Access Controls ◾ 213
Many network devices are left in default or very similar to default configura-
tions. Although leaving these devices in this state is often easier, it can be a severe
detriment to security. Most devices in this configuration are running multiple
unnecessary services and although these services are not directly used by the user
community, the vulnerabilities in these services can be exploited by malicious users
on the network. To minimize the amount of security holes in the network, the
information security manager must disable or remove all the unnecessary services
on the devices. is can quickly become a double-edged sword because determin-
ing which services are unnecessary can disable the functionality of the system. ...