.
3.3.1.1. This includes any authorized USB drives or disks containing company data
3.4.1. Documents must be removed promptly from printers
3.5. Shredders
3.5.1. Shredders must be located on each department. When possible shredders should be located near the printers.
3.5.2. Shredders located in classified network areas must be approved to handle the highest security classification levels in that area.
3.5.3. Classified shredder waste must be disposed of properly.
Network Security
1. Network Security Implementation
1.1. A Network Intrusion Detection System will be install on the internal side of the firewall to detect any threats to the network. The system will configured on the Module 4 Gigabit Ethernet port 7 on both core switches. A Switched Port Analyzer (SPAN) Session will be configured on both switches to monitor for unauthorized traffic.
1.2. Network Address Translation will be implemented on the Catalyst 6504 using the ASA-Service Module. An IP access list will be created to authorized the 172.13.32.0/21, 192.168.33.0/24 subnets to perform address translation through the firewall. Firewall configuration follows:
nat (inside) 1 172.16.32.0 255.255.248.0
nat (inside) 1 192.168.32.0 255.255.248.0
global (outside) 1 (ip address range assigned by ISP)
Some addresses will be reserved to allow static translations between devices internal to the firewall or DMZ. For the customer payment portal the firewall translation would appears as follows:
static (inside,outside) tcp (ip address assigned by ISP) http (private ip of payment portal) http netmask 255.255.255.255
2. Network Security Policies
2.1. Network device hardening
2.1.1. Network devices will be hardened using Cisco recommended procedures. At a minimum the following security tasks must be accomplished on all network devices (if supported). The guide for hardening Cisco IOS devices can be found here: http://www.cisco.com/c/en/us/support/docs/ip/access-lists/13608-21.html
2.1.2. All unused network ports in the core and distribution must be in an administrative shutdown state to prevent unauthorized connections to the network.
2.1.3. All unused switchports must be placed in the blackhole/management VLAN of 999. All switchport trunks must be configured with a native vlan of 999 to prevent VLAN hopping or unauthorized access on vlan 1.
2.1.4. All network devices require a security banner stating the following:
2.1.4.1. This network device is property of World Wide Trading Company. This device is only to be accessed by authorized users. All access is monitored and use constitutes consent to this statement. Access by unauthorized users is strictly prohibited and subject to prosecution to the fullest extent of the law. The IP address of the system which connected to this device has been logged.
2.1.5. All devices require configuration of user accounts for all network personnel in user EXEC mode. This should be accomplished using RADIUS, TACACS, or TACACS+.
2.1.6. All devices require an enable secret password. Only authorized network administrators should have this password. The password will be changed every 180 days.
2.1.7. Telnet should be disabled and SSH should be enabled for connectivity on all network devices.
2.1.8. Timeouts need to be configured for 20 minutes on the console. 30 minutes for a virtual terminal (SSH) connection.
2.1.9. service password-encryption must be enabled to protect network devices passwords.
2.1.10. Network Time Protocol (NTP) needs to be configured on all devices to ensure proper documentation and times on logs.
2.2. Access Network Security
2.2.1. All network ports in the access layer must be configured for port-security and maintain the state for two mac addresses. One mac address should be the VoIP phone, the second mac address should be the workstation attached to the phone.
2.2.2. All network ports provided for personal laptop connectivity must run 802.1x and port security for the first learned mac address. This prevents unauthorized users from plugging into the network and prevents users from randomly attaching devices to the network interface.
2.3. Firewall configuration
2.3.1. All traffic from the Internet inbound to the WWTC network should be implicitly dropped at the firewall except for the following cases.
2.3.1.1. Traffic that is accessing systems within the firewall DMZ.
2.3.1.2. Traffic that is required for WWTC systems to operate with remote systems. These connections must be documented in the systems security plan. The inbound/outbound IP/ports must be listed on the documentation.
2.3.1.3. Traffic from the WWTC network to the Internet will be filtered to prevent systems from going to unapproved websites. The list of unapproved websites will be determined by the Information Systems Security Officer.
2.3.1.4. IP subnets, of known bad networks, will be blocked at the firewall. Substantial business justification will be required to open any IP on these subnets.
2.4. Access control
2.4.1. Between WWTC networks access control will be implemented to provide authorized systems access to network components. Specifically the HQ, IT, and FINANCE VLANS will be restricted to access by only systems in those subnets.
