[Agenda]
[Examples]
[Network Partitioning]
[Policy]
[Concepts]
[Process]
[Organization]
[HW-SW]
[Cases studies]
[Conclusion]
[Resources]
Apply the security policy on the service flows
Security Officer validates the service flow
Apply corporate security policy
Refuse dangerous services
Remove Un-necessary services
Control that no service is missing like NOC, HelpDesk and Security Office services
Gain consensus on the diagrams
Compromise between business needs and security policy
If too many services are denied, HTTP or DNS could be used as covert-channels for TCP/IP encapsulation
Sign-off of the diagrams as Ok for enforcement, by
People responsible for each domain
Security Officer
® ©
Hervé Schauer Consultants
August 1999 - 142, rue de Rivoli - F-75001 Paris - France
Phone: +33 141 409 700 - Fax: +33 141 409 709 - Email: <secretariat@hsc.fr>
- Page 48 -