(NL ISO/IEC, 2010)
4.1. Policy on Use of Network Services
Users should only be provided with access to the services that they have been specifically
authorized to use.
A policy should be formulated concerning the use of networks and network services. This policy
should cover:
a) the networks and network services which are allowed to be accessed;
b) authorization procedures for determining who is allowed to access which networks
and networked services;
c) management controls and procedures to protect access to network connections and
network services;
d) the means used to access networks and network services (e.g. the conditions for
allowing dial-up access to an Internet service provider or remote system).
Unauthorized and insecure connections to network services can affect the whole organization.
This control is particularly important for network connections to sensitive or critical business
applications or to users in high-risk locations. (NL ISO/IEC, 2010)
4.2. Segregation in Networks
One method of managing the security of large networks is to divide them into separate network
domains.
The domains can be chosen based on trust levels (e.g. public access domain, desktop domain,
server domain), along organizational units (e.g. human resources, finance, marketing) or some
combination (e.g. server domain connecting to multiple organizational units). The segregation
can be done using either physically different networks or by using different logical networks
(e.g. virtual private networking).
The perimeter of each domain should be well defined. Access between network domains is
allowed, but should be controlled at the perimeter using a gateway (e.g. firewall, filtering
router). The criteria for segregation of networks into domains, and the access allowed through
the gateways, should be based on an assessment of the security requirements of each domain.
The assessment should be in accordance with the access control policy, access requirements,
value and classification of information processed and also take account of the relative cost and
performance impact of incorporating suitable gateway technology.
Wireless networks require special treatment due to the poorly defined network perimeter. For
sensitive environments, consideration should be made to treat all wireless access as external
connections and to segregate this access from internal networks until the access has passed
Lebanese National Security Policy Guidelines v1.7
Page
26 |