[Agenda]
[Examples]
[Network Partitioning]
[Concepts]
[Policy]
[Process]
[Organization]
[HW-SW]
[Cases studies]
[Conclusion]
[Resources]
Analysis
What the analysis shows up:
A trainee sniffs the network and gets all mailboxes passwords
The trainee doesn't need access to the mail server
A subcontractor shuts down all the 300 WNT servers with a DoS
The subcontractor needed access to only 6 WNT servers to perform his job
Employees look at web site of a subsidiary in another country
Employees of one country didn't need access to the others countries subsidiaries web servers
Someone hacked the bank wire transfers
Nobody needed to be able to connect from the place where the hacker was to the database server
A cooperative partner steals the specifications of version N+1
The cooperative partner should not have access to that part of the database
® ©
Hervé Schauer Consultants
December 1999 - 142, rue de Rivoli - F-75001 Paris - France
Phone: +33 141 409 700 - Fax: +33 141 409 709 - Email: <secretariat@hsc.fr>
- Page 6 -