Auditing Data Systems and Why Your ISP/ASP Must Do This

February 15, 2008 – 7:22 am

Many ISPs and ASPs have servers that are years old, with outdated and unmaintained software. This is a big problem for security because out of date software most certainly has security bugs that aren’t patched, rendering the server vulnerable to attack. Frequent system audits increase the reliability and security of any data system. They also keep the system free of “cobwebs” and the system administrators who maintain the system “fresh”. Too often, turnover and lack of audits cause certain subsystems to be forgotten.

Sentinare Messaging Solutions, Inc. audits their entire network every 6 months to coincide with the semiannual release of the next version of OpenBSD. Every server is recreated from scratch. Sometimes hardware is replaced; sometimes not, but in each case, the servers are all formatted and re-loaded with the latest version of OpenBSD and all application packages configuration files are audited. Only applications which are necessary are loaded. The systems are kept extremely clean this way and reliability and security are maximized.

You must be logged in to post a comment.