This is actually on a clients servers, but your information otherwise deeply
applies.

Thanks all for the information and allowing me to rant.

Up to know, it was supposed to be my boss that handled all policies and
such. That is going to change now.

John Tolmachoff MCSE, CSSA
IT Manager, Network Engineer
RelianceSoft, Inc.
Fullerton, CA  92835
www.reliancesoft.com

> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:IMail_Forum-
> [EMAIL PROTECTED] On Behalf Of Sean P. Malone
> Sent: Tuesday, March 04, 2003 5:55 PM
> To: [EMAIL PROTECTED]
> Subject: Re: [IMail Forum] OT: Policy Question
> 
> 
> John,
> 
> I can only imagine your frustration!
> 
> To proactively address possible, problematic behavior of a third-party,
you should
> really implement a policy at the written and signed level.
> 
> What you mention is a major infraction of information assurance.  In your
case, the
> availability of the services that your organization offers was weakened by
the
> actions of a third-party vender.
> 
> There are at least two written documents that you might consider adding to
your
> standard set of agreements, if you have not already, to address this
specific issue (I
> am assuming that you already require an signed non-disclosure agreement):
> 
> (1)   A Third-Party Network Connection Agreement - This states A LOT of
> things in writing but will specifically include what third-party venders
are allowed to
> do, under what circumstances, who they should work with on your end to
make
> sure that end-users are not affected, and what the plan is when things go
wrong.
> 
> John- even though these may be your clients, your organization still
"owns" the
> systems and network that their virtual presence resides on.  Your
organization is
> liable and, thus, has the right to enforce an acceptable set of standards
that will
> protect the needs of the entire client base from the needs of the few.
> 
> (2)   An Acceptable Encryption Policy - We all now live, to a certain
degree,
> through MS terminal services.  Is the current RDP encryption good enough
for your
> environment?  There are several enhancements to RDP between W2K SP2 and
> SP3, as well as, a few additions after that.  A document such as this will
make
> things very clear to your third-parties just what type of diligence is
expected by your
> organization.
> 
> Keeping up with agreements such as these is always really tough for
everyone.
> However, few legitimate IT folks ever plan to compromise or bring someone
else's
> system down - it is almost always an accident.  Written and signed
documents will
> help everyone involved take that extra second or two to think about the e-
> consequences of the actions that are about to take place.
> 
> If you need some templates for these documents, SANS is the place to
start!
> 
> Regards,
> 
> Sean
> ---------- Original Message ----------------------------------
> From: "John Tolmachoff" <[EMAIL PROTECTED]>
> Reply-To: [EMAIL PROTECTED]
> Date:  Tue, 4 Mar 2003 16:34:36 -0800
> 
> >How many IT admins out there would allow a software vendor access a
server
> >via terminal services to update/upgrade the vendor's software on the
server
> >without their knowledge or oversight?
> >
> >We have a client that has allowed this, and it has become an issue where
the
> >client requested us to make some customizations to the Web screens, but
the
> >software vendor ignored and over wrote with out telling any one. Now the
> >software vendor is saying they did nothing wrong.
> >
> >They made a change based on a user reported problem.
> >
> >Hello, we are the IT support.
> >
> >Sorry for the OT but this kind of actions by a vendor tick me off.
> >
> >John Tolmachoff MCSE, CSSA
> >IT Manager, Network Engineer
> >RelianceSoft, Inc.
> >Fullerton, CA  92835
> >www.reliancesoft.com
> >
> >
> >
> >
> >To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
> >List Archive:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
> >Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
> >
> 
> 
> To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
> List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
> Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to