Home > Financial Services Information Security Tips > Security Architecture Insider > How to perform a network device audit
Financial Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY ARCHITECTURE INSIDER

How to perform a network device audit


Judith M. Myerson, contributor
01.22.2009
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Today's network administrators are no doubt aware that a growing number of rogue devices and applications are increasing enterprise network security risks. For instance, end users often attach USB sticks to their computers unnoticed, downloading sensitive data and potentially uploading malware. Unauthorized applications are commonly installed, resulting in software licensing and copyright infringements, not to mention opening potential holes into the network. While these risks are substantial to any enterprise, to a financial-services firm, lost data or network intrusions can be the difference between making a profit and potentially going out of business.

The examples above are just a few of the reasons why it is important that financial organizations know how to perform network device audits to ensure network devices, such as routers and firewalls, are configured properly. Networks must be audited from all points of entry, such as desktop and laptop computers, remote access, connections to third-party networks, pluggable external devices and wireless access points.

A network device audit tool performs security audits of network device configuration files. A financial-services firm should look for a tool that can modify network-filtering audits. For instance, open-source network infrastructure parser tool Nipper, through its customizable filtering audits, can check rules allowing access from any source to any destination, note rules that are disabled, or deny rules that aren't logged. It supports a wide variety of devices from different manufacturers including Cisco Systems Inc., Nokia, Hewlett-Packard Co. and Nortel Networks Ltd.

Preparing for and performing a network device audit


When implementing network device audit tools, the ultimate goal is to audit the entire network and identify issues that prevent it from functioning at i...


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Security Architecture Insider
Multifactor authentication options to secure online banking
Security benefits of virtual desktop infrastructures
How to secure data backup
Too many encryption methods make secure communications difficult
How to streamline role-based access control
Five considerations for choosing network access control products
Fighting fraud: Understanding technology and threats
How to shift to centralized authentication and ease compliance
Winning the war: Personal information protection
Why financials must implement Web application security best practices

Network security devices for financial institutions
Five considerations for choosing network access control products
Organization aims to develop encryption standard for card data
How to use data loss prevention tools to stop data exfiltration
Event data analysis
Security on the street with SearchFinancialSecurity.com: Mobile banking
Don't let fads dictate your network security strategy
How to easily integrate managed email security services
Integrating firewalls into your financial enterprise systems
How to integrate network behavior anomaly detection into enterprise systems
How to get the most out of a SIM

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


ts optimum state. To achieve this, organizations should take these steps when preparing for and initiating a network device audit:

  • Review firewall management policies to ensure they are keeping pace with new threats (e.g., via firewall logs) and do not conflict with established audit and business policies. Review firewall configurations in response to changes in regulatory requirements, so the time needed for security auditing can be reduced.
  • Conduct a site analysis using a network assessment tool to ensure the audit tools can collect all the required data on all network devices of two types: enterprise and pluggable. Enterprise devices include servers, workstations, routers and switches, firewalls, encryption devices and intrusion detection systems. Pluggable devices are those typically used in conjunction with client machines, such as USB memory sticks, Bluetooth devices, flash cards, smart phones and portable disk drives.
  • Set up a network audit-review team to include both internal and external auditors. Internal auditors have detailed knowledge of the network devices, policies and procedures, while external auditors are hired for a completely independent objective evaluation at additional cost. These network device auditors need to collaborate with the external compliance auditors.
  • Conduct a pilot study of network device audit tools on a sample portion of the network. This will help the auditors and integrators solve any potential problems before making use of the tools on a large scale. It will also help determine what education and training the auditors and integrators will need to solve unusual problems. Without proper training and education, network device audits can be difficult.

As part of the pilot study, do the following:

  • Create a network device auditing checklist. At a minimum, make sure it includes device configuration, administrative and authentication services, network filtering, protocol analysis, operating system version and time synchronization.
  • Consider ISO 27001, an Information System Security Management Standard (ISMS) as part of your checklist on policy, procedures and operation, such as redundancy, log monitoring and incident handling.
  • Change default configurations for antispam, antivirus, routing, VPN, encryption, wireless and firewall systems. Review configuration audit policy for network devices, and review audit configuration options on network filtering audit checks, network firewall port lists, timeouts, password encryption and password audit complexity checks.
  • Ensure compliance regulations can be met and the data required for compliance has not been blocked by firewalls, and that storage of data can be retained for a specified period of time.
  • Test the restoration of backup media as part of a review of backup policies. Run backup media at off-production times to ensure they are in good condition when needed in a disaster recovery.

Knowing how to conduct a network device audit can be a challenge for a financial organization. Following these implementation techniques can make the job easier.

About the author:
Judith M. Myerson is a systems architect and engineer. Her areas of interest include middleware technologies, enterprise-wide system, database technologies, application development, network management, computer security, information assurance, financial, RFID technologies and project management. She is also a consultant. You can reach her jmyerson at bellatlantic.net


Rate this Tip
To rate tips, you must be a member of SearchFinancialSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Finance Sector Security - Anti-Phishing, Remote Access Security, Firewall Systems
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts