Disclaimer: The opinions of the columnists are their own and not necessarily those of their employer.
Frank Cassano

Assessing your Organization’s Network Perimeter (pt. 3)

processes are the following potential issues you may encounter:

  1. A process being performed has no formal documentation
  2. A process being performed does not match what was documented in the formal documentation.
  3. Operators commonly skip or ignore key documented steps in a process.
  4. The formal process is out of date and if used as documented would pose a threat to the environment.
  5. There are no metrics to ensure the process is being performed effectively.
  6. The operators have their own informal set of documentation or guidance that they use to support their function.
  7. Operators have no knowledge of documentation\
  8. There are no defined custodians of a process
  9. There are no defined owners of a process.
  10. The owners of a process do not know they own the process.
  11. A process is being performed that is no longer needed.
  12. There are elements of the network perimeter that have no processes supporting them. (hard to believe but true).
  13. Monitoring and security processes that only confirm what should be happening but not what could be happening and shouldn’t be. (think about it)

I hope this article has been hopeful to focus you in the review of processes of a network perimeter. Hope to see you next time at “The Risk Rack”.

Popularity: 1%

Post a Comment

Your email is never published nor shared. Required fields are marked *

*
*