network security - clemson university study... · network security this is a case study of a...

1
Network Security This is a case study of a company doing business on the internet, addressing their computing and networking system requirements. We will be looking at the security policy for their network. This company wants to provide WEB access for product information and on-line ordering. They also want to provide e- mail access for their customers and their employees. The company software developers need access to the internet, but non-company employees should not be allowed to access any system other than the system that provides company information and the ordering of company products. Company officers and lawyers need access to the development data, but the developers should not be able to access the company’s legal or accounting data. The company players could be depicted as The above scenario can be summarized in the following security goals. Security Policy Goals 1. Data related to company plans is to be kept secret. Specifically, sensitive corporate data, such as data involved in the development of potential products, is to be available only to those on a need to know basis. 2. Customer data is only available to those in the sales department who process the orders. This would include credit card information, and other customer related information obtained through the purchasing process via the company’s web site. Corporate planning analysts may obtain statistics about the number of orders, etc, for product planning purposes. 3. Releasing sensitive data requires the consent of company officials and lawyers approval.

Upload: trantu

Post on 05-Jul-2018

217 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Network Security - Clemson University Study... · Network Security This is a case study of a company doing business on the internet, addressing their computing and networking system

Network Security This is a case study of a company doing business on the internet, addressing their computing and networking system requirements. We will be looking at the security policy for their network. This company wants to provide WEB access for product information and on-line ordering. They also want to provide e-mail access for their customers and their employees. The company software developers need access to the internet, but non-company employees should not be allowed to access any system other than the system that provides company information and the ordering of company products. Company officers and lawyers need access to the development data, but the developers should not be able to access the company’s legal or accounting data. The company players could be depicted as The above scenario can be summarized in the following security goals. Security Policy Goals 1. Data related to company plans is to be kept secret. Specifically, sensitive corporate data, such as data

involved in the development of potential products, is to be available only to those on a need to know basis.

2. Customer data is only available to those in the sales department who process the orders. This would

include credit card information, and other customer related information obtained through the purchasing process via the company’s web site. Corporate planning analysts may obtain statistics about the number of orders, etc, for product planning purposes.

3. Releasing sensitive data requires the consent of company officials and lawyers approval.