White House Network Security
The security network build for the White is unique in manner that the policy differs from any other institution practicing the network safety because it is the major need of the white house that their each and every moment in the White house has been recorded and its safety and date protection is the main requirement. Another important parameter for the safety of the network of White house is to watch over and monitor the activity which is done by any one via network and internet that what kind and type of material and data has been sent and in case of any unique event happen in the White house then special precaution shall be taken to avoid any security breech in the future. These precautions include the specific entry for the people to the network department, the use of cameras and sound system must be catered carefully so as not only the video but the audio shall be protected. The use of network within the White house quite different and vary time to time according to the needs therefore, a requirement of up to date team is required which will observe the future necessities and changes in the network security. Following steps must be taken for the network security;
· A complete secure and unique communication system is required so the hackers won’t be able to breech its security.
· The networking system within the White house and the communication made outside the White house via network and communication device must be recorded, tapped and secured.
· Counter network attack team should be enforced so in case of any emergency the security of the network can be protected within no time.
The duty of White House Network Security Czar one is to come up with security policies that protect data and that guidelines that provide different officials using the network on what is expected of them to ensure they are no breach of the attack by unauthorized personnel which may put the state crucial and confidential information at the risk of cyber-attacks. The other duties of the undertaking serious complex engineering problems, sensitive public policy challenges, protection of commercial interelletual property, military command and control interoperability issues among.
Security policies that the Czar comes up with are important as they inform the official using the network the specific mechanisms and to provide the baselines. The most common security policy should be the acceptable use policy (AUP). The policy tells the users what they are allowed or not allowed on the network system. The AUP should be explicit to avoid ambudigity and misunderstanding. The AUP should be explained to allow the staffs and official involved in the network in session and signed by each user. The agreement should be updated periodically as a refresher and definitely when a new change is made. The other important security policy that the czar should reinforce network security training. They should be additional training and sign- offs on those portions security policies that affect their job and are not covered under the AUP. They should be handled proactively with enough detail to ensure that each individual understand their responsibility and limits of the authority (Rouse, 2007).
The other measure should be taken is to educate the officials and staffs to protect the hardware and software under them. They should ensure that no another person as access over their passwords and should be held up accountable for any breach done under their accounts. It also his role to educate everybody using the network to constantly change their password and incase their suspect that their passwords have being compromised they should report that the people in charge. Users should also be encouraged to protect the network from unauthorized access by ensuring they log off after using the different network systems. Users of dumb terminals should log out when not using the terminals. (Chabrow, 207) Wireless network should only be accessed by authorized and measures to ensure that unauthorized people do not should be put across. The wireless network should have the following standards:
Access/ layers; Users will connect the wireless WLAN via access points only
Service set identifier (SSID); this ensures that only authorized people have access to the wireless
Unauthorized access should be blocked without warning.
Staff should not try and connect with their personal devices using the white house network.
Use of selected Authentication
Encryption; wireless networks will utilize AES (Advanced Encryption Standards) level of encryption.
In case of third party access control to the network over the White House Network they should be formal contracts that testify over access over the network. It should be ensured they are logged off after their use. In case of connections over wireless network proper communication from the head of security in state house.
Security monitoring should be frequently to ensure potential security breaches are dealt with. All monitoring should comply according to national Security Council. Any device is that not approved connected to any of white house should be blocked immediately.
Disaster recovery plans are the network and that these plans are tested on regularly and in accordance to the national Security Council. Reporting data security breaches and weakness, such as loss of data or theft of a laptop, must be reported according the national security and quick actions taken to ensure that this does not result to access of classified information that pose national threat if enemies of the state have aces to the information.
They should be data back up and restoration this should be undertaken on regularly. A log switch shift of configuration and data backups detailing the date of backup and whether it was successful. The right procedures should be produced and communicated to all relevant staffs. Documented procedures for the storage of backup tapes should be produced and communicated to the relevant staff. All the copies should be stored securely and their storage made confidential depending on the content of information. Users should be made responsible for their own information back up (Espanol, 2016).