0% found this document useful (0 votes)
5 views10 pages

Unit 2

The document outlines the control, audit, and security measures for information systems, emphasizing the importance of access controls, IT audits, and layered security strategies for both consumers and enterprises. It details various security principles, types of audits, and methods for remote access authentication, alongside the significance of SSL and Extended Validation certificates in securing online transactions. Additionally, it discusses content control and policy-based encryption to ensure the integrity and confidentiality of electronic communications.

Uploaded by

Lalit Pant
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views10 pages

Unit 2

The document outlines the control, audit, and security measures for information systems, emphasizing the importance of access controls, IT audits, and layered security strategies for both consumers and enterprises. It details various security principles, types of audits, and methods for remote access authentication, alongside the significance of SSL and Extended Validation certificates in securing online transactions. Additionally, it discusses content control and policy-based encryption to ensure the integrity and confidentiality of electronic communications.

Uploaded by

Lalit Pant
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

UNIT 2: CONTROL, AUDIT AND SECURITY OF IS

2.1 Control of Information System


Information system is an integrated set of components for collecting, storing, and processing
data and for delivering information, knowledge, and digital products. Business firms and
other organizations rely on information systems to carry out and manage their operations,
interact with their customers and suppliers, and compete in the marketplace. Access controls
of information systems are as below:

 Deny access to systems by undefined users or anonymous accounts.


 Limit and monitor the usage of administrator and other powerful accounts.
 Suspend or delay access capability after a specific number of unsuccessful logon
attempts.
 Remove obsolete user accounts as soon as the user leaves the company.
 Suspend inactive accounts after 30 to 60 days.
 Enforce strict access criteria.
 Enforce the need-to-know and least-privilege practices.
 Disable unneeded system features, services, and ports.
 Replace default password settings on accounts.
 Limit and monitor global access rules.
 Ensure that logon IDs is non descriptive of job function.
 Remove redundant resource rules from accounts and group memberships.
 Remove redundant user IDs, accounts, and role-based accounts from resource access
lists.
 Enforce password rotation.
 Enforce password requirements (length, contents, lifetime, distribution, storage, and
transmission).
 Audit system and user events and actions and review reports periodically.
 Protect audit logs.

2.2 Audit of Information System


An information technology audit, or information systems audit, is an examination of the
management controls within an Information technology (IT) infrastructure. The evaluation of
obtained evidence determines if the information systems are safeguarding assets,
maintaining data integrity, and operating effectively to achieve the organization's goals or
objectives. These reviews may be performed in conjunction with a financial statement
audit, internal audit, or other form of attestation engagement.
IT audits are also known as "automated data processing (ADP) audits" and "computer
audits". They were formerly called "electronic data processing (EDP) audits".
The primary functions of an IT audit are to evaluate the systems that are in place to guard an
organization's information. Specifically, information technology audits are used to evaluate
the organization's ability to protect its information assets and to properly dispense
information to authorized parties. The IT audit aims to evaluate the following:
1. Will the organization's computer systems be available for the business at all times
when required?
2. Will the information in the systems be disclosed only to authorized users?
3. Will the information provided by the system always be accurate, reliable, and timely?

Compiled by: Er. Bhim Bahadur Pun, NAST, DHANGADHI Page 1


Types of Audit:

 Technological innovation process audit.


 Innovative comparison audit.
 Technological position audit.
 Systems and Applications.
 Information Processing Facilities.
 Systems Development
 Management of IT and Enterprise Architecture.
 Client/Server, Telecommunications, Intranets, and Extranets
Audit Processes:
The following are basic steps in performing the Information Technology Audit Process:

1. Planning
2. Studying and Evaluating Controls
3. Testing and Evaluating Controls
4. Reporting
5. Follow-up
6. Reports

2.3 Security of Information System

Following are the security principles of information system:

 Fundamental Principles (CIA)


 Identification
 Authentication
 Authorization
 Non Repudiation
 Encryption and Decryption
 Extended validation
 SSL (Secure socket layer)
 Content Control
 Certificate Authority (CA)
 Network Security
 Backup Security
 Physical Security
 Risk Security
 Application Security

