Solved

Network security questions for change control requests...

Posted on 2016-11-08
2
95 Views
Last Modified: 2016-11-14
I am putting together a list of default questions that users need to fill out to request a change to our security systems.  Here is what I have so far...

1. Is there a project associated with this change? If so, what is the project identification information?

2. What is the expected business impact of the change?

3. Provide an explanation of the requested change (what is the business case/goal for this change?):

4. Can you provide information regarding the sources/destinations requested in the change (noted below):
      Source:
      IP Address - FQDN - Type of server
      Example:
            192.168.1.100 - windows001.example.com - Microsoft Web Server
      Destination:
      IP Address - FQDN - Type of server
      Example:
            172.16.1.100 - windows095.example.com - Microsoft SQL Server

5. Can you provide an explanation for each port/port range requested in the change.  Also, please       specify if the port is either TCP or UDP.
      Ports:
      TCP/UDP - Port # - Reason needed for port
      Example:
            TCP - 1433 - This port is required to allow the DMZ server connect to the MSSQL database instance on the internal server.

6. What is the timetable for this change?
0
Comment
Question by:Michael Kowalski
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 22

Accepted Solution

by:
eeRoot earned 500 total points
ID: 41882196
A few other things to ask:

1) Has the change been tested on a test system?

2) Is there any expected down time for the change window?  If so, what systems will be impacted and who needs to be notified?

3) Is there a rollback plan in case the change is unsuccessful?

4) Who is the owner of the systems be impacted and do they approve the change?
0
 

Author Closing Comment

by:Michael Kowalski
ID: 41886260
Thank you for your input.  This is very useful.
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Most MSPs worth their salt are already offering cybersecurity to their customers. But cybersecurity as a service is wide encompassing and can mean many things.  So where are MSPs falling in this spectrum?
I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question