Is this bad practice?
I have a situation at work that is bothering me and was curious if it should. In my department right now there is a giant white board, with IP addresses to everything in our infrastructure. The thing that bothers me is that it is sitting in what is essentially a hallway where everyone can see it.
It isn't just employees who can see it, also any guests on site could as well.
Is this a bad practice?
It isn't just employees who can see it, also any guests on site could as well.
Is this a bad practice?
Comments
-
Verities Member Posts: 1,162I'm surprised that you're asking this kind of question having Security + under your belt. This is a pretty basic example of bad security practices.
-
BowlJar Member Posts: 24 ■□□□□□□□□□The fact that it seems like such a basic security issue is why it bothers me. But I was wondering if there is a standpoint where this procedure is acceptable, or commonplace. My Network admin who has past experience in Security procedures on corporate scale is who put it up. I have the least amount of real world experience on my team so I don't know what it is common procedure.
Theory over practice kind of deal. -
Edificer Member Posts: 187 ■■■□□□□□□□We on a regular basis receive guests and showcase our server rooms and Emergency Command Posts, but we make 110% sure the curtains are pulled over the whiteboards first.“Our greatest glory is not in never falling, but in rising every time we fall.” Confucius
-
Verities Member Posts: 1,162Have you voiced your concerns to him/her about it? The only place I could see this not being an issue is if you're in a secure office/room or if you're in a NOC that limits access to anyone outside of support.
-
MTciscoguy Member Posts: 552When I was working in DC, if something like that had been made visible to anyone other than those with the proper clearance as well a reason to see them, such as security personal that worked on it, you would have been taken into custody and charged with a crime. Company infrastructure maps should be in a place that the only people who see them are those that need to know them. In this day and age of high quality pocket cameras it is way to easy for somebody with nefarious intentions to do a massive amount of damage.Current Lab: 4 C2950 WS, 1 C2950G EI, 3 1841, 2 2503, Various Modules, Parts and Pieces. Dell Power Edge 1850, Dell Power Edge 1950.
-
hurricane1091 Member Posts: 919 ■■■■□□□□□□We don't always follow best practice. I've mentioned it and was basically told "deal with it kid" so take that FWIW.
-
BowlJar Member Posts: 24 ■□□□□□□□□□Which in a round about way is what I was told when I brought it up today.
-
nster Member Posts: 231It's a pretty bad security risk IMO. You could go over your boss' head to voice your concerns
EDIT: would def piss him off if action was taken though -
MTciscoguy Member Posts: 552BowDar, you have to understand the hierarchy in the IT business is pretty amazing, the prevailing thought process is, you are lower than me, you can't understand why we are willing to breach the companies security! LOL
Don't push it so far you get in trouble, but I would continue to drop subtle hints anytime I could.Current Lab: 4 C2950 WS, 1 C2950G EI, 3 1841, 2 2503, Various Modules, Parts and Pieces. Dell Power Edge 1850, Dell Power Edge 1950. -
rsutton Member Posts: 1,029 ■■■■■□□□□□I don't see the problem with listing your IP addresses. Maybe I'm missing something - what is the risk here?
-
Christian. Member Posts: 88 ■■■□□□□□□□I don't see the problem with listing your IP addresses. Maybe I'm missing something - what is the risk here?
Is not a really huge issue, but you are basically showing hints on your topology.CISSP | CCSM | CCSE | CCSA | CCNA Sec | CCNA | CCENT | Security+ | Linux+ | Project+ | A+ | LPIC1 -
MTciscoguy Member Posts: 552I don't see the problem with listing your IP addresses. Maybe I'm missing something - what is the risk here?
With a little bit of basic information you can create some real havoc for a company.Current Lab: 4 C2950 WS, 1 C2950G EI, 3 1841, 2 2503, Various Modules, Parts and Pieces. Dell Power Edge 1850, Dell Power Edge 1950.