2.4 Consumer layered security strategy


Layered security, in its simplest form, consists of stacking security solutions, one on top of
the other, to protect a computer from current, and zero day malware attacks. Layering (or
stacking) security applications, offers the best chance of remaining infection free, by closing
these gaps. So layered security is “knowledge, awareness, and experience are critical
ingredients in the escalating battle, against cybercriminals”. So consumer layered security
strategy is as below:

Compiled by: Er. Bhim Bahadur Pun, NAST, DHANGADHI Page 2


1. Backup – While you may not think that a backup strategy forms part of a layered
security approach to Internet security, it is, without exception, a most crucial part.
2. Operating System and Application Patch Management – Again, this is an area that
is often not considered as critical by many users which will constantly monitor your
system for insecure software installations, notify you when an insecure application is
installed, and even provide you with detailed instructions for updating the application,
when available.
3. Firewall – a firewall is an application, or a hardware appliance, designed to block
unauthorized access to your computer from the Internet, at the same time permitting
authorized communications.
4. Antimalware – A front line antimalware application is absolutely critical to avoid
system infection. Your primary application should be supplemented by an on-demand
scanner (part of the stacking approach). There is no harm in downloading more than
one antimalware application to be used as a secondary scanner.
5. Antivirus – An antivirus application is another critical component in a layered
defense strategy to ensure that if a malicious program is detected, it will be stopped
dead in its tracks.
6. System Isolation – An isolator is a security application which dynamically isolates
Internet applications including Web Browsers, Chat Clients, Email Clients, and so on.
Isolators, or sandbox applications, prevent damage from intrusions and malicious
software: viruses, worms, spyware.
7. Zero Day Protection – Since most viruses, worms, Trojans and other types of
Internet threats only last 24 hours, how do security applications that rely on a
definition database to identify malware files.

2.5 Enterprise layered security strategy

It is a technique of preventing to the enterprise from the failure and attack from the attacker
and bugs to fulfill the desired result of any enterprise. Consumer layered security strategy
refers to the security of consumer information but enterprise layered security strategy refers
to the security of information of any enterprise or organization. So enterprise security strategy
can be explained as below:

1. Physical Security – It seems obvious that physical security would be an important layer
in a defense-in-depth strategy, but don’t take it for granted. In addition, the lines between
the physical security systems and information systems are blurring as physical access can
be tied to information access.
2. Network Security – An essential part of a plant’s information fabric, network security
should be equipped with firewalls, intrusion detection and prevention systems (IDS/IPS),
and general networking equipment such as switches and routers configured with their
security features enabled.
3. Computer Hardening – Well known (and published) software vulnerabilities are the
number one way that intruders gain access to automation systems. Examples of Computer
Hardening include the use of:

 Antivirus software
 Application white listing
 Host intrusion-detection systems (HIDS) and other endpoint security solutions
 Removal of unused applications, protocols and services
 Closing unnecessary ports

Compiled by: Er. Bhim Bahadur Pun, NAST, DHANGADHI Page 3


 Disable software automatic updating services on PCs
 Inventory target computers for applications, and software versions and revisions
 Subscribe to and monitor vendor patch qualification services for patch
compatibility
 Obtain product patches and software upgrades directly from the vendor
 Pre-test all patches on non-operational, non-mission critical systems
 Schedule the application of patches and upgrades and plan for contingencies

4. Application Security –This refers infusing industrial control system applications with
good security practices, such as a Role Based Access Control System, which locks down
access to critical process functions, force username/password logins, combinations, etc.

5. Device Hardening – Changing the default configuration of an embedded device out-of-


the-box can make it more secure. The default security settings of PLCs, PACs, routers,
switches, firewalls and other embedded devices will differ based on class and type, which
subsequently changes the amount of work required to harden a particular device.

