0% found this document useful (0 votes)
3 views8 pages

Chapter 1

Uploaded by

olivviawhitee
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views8 pages

Chapter 1

Uploaded by

olivviawhitee
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Computer Security:

Principles and Practice


Fourth Edition, Global Edition

By: William Stallings and Lawrie Brown


Operating System Security
Strategies
The 2010 Australian Signals Directorate (ASD) lists the

Over 85% of the targeted cyber intrusions investigated


by ASD in 2009 could have been prevented
The top four strategies for prevention are:
White-list approved applications
Patch third-party applications and operating system vulnerabilities
Restrict administrative privileges
Create a defense-in-depth system

Department of Energy, SANS, and others in the United


States
Operating System
Security
Possible for a system to be compromised during the
installation process before it can install the latest patches
Building and deploying a system should be a planned
process designed to counter this threat
Process must:
Assess risks and plan the system deployment
Secure the underlying operating system and then the key applications
Ensure any critical content is secured
Ensure appropriate network protection mechanisms are used
Ensure appropriate processes are used to maintain security
System Security Planning
The first step in
Plan needs to deploying a new system
identify is planning
appropriate
personnel and Planning should
training to install include a wide
and manage the security
system assessment of the
organization

Planning process needs


to determine security Aim is to
requirements for the maximize security
system, applications, while minimizing
data, and users costs
System Security Planning
Process
The purpose of the
Who will administer the
system, the type of Any additional security
system, and how they
information stored, the measures required on the
will manage the system
applications and services system, including the use
(via local or remote
provided, and their of host firewalls, anti-
access)
security requirements virus or other malware
protection mechanisms,
and logging

The categories of users of What access the system


the system, the privileges has to information stored
they have, and the types on other hosts, such as
of information they can file or database servers,
access and how this is managed

How access to the


How the users are
information stored on the
authenticated
system is managed
Operating Systems
Hardening
First critical step in securing a system is to secure the
base operating system
Basic steps
Install and patch the operating system
Harden and configure the operating system to adequately
address the indentified security needs of the system by:
Removing unnecessary services, applications, and protocols
Configuring users, groups, and permissions
Configuring resource controls
Install and configure additional security controls, such as anti-
virus, host-based firewalls, and intrusion detection system (IDS)
Test the security of the basic operating system to ensure that the
steps taken adequately address its security needs

You might also like