The GIAC
Security Audit Report for Unix Systems at GIAC Enterprises
Pages
73
Time to read
118 mins
Publication
Language
English
Pages
73
Time to read
118 mins
Publication
Language
English
This report is a security audit conducted on Unix-based servers within the DMZ segment of the GIAC Enterprises network. The audit was authorized by GIAC Enterprises and its Information Systems staff and took place during the week of December 17, 2001. The primary objective of the audit was to assess the security of the servers that are critical for the company's web and email operations. The audit involved a manual review and vulnerability scans of the servers. The findings indicate that while the external corporate firewall provides a level of security, three of the four servers in the DMZ exhibit vulnerabilities that require immediate attention. A total of fifteen vulnerabilities were identified for urgent repair, while thirteen others can be addressed within a 60-day timeframe. The report includes recommended updates and necessary repairs, which can be executed by the existing staff, although external assistance may be advisable for immediate repairs. Implementing these recommendations is expected to enhance the security posture of the GIAC network against known internet threats.