Identify several best practices related to User Domain policies

User Domain Policies

ATENET OF TELECOMMUNICATIONS SAYS the more people who access a network, the more valuable the network becomes. This is called Metcalfe’s law. Consider a telephone system as an example. If only two telephones were on the system, the value of the system is limited. Only two people can talk at any given time. But add millions of phones and people, and suddenly the value of the network rapidly increases.

This same principle can also be applied to the introduction of technology. As new technologies introduce new capabilities, the value of the network increases yet again. However, it’s also true that the more users and technology involved in a network, the more complex it becomes, and the more potential security risks are introduced.

To illustrate these points, consider what happens when you bring home a new laptop. Typically, a new computer has a new installation of the operating system, pre-loaded applications, and games. The number of users is one, you. The security risks are low. Then you add technology such as an Internet connection, new social media software, and more users, such as family and friends. The laptop now becomes far more valuable. However, the value comes at a cost of increased security risks.

This increase in the number of people accessing your network, along with the introduction of new and emerging technology (such as mobile devices) has dramatically increased the number of security risks. As the user population and the diversity of technology increase, so does the need to access information. This need translates into complex security controls that must be maintained. Inevitably, this complex jumble of controls leads to gaps in protection and security risks.

This chapter examines different types of users on networks. It reviews individual need for access and how those needs lead to risks that must be controlled. We will also discuss how security policies mitigate risks in the User Domain. The last part of the chapter presents case studies to illustrate the alignment between types of users, risks, and security policies.

Chapter 9 Topics

This chapter covers the following topics and concepts:

• What the weakest link in the information security chain is

• What different types of users there are

• How to govern different types of users with policies

• What acceptable use policies (AUPs) are

• What the significance of a privileged-level access agreement (PAA) is

• What security awareness policies (SAPs) are

• What best practices for User Domain policies are

• What the difference between least access privileges and best fit access privileges is

• What some case studies and examples of User Domain policies are

Chapter 9 Goals

When you complete this chapter, you will be able to:

• Understand why users are considered the weakest link in implementing security policies and controls

• Understand the different users in a typical organization

• Explain how different users have different information needs

• Define an AUP

• Define a PAA

• Explain how a SAP can reduce risks

• Explain the importance of risk acceptance in understanding security risks

• Identify several best practices related to User Domain policies

• Understand through case studies how security policies can reduce risk

× How can I help you?