Network Security - Audit from client

Feb 16, 2010
39
0
0
Long story short, they want to be able to prove that we seperate data specific from them from everyone else. From the networking side that's fine with tagging Vlans, ACL's etc. But if their data all comes to the same host (a file server) as others, how can we mitigate that out without creating another host specifically for them? Is this feasible?
 

kevnich2

Platinum Member
Apr 10, 2004
2,465
8
76
Ok you need to provide alot more info on this. First, what kind of provider are you? What services are you providing to this client? What industry is the client in and what are they trying to comply with?
 

JackMDS

Elite Member
Super Moderator
Oct 25, 1999
29,485
391
126
Long story short, they want to be able to prove that we seperate data specific from them from everyone else.

When it comes to this type of "Demands", it can be anything from just a need of a written statement from your organization to be submitted to their insurance files for self legal protection. Or some real Security concern that is on their mind (or someone is looking for an excuse to terminate your service).

Whatever we will say about it is meaningless, you have to ask them what exactly they mean and need as a proof.


 
Feb 16, 2010
39
0
0
Client is in the banking industry. We provide logistics. In order for us to do business with them we must meet a compliance. Essentially they want any of their data to be monitored, traced, and secured. From a network level - easy. Once some of their data hits a "shared resource" such as a file server. What can I do about that? Other than making specific file servers/hosts JUST for their data, where the network traffic routes directly to them from their sources....
 

azazel1024

Senior member
Jan 6, 2014
901
2
76
Probably going to need specific file servers/hosts just for them. Possibly VMs and their own paritions/drives might cover it. This is likely a question for them.

It sounds like they have requirements and should be providing them. Not simply a nebulous "we need security and stuff seperated".
 

Mushkins

Golden Member
Feb 11, 2013
1,631
0
0
Client is in the banking industry. We provide logistics. In order for us to do business with them we must meet a compliance. Essentially they want any of their data to be monitored, traced, and secured. From a network level - easy. Once some of their data hits a "shared resource" such as a file server. What can I do about that? Other than making specific file servers/hosts JUST for their data, where the network traffic routes directly to them from their sources....

Wouldnt that shared resource have a filesystem that presumably supports security settings? I would audit the filesystem security settings on that shared fileserver to show them that only XYZ authenticated users on XYZ domain have access to the partition with that companies data. The data is technically split up on the same disks as other clients on the SAN, but it's a RAID array, if someone were to pull a single disk they'd just get junk. If they have physical access to pull all the drives on the SAN, well, i'd hope it's all encrypted

At this point it's not really a network architecture issue, its a securities and permissions issue on the software end.
 
Feb 16, 2010
39
0
0
My 2 factor authentication system can utilize an LDAP to talk to AD, With Windows Auditing (EFS) can I integrate that with my multifactor authentication as well?
 

cmetz

Platinum Member
Nov 13, 2001
2,296
0
0
whitedragon2203,

>they want to be able to prove that we seperate data specific from them from everyone else
>their data all comes to the same host (a file server) as others

So you're not separating their data from everyone else.

You need to turn the question around and ask them for detailed information on what kinds of separations they're looking for. Could be anywhere from directory permissions to a complete second everything - you need to work this out with your customer.
 

alkemyst

No Lifer
Feb 13, 2001
83,769
19
81
whitedragon2203,

>they want to be able to prove that we seperate data specific from them from everyone else
>their data all comes to the same host (a file server) as others

So you're not separating their data from everyone else.

You need to turn the question around and ask them for detailed information on what kinds of separations they're looking for. Could be anywhere from directory permissions to a complete second everything - you need to work this out with your customer.

QFT, you need the customer/client to tell you what the requirements really are. Else you are just poking around in the dark.
 

imagoon

Diamond Member
Feb 19, 2003
5,199
0
0
whitedragon2203,

>they want to be able to prove that we seperate data specific from them from everyone else
>their data all comes to the same host (a file server) as others

So you're not separating their data from everyone else.

You need to turn the question around and ask them for detailed information on what kinds of separations they're looking for. Could be anywhere from directory permissions to a complete second everything - you need to work this out with your customer.

Thirded.

File server has ACL's also. Just like network gear.
 
Feb 25, 2011
16,905
1,551
126
Fourthed.

And I'd point out that if you aren't using a VM cluster to stand up and kill new hosts as needed for your clients, you're missing out on all the fun.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |