John,

I can only imagine your frustration!

To proactively address possible, problematic behavior of a third-party, you should 
really implement a policy at the written and signed level.

What you mention is a major infraction of information assurance.  In your case, the 
availability of the services that your organization offers was weakened by the actions 
of a third-party vender.

There are at least two written documents that you might consider adding to your 
standard set of agreements, if you have not already, to address this specific issue (I 
am assuming that you already require an signed non-disclosure agreement):

(1)     A Third-Party Network Connection Agreement � This states A LOT of things in 
writing but will specifically include what third-party venders are allowed to do, 
under what circumstances, who they should work with on your end to make sure that 
end-users are not affected, and what the plan is when things go wrong.

John- even though these may be your clients, your organization still �owns� the 
systems and network that their virtual presence resides on.  Your organization is 
liable and, thus, has the right to enforce an acceptable set of standards that will 
protect the needs of the entire client base from the needs of the few.

(2)     An Acceptable Encryption Policy � We all now live, to a certain degree, 
through MS terminal services.  Is the current RDP encryption good enough for your 
environment?  There are several enhancements to RDP between W2K SP2 and SP3, as well 
as, a few additions after that.  A document such as this will make things very clear 
to your third-parties just what type of diligence is expected by your organization.

Keeping up with agreements such as these is always really tough for everyone.  
However, few legitimate IT folks ever plan to compromise or bring someone else�s 
system down � it is almost always an accident.  Written and signed documents will help 
everyone involved take that extra second or two to think about the e-consequences of 
the actions that are about to take place.

If you need some templates for these documents, SANS is the place to start!

Regards,

Sean
---------- Original Message ----------------------------------
From: "John Tolmachoff" <[EMAIL PROTECTED]>
Reply-To: [EMAIL PROTECTED]
Date:  Tue, 4 Mar 2003 16:34:36 -0800

>How many IT admins out there would allow a software vendor access a server
>via terminal services to update/upgrade the vendor's software on the server
>without their knowledge or oversight?
>
>We have a client that has allowed this, and it has become an issue where the
>client requested us to make some customizations to the Web screens, but the
>software vendor ignored and over wrote with out telling any one. Now the
>software vendor is saying they did nothing wrong.
>
>They made a change based on a user reported problem.
>
>Hello, we are the IT support.
>
>Sorry for the OT but this kind of actions by a vendor tick me off.
>
>John Tolmachoff MCSE, CSSA
>IT Manager, Network Engineer
>RelianceSoft, Inc.
>Fullerton, CA  92835
>www.reliancesoft.com
>
>
>
>
>To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
>List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
>Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
>


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to