TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------

We are considering re-designing default policies for Server Sensor and need your 
input, as customers, on what policies would help you the most.  Option 1a has been 
requested by several customers already, because they want enforce auditing turned off 
as it changes their default Corporate security audit policy, and the dynamic blocking 
can block custom applications - so Development is currently using 1a as the default 
install policy.

1)  What kind of default policy file would you like installed from the beginning (at 
install and startup of time) of Server Sensor?  We are considering offering the 
following options:
1a) Log Audit Signatures/ Enforce Audit Policy are turned off, Selection of Network 
Attack Signatures turned on, dynamic firewall blocking is turned off.  
1b) Blank Policy - nothing is turned on - ready for your complete customization
1c) Audit signatures turned on, enforce audit policy turned on, selection of network 
attack signatures turned on, some dynamic blocking for high priority signatures turned 
on.

2) Do you need canned policies?  What kind of canned policies do you need?  Would you 
be satisfied with no canned policies so you can customize to your environment?  

-------------------------------------------------------------------
Audra Eng
Product Manager - Host Protection Systems
Internet Security Systems
Cell phone: +1 415.720.2898
Telephone: +1 415.379.3566
Fax: +1 415.831.4780
Internet Security Systems -- The Power to Protect
<http://www.iss.net/>
-------------------------------------------------------------------
CONNECT 2002: The Premier Conference for Internet, Enterprise and Network Security 
> Join us at Internet Security Systems' International Security Summit, September 30 - 
>October 4, 2002 in Atlanta 
> Visit <http://www.issconnect.net> for details
> 
> 
> 


Reply via email to