Atleast here in Finland monitoring network traffic is illegal if it is done in a way that can be used to identify individual users. Or individual users actions. Unless you have a court order to do so ofcourse. It is considered equal to wire-tapping. So even if you do monitor in individual level, you really can't go and point out ones illegalities without committing a crime by yourself, effectively rendering your evidence unusable.
Best practise could be to just monitor port level instead of ip level. Then when you have adequate statistics, you could post them on your board or somewhere similiar with a note asking if anyone knows why there is such high use of certain ports which "you don't regognize as an orthodox use of the network".
(Hey! I Think this is my very first post! So i hereby apologize my obscure sentence structures in this and any future posts. I'm not a native english speaker you know...)
Actually, i think the point was quite valid.
This was pretty much what i thought when I read the comments of the "expert".
Atleast here in Finland monitoring network traffic is illegal if it is done in a way that can be used to identify individual users. Or individual users actions. Unless you have a court order to do so ofcourse. It is considered equal to wire-tapping.
So even if you do monitor in individual level, you really can't go and point out ones illegalities without committing a crime by yourself, effectively rendering your evidence unusable.
Best practise could be to just monitor port level instead of ip level. Then when you have adequate statistics, you could post them on your board or somewhere similiar with a note asking if anyone knows why there is such high use of certain ports which "you don't regognize as an orthodox use of the network".
(Hey! I Think this is my very first post! So i hereby apologize my obscure sentence structures in this and any future posts. I'm not a native english speaker you know...)