GPO Add-On Management
our security departement wants to manage add-ons when moving to ie8 using whitelist approach. gpo team use blacklist (where block add-ons know malicious). i've read few articles on headaches caused using whitelist method, looking more relevant feedback.
so, wondering if uses whitelist approach , if overall experience (was difficsult manage)?
thanks!
hi,
i used whitelist approach in company , worked well. however, need aware that it requries alot management if want properly. developed ie - add-on life cycle management covered following:
- adding new add-on's
- adding updated add-on's
- retiring add-on's
- tracking business need of add-on's
- evaluation of risk add-on's
- periodic review release add-on's
- documenting add-on's
- approval of add-on's
so, established full change management process around this. , has cost associated it.
hope helps,
gunter
Windows Server > Group Policy
Comments
Post a Comment