Changes to the hardware or software components of the network device can have significant effects on the overall security of the network. Therefore, the network device must be configured to use automated mechanisms to enforce access restrictions and prevent unauthorized changes or upgrades to network device hardware or software.
Access restrictions may include the following controls.
(i) Physical and logical access controls, workflow automation, and media libraries;
(ii) Abstract layers (e.g., changes are implemented using third party interfaces rather than directly onto the network device); and
(iii) Change windows (e.g., changes occur only during specified times, making unauthorized changes easy to discover). |