Customer Communications Group Streamlining a diverse, high security, multi-user environment.
CCG is a branding and marketing firm with a strong history of providing and tracking brand loyalty programs. They have been in business since 1978 and have seen many changes in technology since then. Among the team of skilled employees are graphic designers, writers, account managers, sales staff and support crew. A company with a diverse employee set required a diverse technological solution.
Customer Communications Group uses a combination of Mac and PC based computers to get the job done. Because much of the work that is done is with banks and financial institutions, there was a heavy focus on security and encryption. CCGs graphic designers and web designers use Adobe Creative Suite 3 to produce the marketing assets and web sites. Writers and Account Managers were mainly using Microsoft Office for Mac. All users access a shared calendar and tracking system hosted by Creative Manager Pro through Firefox.
CCGs Challenges In 2006 a security audit was performed and shed light on a number of security holes that needed to be filled. These security holes included a wireless access point that was out of date and using a less than perfect encryption scheme, no asset tracking or media tracking, insecure storage of private data and an inconsistent patch level among all of the computers and the absence of a computer and network use policy. A large amount of data from all departments is shared among departments which consist of Mac and PC users. The data needed to be segregated into volumes that re- flected the departmental groups and were shared only to authenticated users but still allowed the different departments to share resources. In addition to having to employees in-house, there are outside sales employees based in the midwest and east coast who needed to have secure access to the company resources.
The Solutions To solve the issues presented by the security audit a policy handbook was created to present acceptable use policies, asset tracking policies and encryption policies. The wireless access point was updated to use WPA2 encryption and the Cisco PIX 501 router was updated with new and more secure VPN policies. A database of all tech as- sets was created and updated as changes occurred. Apple Remote Desktop was used to push updates, ensure the security policies were being enforced and to review changes. An intrusion detection system, based on the industry standard IDS Snort, was built and monitored. Logs from all computers were aggregated to a server running Splunk 3 and NTOP was used to monitor network traffic. Access logging was implemented on the Microsoft Windows XP Professional file server. To protect the sensitive data PGP encryption was implemented for encrypting files to be transferred and to secure chat traffic. Email was encrypted through SSL connections to the host. Mac OS X Server was used to manage user and group access to Apple and Windows file sharing services. A backup system was created using EMC Insignia's Retrospect to backup local server data and email is backed up to 3 rotating external hard drives, 2 of which were kept off site when not in use.
Time Requirements The entire project required 12 hours initially to assess the situation and create a customized plan. The execution required 4 onsite hours per week to maintain the hardware, software and troubleshooting with phone support available as necessary.
The Benefits that the Transition brought to CCG
- Solutions were created to meet the requirements presented by the security audit
- Communication and speed were increased with cross platform file sharing
- Security was greatly enhanced by the new backup system and secure remote access to the company network.
- This medium size business was serviced with efficiency and regularity at a fraction of what it would cost to maintain a skilled employee.
- CCG employees were able to interface with the consultant, who was patient and ready to listen to their concerns.
- The consultant was able to communicate technical issues to the owners in a clear language to discuss technical challenges and future projects.
|