Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Is a two-tier firewall architecture a requriement for BS7799?

Thread Tools
 
Search this Thread
 
Old 07 January 2003, 03:16 PM
  #1  
akshay67
Scooby Regular
Thread Starter
 
akshay67's Avatar
 
Join Date: Nov 2001
Posts: 2,342
Likes: 0
Received 0 Likes on 0 Posts
Question

As far as I know, there is no requirement in BS7799 to use mutiple firewalls, i.e. one for internet facing and one between DMZ and back-end.

Can someone please confirm?

Cheers...
Old 07 January 2003, 04:29 PM
  #2  
David_Wallis
Scooby Regular
 
David_Wallis's Avatar
 
Join Date: Nov 2001
Location: Leeds - It was 562.4bhp@28psi on Optimax, How much closer to 600 with race fuel and a bigger turbo?
Posts: 15,239
Likes: 0
Received 1 Like on 1 Post
Post

I dont think it is and Im not looking through the massive document I have... you can get it on pdf... and then search..

David
Old 07 January 2003, 05:12 PM
  #3  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

More flexible for your budget as well
Old 08 January 2003, 08:44 AM
  #4  
akshay67
Scooby Regular
Thread Starter
 
akshay67's Avatar
 
Join Date: Nov 2001
Posts: 2,342
Likes: 0
Received 0 Likes on 0 Posts
Post

Yeah I had a 'quick' read through Pt1 and 2, and can't see it *explicity* saying you should use two firewalls. However, it may be implied somewhere.

A two-tier approach is obviously a better approach for many reasons, but I doubt quoting BS7799 (like someone did) is not a valid reason.
Old 08 January 2003, 11:36 AM
  #5  
mega_stream
Scooby Regular
 
mega_stream's Avatar
 
Join Date: May 2001
Location: Scotland
Posts: 4,580
Likes: 0
Received 0 Likes on 0 Posts
Talking

Ok, BS7799 does not state that you need dual level protection, it would be your risk assessment that states if dual level is required to protect your system.

Old 08 January 2003, 01:57 PM
  #6  
jimbob2
Scooby Regular
 
jimbob2's Avatar
 
Join Date: Apr 2001
Posts: 229
Likes: 0
Received 0 Likes on 0 Posts
Post

Not completely necessary for BS7799 - is this for commercial or gov use?

Good security practice states that you should have different firewalls here say a Nokia FW1 box at the front, then something like a PIX or a cyberguard on a seperate LAN for your databases - good Intrusion Detection systems area also advisable providing you have the man power to resource it - the same goes for all IP related security.

At the end of the day, the clever hacker will merely phone someone up in your company and ask for their user name and password - it's so easy!

You shoyuld also dual everything if you want the maximum uptime - bet you've got more than one disk in your server?
Old 08 January 2003, 02:42 PM
  #7  
BlueBlood
Scooby Regular
 
BlueBlood's Avatar
 
Join Date: Jan 2003
Posts: 64
Likes: 0
Received 0 Likes on 0 Posts
Post

Not a direct requirement for BS7799, more relevant to BS7799 is how staff are trained as suggested above (and other things). Sometimes they just give out the password to a phone call.....oh and keep an eye on those server boys. A Vulnerability is a vulnerability regardless how many firewalls it traverses.

In a Corp environment it is best practise, perhaps mix Network/Application and other technologies (more so than badges of the same thing).

..r
Old 09 January 2003, 01:17 PM
  #8  
Chris L
Scooby Regular
 
Chris L's Avatar
 
Join Date: May 2000
Location: MY00,MY01,RX-8, Alfa 147 & Focus ST :-)
Posts: 10,371
Likes: 0
Received 0 Likes on 0 Posts
Arrow

Might be worth your company considering to join the Information Security Forum

Have a look at their site and look at the guidelines they setout. It is based around BS7799 certification. It is also good to pick other members brains, as you can bet that someone has already come across a problem you are having before.

Chris
Old 01 July 2003, 04:22 PM
  #9  
DrEvil
Scooby Regular
 
DrEvil's Avatar
 
Join Date: Oct 2000
Location: Surrey, UK
Posts: 8,384
Likes: 0
Received 0 Likes on 0 Posts
Arrow

Sorry, this isn't what you asked for - but surely whether this is a requirement of BSxxxxx or not - it is highly advisable, as the environment will be more flexible, secure, etc.. tried n tested and all that.

Plus.. BTTT for you...

[Edited by DrEvil - 1/7/2003 4:23:26 PM]
Old 01 July 2003, 07:29 PM
  #10  
mega_stream
Scooby Regular
 
mega_stream's Avatar
 
Join Date: May 2001
Location: Scotland
Posts: 4,580
Likes: 0
Received 0 Likes on 0 Posts
Talking

I'm 99% certain its not a requirement for this, I can check tomorrow though, I'm on a ISMS BS7799 pt2 auditors course this week



[Edited by mega_stream - 1/7/2003 7:30:36 PM]
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
dantiel
General Technical
8
29 September 2015 11:33 PM
David_Wallis
Computer & Technology Related
11
05 December 2002 11:29 PM
ChristianR
Computer & Technology Related
6
31 December 2001 06:00 PM



Quick Reply: Is a two-tier firewall architecture a requriement for BS7799?



All times are GMT +1. The time now is 03:41 AM.