Incompetence #
Posted Friday 27th March 2009 15:27 GMT
Bear in mind this is a government system and due to the sensitivity/confidentiality of some of the data, I found the following excerpts from the leaked memo shocking to say the least.
"We are unable to clean PCs and portable computers which are either not switched on or which are not authorised devices. We therefore ask that if you are running a PC or portable computer not authorised to be on the Network that you take it off immediately."
They allow unauthorised harware to connect to the network! Anyone connecting unauthorised hardware to the network should be given a written warning. Any network ports on walls etc. that are not in use should be locked out at the switch or disconnected physically from the switch. All wireless access should be authorised by MAC address. If Internet access is desired for visitors it should be on a physically separate network
"An additional characteristic of this virus is that for some types of files it can skip direct to the Network from a USB memory stick or other portable storage device (e.g. mp3 players) without hitting the virus checker software. We ask that for the time being you do not use memory sticks or any other portable storage devices on the Parliamentary Network."
They allow staff to connect memory sticks and MP3 players to the PC's! All PC's should have USB/Firewire ports disabled in BIOS, physically disconnected where possible and the BIOS locked by password. The AV software should be configured to scan files transferred via USB (even if disabled) devices, and if it can't then someone chose the wrong AV product.
Perhaps our government's IT dept don't take security seriously.
Who ever drew up the security policy should be sacked. Unless of course security policy is in fact solid and just being ignored. In which case those who are supposed to enforce policy should be sacked.



