»
«
  • About
  • First Time?
  • Newsletter
  • Find Jobs
  • Guest Bloggers

  • All Featured Articles
  • Professional
  • Leader
  • Graduate
  • Freelancer
  • Recommended Books
  • Other Stuff

Home » Freelancer » The 12 Dumbest Mistakes Network Managers Make

The 12 Dumbest Mistakes Network Managers Make

Posted by: Simon    Tags:  data security, information security, network manager    Posted date:  July 12, 2009  |  5 Comments

What are the 12 most stupidest gaffes a network manager can make? More to the point, have you made one, or experienced one yourself? See if you recognize any of these clangers?

Data-security breaches are front-page news items now, and any company that finds their name on there is going to suffer. CIOs won’t tolerate their name emblazoned on these news stories – especially when the accountability lies on the head of the Network Manager. Here are twelve common, totally dumb mistakes that Network Managers should really know better than to allow on their systems.

The first ten of these mistakes I found on a great article by Carolyn Duffy Marsan on CIO.COM which is the result of research recently completed and published by Verizon , based from 285 Million compromised records.

Yes, that’s 285,000,000 compromised records . Wow.

I added another essential two (11 & 12) which I didn’t see in the original list, but I have to include them as these are equally disastrous based on my own experience.

The 12 Dumbest Mistakes Network Managers Make

  1. Not changing the default passwords on all network devices – it’s gob-smacking that many devices are installed onto networks without having their admin passwords changed. Maybe vendors should not build in default passwords? Rather they, should should be setup as a mandatory installation activity, and won’t function until set?
  2. Sharing a password across multiple network devices – this is just like the above, although the ‘default’ is that used across and within the organization. It’s used for convenience, but once a technician or hacker gets access to one device, then heck, they’ve got access to them all!
  3. Failing to find SQL coding errors – the dreaded ‘SQL injection ‘ is the most common vulnerability where SQL code allows hackers to run their own queries on your database. Thing is, this is a long-known issue with well documented solutions. It’s unthinkable to leave your SQL database open to such attacks, but it is still prevalent. Any network manager who doesn’t close them down should be shot.
  4. Misconfiguring your access control lists – often the result of lazy or inexperienced engineering. Network equipment should only be allowed to talk to each other if there is a business reason to do so.
  5. Allowing nonsecure remote access and management software – in this age, nonsecure access is suicide!
  6. Failing to test noncritical applications for basic vulnerabilities – your security is only as strong as the weakest component on the network. A lot of focus is placed on making the public-facing application, such as web, bullet-proof, but less attention is given to the noncritical applications. But in an inter-networked environment, any vulnerability will be exploited at some point. Network managers must insist that ALL components are tested for vulnerabilities, not just the critical ones. If the money-men don’t like it, then remind them about the cost of failure!
  7. Not adequately protecting your servers from malware – intrusion-detection systems should run on all servers, not just those that contain data. Malware is smart, and often undetectable by anti-virus software.
  8. Failing to configure your routers to prohibit unwanted outbound traffic – most of the attention is placed on preventing unwanted inbound traffic, but what about filtering outbound traffic ? If malware finds its way onto one of your servers, it can begin sending all sorts of traffic to harm your infrastructure, unless you prevent it. A mail server should send just mail traffic. So allow it only to do this.
  9. Not knowing where credit card or other critical customer data is stored – if your data is spread across your network, and you don’t know exactly where, then you’re in for trouble. If you can’t locate the data, you can’t protect it!
  10. Not following the Payment Card Industry Data Security Standards – if you’re the ‘standards-shmandards’ type, then you’re putting yourself at risk. Nobody has lossed their job for following standards (well, the right one, anyway). These standards exist because they are best practice. Why take an unecessary risk by ignoring them?
  11. Not accounting for the human-factors - rigorous security measures often mean that your people have to do more to work with them, often at their inconvenience. Frequent password changes, for example, means that people must remember what their new password is. So what happens? People write them down, or do something equally as dumb. Remember, too much rigor too quickly can mean that people don’t cope with it and totally destroy your efforts by creating different vulnerabilities like this.
  12. Assuming the threat is restricted to sources outside of your network boundary - especially when it’s been long-known that most hacks are done from the inside . Almost all human endeavor is based on trust, somewhere along the line, but too much trust in your people means too much risk. Smart network managers apply as much focus on internal security measures as they do on the external environment.

Made Any of These Mistakes?

