Community College Security Design Considerations SBA
Total Page:16
File Type:pdf, Size:1020Kb
Community College Security Design Considerations SBA As community colleges embrace new communication and collaboration tools, • Network abuse—Use of non-approved applications by students, faculty, and staff; transitioning from traditional classroom teaching into an Internet-based, media-rich peer-to-peer file sharing and instant messaging abuse; and access to forbidden education and learning environment, a whole new set of network security challenges content arise. Community college network infrastructures must be adequately secured to protect • Unauthorized access—Intrusions, unauthorized users, escalation of privileges, IP students, staff, and faculty from harmful content, to guarantee confidentiality of private spoofing, and unauthorized access to restricted learning and administrative data, and to ensure the availability and integrity of the systems and data. Providing a safe resources and secure network environment is a top responsibility for community college administrators and community leaders. • Data loss—Loss or leakage of student, staff, and faculty private data from servers and user endpoints Security Design • Identity theft and fraud—Theft of student, staff, and faculty identity or fraud on servers and end users through phishing and E-mail spam Within the Cisco Community College reference design, the service fabric network provides the foundation on which all solutions and services are built to solve the business The Community College reference design accommodates a main campus and one or challenges facing community colleges. These business challenges include building a more remote smaller campuses interconnected over a metro Ethernet or managed WAN virtual learning environment, providing secure connected classrooms, ensuring safety service. Each of these campuses may contain one or more buildings of varying sizes, as and security, and operational efficiencies. shown in Figure 2. The service fabric consists of four distinct components: LAN/WAN, security, mobility, and unified communications, as shown in Figure 1. Figure 1 Service Fabric Design Model Service Fabric Design Model Unified Mobility Security Communications Local Area Wide Area Network (LAN) Network (LAN) 228538 The Community College reference design includes security to protect the infrastructure and its services to provide a safe and secure online environment for teaching and learning. This design leverages the proven design and deployment guidelines of the Cisco SAFE Security Reference Architecture to secure the service fabric by deploying security technologies throughout the entire solution to protect students and faculty from harmful content; to guarantee the confidentiality of student, staff, and faculty private data; and to ensure the availability and integrity of the systems and data. Protecting the infrastructure and its services requires implementation of security controls capable of mitigating both well-known and new forms of threats. Common threats to community college environments include the following: • Service disruption—Disruption to the infrastructure and learning resources such as computer labs caused by botnets, worms, malware, adware, spyware, viruses, denial-of-service (DoS) attacks, and Layer 2 attacks Community College Security Design Considerations SBA Figure 2 Community College Reference Design Overview Figure 3 Community College Network Security Design Overview Main Large Campus Large Building Medium Building Small Building Extra Small Building Large Building Medium Building Small Building Extra Small Building IP IP IP IP Service Block GigaPOP Wireless LAN NAC QFP WAE Commodity Controller Server Internet2 Internet Services Data Center Block www NLR Anchor SensorBase V Web M Security WLC SRST/Video Cisco ACS NAC Video Surveillance Email Web Cisco Security Email UCM Gateway Appliance Manager Media Server Core QFP Server Server Internet Edge Data MetroE HDLC Center Service Block Core Core Service Block Small Data Center Small Data Center Service Block Internet QFP QFP Main Campus Edge GigaPOP WAN PSTN Internet NLR Internet2 Serverfarm IP IP IP IP IP IP Large Building Medium Building Small Building Medium Building Small Building Small Building Remote Large Campus Remote Medium Campus Remote Small Campus Services Services 228539 Block Block Services The following security elements should be included in the Community College Security Block design depicted in Figure 3: Data Data Center Center • Endpoint Security—Desktop endpoint protection for day-zero attack protection, data Data Center loss prevention, and signature-based antivirus. • Network Foundation Protection—Device hardening, control, and management plane Remote Small Campus protection throughout the entire infrastructure to maximize availability and resiliency. • Catalyst Integrated Security Features—Access layer protection provided by port security, Dynamic ARP inspection, IP Source Guard, and DHCP Snooping. Large Building Medium Building Small Building Medium Building Small Building • Threat Detection and Mitigation—Intrusion prevention and infrastructure based Remote Large Campus Remote Medium Campus network telemetry to identify and mitigate threats. 228612 • Internet Access—E-mail and Web Security. Stateful firewall inspection. Intrusion Operating on top of this network are all the services used within the community college prevention and global correlation. Granular access control. environment, such as safety and security systems, voice communications, video surveillance equipment, and so on. The core of these services are deployed and • Cisco Video Surveillance—Monitor activities throughout the school environment to managed at the main campus building, allowing each remote campus to reduce the need prevent and deter safety incidents. for separate services to be operated and maintained by community college IT personnel. • Enhanced Availability and Resiliency—Hardened devices and high availability These centralized systems and applications are served by a data center in the main design ensure optimal service availability. System and interface-based redundancy. campus. • Unified Communications—Security and emergency services, enhanced 911 The security design uses a defense-in-depth approach where multiple layers of security support. Conferencing and collaboration for planning and emergency response. protection are integrated into the architecture. Various security products and • Network Access Control—Authentication and policy enforcement via Cisco technologies are combined to provide enhanced security visibility and control, as shown Identity-Based Networking Services (IBNS). Role-Based access control and device in Figure 3. security compliance via Cisco Network Admission Control (NAC) Appliance. The Community College reference design recognizes that cost and limited resources are common limiting factors. Therefore, architecture topologies and platforms are carefully selected to increase productivity while minimizing the overall cost and operational complexities. In certain cases, tradeoffs are made to simplify operations and reduce costs where needed. Community College Security Design Considerations SBA The security design for the community college service fabric focuses on the following key – Enforce authentication, authorization, and accounting (AAA) with Terminal areas. Access Controller Access Control System (TACACS+) or Remote Authentication • Network foundation protection (NFP)—Ensuring the availability and integrity of the Dial-In User Service (RADIUS) to authenticate access, authorize actions, and log network infrastructure by protecting the control and management planes to prevent all administrative access. service disruptions network abuse, unauthorized access, and data loss. – Display legal notification banners. • Internet perimeter protection – Ensure confidentiality by using secure protocols such as Secure Shell (SSH) and – Ensuring safe connectivity to the Internet, Internet2, and National LambdaRail HTTPS. (NLR) networks – Enforce idle and session timeouts. – Protecting internal resources and users from botnets, malware, viruses, and – Disable unused access lines. other malicious software • Routing infrastructure – Protecting students, staff, and faculty from harmful content – Restrict routing protocol membership by enabling Message-Digest 5 (MD5) – Enforcing E-mail and web browsing policies to prevent identity theft and fraud neighbor authentication and disabling default interface membership. – Blocking command and control traffic from infected internal bots to external – Enforce route filters to ensure that only legitimate networks are advertised, and hosts networks that are not supposed to be propagated are never advertised. • Data center protection – Log status changes of neighbor sessions to identify connectivity problems and – Ensuring the availability and integrity of centralized applications and systems DoS attempts on routers. – Protecting the confidentiality and privacy of student, staff, and faculty records • Device resiliency and survivability • Network access security and control – Disable unnecessary services. – Securing the access edges – Implement control plane policing (CoPP). – Enforcing authentication and role-based access for students, staff, and faculty – Enable traffic storm control. residing at the main and remote campuses – Implement topological, system, and module redundancy for the resiliency and – Ensuring that systems are up-to-date and in compliance with the community survivability of routers and switches and to ensure