27.01.2014 Views

NIST 800-44 Version 2 Guidelines on Securing Public Web Servers

NIST 800-44 Version 2 Guidelines on Securing Public Web Servers

NIST 800-44 Version 2 Guidelines on Securing Public Web Servers

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

GUIDELINES ON SECURING PUBLIC WEB SERVERS<br />

3.2.1<br />

Senior IT Management/Chief Informati<strong>on</strong> Officer<br />

The Senior IT Management/Chief Informati<strong>on</strong> Officer (CIO) ensures that the organizati<strong>on</strong>’s security<br />

posture is adequate. The Senior IT Management provides directi<strong>on</strong> and advisory services for the<br />

protecti<strong>on</strong> of informati<strong>on</strong> systems for the entire organizati<strong>on</strong>. The Senior IT Management/CIO is<br />

resp<strong>on</strong>sible for the following activities associated with <strong>Web</strong> servers:<br />

Coordinating the development and maintenance of the organizati<strong>on</strong>’s informati<strong>on</strong> security policies,<br />

standards, and procedures<br />

Coordinating the development and maintenance of the organizati<strong>on</strong>’s change c<strong>on</strong>trol and management<br />

procedures<br />

Ensuring the establishment of, and compliance with, c<strong>on</strong>sistent IT security policies for departments<br />

throughout the organizati<strong>on</strong><br />

Coordinating with upper management, public affairs, and other relevant pers<strong>on</strong>nel to produce a<br />

formal policy and process for publishing informati<strong>on</strong> to <strong>Web</strong> sites and ensuring this policy is<br />

enforced.<br />

3.2.2<br />

Informati<strong>on</strong> Systems Security Program Managers<br />

The Informati<strong>on</strong> Systems Security Program Managers (ISSPM) oversee the implementati<strong>on</strong> of and<br />

compliance with the standards, rules, and regulati<strong>on</strong>s specified in the organizati<strong>on</strong>’s security policy. The<br />

ISSPMs are resp<strong>on</strong>sible for the following activities associated with <strong>Web</strong> servers:<br />

Ensuring that security procedures are developed and implemented<br />

Ensuring that security policies, standards, and requirements are followed<br />

Ensuring that all critical systems are identified and that c<strong>on</strong>tingency planning, disaster recovery plans,<br />

and c<strong>on</strong>tinuity of operati<strong>on</strong>s plans exist for these critical systems<br />

Ensuring that critical systems are identified and scheduled for periodic security testing according to<br />

the security policy requirements of each respective system.<br />

3.2.3<br />

Informati<strong>on</strong> Systems Security Officers<br />

Informati<strong>on</strong> Systems Security Officers (ISSO) are resp<strong>on</strong>sible for overseeing all aspects of informati<strong>on</strong><br />

security within a specific organizati<strong>on</strong>al entity. They ensure that the organizati<strong>on</strong>’s informati<strong>on</strong> security<br />

practices comply with organizati<strong>on</strong>al and departmental policies, standards, and procedures. ISSOs are<br />

resp<strong>on</strong>sible for the following activities associated with <strong>Web</strong> servers:<br />

Developing internal security standards and procedures for the <strong>Web</strong> server(s) and supporting network<br />

infrastructure<br />

Cooperating in the development and implementati<strong>on</strong> of security tools, mechanisms, and mitigati<strong>on</strong><br />

techniques<br />

Maintaining standard c<strong>on</strong>figurati<strong>on</strong> profiles of the <strong>Web</strong> servers and supporting network infrastructure<br />

c<strong>on</strong>trolled by the organizati<strong>on</strong>, including, but not limited to, OSs, firewalls, routers, and <strong>Web</strong> server<br />

applicati<strong>on</strong>s<br />

3-4

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!