SC-5 Denial of Service Protection
Description
The purpose of this Control is to prevent or mitigate denial of service attacks on University networks.
Applicability
- This Control applies to all Texas A&M network information resources. The intended audience for this Control includes all information resource owners and custodians.
Implementation
-
1Each university unit managing a network shall establish a security strategy that includes perimeter protections (e.g., DMZ, firewall, intrusion detection or prevention system, or router) and incorporates:
-
2Units shall operate firewall technology with procedures and guidance from Technology Services security operations.
Related Resource- 2.1The Technology Services security operations staff are authorized to disconnect users from the University network if these procedures are not followed.
-
3The Technology Services security operations staff are responsible for managing the campus firewall and may provide specific guidance and procedures to units in the following areas:
- 3.1Virtual and physical architecture;
- 3.2Protocols and applications that are permitted through the firewall, both inbound and outbound;
- 3.3Traffic monitoring rule set;
- 3.4Approval process for updating or changing rule sets; and,
- 3.5Auditing and testing to verify a firewall’s configuration, rule set accuracy, and effectiveness.