Recommended Standard Operating Procedures to have in-place:
- Setting up, changing, or decommissioning servers
- Setting up, changing, or decommissioning employee workstations
- Setting up, changing, or decommissioning public terminals
- Configuring new employee accounts upon hiring/position change
- Removing/disabling employee accounts upon termination/position change
- Inspecting or running backups
- Restoring files from backups
- Restoring servers from backups
- Applying operating system and application patches to employee workstations and public terminals
- Applying operating system and application patches to servers
Recommended Recurring Procedures:
- Periodic review of IT budget and development of an operational IT plan, including budget.
- Apply patches to software, malware protection, and operating systems.
- Distribute training procedures to personnel to remind each person of their contribution to network security.
- Review authentication logs for attempted brute-force attacks or other abnormalities.
- Review firewall traffic logs for nefarious traffic and other abnormalities.
- Review backup logs or backup email notifications to ensure that backups are functioning correctly.
- Spot check backups by attempting to access files from the backup volumes and restore them.
Other documentation to have on-hand:
- Per physical network device:
- Type of device (server, workstation, network switch, etc.)
- Make, model
- Serial Number / Service Tag Number
- Date of purchase
- Length of warranty/service-contract
- MAC addresses of all interfaces
- Responsible party
- Physical location assigned to
- Purpose
- Technical Specifications, including:
- CPU, Memory, Hard Disk
- RAID configuration (if any)
- Redundant power configuration (if any)
- Other specs, depending on the device
- Basic network map showing subnets and network devices
- Schedule for:
- Checking UPS batteries
- Scanning network for vulnerabilities