home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers






RFP: Security Services

In Coopers & Lybrand's Words: Solution Summary
It is our desire to provide PRIS with timely and meaningful information after assessing the security environments of its various organizations. In that light, we have developed the following strategy for providing value-added deliverables to PRIS.

At the outset of our security assessment procedures at every PRIS location, we will review our anticipated timeline for initiating and completing each major phase of the project. At the conclusion of each major phase of the assessment project--for example, the NT Server security assessment--we will provide a draft report that outlines the security-related findings and observations resulting from t he detailed work-program tasks performed, along with recommendations for mitigating risks and vulnerabilities. This report will be provided in draft and later consolidated with other reports resulting from completed phases of the organization's security assessment.

At the conclusion of our fieldwork, we will consolidate interim draft documents as described above; present a consolidated draft of our findings, observations and recommendations to PRIS of the assessed organization; revise our draft document based on comments received from the assessed organization; revise our draft document based on comments received from the PRIS corporate security council; and issue a final document to the PRIS corporate management of the assessed organization.

Potential findings developed during the execution of our work programs will be discussed with appropriate personnel as they are uncovered.

At the conclusion of our assessment, a security infrastructure design will be possible. Many geographically dispersed compa nies with diverse computing and network environments are using the open systems of Web and Internet standards to communicate securely among all locations. The diagram (on page 60) depicts a possible network security infrastructure for PRIS. Each office uses redundant Internet connections with the supporting firewalls and intrusion-prevention mechanisms. Encrypted tunneling VPNs (virtual private networks) can be established among all of the offices. Even remote users, such as IS staff and executives, can securely connect to the corporate network. Eventually, customers and trading partners also can be included in the circle of trust created by these VPNs.

Coopers & Lybrand

Pros: Large organization able to offer a range of services, including application-level inspection

Cons: Moderately expensive for what is proposed; doesn't thoroughly address all issues

Network Computing's Evaluation Of Coopers & Lybrand's Response
Coopers & Lybra nd's proposal was perhaps the most detailed we received at the base auditing level. Its approach was very thorough, documenting every point of coverage within individual platforms: Windows NT, NetWare, Unix and Windows95. Details ran the gamut from file system rights checks, to higher level NDS policies, to drilling all the way down to transmission media from a physical standpoint. However, as in many of the other proposals we received, the OS/390 issue was completely ignored. In fact, only Miora and Price Waterhouse specifically addressed, or even mentioned, OS/390.








Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights