To secure the extended enterprise, partners must collaborate on security procedures. Douglas Potts, a security expert at computer retailer CDW, calls out these must-consider points.
Contacts – Each company should decide who on their teams will have access to the shared network. The manner and frequency of communication among the points of contact also should be specified. Will the contacts meet – weekly, monthly, by e-mail, by phone?
Rules – IT groups usually have a predetermined set of rules for network access and acceptable use. The two teams should reach common ground on these rules as they relate to the extended enterprise.
Technology – Partners must decide on the degree of security they are going to implement and put that in writing. What level of encryption will be used? Also, each partner needs to take an inventory of security tools, then the teams should check for compatibility between their tools.
Test – Partners must assign members of each team to install and test the security equipment on both sides of the network. Each partner should regularly report on the vulnerability status of those links.
Maintenance – Team members must be aware of security threats and update the network accordingly with patch management or other tools. Establish a review procedure to make sure that the threats on both sides are being managed.
Security breaches – When a security breach is identified, both teams should be alerted. Partners should have a list of procedures to follow that includes a contact list and immediate action steps.
Exit strategy – The dissolution of a partnership should mean the termination of the network link. Rules and processes must be put in place that dictate how to break down the relationship, including password changes, port closings and the blocking of IP addresses. Both parties should be aware of these procedures.




