Enterprise SAFE Design Objectives

The following are listed as design objectives for the SAFE Blueprint (listed in priority order):

  • Security and attack mitigation based on policy

  • Security implementation through the infrastructure (not just on specialized security devices)

  • Cost-effective deployment

  • Secure management and reporting

  • Authentication and authorization of users and administrators to critical network resources

  • Intrusion detection for critical resources and subnets

Not listed as an objective, per se, but also to be accomplished, is ensuring that the network is resilient and scalable. Resiliency requires that there be no single point of failure; this makes the network more complex because of the additional devices required, as well as the more involved configurations required on all devices. Scalability implies a hierarchical structure, with patterns that can be replicated to yield a larger structure that can be managed in units instead of one device at a time.

Trade-offs will be needed when applying the Blueprint, and some trade-offs will be between the cost savings inherent in adding another function to an existing device (or acquiring one multifunction device) and the performance capabilities of using dedicated devices. The SAFE Blueprint recommends that the decision be made based on performance, not costthe driver should be the capabilities of the dedicated device compared to the advantages gained from integrating that function with another device. That does not mean that cost will not be a factor because, of course, it will. However, all costs must be considered , including the direct and indirect costs of a security incident (indirect costs include loss of reputation, work not accomplished by those repairing damage done, and so on). In that light, you must have a certain level of performance to avoid those costs, so performance should be your first criterion. (If you have multiple possible solutionsboth dedicated appliances and integrated devices will perform as you needcost could be a deciding factor among the acceptable choices.)



CSI Exam Cram 2 (Exam 642-541)
CCSP CSI Exam Cram 2 (Exam Cram 642-541)
ISBN: 0789730243
EAN: 2147483647
Year: 2002
Pages: 177
Authors: Annlee Hines

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net