Southern New Hampshire University CYB 400 Project Three
Access Control Compliance Assessment Worksheet
Grey Ma er security team ndings
Does this nding meet compliance? (Yes or No)
If thending does not comply with Grey Ma er requirements, explain the issue.
Employee Access
Log-in access is required to Iaptops/worksta ons; employees authen cate with their Grey Ma er Ac ve Directory domain creden als and have local administrator rights.
No
AC-4: Ensure the Use of Dedicated Administra ve Accounts
AC-5: Use Dedicated Worksta ons for All Administra ve Tasks
AC-9: Protect Informa on through Role-Based Access Control
Not everyone should have access to admin rights. They can change things on the network without realizing or choose an easy password to brute force in to the system with and give a ackers access to the en re network. Having a centralized worksta on for admin tasks minimizes the risk from physical a ack and is easier to centralize issues. Employing least privilege ensures protec on of the network.
Southern New Hampshire University
Grey Ma er security team ndings
Does this nding meet compliance? (Yes or No)
If the nding does not comply with Grey Ma er requirements, explain the issue.
Employees receive a monthly s pend to be used for personal smartphones or other mobile devices (bring your own device). Employees o en access email, team collabora on tools, and web applica on services from their devices.
Yes
In compliance
Legacy BrainMeld VPN Service
VPN service is an integrated service on the No o ce rewall; it uses username/password for authen ca on.
AC-3: Use Mul factor Authen ca on for All Remote Access to Sensi ve Data
AC-6: Use Mul factor Authen ca on for All Administra ve Access
There should be MFA used for anyone accessing the network on a VPN
Users request accounts from the local IT team, which creates the accounts and passwords used only for the VPN.
Yes
In compliance
2
Southern New Hampshire University
Grey Ma er security team ndings
Does this nding meet compliance? (Yes or No)
If the nding does not comply with Grey Ma er requirements, explain the issue.
All authen cated users are provided the same No level of network access.
AC-4: Ensure the Use of Dedicated Administra ve Accounts
AC-9: Protect Informa on through Role-Based Access Control
If everyone has admin rights, it endangers the system more than if you have dedicated admins. Only authorized users should be able to access the informa on necessary to their jobs.
Employees use legacy BrainMeld VPN to access internal services from home or other remote loca ons.
Yes
In compliance
There is a rota ng on-call schedule for a er- No hours support. Administrators use the legacy BrainMeld VPN to access the network and systems from home or other remote loca ons.
AC-3: Use Mul factor Authen ca on for All Remote Access to Sensi ve Data
AC-5: Use Dedicated Worksta ons for All Administra ve Tasks
AC-6: Use Mul factor Authen ca