Don’t Get (TIC)ked-off -- Implementing TIC, the Trusted Internet Connection initiative

As a part of this process, external address blocks should be labeled and a full network test should be administered, using agreed upon discovery methods and including any revised locations. This process should lead to a tuned network discovery being performed in order to find all internal and external devices on the network.
Ultimately, the best network assurance technology providers will produce a complete map of routed infrastructure which details all active Internet points of presence, as well as any potential unknown or back-door Internet connectivity. The best of the best will provide multiple location Internet-based scanning to ensure that all routed points of Internet presence are carefully documented from the public Internet. When coupled with the internal scans, these scans provide the most comprehensive view of all possible Internet connectivity for any federal agency.
Agencies should look for the following deliverables:
• An inventory of all existing Internet connections;
• Validation as connections are moved, changed or decommissioned;
• Identification of the true network perimeter to ensure properly managed entry points;
• A determination of where horizon boundaries exist;
• Testing of router and firewall access controls to ensure compliance, even after network changes.
Additionally, agencies should require the provider to work with their internal personnel and contractor employees to develop a plan to consolidate Internet gateways.
Given the looming deadline for the TIC initiative, agencies need to know which criteria should be considered when judging potential partners who can assist them with this transition. Equally important, these partners need to drill down to the appropriate level in the network in order to mine critical data without disrupting ongoing operations or current security measures. Agencies that perform their due diligence during this process will be assured of a smoother transition. They’ll also have a solution to turn to down the road when additional initiatives are announced.
Michael Markulec is executive vice president for technology and operations at Lumeta Inc. He can be reached at:
- Add your comment
- trackback url: http://www.gsnmagazine.com/cms/trackback/592-1