IT Area of Focus Areas of Concern Relevant Toolkits


Endpoints  OS level  OS update appliance
 File access Patch/configuration
 File storage appliance
 VPN authentication  Secure browser
Browsing  Secure email
 Email  Incremental backup
 Backups

Network Edge  Configuration  Optional off-site


hardening management
 VPN
 Firewall
 Data-loss prevention
 Log archiving/backup
Email  OS level  Secure Email cluster
 Boundary encryption appliance management
 Backups and archiving  Archive management
Endpoint Data Encryption  OS level  Automated
 Stateful inspection infrastructure
 DB encryption management
 Backups and archiving  Patch/configuration
appliance
 Backup management

Compiled by: Er. Bhim Bahadur Pun, NAST, DHANGADHI Page 4


2.6 Extended validation and SSL Certificates
2.6.1 Extended Validation (EV)
An Extended Validation Certificate (EV) is an X.509 public key certificate issued
according to a specific set of identity verification criteria. These criteria require extensive
verification of the requesting entity's identity by the certificate authority (CA) before a
certificate is issued. Certificates issued by a CA under the EV guidelines contain a subject
with for Country Name, business Category, and serial Number, with the serial Number
pointing to the ID, CA-specific policy identifier so that EV-aware software, such as a web
browser, can recognize them. EV certificates use the same encryption as domain validated
certificates. The difference in security is due to the identity validation process, which is
indicated inside the certificate by the policy identifier.
Web Server Certificates with EV enable the most visible security indicator: the green address
bar in high-security browsers, assuring users that your site is secure and your identity has
been authenticated to the industry’s highest standard. When customers see the green address
bar and the trusted Site Seal, they gain the confidence to complete their transaction. SSL Web
Server Certificates with EV include Extended Validation.

2.6.2 Secure Socket Layer (SSL) certificates

SSL Certificates, sometimes called digital certificates, are used to establish a secure
encrypted connection between a browser (user's computer) and a server (website). The SSL
connection protects sensitive data, such as credit card information, exchanged during each
visit (session). Whether you need to secure one or many domains, one or multiple servers,
Digital Certificates offers a full line of SSL Certificate products to meet your needs.
 Wildcard SSL ("Wildcard Plus"): Secure all servers and sub domains on a given
domain
 Single Certificate ("SSL Plus"): Secure a single server with a single name
 Unified Communications Certificate ("UC Certificate" or "SAN Certificate"):
Secure up to 25 server names – perfect for Exchange Server
 Extended Validation Certificate ("EV Plus"): Activate the green bar in newer
browsers
 Digital Certificates Extended Validation Multi-Domain Certificate ("EV MD
Certificate"): Secure up to 25 server names with EV security.

2.6.3 Process of EV and SSL:

SSL Certificates are small data files that digitally bind a cryptographic key to an
organization’s details. When installed on a web server, it activates the padlock and the https
protocol (over port 443) and allows secure connections from a web server to a browser.
Typically, SSL is used to secure credit card transactions, data transfer and logins, and more
recently is becoming the norm when securing browsing of social media sites. SSL
Certificates bind together:
 A domain name, server name or hostname.
 An organizational identity (i.e. company name) and location.

Compiled by: Er. Bhim Bahadur Pun, NAST, DHANGADHI Page 5


2.6.4 SSL Certificate Details
To view the details of an SSL Certificate, go to a secure site, click on the padlock and select
“View Certificate”. All browsers are slightly different, but the Certificate always contains the
same information.

To view the actual contents of the Certificate click the "Details" tab and for certificate click
to “Certificate Path” tab.

Compiled by: Er. Bhim Bahadur Pun, NAST, DHANGADHI Page 6


2.7 Remote Access Authentication
Remote access authentication is the process whereby computer users can securely
communicate with a network. There are many methods that accomplish this, and some are
more secure than others. A shared theme to all of these methods is the use of a digital
certificate that contains information that identifies the user to a server and provides their
credentials. Remote access authentication protocols make it safer to conduct business online
are as below:
Compiled by: Er. Bhim Bahadur Pun, NAST, DHANGADHI Page 7
1. Challenge Handshake Authentication Protocol (CHAP)
Designed to prevent relay attack, CHAP is an authentication protocol that uses a three-
step process to confirm identity. The password of one can be obtained and later used by
the hacker to pose as that person. CHAP prevents this by preventing the transmission of a
password.
2. Microsoft CHAP (MS-CHAP)
MS-CHAP is a version of CHAP that was designed and implemented by Microsoft. MS-
CHAP has been released in two versions, MS-CHAPV1 and MS-CHAPV2. Both versions
were supported in Windows 95 and 98. MS-CHAP is convenient for users of Windows
servers because it uses protocols already utilized in Windows systems.
3. Password Authentication Protocol (PAP)
PAP was one of the first authentication protocols. The PAP protocol consists of a frame
that contains information on the sender's user name and password. However, PAP is not a
viable security option because it does not mask the user's password during transmission.
4. Extensible Authentication Protocol/Transport Layer Security (EAP/TLS)
Often touted as the most secure authentication protocol, EAP/TLS is most often used in
digital certificates and wireless networking. This authentication method is universally
supported by wireless LAN manufacturers. EAP/TLS requires the user submit a digital
certificate to a server for confirmation.

