The DMZ as an Acceptable AUS

The DMZ as an Acceptable AUS

Executive Summary

Modern day organizations are challenged predominantly by how to generate, safeguard and share data. In most cases, data is subject to compromise both internally and externally. To limit this, organizations should apply required legal standards; for instance the use of Acceptable Use Policy (AUP). AUP is primarily responsible to compel competitors, clients, contracts, and staff on secure methods of resource sharing. The commencing discussion will attempt to establish respect to Demilitarized Zones as a coherent AUP, and how this respect abides with the above named parties. The paper is structured into two main parts; first, the nature of DMZ, which in this case will attempt to show the how respect to the DMZ can be recognized as AUS. The second part will attempt educate on how organizations can implement the DMZ as an acceptable AUS policy.

Purpose of DMZ as an Acceptable Use Policy

When considering the better use of information systems, questions of availability, confidentiality and integrity often become a significant debate in integrating AUP. To ensure these goals are met, AUP endeavors to be concise by covering important points. Concerns stretch valiantly from efficiency, cost and security. Provenzo et al (2013, p. 159) presents a situation where AUP is applied to regulate the usage of the internet with an inert goal to protect students presumed watching online pornography. With this goal, it is clear that AUP is based on decorum principles; however, AUP attempts to establish regulatory principles, which do have advance repercussion to staff members who are considered to be going against work area ethics courtesy of respect to the DMZ. Inversely, AUPs are instrumental in developing security systems; for instance, DMZs firewalls. DMZs firewalls will not only be essential in backing-up data, but as well as, securing the data, therefore, promoting data reliability and security. Calder (2005, p. 69) argues that AUP will be essential in developing firewalls, which will separate internal systems based on departments or categories, as well as, external indulgence, chiefly, extranets and the internet. Conversely, organizational data will be protected from external malicious attacks from a range of external attacks stretching from scum-ware writers, spies, virus writers, hackers and spies. So to it, the newly created demilitarized zones (DMZs) will be essential in promoting integrity and confidentiality within the intra-organization departments and also outside the organization. Also, AUP will be instrumental in developing Enterprise Management System, primarily those which will manage system logs. Organizational members will have the ability to control individual accounts; thus, limiting the vulnerability occasioned fraudulent unauthenticated users.

Criticizing the AUP (DMZ) selected and how it can be adjusted

Even though the DMZ seems a reliable AUP methodology, the instigating discussion will attempt to show the shortcomings associated with this system and inversely offer breakthroughs which can be applied to improve the system. Primarily, the DMZ is located behind the firewall, which in this case happens on a different LAN. This is risky since the DMZ security will be defending against external attacks only; thus, grounding the organizational against vulnerable internal attacks. Syngress (2003, p. 89) exemplifies the case of web-servers which provide services to both internal and external networks. Syngress argues that there are several advertisements of vulnerabilities, with the development of poor relationships between internal and external networks. Well established demerits of DMZs are lower security due to limitation in expandability. Secondly, the DMZ is inefficient since it grounds loss of absolute security due to its inability to update content. Thirdly, an eminent point of failure is occasioned by products limiting networks addressing to the DMZ.

Based on the arguments of confidentiality and integrity required inside AUP, it is prudent to establish the necessity of constructing an internal firewall mechanism to manage internal vulnerability. To ensure the system is not comprised, Stewart (2003, p. 301) advocates the application of DMZ in a Multi faced interface, one that addresses private LAN, the DMZ and external network. This looks for a lucid development of intranets and extranets. This paper proposes the use of IPv6 since it is reliable from comprises attacks common in IPv4 cloning.

Methods that organizations can implement DMZ to help ensure compliance with the AUP

Hernandez, (2009, p. 31) advocates the use of directive controls which provide general guidelines that staff are expected in order to access information. Directive controls are effective since they look beyond internal organization measurements, to external considerations, one which manages competitors, contractors, clients, vendors, and guests. Inversely, the organization should endeavor championing the use of ethical behavior, one which will look into merging legal and democratic governance inside the organization. Hernandez et al (2009, p. 31-32) advises on the notion of best practice that an organization should compel the employees to sign and annually update the AUP before being granted to organizational resources. This updates the employee on the necessity to respect organization resources with the intentions of benevolence, confidentiality, integrity, and responsibility. The DMZ will accomplish these in a diversified manner. In this case, it is good to consider that the DMZ is a physical and a virtual zone, one which should be protected from direct external attacks physically or use of remote hacking methods. To ensure compliance is achieved, the organization should establish statutory concerns, those which look into the application of sanctions as a responsive method. Sanctions will be primarily responsible to develop law, rules and regulations. So to it, attacks should be criminalized, and conversely attracts punishments depending on the area jurisdiction laws and definitions of cybercrime accepted and applied in that authority.

How to increase the awareness of the AUP, and other policies, within the organization

An eminent challenge in failures of AUP is the inability of staff members to fully abide to the AUP requirements and stipulations, also, poor follow-up methods by regulators and organizations sergeants. These grounds riskier situations grounded on negligence. For instance, most organizations consider that company admin should access all files, on the basis of sergeant at work. However, this notion is highly contested on the argument of confidentiality. Doubts and spy and blame games are unproductive to the company. To manage this, the organization should endeavor to use a plethora of widely accepted methods. This technique encompasses on the right of using fair and effective methods with a primary goal of improving organization relationships. It is important for the organization to use the principles of education rather than punishment. Education looks into a wider scope of explaining to new staff why violations of AUP will be unethical both to self and to the company. This can be improved by prioritizing top-bottom and bottom up communications. Expected products will directly pioneer the frequent meetings, seminars and the development of personal business relationships inside the organizations. Secondly, the organization should endeavor to provide legal notices to violators in line with the AUP contract. These can be use of copyright laws, misuse, and ownership. In case of education failure because of persistent violations, Phillips & Sianjina (2013, p.22) advises the development of robust tracking technologies; for instance, Internet Protocol IP, which are transmitted from logged on computers to establish violators.  

Conclusion

This document has attempted to argue on the importance of developing Acceptable Use Policy (AUS) with a goal of improving information systems inside and organization. The paper has been structured to reflect; firstly, appointing AUS of choice courtesy of DMZ and how organization policy on resource sharing and security are subject of DMZ.  The paper has also criticized the DMZ for its failure to provide sufficient levels of security inside the LAN. Thirdly, the paper has attempted to educate how organization can endeavor to achieve sufficient results of AUS while using the DMZ, and finally how the organization can successfully implement the AUS.

References

Calder, A. (2005). A Business Guide To Information Security: How to Protect Your Company’s

IT Assets Reduce Risks and Understand the Law. London: Kogan Page Publishers.

Cyber Security for Educational Leaders: A Phillips, R., & Sianjina, R. (2013). Guide to

Understanding and Implementing Technology Policies. London: Routledge, 03 (1) 22-23.

Hernandez, S. (2009). Official (ISC)2 Guide to the CISSP CBK, Second Edition. CRC Press, 11

(1) 30 -31.

Provenzo, E., Brett, A., & Mc Closeky. (2013). Computers, Curriculum, and Cultural Change:

An Introduction for Teachers. London: Routledge, 12 (2) 159-160.

Stewart, J. (2011). CompTIA Security+ Review Guide: Exam SY0-301. New York: John Wiley &

Sons, 16 (4) 300-301.

Syngress. (2003). The Best Damn Firewall Book Period. New York: Syngress.

 

Use the order calculator below and get started! Contact our live support team for any assistance or inquiry.

[order_calculator]