Designing Access Controls

Finalize Security Policies

Other services might be required in your system. You might want to check for those services but not quarantine endpoints that do not have them.

You must specify Windows services with the exact names that are dis- played in Control Panel > Administrative Tools > Services.

If you enable the Mac services test, only the services that you select from a list are allowed (others are prohibited). Record the services that you want to allow in Table 3-102.

Table 3-102. Tests for Services

Windows Services Not Allowed

Windows Services Required

Mac Services

13.Do your security policies prohibit users from granting others access through their connection?

Check the cells in Table 3-103.

Table 3-103. Tests for Shared Connections

Windows Bridge Network Connection Mac Internet Sharing

14.Does your organization require Mac endpoints to protect their wireless (Airport) connections?

If you are concerned about endpoints connecting to a rogue AP, you might activate the first two tests displayed in Table 3-104. If you are concerned about users who send data over insecure wireless connections, you might activate the third.

Table 3-104. Tests on Mac Airport

Mac Airport Preference

Mac Airport User Prompt

Mac Airport WEP Enabled

 

 

 

Activate this test?

15.Are your security requirements so high that the risk of malware outweighs all other risks (including that of a user inadvertently making an endpoint inoperable in an attempt to comply)?

3-127

Page 243
Image 243
HP Access Control Client Software manual Tests for Services, Tests for Shared Connections, Tests on Mac Airport