Pre-Contract: Connectivity Flashcards

1
Q

Connectivity

A

Connectivity adds more risk
-open hole in your network. We need to be aware of what they are, even if we don’t have control over who they are.
-Your ability to do due diligence can get complicated.

Relationships are complicated
Types of Connectivity
-Leased-line (from ISDN to P2P to MPLS and on): usually requires a piece of hardware (now sometimes software-only routers) at each end and sometimes in between to route traffic.
Follow-Up: What is the patch management process for
this hardware?
-File Drops: From Box to SFTP to Email
-Web: HTTP or HTTPS
-Screen-Scrapers
-Intermittent Connectivity (hard drive transfers, USB drives, etc.)
-Encryption
-Access Management
-Out-of-Band Devices

*E.g. Business owners will say they don’t have a connection to use but they have data so how are they getting the data? They’re connected.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Types of Connectivity

A

-Leased-Line
-File-Drops
-Web
-Screen-Scrapers
-Intermittent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Types of Connectivity:
Leased-Line

A

(from ISDN to P2P to MPLS and on): usually requires a piece of
hardware (now sometimes software-only routers) at each end and sometimes in between to route traffic.
Follow-Up: What is the patch management process for this hardware?

Leased line is always on.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Types of Connectivity:
File Drops

A

From Box to SFTP to Email

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Types of Connectivity:
Web

A

HTTP or HTTPS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Types of Connectivity:
Screen-Scrapers

A

Go to your site and take data off of them

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Types of Connectivity:
Intermittent

A

-Hard drive transfers
-USB drives
-Intermitted connectivity once a month
-Most challenging because they’re not always on. You won’t always get a vendor that is open about how often they need to connect.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Connectivity:
Access Management

A

Who has access to the devices and how do they get into those?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Connectivity:
Out-of-Band Devices

A

Most common way we see them is hardware device such as a network router that gives your company access to the internet.
-If the service is off, this gives your vendor the ability to remove access to the machine to get the access back.
-You should have a process that asks for business justification for it, what is the timeline you need it back.
-Generally are not connected to monitoring activity, they are a backdoor. Search out of band device controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly