遇见数据集

Audit of IT General Controls

收藏
Mendeley Data2026-04-18 收录
官方服务:

资源简介:

At present, branch routers rely on shared local passwords administered informally among network staff. This approach creates multiple risk vectors: lack of accountability (no way to attribute configuration changes to specific admins), stale credentials that remain valid after staff departures, and non-compliance with regulatory frameworks such as ISO 27001 and SOX ITGC requirements. To address these gaps, senior management has mandated a migration to centralized AAA (Authentication, Authorization, and Accounting). The goal is to enforce identity-based access, provide a tamper-resistant audit trail of all logins and configuration changes, and implement a least privilege model. R2 will be integrated with a TACACS+ server (192.168.2.2) for granular command authorization and full-payload logging, while R3 will leverage a RADIUS server (192.168.3.2) suitable for scalable user authentication. Students are tasked with staging and validating this migration in a lab environment. They must configure local fallback accounts (Admin2 on R2, Admin3 on R3) to guarantee business continuity if AAA servers become unreachable. The exercise includes connectivity verification (ICMP reachability), AAA new-model enablement, group definition, console/VTY method list application, and functional testing with valid, invalid, and fallback credentials. Finally, students will trigger failed logins, pull logs from TACACS+ and RADIUS servers, and perform a comparative analysis of log fidelity and forensic usefulness. Deliverables include configuration snippets, test evidence, and a formal recommendation report for NetBank’s CISO.

当前,分支机构路由器依赖网络工作人员间非正式管理的共享本地密码。该方案存在多重风险向量:缺乏问责机制(无法将配置变更追溯至具体管理员)、员工离职后仍有效的过期凭据,以及不符合ISO 27001、SOX ITGC等监管框架要求。 为弥补上述不足,高级管理层已下令迁移至集中式AAA(Authentication, Authorization, and Accounting)架构。其目标为实施基于身份的访问控制,提供所有登录与配置变更的防篡改审计轨迹,并落实最小权限模型。R2将与TACACS+服务器(192.168.2.2)集成,以实现精细化命令授权与全负载日志记录;而R3将依托适用于可扩展用户认证的RADIUS服务器(192.168.3.2)。 学生需在实验室环境中部署并验证此次迁移工作。他们必须配置本地回退账户(R2上的Admin2、R3上的Admin3),以在AAA服务器无法访问时保障业务连续性。该实操练习涵盖连通性验证(ICMP可达性)、启用AAA新模型、组定义、控制台/VTY方法列表应用,以及使用有效、无效与回退凭据开展功能测试。 最终,学生将触发登录失败事件,从TACACS+与RADIUS服务器中提取日志,并对日志的保真度与取证可用性开展对比分析。交付物包括配置片段、测试证据,以及一份提交给NetBank首席信息安全官(Chief Information Security Officer,简称CISO)的正式建议报告。

创建时间:
2025-09-29
二维码
社区交流群
二维码
科研交流群
商业服务