NO MORE UPDATES TO THIS PAGE PLEASE. SUBMIT ALL FUTURE COMMENTS TO |
9.1.6 pg 185
when discussing social engineering to get an account created and the modem pool number. It might be worth saying that while defined business processes may help mitigate such issues (eg having an approvals process in place before accounts are created) they can't solve all the issues
[ Tom: Good idea. I can't figure out where to fit it in. ]
9.2.1 pg 187
"occaisionally reprint privacy statements in newsletters or bulletins". Also worth putting a summary/reminder of the privacy policy on the login screen so the SA effectively has to agree to the policy every time he accesses a box.
[ Tom: Good idea. Status: DONE ]
--
StephenHarris - 16 Aug 2006