Home > Security Tips > Network Security Tactics > Extranet security strategy considerations
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

Extranet security strategy considerations


Mike Chapple
05.30.2006
Rating: -5.00- (out of 5)


Network Security Tactics
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


In our connected society, the lines between an organization's intranet and the Internet are blurring. Almost every organization possesses some need to extend limited access to business partners, suppliers, vendors and/or customers via an extranet. In this tip, we take a look at four important strategies for securing extranets: isolation, strong authentication, granular access controls and use of adequate encryption.

1.) Isolation
Perhaps the most important step you can take when designing an extranet is to protect the network from itself. You're likely used to managing a firewall environment using the screened subnet approach with three zones: a private network, a public network and a DMZ. (For more on this, read my article, Choosing the right firewall topology.) The goal of this strategy is to isolate systems with differing levels of public access from each other. The same is true with an extranet; you need to isolate extranet systems from both the public network and the private network. You certainly don't want to expose sensitive internal systems to your business partners carte blanche. When you design your extranet, keep in mind that you want to expose only the information assets required for successful partnership.

2.) Strong authentication
The second key component of a secure extranet is the use of strong authentication techniques. Where possible, extranets should implement some form of two-factor authentication. The most likely solution where a human is involved in t...



he authentication process is the use of a key fob token approach, such as RSA's SecurID or Secure Computing's SafeWord. If extranet communications take place between unattended servers, consider the use of digital certificates to provide an added level of confidence in the authentication process.

3.) Granular access controls
Granular access controls are essential to the secure operation of complex extranets. If your organization must interact with a number of different suppliers, customers, vendors and business partners, you need to take steps to enforce the principle of least privilege. The ideal scenario, of course, is to implement isolation to such a degree that extranet clients get access to a network zone that only contains resources they are authorized to access. However, the more complicated your extranet, the less likely it is that this approach is practical. Therefore, you should complement your strong authentication controls with granular authorization controls. Administrators should configure access lists in a manner that limits the access of each extranet client to those specific resources necessary for the partnership.

4.) Encryption
Finally, extranets should make use of available encryption technology. By nature, extranets involve sharing sensitive organizational data over the Internet. Ensure that extranet clients make use of virtual private network (VPN) technology that provides strong encryption for data in transit over these unsecured networks. Also, ensure that both the VPN solution (both client and server hardware and software) and the encryption algorithm they use meet your security requirements.

Remember, the security controls outlined in this article are merely a starting point for a secure extranet design. You need to complement these controls with policies and other mechanisms that comprise basic security best practices. For example, your extranet agreements should clearly specify the security configuration standards for systems that connect to the extranet. You wouldn't want to implement the technical controls described in this tip only to have them defeated by a poorly managed user workstation that's infected by a virus!

About the author
Mike Chapple, CISSP is an IT Security Professional with the University of Notre Dame. He previously served as an information security researcher with the National Security Agency and the U.S. Air Force. Mike is a frequent contributor to SearchSecurity, a technical editor for Information Security magazine and the author of several information security titles including the CISSP Prep Guide and Information Security Illuminated.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Network Security Tactics,   Web Authentication and Access Control,   Enterprise Identity and Access Management,   Enterprise Data Protection,   Enterprise Data Governance,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Network Security Tactics
How to keep networks secure when deploying an 802.11n upgrade
Screencast: Find rogue wireless acess points with Vistumbler
How to prepare for a secure network hardware upgrade
Preventing SQL injection attacks: A network admin's perspective
Screencast: How to launch an OpenVAS scan
Wireless network guidelines for PCI DSS compliance
Aligning network security with business priorities
Scanning with N-Stalker offers basic Web application security assessment
Lifecycle of a network security vulnerability
Screencast: BackTrack 4 offers an arsenal of penetration testing tools

Web Authentication and Access Control
Group to shed light on secure identity management threats
IT business justification to limit network access
How to confirm the receipt of an email with security protocols
Schneier-Ranum Face-Off: Is Perfect Access Control Possible?
Kaminsky reveals key flaws in X.509 SSL certificates at Black Hat
Changing times for identity management
How to use single sign-on for Web access control to prevent malware
IBM USB banking device stops keyloggers, malware
Can mutual authentication beat phishing or man-in-the-middle attacks?
Could someone place a rootkit on an internal network through a router?

Enterprise Data Governance
How to protect distributed information flows
Interpreting 'risk' in the Massachusetts data protection law
Creating an enterprise data protection framework
Analyst DLP study finds maturity, ranks top DLP vendors
Voltage, RSA spar over tokenization, data protection
Twitter gets condemned by CISOs at Forrester forum
PCI DSS compliance requirements: Ensuring data integrity
Trustwave acquires data loss prevention vendor Vericept
Data has become too distributed to secure, Forrester says
Cloud-based security services should start private

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
access log  (SearchSecurity.com)
anonymous Web surfing  (SearchSecurity.com)
authentication, authorization, and accounting  (SearchSecurity.com)
identity chaos  (SearchSecurity.com)
knowledge-based authentication  (SearchSecurity.com)
multifactor authentication (MFA)  (SearchSecurity.com)
walled garden  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts