 |
Security Assessments and Needs Security is not a checkbox. Security is a state of mind.
ZAG understands that security should permeate a network. It should be all encompassing. The need for security is obvious with a corporation’s firewalls and servers. But security is also required at the desktops and the users that operate them.
Failure to properly address all aspects of security can result in lost time, data and even leave you in violation of governmental regulations.
While a holistic approach to security is needed, there are certain items that every network needs. Following are a few topics and ZAG’s methodology related to them:
 |  | Firewall - It is a requirement in today’s world that every network have a firewall. ZAG has worked with many. Included in this are the NetScreen, Cisco Pix and various other products. Many companies configure inbound filters but leave the outgoing policies open to allow any traffic out; a firewall should be configured bidirectionally. No longer is it enough to filter bad from coming in, now you also have to block the unknown from going out. Only trusted ports should be allowed out. This can protect a network in the event that something bad does get in.
AntiVirus - AntiVirus is one of the most fundamental elements of security. AntiVirus needs to be centrally managed to ensure that desktops are always updated with the latest virus definition files. Not having the latest definition files is barely better than not having protection at all. |
ZAG also generally recommends that users be unable to modify their AntiVirus settings. Users who have the ability to do so will often disable scanning on their systems in a mis-guided attempt to improve performance. This can obviously have catastrophic effects on a network. Wherever possible, it is best to limit potential problems with security.
ZAG has a great deal of experience with many AntiVirus solutions. ZAG has had excellent experience with Symantec Corporate and Enterprise Editions, Trend Micro and the McAfee suite.
 |  | Anti-Spyware - The need for anti-spyware is as present today as antivirus. Failure to deploy anti-spyware can lead to security problems as well as lost time for a company.
Rights Management - Rights Management is a key to securing data. Users should not have access to data unless they need it. Your data is much less at risk if it can’t be viewed by users that don’t require access.
Training - End user training is one of the most overlooked lines of security. We can configure hard password requirements, take away rights from users, and a plethora of other security steps. Ultimately, this can be all for naught if the users are not educated properly.
Backups - Backups are of course the last line of defense of a network’s security. ZAG has extensive history with working with all of the major backup protection vendors. These vendors include Veritas, Computer Associates, and even off site vendors such as Managed Storage International. A network cannot be considered secure unless it has the last line of defense to recover from total catastrophe. |
ZAG understands that security is more than any of the above single elements. Security is the sum of the above items plus a host of others (wireless, home networks, etc.). The network as a whole has to be reviewed to determine the completeness.
After all, security isn’t just a checkbox.
Click here to learn how ZAG was able to conduct a security assessment and ultimately deliver network security to a customer.
|