2 cissp ® Official Study Guide Eighth Edition



Download 19,3 Mb.
Pdf ko'rish
bet455/881
Sana08.04.2023
Hajmi19,3 Mb.
#925879
1   ...   451   452   453   454   455   456   457   458   ...   881
Bog'liq
(CISSP) Mike Chapple, James Michael Stewart, Darril Gibson - CISSP Official Study Guide-Sybex (2018)

Boosting Performance
Network segmentation can improve performance through an orga-
nizational scheme in which systems that often communicate are located in the same seg-
ment, while systems that rarely or never communicate are located in other segments. Often 
the use of routers is employed for the purpose of dividing broadcast domains, which can 
significantly improve performance for larger networks.
Reducing Communication Problems
Network segmentation often reduces congestion and 
contains communication problems, such as broadcast storms, to individual subsections of 
the network.
Providing Security
Network segmentation can also improve security by isolating traffic 
and user access to those segments where they are authorized.
Segments can be created by using switch-based VLANs, routers, or firewalls, individu-
ally or in combination. A private LAN or intranet, a DMZ, and an extranet are all types of 
network segments.
When you’re designing a secure network (whether a private network, an intranet, or an 
extranet), you must evaluate numerous networking devices. Not all of these components are 


Secure Network Components 
487
necessary for a secure network, but they are all common network devices that may have an 
impact on network security.
Network Access Control
Network Access Control (NAC)
is a concept of controlling access to an environment 
through strict adherence to and implementation of security policy. The goals of NAC are as 
follows:

Prevent/reduce zero-day attacks

Enforce security policy throughout the network

Use identities to perform access control
The goals of NAC can be achieved through the use of strong detailed security policies 
that define all aspects of security control, filtering, prevention, detection, and response for 
every device from client to server and for every internal or external communication. NAC 
acts as an automated detection and response system that can react in real time to stop 
threats as they occur and before they cause damage or a breach.
Originally, 802.1X (which provides port-based NAC) was thought to embody NAC, but 
most supporters believe that 802.1X is only a simple form of NAC or just one component in 
a complete NAC solution.
NAC can be implemented with a preadmission philosophy or a postadmission philoso-
phy, or aspects of both:
The preadmission philosophy requires a system to meet all current security require-
ments (such as patch application and antivirus updates) before it is allowed to commu-
nicate with the network.
The postadmission philosophy allows and denies access based on user activity, which is 
based on a predefined authorization matrix.
Other issues around NAC include client/system agent versus overall network monitoring 
(agent-less); out-of-band versus in-band monitoring; and resolving any remediation, quar-
antine, or captive portal strategies. These and other NAC concerns must be considered and 
evaluated prior to implementation.

Download 19,3 Mb.

Do'stlaringiz bilan baham:
1   ...   451   452   453   454   455   456   457   458   ...   881




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish