11 Network Security Policy
Network devices must be configured and deployed in accordance with platform-specific security build requirements to be maintained by deployment teams and reviewed by the security team at least annually. Deployment procedures must use automated processes to ensure consistency and compliance with requirements when more than 5 systems of a given platform are to be deployed.
System Accounts. Built-in or other local accounts should be eliminated where possible. All default passwords must be changed to 48-character randomized strings stored in an approved centralized password vault with restricted access. Where configurable platforms should use the strongest cryptographic hashing function available for local passwords.
User Provisioning. Systems should use an approved centralized company authentication protocol and service such as TACACS or RADIUS in lieu of local accounts for all users, administrative and otherwise. Approval and provision processes must be documented in approved procedures.
MFA. Elevated credentials including privileged accounts as well as “become” or “sudo” passwords must require a one-time password.
Network Registration. Public network registration with Internet providers or whois registries should use aliased department-leven contact information affiliated with $company. Dedicated specific SMTP addresses should be used that can have membership later modified internally to the company to reflect changing individual responsibilities. Contacts should always distribute incoming messages to at least two active personnel. Where available, the ability to share contacts for abuse reporting should be utilized with a dedicated but generic alias that delivers to the security group in addition to responsible network individuals.
Reverse DNS. Reverse DNS entries for company-owned Internet space shall have generic number-related entries in company-owned domains by default, but should not expose system or service-level information unless it is required by specific services such as mail transfer agents.
WiFi
Internet-Only. Wireless networks must be provisioned with only Internet access. Internal wireless networks with direct routing and access to internal networks are prohibited.
VPN Required. Connections to an on-site or otherwise company-managed wireless network should not grant any additional privileges over a public network, and both should require additional authentication and protection via a VPN or equivalent service before corporate resources can be accessed.
No Public Usage. Wireless networks should have mechanisms deployed to restrict usage to authorized personnel to mitigate the threat of company networks being used to access illegal material, attack other Internet resources, or otherwise represent company networks across the Internet without authority.
Access Credentials. A random but pronounceable SSID-level password shared across all company wireless networks may be used provided it is rotated at least monthly. This password may be shared on internal-only communication systems or via placards displayed in company facilities but not in public-facing resources. Unique individual logins are not required at the SSID level or via a captive portal.
Guest and Visitor Access. Wireless access may be provisioned to guests and visitors.