Security Solutions

3-127
Designing Access Controls
Finalize Security Policies
Other services might be required in your system. You might want to check
for those services but not quarantine endpoints that do not have them.
You must specify Windows services with the exact names that are dis-
played in Control Panel > Administrative Tools > Services.
If you enable the Mac services test, only the services that you select from
a list are allowed (others are prohibited). Record the services that you
want to allow in Table 3-102.
Table 3-102. Tests for Services
13. Do your security policies prohibit users from granting others access
through their connection?
Check the cells in Table 3-103.
Table 3-103. Tests for Shared Connections
14. Does your organization require Mac endpoints to protect their wireless
(Airport) connections?
If you are concerned about endpoints connecting to a rogue AP, you might
activate the first two tests displayed in Table 3-104. If you are concerned
about users who send data over insecure wireless connections, you might
activate the third.
Table 3-104. Tests on Mac Airport
15. Are your security requirements so high that the risk of malware outweighs
all other risks (including that of a user inadvertently making an endpoint
inoperable in an attempt to comply)?
Windows Services Not Allowed Windows Services Required Mac Services
Windows Bridge Network Connection Mac Internet Sharing
Mac Airport Preference Mac Airport User Prompt Mac Airport WEP Enabled
Activate this test?