Guidelines on Securing Public Web Servers
Ensuring the establishment of, and compliance with, consistent IT security policies for
departments throughout the organization
Coordinating with upper management, public affairs, and other relevant personnel to
produce a formal policy and process for publishing information to Web sites and
ensuring this policy is enforced
3.2.2 Information Systems Security Program Managers
The Information Systems Security Program Managers oversee the implementation of, and
compliance, with the standards, rules, and regulations specified in the organization's security
policy. The ISSMs are responsible for the following activities associated with Web servers:
Developing and implementing standard procedures (security policy)
Complying with security policies, standards, and requirements
Ensuring that all critical systems are identified and that contingency planning, disaster
recovery plans, and continuity of operations plans exist for these critical systems
Ensuring that critical systems are identified and scheduled for periodic security testing
according to the security policy requirements of each respective system.
3.2.3 Information Systems Security Officers
Information Systems Security Officers (ISSOs) are responsible for overseeing all aspects of
information security within a specific organizational entity. They ensure that the organization s
information security practices comply with organizational and departmental policies,
standards, and procedures. ISSOs are responsible for the following activities associated with
Web servers:
Developing internal security standards and procedures for the Web server(s) and
supporting network infrastructure
Cooperating in the development and implementation of security tools, mechanisms,
and mitigation techniques
Maintaining standard configuration profiles of the Web servers and supporting
network infrastructure controlled by the organization, including but not limited to,
operating systems, firewalls, routers, and Web server applications
Maintaining operational integrity of systems by conducting security tests and ensuring
that designated IT professionals are conducting scheduled testing on critical systems.
3.2.4 Web and Network Administrators
Web administrators are system architects responsible for the overall design, implementation,
and maintenance of a Web server. Network administrators are responsible for the overall
design, implementation and maintenance of a network. Daily, Web and network
administrators must address the security requirements of the specific system(s) for which they
are responsible. Security issues and solutions can originate from either outside (e.g., security
12
Unlimited Web Hosting
|
|
TotalRoute.net Business web hosting division of Vision Web Hosting Inc. All rights reserved. |