2.8 Content Control and policy based encryption

Content Control
Content control means checking that electronic communications, like emails, instant
messages, Web postings, and electronic documents, contain acceptable information. For
example, organizations want to ensure that material doesn't contain racial slurs or sexual
innuendo, or that valuable product designs aren't being sent to competitors or posted to news
groups, or that viruses aren't being transmitted.
Content control needs to take place within an organization. It must also apply to electronic
communications coming in from the outside, and to electronic communications that depart
the organization for the outside world.
Inbound content control is heavily oriented toward the control of malevolent content, such as
viruses, malware, spam control, and denial-o f-service attacks. Outbound content control, by
contrast, is much more concerned with ensuring that only appropriate material is sent
externally; for example, that sensitive material only goes to certain people, or is suppressed
entirely.

Policy Based Encryption


Policy-Based Encryption service allows customers to set up filters based on the content of a
message, if the message meets the set criteria it will be encrypted. Once the service is
enabled, all messages sent from Intermediate mailboxes to external recipients are processed
according to configured policies and encrypted if required.
Email encryption is the process of converting plain text (the original message and
attachments) to cipher text, and serves two functions: maintain confidentiality and establish
non-reputability that is the sender cannot disclaim the contents of the message.
Policy-based encryption is about enforcing encryption according to a policy defined by the
organization, automatically encrypting and decrypting email based on specific considerations.

Compiled by: Er. Bhim Bahadur Pun, NAST, DHANGADHI Page 8


When considering policy-based email encryption, there are best practices that an organization
can follow for policy-based email encryption. Below figure shows the content control and
policy based encryption phenomena.

2.9 Example of security in e-commerce transaction

Following are the example of security of e-commerce transaction:

1. Intellectual property protection


– Legislature
– Authentication
2. Client computer protection
– Privacy
– Digital certificate
– Browser protection
– Antivirus software
3. Communication channel protection
– Encryption
* Public-key encryption (asymmetric) vs Private-key encryption (symmetric)
* Encryption standard: Data Encryption Standard (DES), Advanced Encryption
Standard (AES)
– Protocol
* Secure Sockets Layer (SSL) (Figure 5.10)
* Secure Hypertext Transfer Protocol (S-HTTP)
– Digital signature
4. Server protection
– Access control and authentication
* Digital signature from user
* Username and password
* Access control list
– Firewalls

Compiled by: Er. Bhim Bahadur Pun, NAST, DHANGADHI Page 9


Information system security refers to the way the system is defended against unauthorized
access, use, disclosure, disruption, modification, perusal, inspection, recording or destruction.
There are two major aspects of information system security:
 Security of the information technology used - securing the system from malicious
cyber-attacks that tend to break into the system and to access critical private
information or gain control of the internal systems.

 Security of data - ensuring the integrity of data when critical issues arise such as
natural disasters, computer/server malfunction, physical theft etc. Generally an off-
site backup of data is kept for such problems.

Guaranteeing effective information security has the following key aspects:


 Preventing the unauthorized individuals or systems from accessing the information.

 Maintaining and assuring the accuracy and consistency of data over its entire life-
cycle.

 Ensuring that the computing systems, the security controls used to protect it and the
communication channels used to access it, functioning correctly all the time, thus
making information available in all situations.

 Ensuring that the data, transactions, communications or documents are genuine.

 Ensuring the integrity of a transaction by validating that both parties involved are
genuine, by incorporating authentication features such as "digital signatures".

 Ensuring that once a transaction takes place, none of the parties can deny it, either
having received a transaction, or having sent a transaction. This is called 'non-
repudiation'.

 Safeguarding data and communications stored and shared in network systems.

Compiled by: Er. Bhim Bahadur Pun, NAST, DHANGADHI Page 10

You might also like