2.4.2. Wireless networks will only have access to Internet to prevent unauthorized access to corporate resources and systems.
Server/Workstation Security Policies
1. DMZ Network
1.1. All WWTC servers and workstations which are required to be publically accessible from the Internet must be physically and logically located on WWTC's public facing DMZ network segment.
1.2. WWTC servers and workstations that do not require accessibility from external public networks are not to be placed onto WWTC's public facing DMZ network segment.
1.3. All traffic from servers and workstations on the WWTC DMZ network into the WWTC internal must abide by and fall under the Network Security Polices, 2.1 Network Security Policies section.
1.3.1. Remote Desktop Protocol from the external public facing DMZ network segment to the internal network segment will be limited a selected few jump stations outfitted with additional network, application, and services hardening. All unused services and applications hosted on servers and workstations configured on the WWTC public facing DMZ network segment must be disabled.
1.3.2. All firewall configurations and Access Control Lists configuration defining network traffic traverse in between the WWTC publicly facing DMZ network to and from the internal network and the public to and from the DMZ fall under the Network Security Polices, 2.3 Firewall Configuration .
1.3.2.1. Remote desktop access to servers hosted on the external publicly facing DMZ network from the internal WWTC network segment will follow the principle of least privilege. Developers and administrator accounts will be granted access to DMZ jump servers with specific business justifications.
1.3.2.2. All other remote administration shall be performed over secure network configured channels such as SSH and IPSEC.
1.3.2.2.1. Remote console administration to physical and virtual servers hosted on the DMZ network will fully accessible to a restricted set of administrators on the internal network as all remote administration cards and devices must be configured onto a separate internally accessible network segment.
1.4. All enabled services and applications hosted on servers and workstations configured on the WWTC public facing DMZ network must be provided with strict business justifications prior to configuration and every three months of continuous production configuration.
2. Servers and Workstations General
2.1. All WWTC servers must have development/test counterpart servers available. These servers will direct copies of their production counterparts. They are to be used to test any changes before they are applied to production systems. They will consume minimal resources as they will not carry production load and only used periodically for testing.
2.2. Security, application, and event logs must be configured at minimum of 90 days on all WWTC servers and workstations. Specified logs and counters will be configured to send alerts and logs to security event management tools.
2.3. All servers and workstations will be managed for security patches, system state, system status, and various other metrics to ensure server operational health.
2.4. Workstation and server hardware will be replaced on a regular maximum 4-year replacement cycle. Hardware should be replaced before support for it ends.
2.4.1. Discontinued support for irreplaceable proprietary hardware must be enrolled into a 24/7 high priority maintenance and support contract with a hardware support vendor.
2.4.2. Commonly failed hardware parts must be stored on site at the premises at which the devices are hosted for immediate replacement of failed parts.
2.5. Server security standards such as locking faceplates and servers racks fall under Physical Security Polices Section, 1. Physical Security Policies .
2.5.1. All USB ports and unused peripheral connection ports will be administratively disabled through the hardware BIOS.
2.6. Anti-Virus software must be running on every single workstation and server on the network.
2.6.1. Anti-virus agents must be forcefully installed on every workstation and server through a central distribution.
2.6.2. Anti-virus agents must be administered and managed through a central anti-virus management server.
2.6.3. Anti-virus software must be updated on a daily basis. The latest and greatest updates must be installed a soon as available by the anti-virus vendor.
2.6.4. Anti-virus software patches and updates, minor and major, must be first pushed to development/test versions of all servers.
2.7. Separate Administrator accounts are required to log into servers. These elevated privilege administration accounts will be annotated with an SO (Service Operator), DA (Domain Administrator), or EA (Enterprise Administrator) in front of the users regular network ID. For example, users regular network account ID of gkhatta would be annotated to DA-gkhatta if the account has domain admin privileges.
2.7.1. Elevated administrator accounts must be presented with a business requirement for every user before created, and confirmed every 90 days.
2.7.1.1. Non-elevated administrator network accounts will be restricted from logging onto any server.
2.7.1.2. Service Operator (SO) network administrator accounts are granted remote access onto all servers, excluding domain controllers. They have basic administration rights on servers.
