© Cengage Learning, Inc. This content is not final and may not match the published product.
Introduction to Protection Mechanisms
You should know by now that technical controls alone cannot secure an information
technology (IT) environment, but they are almost always an essential part of the
information security (InfoSec) program. Managing the development and use of
technical controls to treat the risks facing the organization requires some knowledge
and familiarity with the technology that enables those controls. In this chapter, you
05713_ch12_hr_619-[Link] 620 19/02/18 6:00 pm
will learn about firewalls, intrusion detection and prevention systems, encryption
systems, and some other widely used security technologies. The chapter is designed
to help you evaluate and manage the technical controls used by InfoSec programs.
If you are seeking expertise in the configuration and maintenance of technical
control systems, you will need education and training beyond the overview
presented here.
Technical controls can enable and/or amplify policy enforcement where human
behavior is difficult to regulate. A password policy that specifies the strength of
the password (its length and the types of characters it uses), regulates how often
© Cengage Learning, Inc. This content is not final and may not match the published product.
passwords must change, and prohibits the reuse of passwords would be impossible to
enforce by asking each employee if he or she had complied. This type of requirement is
best enforced by the implementation of a rule in the operating system.
Figure 12-1 illustrates how technical controls can be implemented at a number of
points in a technical infrastructure. The technical controls that defend against threats
from outside the organization are shown on the left side of the diagram. The controls
that defend against threats from within the organization are shown on the right side
of the diagram; these controls were covered in previous chapters. Because individuals
inside an organization often have direct access to the information, they can circumvent
many of the most potent technical controls. Controls that can be applied to this human
element are also shown on the right side of the diagram.
Patches
and upgrades
Monitoring
systems Education,
Redundancy Firewalls and
Security planning training, and
proxy servers
(IR, DR, BC, CM) awareness
Encryption
Backups
Employees
Information Information
Policy and law
IDPS Access controls
External threats Internal threats
05713_ch12_hr_619-[Link] 621 19/02/18 6:00 pm