You are on page 1of 11

CIS288 Security Design in a Windows 2003 Environment

CIS288 Securing the Network Management Process

Objectives
When you complete this lesson you will be able to:
Design security for network management Manage the risk of managing networks Design security for Emergency Management Services Design Group Policy to deploy software updates Design forest and domain trust models

Securing the Network Management Process


The problem of implementing security in networks lies in the fact that you are always defending against attacks and you are defending against an enemy you dont know, dont see, and cant predict. Windows Server 2003 allows you to implement role-based administration and enforce many security guidelines and policies using Group Policy and Delegation of Administration.

Managing the Risks of Network Administration


When a company experiences a period of growth and expansion, it often adds more IT staff in addition to infrastructure such as servers and networking equipment. The network administration process itself can become a threat to the security of your enterprise network if you do not take steps to design a secure model for network management.

Security Policies for Administrators and IT Personnel


Network Management Policy OU

Delegating Authority Securely


Divide administrative duties among your IT staff so that they have enough permission to do the task they were hired to do. Within Active Directory itself, you can structure your delegation strategy based on roles.

Securing Common Administrative Tools


All the security in the world cant help if the tools at the administrators disposal are not properly secured Inappropriate use of network management tools can reveal administrative credentials and other sensitive information about your network

Designing Security for Emergency Management Services


Out-of-band connection EMS (Emergency Management Services) EMS allows you to perform the following tasks: Start up or shut down a server Install the Windows operation system if the server can communicate with Remote Installation Services Manage a Windows Server 2003 system when you are unable to access it the traditional way, over the network using standard tools View system Stop errors Change the Bios settings Select which operating system to start View Power on Self-Test result

Designing a Security Update Infrastructure


Patching SUS (Software Update Services)

Designing Trust Relationships Between Domains and Forests


A trust creates the framework that governs domain-to-domain or forest-to-forest relationships One-way trusts Two-way trusts Transitive trusts Nontransitive trusts

Summary
Securing the Network Management Process Managing the Risks of Network Administration Security Policies for Administrators and IT Personnel Designing Security for Emergency Management Services Designing Trust Relationships between domains and forests

You might also like