Home > Enterprise Security Policy > 7. Computers and Servers > 7.4 Network Take-down and Vulnerability Scanning

7.4 Network Take-down and Vulnerability Scanning

Policy

Network managers are authorized by the University to run vulnerability scans in order to identify security risks and to protect computing and networking resources. Network operators should monitor network activity for signs of attack and take action in the absence of action by the operators of a compromised computer.

Discussion

The operators of school or University networks should run intrusion detection and other vulnerability assessment systems to scan for signs of network-based attacks on computers connected to the networks.

Operators of school or University networks should also conduct vulnerability scans of computers connected to their networks to be sure that security vulnerabilities are detected, reported, and remediated.

In cases of emergency, network operators may act to block some or all network traffic to or from a computer that the operators have reason to think may be specifically vulnerable to attack, under attack or has been compromised or disconnect the computer from the network as approved by school or University senior management.

The response to a security incident should consistently follow a predetermined checklist that includes steps to end the incident, preserve forensic data, repair the damage, prevent a repeat attack, and scan for new vulnerabilities. Note that any potential breach in a system containing or processing high-risk confidential information needs to be reported as soon as possible. (See Section 9.2: Reporting Security Breaches [1].)

In the case where a school's network is not operated by the school all monitoring, scanning and blocking should be done in consultation with the school's CIO or network manager.

© 2009 President and Fellows of Harvard College.
 
Trademark Notice | Privacy Policy



Source URL (retrieved on 11/25/2009 - 02:35): http://www.security.harvard.edu/enterprise-security-policy/7-computers-and-servers/policies-7_4

Links:
[1] http://www.security.harvard.edu/enterprise-security-policy/9-federal-regulatory/policies-9_2