Special OPS: Host and Network Security for Microsoft, UNIX, and Oracle

Chapter 1: Assessing Internal Network Security
Chapter 2: Inventory and Exposure of Corporate Assets
Chapter 18: Creating Effective Corporate Security Policies
Developing, implementing, and managing enterprise-wide security is a multiple discipline project. As an organization continues to expand, management's demand for usability and integration often takes precedence over security concerns. New networks are brought up as quickly as the physical layer is in place, and in the ongoing firefight that most administrators and information security staff endure every day, little time is left for well-organized efforts to tighten the "soft and chewy center" that so many corporate networks exhibit.
In working to secure and support systems, networks, software packages, disaster recovery planning, and the host of other activities that make up most of our days, it is often forgotten that all of this effort is ultimately to support only one individual: the user. In any capacity you might serve within an IT organization, your tasks (however esoteric they may seem) are engineered to provide your users with safe, reliable access to the resources they require to do their jobs.
Users are the drivers of corporate technology, but are rarely factored when discussions of security come up. When new threats are exposed, there is a rush to seal the gates, ensuring that threats are halted outside of the organization's center. It is this oversight that led to massive internal network disruptions during events...