Designing Access Controls
Finalize Security Policies
“Customer Needs Assessment,” meet with users and consider their input when formulating the policy. Also test policies before enforcing quarantining. (See the ProCurve Access Control Implementation Guide.)
Due to the high level of control exerted by these tests, these tests are most appropriate for checking endpoints in private zones. It is a rare security policy that requires all of the tests in this section. Go through the steps below to choose the tests for your environment.
N o t e | You might want to use some tests more as reminders to users and you than as | ||||
|
| ||||
|
| test actions for different tests. Failing a particular test could trigger an email | |||
|
| to the network administrator but not quarantine the failed endpoint. | |||
|
| 1. Do you require hotfixes for IE? |
| ||
|
|
| |||
|
| 2. Do your security policies dictate specific settings for IE security zones? | |||
|
|
| Circle the security level (high, medium, | ||
|
|
| in Table |
|
|
|
| 3. Does your organization require users to run a particular version of Web | |||
|
|
| browser? |
|
|
|
|
| Enter the required versions in Table |
| |
|
| Table |
|
| |
|
|
|
|
| |
Test Settings |
| IE |
| Mozilla Firefox | |
|
|
|
|
| |
Required version |
| For Windows XP or 2003: | For Windows 2000: |
| |
|
|
|
|
| |
Hotfixes required? |
| Yes or no |
| Not applicable | |
|
|
|
|
| |
Internet |
| High | Medium | Not applicable | |
setting |
| Low |
| ||
|
|
|
| ||
Local | High | Medium | Not applicable | ||
|
|
| Low |
| |
|
|
|
|
| |
Trusted |
| High | Medium | Not applicable | |
setting |
| Low |
| ||
|
|
|
|
| |
Restricted |
| High | Medium | Not applicable | |
setting |
| Low |
| ||
|
|
|
|
|
|
4.Do your security policies dictate specific settings for macros?
Circle the security level (high, medium,