FEDERAL INTERNET SECURITY

- A Framework for Action -

- DRAFT - (Revised: 10/05/95)


TABLE OF CONTENTS

Preface

Abstract

Section 1 - Introduction


Section 2 - Goals and Challenges


2.1 - The Opportunity

2.2 - Goals of the National Performance Review Task

2.3 - The Threat Environment

2.4 - Internet Security Scenarios

2.5 - Challenges


    2.5.1 - Policy
    2.5.2 - Technology
    2.5.3 - Services and Infrastructure
    2.5.4 - Education


2.6 - A New Conceptual Framework


Section 3 - Strategy for Action


3.1 - Basic Protection Concepts

    3.1.2 - Enclaves.
    3.1.3 - The Open Internet
    3.1.4 - Protect What You Connect
    3.1.5 - Proceed with a Sense of Urgency
    3.1.6 - Employ a Comprehensive Systems Approach
    3.1.7 - Establish a Continuous Improvement Process
    3.1.8 - Build On and Extend Existing Technology Base
    3.1.9 - Work with Existing Open Internet Community Processes


3.2 - Approach

    3.2.1 - Organizational
    3.2.2 - Architectural Needs
    3.2.3 - Implementation Time Frames
3.3 - Current Internet Security Activities

    3.3.1 - Policy Activities
    3.3.2 - Security Technology
    3.3.3 - Security Infrastructure Development
    3.3.4 - Security Education
    3.3.5 - Professional Development

3.4 - Coordination of Efforts

Section 4 - Action Plan




4.1 - Internet Security Policy and Policy Support Activities

4.2 - Internet Security and Technology Development

4.3 - Internet Security Infrastructure

4.4 - Education and Awareness

4.5 - Implementation Considerations

Appendix 1: The National Performance Review

Appendix 2: The Federal Networking Council

Appendix 3: Bibliography

Appendix 4: A Sample Internet Security Policy