If you have made any of these mistakes, how did you feel about it, and did you learn to put it right? What were the consequences to you? Share YOUR story…

VN:F [1.9.13_1145]
please wait...
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.13_1145]
Rating: 0 (from 0 votes)

    Share This
About the author
Simon
Simon is a creative and passionate business leader dedicated to having fun in the pursuit of innovation and personal development




5 Comments for The 12 Dumbest Mistakes Network Managers Make

Mark McClure

re #11 – true, but accountability (if not wielded as a weapon by mgt) helps ordinary grunts raise their game e.g. logging all commands entered on a network device by username, time/date, IP etc.

re #12
Secure access to the network L1 and L2 devices – the days of unencrypted access to the command prompt should be history.

VA:F [1.9.13_1145]
please wait...
Rating: 0.0/5 (0 votes cast)

Michael Cruse

Well I have had run-ins with #2 and #12.

#2 was minor, annoying, and a lesson learned. I must still admit that it is intentionally forgotten at times.

#12 was sad and painful.

VA:F [1.9.13_1145]
please wait...
Rating: 0.0/5 (0 votes cast)

simonstapleton

@Michael – Thanks for your comment! When you look at these gaffes, it’s easy to think back to what a stupid mistake it was. They’re ‘obvious’ no-nos, but it’s also surprising how commonly they are made. I cannot admit to being guilt-free myself…

VN:F [1.9.13_1145]
please wait...
Rating: 0.0/5 (0 votes cast)

Helene

Thanks for your contribution to The Work at Home Family Carnival. My readers will appreciate these important tips for keeping their networks safe.

VA:F [1.9.13_1145]
please wait...
Rating: 0.0/5 (0 votes cast)

simonstapleton

I do hope so Helene

VN:F [1.9.13_1145]
please wait...
Rating: 0.0/5 (0 votes cast)






Wanna say something?





  Cancel Reply

CAPTCHA Image
Refresh Image
*

« Review This Blog and I’ll Give Cancer Charities $10!
Why Don’t Graduates Get Jobs? »
  • Follow Me

  • Recent Comments

    • Simon Stapleton on “The Industrialization of IT” - Eric D. Brown on You Must Industrialize IT to Secure your Organization’s Future
    • Simon Stapleton on “The Industrialization of IT” - Eric D. Brown on Industrialization of IT Will Create a Blue-Collar Sub-Class of IT Workers
    • Joyful Days on Who Would You Throw Your Shoes At?
    • Education, Nonstop - The Core Benefits of Continuing Education on What Is Job Security (and does it really exist?)
    • poloalb on Do We Have to be Articulate to be an Executive?
  • My Tweets...

    • New blog post: Stand Up and Be Counted (in Meetings) http://t.co/jfBj4pPZ
    • New blog post: How To Make a Great Impression at an Interview http://t.co/jWSGkF9x
    • New blog post: Copying Ideas is the Shortcut to Success http://t.co/dUczJQJ3
    • New blog post: How New Managers Can Get To Know Their Employees http://t.co/9dgCns56
    • New blog post: Ask Yourself the RIGHT Question http://t.co/7zxCJpsC
  • Sponsored Links

  • Jobs in Your Area




 
  • Blogroll

    • Business Acceleration Make Your Project Work
    • Dave Crain Online Leadership, Growth and Excellence through Entrepreneurship
    • Eric Brown Technology, Strategy, People & Projects
    • Lead Well & Prosper The Home of Joe and Wanda
    • Mark McClure Today Mark McClure – Mid-Career Coaching
    • My Management Guide Following the best management practices – Succeeding in organizing businesses, projects and life
  • boss effectiveness facebook Freelancer freelancing jobhunting job hunting jobseeking Leadership linkedin management outsourcing performance performance appraisal performance review productivity professional freelancer project management recession web2.0

    WP Cumulus Flash tag cloud by Roy Tanck and Luke Morton requires Flash Player 9 or better.

  • Popular Posts

    • Mistakes I Made as a Freelance Web Developer and How To Avoid Them
      Hindsight is always 20/20, and this is especially true when it comes to the world...
    • The SimonStapleton.com Cancer Charity Fundraiser
      Some of the worst-hit organizations in an economic downturn are Charities. According...
    • 35 FREE Tools for IT/Developers And Business
      The Open Source movement continues strongly, and with it comes a greater number of more...
    • 7 Keys To Describe Your Achievements... Know Any More?
      It's amazing how many people can't describe their achievements in order to maximize...
    • What Should You Do If Your Boss Hates You?
      Your boss hates you – what should you do? This is a common problem, I’ve...

 
(c) Copyright 2011 Simon Stapleton