|
Network Security
How secure is your company’s information? In this age of distributed computing and of client-server and Internet-enabled information access, computer security consistently raises to the top of most “important issues” lists. To answer this question with certainty is difficult. There are no absolutes with security. An important first step for most corporations is a security policy that establishes acceptable behavior. The next, and more critical step, is to enforce that security policy and measure its effectiveness.
Vision Technologies will assess your Network from multiple viewpoints for the best over all picture. These perspectives range from the physical security of the machines to the configuration of the firewalls to the trustworthiness of workers. The history of industrial espionage has been in the physical world and thus numerous practices have been developed to handle this portion of security assessment. The age of network based industrial espionage has a brief history and thus less developed security assessment practices.
Vision Technologies believes the security profile of a network of machines can be assessed from three principle vantage points:
- From the outside of the Enterprise - the view of the computer infrastructure through the firewall
- From the inside of the Enterprise - the view of computers from behind the firewall
- From the computer keyboard - the view from the actual operating system of the individual machine itself
Each of these perspectives will reveal unique security vulnerabilities. Removing the vulnerabilities as seen from outside the enterprise is the first step to halt the efforts of the casual hacker and industrial espionage age. Removing the vulnerabilities as they appear from behind the firewall accomplishes two goals. It creates a second line of defense should the firewall become compromised. It also creates a defense for the attacks around the firewall through a modem or other non-protected entryway. Finally evaluating security from the machines themselves will close vulnerabilities that could be exploited through a firewall or from other machines on the network. It also hardens the security of the machines, restricting the avenues of attack for the disgruntled worker or the co-opted contractor.
Vision Technologies will employ several lines of defense for the Corporate Information System. Vision Technologies realizes that a successful security audit must be thorough; it can not leave out possible vulnerabilities. It must also be repeatable to provide a consistent perspective on the firm''s security practice. By its very nature a security assessment will initially increase the workload for an MIS department. These seemingly conflicting goals can be met through the use of a security audit tools that can be provided by Vision Technologies thorough and repeatable process with an effective means of implementing corrective actions.
|