2.7.1.3. Domain Admin (DA) network administrator accounts are granted full administrator access to most servers and domain controllers throughout the domain.
2.7.1.4. Enterprise Admin (EA) network administrator accounts are granted absolute full control throughout the domain, including the ability to alter a few domain services and applications.
2.7.2. Elevated Administrator network accounts must not be used to log into workstations.
2.8. All servers and workstation Operating systems, services, and applications will undergo vendor recommended hardening against security vulnerabilities.
2.9. All servers and workstations shall undergo manufacturer recommended hardware against security vulnerabilities.
3. User Data Hosted on Customer (Public) Website
3.1. Databases containing user data will not be hosted on the internal network. Firewall ports will be opened in between the DMZ and internal network allowing publically accessible applications and websites on the DMZ to communicate back into the internal network to the database. The database will be accessible by specific applications and websites only.
3.2. All stationary database information will be encrypted using Transparent Data Encryption (TDE).
3.3. Database encryption on the application level will be encrypted using Encrypting File Systems (EFS).
4. System Security
4.1. PKI for Smart Cards
4.1.1. Smart cards will be implemented using a Windows PKI infrastructure
4.1.2. Smart card certificates will be issued by a WWTC CA
4.1.3. Certificate expiration dates must be no more than one year from issue date
4.1.4. Certificates will be used for logon and digital signatures.
4.1.4.1. IT staff will configure user account to utilize smart card during initial account setup.
5. Public Servers
5.1. All public we servers must use SSL & TLS for all connections.
5.2. SSL will be used to provide a secure means of customer purchase and payment over the Internet.
5.3. SSL certificates will be acquired by a trusted third party, such as Symantec, Comodo, or GoDaddy.
Vulnerability Management
Vulnerability management is an important network security tool. Patching systems closes or mitigates known security vulnerabilities and reduces the risk of the network being exploited. It is also important to scan the network to identify vulnerabilities so that they can be corrected or mitigated.
1. Patch Management Policies
1.1. Patch management will be performed by the IT staff on all network devices and server equipment.
1.2. Patches will be installed during the weekly maintenance window.
1.2.1. Systems may be rebooted during this period for maintenance and upgrades.
1.3. WSUS
1.3.1. WSUS servers must be deployed on unclassified and classified networks.
1.3.1.1. Classified WSUS server patches must be imported manually.
1.3.2. WSUS will be used to approve and deploy all Windows patches.
1.3.3. WSUS settings will be enforced on all WWTC windows systems by GPO.
1.3.4. All patches must be deployed to test groups first
1.3.4.1. Test groups will consist of at least two systems for each OS.
1.3.4.2. After patches have been installed on test groups there must be at least 48 hours before deploying patches to all systems.
1.3.4.3. Patches must be deployed during maintenance window.
1.3.5. IT staff must monitor logs to identify systems not properly receiving patches.
1.3.6. Remote users will receive patches using DirectAccess connection.
1.4. Third Party Applications
1.4.1. All third party applications must be kept up to date with the current versions.
1.4.2. Patches may be deployed manually or by using Microsoft System Center.
1.5. Network devices
1.5.1. All network devices must be kept up to date.
1.6. WDS workstation and server images will be updated quarterly to meet current patch baselines.
2. Vulnerability Assessment
2.1. All network assets must be scanned to identify vulnerabilities and ensure compliance with current patch baselines.
2.2. Network scanning must be done on a regular basis using the Nessus vulnerability scanning software.
2.2.1. Nessus software can be used to scan a wide range of equipment including Windows, Linux, Cisco, Oracle, MS SQL Server, and a number of web applications
.
2.2.2. IT staff must complete Nessus training before running scans.
Resources
https://www.sans.org/security-resources/policies/retired/pdf/dmz-lab-security-policy
http://www.computerworld.com/article/2550050/security0/keeping-the-dmz-safe.html
http://sqlmag.com/database-security/sql-server-encryption-options
https://www.sans.org/security-resources/idfaq/emerg_nids.php
http://www.cisco.com/c/en/us/support/docs/ip/network-address-translation-nat/13772-12.html
http://www.cisco.com/c/en/us/support/docs/ip/network-address-translation-nat/13772-12.html#topic3
https://supportforums.cisco.com/discussion/12437391/using-both-dynamic-and-static-nat-two-different-internet-facing-subnets