Firewall Wizards mailing list archives
RE: Separate firewall administrator and firewall system administrator
From: "Bill Royds" <lists () royds net>
Date: Fri, 14 Jun 2002 13:53:41 -0400
That's not a bad idea, since it follows separation of duties principles and allows experts to be working in their area of expertise. The main caveat is that there needs to be a change management procedure for any changes n either the firewall configuration or system configuration so that the both administrators are confident that there is no conflict that could create risk. Your main concern as security administrator is that changes to OS configuration could create a vulnerable system holding your firewall. So you need to be aware of and have control of patches and all services running on the firewall platform. You don't want your box administrators putting in SNMP on the firewall, for example. But if they administrate what you specify, you now have two sets of eyes looking at things, lowering the risk of misconfiguration. -----Original Message----- From: firewall-wizards-admin () nfr com [mailto:firewall-wizards-admin () nfr com]On Behalf Of Joe Matusiewicz Sent: Fri June 14 2002 11:58 To: firewalls () lists gnac net Cc: firewall-wizards () nfr com Subject: [fw-wiz] Separate firewall administrator and firewall system administrator Greetings, Management came up with this new proposal. Our firewalls should now have the operating system managed by the system administration group. The current firewall administrators should only handle the firewall software. I never heard of this before. Is there anyone out there doing this? Please feel free to comment on this idea. -- Joe _______________________________________________ firewall-wizards mailing list firewall-wizards () nfr com http://list.nfr.com/mailman/listinfo/firewall-wizards _______________________________________________ firewall-wizards mailing list firewall-wizards () nfr com http://list.nfr.com/mailman/listinfo/firewall-wizards
Current thread:
- Separate firewall administrator and firewall system administrator Joe Matusiewicz (Jun 14)
- Re: Separate firewall administrator and firewall system administrator Adam Shostack (Jun 16)
- Re: Separate firewall administrator and firewall system administrator Robert Sim (Jun 16)
- Re: Separate firewall administrator and firewall systemadministrator Mikael Olsson (Jun 16)
- RE: Separate firewall administrator and firewall system administrator Bill Royds (Jun 16)
- RE: Separate firewall administrator and firewall system administrator Paul D. Robertson (Jun 16)
- RE: Separate firewall administrator and firewall system administrator Ron DuFresne (Jun 16)
- Re: Separate firewall administrator and firewall system administrator Paul D. Robertson (Jun 16)
- Re: Separate firewall administrator and firewall system administrator Rick Smith at Secure Computing (Jun 16)
- RE: Separate firewall administrator and firewall system administrator Yin To Chu (Jun 16)
- RE: Separate firewall administrator and firewall system administrator Yin To Chu (Jun 16)
- Re: Separate firewall administrator and firewall system administrator David R. Matusiak (Jun 16)
- Re: Separate firewall administrator and firewall system administrator Paul D. Robertson (Jun 16)
- Re: Separate firewall administrator and firewall system administrator Paul Alukal (Jun 17)
