The Cisco network designer may or may not have a role in creating the corporate security policy. Every organization, regardless of size, should have some form of written security policy and procedures, along with a plan for enforcing that policy and a disaster and recovery plan.
Figure 8.4 – Cisco Security Policy Methodology
When initially developing a security policy, Cisco recommends a methodology that is comprised of the following five steps (illustrated in Figure 8.4 above):
- Risk assessment
- Determine and develop the policy
- Implement the policy
- Monitor and test security
- Re-assess and re-evaluate
Risk assessment involves determining what the network threats are, making sure the entire network is documented, and identifying the current vulnerabilities and the countermeasures that are already in place. The second step is determining and developing a security policy. The policy should be based on a wide variety of documents, depending on the organization. The policy should also take into account the company’s strategy, the decision-makers of the company, their obligation to the company, the value of the company’s assets, and prioritization of the security rules.
After the policy is developed, it should be implemented from a hardware and software standpoint. This involves putting into place all the mechanisms involved in the Cisco SAFE blueprint (this will be covered in detail later in this chapter) and applying these to the campus infrastructure modules and submodules. The next step is to monitor and test the security plan, and, finally, to re-evaluate it in order to make changes that will improve the policy.
This methodology closely relates to the PPDIOO design methodology presented earlier. The security policy documentation can be different for each organization and can be based on different international standards. Some common written documents include the following:
- Organizational security policy
- Acceptable use policy
- Access control policy
- Incident handling
- Disaster recovery plan
- Personnel policies and procedures
The organizational security policy is a general document that is signed by the management of the organization and contains high-level considerations, such as its objectives, the scope of the security policy, risk management aspects, the company’s security principles, planning processes (including information classification), and encryption types used in the company.
The acceptable use policy and the personnel policies and procedures detail the way in which individual users and administrators use their access privileges. The access control policy involves password and documentation control policies, and incident handling describes the way a possible threat is handled in order to mitigate a breach in the organization’s security. The disaster recovery plan is another document that should be included in the organizational security policies, and it should detail the procedures that will be followed in case of a total disaster, including applying backup scenarios.
When documenting the security policy, the components may be divided into the major security mechanisms that will be applied in the organization, including the following:
- Physical security
- Authentication
- Authorization
- Confidentiality
- Data integrity
- Management and reporting
Physical security is often ignored when documenting the security policy. This involves physically securing the data center and the wiring closets; restricting access to network devices, LAN cabling, and the WAN/PSTN connection points; and securing access to endpoint devices such as workstations and printers.
Authentication ensures that the individual users who are actually accessing particular devices on the network are authorized to do so. Authentication is used to determine the identity of the subject and authorization is used to limit access to network devices based on their identity. Confidentiality and data integrity define encryption mechanisms to be used, such as IPSec, digital signatures, or physical biometric user access. Management and reporting involve auditing the network from a security standpoint, logging information, and auditing the actions of users and administrators. This can be supported by the use of Host Intrusion Detection Systems (HIDSs) to ensure that network servers can detect and protect themselves against attacks.
