Janet Updates Security Requirements

Janet Updates Security Requirements

JANET (Joint Academic Network) is the computer network backbone used by UK Universities, Colleges and research centres.

Updates have been made to the policy of use for JANET some of which have come into force from 1st April 2022.  There are 3 core themes to these changes.

Some ports and protocols will be blocked by default although institutions will have the option to allow their use.  At present the only specific block is to port 3389.  This is the recommended port for RDP so will be the assumed port for attacks using that protocol.  A system could continue to use RDP on one of the non-reserved ports (49152-65535) but any remote users would need to know the new assigned port which in turn would reduce the protection from that port being ‘unknown’.

Users will be required to take an annual security posture review.  Unfortunately there is no set outline for this review nor any need for an organisation to share the results of such a review.  JISC (Joint Information Systems Committee) who administer JANET has published a 1-page outline of 16 questions to assess cyber security posture.  All but 2 of these questions could be answered as yes or no but a serious review would require considerable time and effort.  UK Further Education institutions have been required to endeavour to meet Cyber Essentials since March 2021.  Cyber Essentials and the more detailed Cyber Essentials Plus would hence be one means of achieving the security posture review.

The third change is that more proactive scans will be made on systems attached to JANET.  The scans will be looking for ports open to known vulnerabilities.  JANET vulnerability scans have been performed before but only in exceptional cases.  The new policy is seen to be preventative rather than reactive.

These changes reflect a light touch.  There will be little impact on JANET users but the scanning and blocking options allow procedures to be ramped up without any further changes to the usage policy.  The security posture review should be a tool to identify system improvements.  There is not yet a requirement that any review be passed only that note be taken of the results.   Kindus are able to offer support and advice in drawing up security reviews and setting an action plan to address any issues identified.

More from Security

03/09/2024

Google and Facebook Single Sign On (SSO)

Single Sign On (SSO) options are commonly seen through providers such as Google, Facebook and to a lesser extent Apple.  There are also less …

Read post

13/08/2024

Ransomware in Healthcare

The ThreatLabz 2024 Ransomware Report highlights the relative susceptibility of the healthcare industry to ransomware attacks.  312 attacks on the Healthcare industry were reported …

Read post

29/07/2024

Bad Bots

Kindus has discussed the role of bots on the Internet and how webmasters can use ‘robots.txt’ to control them.  Unfortunately many bots do not …

Read post

22/07/2024

Lessons from the Cloudstrike Outage

On July 19, 2024 at 04:09 UTC, CrowdStrike released an update for ‘Falcon Sensor 7.11’ or above to Windows systems.  This caused a system …

Read post

Sign Up

Sign up to our newsletter list here.

    Successful sign up

    Thank you for signing up to our newsletter list.

    Check your inbox for all the latest information from Kindus

    Categories