Fix
Part 3: Application/End-User Security Recommendations
Introduction
A robust network security strategy is one that actively involves the entire stakeholders of the system. The network administrator has the responsibility of ensuring that best practices in information security management are implemented throughout the entirety of the system they oversee. Threats to a system exist both within and outside an organization. This necessitates the need for a comprehensive security strategy that can cover all those potential threats. Information security threats are of a dynamic nature and the network administrator should take this consideration to ensure that they are always on top of any emerging threats. System vulnerabilities should be sought and effectively sealed and this should be a regular task.
End User Security Recommendations
Best practice in network security will require that the users and the firm abide by the following:
• Training and awareness – all employees of the company should have a firm grasp of matters pertaining network security. This will come through the training that should be offered by the company. The training should involve how to spot and identify threats, how to combat them, and how to handle them should they occur. As new threats emerge, the firm will need to create a continuous awareness program to inform its employees on them.
• Effective monitoring program – even after training has been done, this is not reason enough to believe employees will adhere to the lessons learnt. As such, the IT personnel should be empowered to conduct random checks on the security behavior of the firm’s employees. This will help in identifying potential weak spots.
• Unique user credentials – each and every employee that has been granted use of computer resources should do so with their own unique username and a password that should not be shared with any other user. The password should be complex enough that no one could possibly guess. The user should avoid using passwords from familiar objects or people. A strong password should have a mix of alphanumeric and special characters. For every activity a user does on any computer, they will be required to use their own unique credentials. This should leave an audit that can be followed should there be an incident.
• Automatic logoff – it is possible that a user might leave a computer without logging out from their session. This opens the possibility that another user might access resources using the logged in credentials. This could be devastating should the unauthorized have malicious intent and the logged on credentials have advanced permissions. Automatic logoff should be set to happen after a given period of time. This should especially happen after the end of prescribed business hours.
• Regular event log audits – event logs are very important when it comes to monitoring the performance of a given system. They can also be used to spot any anomalies within the system. Event logs collected over a long period of time can establish a baseline of operations for a system. Any deviations from this baseline can then be checked further to identify if they are a threat to the system. (Huang, MacCallum, & Du, 2013).
• Least privilege – the principle of least privilege has it that a user should only be granted permissions only to the extent of their job description and responsibilities. This will ensure that no single user has complete or unnecessary control over the system. The network administrator account with power over the entire system should be used sparingly and only when necessary to do so.
• Incident reporting procedures – employees should now how they can report a security incident. This could a suspicion of an intruder or even another user’s activity. Whatever reason, users should be provided with a clear cut procedure to make sure these reports reach the right people who can handle them. (Pardoe, & Snyder, 2015).
• Anti-malware programs – the entire system should be protected by a regularly updated anti-virus program that can identify and prevent any threats before they get into the system.
• Up to date disaster recovery and business continuity plan – even with all the above security measures implemented, there still exists the chance that a security breach event might occur. It is important have a response ready for such an eventuality. A disaster recovery and business continuity plan can go a long way in mitigating the effects of a security breach.
References
Huang, S. C.-H., MacCallum, D., & Du, D. (2013). Network security. New York: Springer.
Pardoe, T. D., & Snyder, G. F. (2015). Network security. Clifton Park, NY: Thomson/Delmar Learning.