In-Portal Developers Guide

This is a wiki-based Developers Guide for In-Portal Open Source CMS. The purpose of this guide is to provide advanced users, web developers and programmers with documentation on how to expand, customize and improve the functionality and the code the In-Portal software. Please consider contributing to our documentation writing effort.

User:EramanaEton2200

From In-Portal Developers Guide

Revision as of 13:21, 29 October 2012 by EramanaEton2200 (Talk | contribs)
(diff) ←Older revision | Current revision (diff) | Newer revision→ (diff)
Jump to: navigation, search

Network Security Services and Your Business


Network security services are now implemented by businesses, small and big, facing the growing number and variety of Internet threats. Today, almost all firms are connected to the Internet no less than to some extent, and therefore experience risks that did not exist obviously any good several years ago. However, many businesses or managers are ignorant each the entire variety of cyber-threats, and also of the various ways these threats may be countered. This is particularly the truth in computer network security.


Should your organisation's computer network is connected to the Internet, then it includes a real requirement of network security services to counter the large expansion in computer viruses, Trojans, spyware, inappropriate material and "phishing" emails that have burgeoned recently. Information security is often a critical area for any company that utilizes the net, and particularly people who depend upon e-commerce. There are a few main areas of network security services to take into consideration, the following:

Firewall configuration review, to test that this rules currently accompanied by the firewall, and the kind of firewall used, are appropriate towards the given situation.

Detailed audit of computers and devices (including routers and firewalls), as well as their location for the network. This includes a review of any DMZ (De-Militarised Zone) waiting in front of the organisation's core network.

Network vulnerability assessment, to check on previously-addressed vulnerabilities in order that they're still included in effective countermeasures.

Penetration testing, to probe the defences actively for first time vulnerabilities. This sort of test should be approached with caution, because it has the potential to disrupt operational systems or cause a temporary denial of service. The guidelines of engagement needs to be agreed beforehand and set written.

The above functions can either be provided by an in-house team (when it comes to larger organisations) if not may be outsourced to some specialist information security firm. In any case, it is imperative that network security services are implemented at regular intervals, and especially after any major changes towards the network.

The gateway on your internal network is actually the firewall. However, there exists a large amount more to network security services than only a firewall. Also involved are considerations such as the following:

Network configuration: Are there a DMZ? What Internet-facing computers and servers are mixed together? Type and variety of devices: A choice of whether or not to utilize a hub, a switch or a router will have security implications, as will the question products sort of cabling has become installed.

Protocols and ports supported: In the event the network supports services and open ports (like "Telnet" on port 23) which are not actually required by your organisation, then they must be disabled for security reasons. Auditing and monitoring facilities: Are there logs of network activity and so are they in the form that will easily be scanned with a human?

Clearly, there is considerably more to http://nuvalo.com than installing a firewall having its default configuration enabled. It is deemed an division of information security that needs an in depth degree of technical expertise, plus a computer security specialist should oversee the deployment and configuration of your organisation's network.