Monday, August 4, 2008

mindterm blospot#2

Park Bench source newoking
The wilful introduction of computer viruses or disruptive/destructive programs into Park Bench Source's environment is prohibited, and violators may be subject to prosecution. All desktop systems that connect to Park Bench Source network must be protected with an approved, licensed anti-virus software product that it is kept updated according to the vendor's recommendations. All servers and workstations that connect to the network and that are vulnerable to virus or worm attack must be protected with an approved, licensed anti-virus software product that it is kept updated according to the vendor's recommendations. Headers of all incoming data including electronic mail must be scanned for viruses by the email server where such products exist and are financially feasible to implement. Outgoing electronic mail should be scanned where such capabilities exist. Where feasible, system or network administrators should inform users when a virus has been detected. Virus scanning logs must be maintained whenever email is centrally scanned for viruses.
Intruder detection must be implemented on all servers and workstations containing data classified as high risk. Operating system and application software logging processes must be enabled on all host and server systems. Where possible, alarm and alert functions, as well as logging and monitoring systems must be enabled. Server, firewall, and critical system logs should be reviewed frequently. Where possible, automated review should be enabled and alerts should be transmitted to the administrator when a serious security intrusion is detected. Intrusion tools should be installed where appropriate and checked on a regular basis.
All connections to the Internet must go through a properly secured connection point to ensure Park Bench Source's network is protected when the data is classified high risk. All connections to the Internet should go through a properly secured connection point to ensure the network is protected when the data is classified confidential.

No comments: