0% found this document useful (0 votes)
16 views19 pages

Operating System Security Audit Guide

The document outlines the importance of auditing operating system controls within a CIS environment, detailing main activities, risks, and security measures. It emphasizes the need for access privilege controls, password management, and protections against malicious programs, as well as the role of system audit trails in maintaining security integrity. Additionally, it provides specific audit procedures to evaluate the effectiveness of these controls and ensure compliance with organizational policies.

Uploaded by

Fraveese
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
16 views19 pages

Operating System Security Audit Guide

The document outlines the importance of auditing operating system controls within a CIS environment, detailing main activities, risks, and security measures. It emphasizes the need for access privilege controls, password management, and protections against malicious programs, as well as the role of system audit trails in maintaining security integrity. Additionally, it provides specific audit procedures to evaluate the effectiveness of these controls and ensure compliance with organizational policies.

Uploaded by

Fraveese
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

AUDITING OPERATING SYSTEM

CONTROLS
AUDITING IN A CIS ENVIRONMENT
OPERATING SYSTEM RISKS
OVERVIEW OF THE OF OPERATING SYSTEM

• The computer’s control program. Software

• The system software that manages System Application


computer hardware and software software software
resources and performs basic tasks
for computer programs. Software designed to Software used to
provide a platform for perform specific
other software. functions.
MAIN OPERATING SYSTEM ACTIVITIES

• Translation of high-level languages (programming language) into machine


readable language.

• Allocation of computer resources to users, workgroups and applications.

• Management of job scheduling and multiprogramming tasks.


THREATS TO OPERATING SYSTEM INTEGRITY

Threat Description

Abuse of authority and People with authority or assigned with incompatible duties may intentionally access data or violate user
privilege privacy for financial gains.
Malicious and destructive Malware are software created to harm an information system. Malware are often installed into the
programs system by unaware users. Malware can cause system overload, corrupt information or expose corporate
data to outsiders.
OPERATING SYSTEM CONTROLS
OPERATING SYSTEM SECURITY
Operating system security Operating system security components
involves policies, procedures, and
• First line of defence against unauthorized access.
controls that determines: Log-in • A valid ID and password must be provided in a dialogue box before a
procedure user can access the program.
• Who can access the operating • Repeated failed attempts will lock out the user from the system.
system;
• If the log-on attempt is successful, the operating system creates an
access token.
• Which resources (files, Access token
• Access token contain the user information as well as detail of access
programs, printers) they can privileges granted to specific users.
use; and,
• Lists provided in every IT resource containing information that defines
Access control the access privilege of valid users
• What actions they can take. list • Access to the program is granted if the information on the access
token matches with the access control list.

• Resource owners may be granted discretionay access privileges, allow


Discretionary
them to grant access privileges to other users.
Access
• Discretionary access control needs to be closely supervised to prevent
Privileges
security breaches resulting from too liberal use.
OBJECTIVES OF OPERATING SYSTEM SECURITY

Protect itself from Protect users from Protect users from Be protected from Be protected from
users each other themselves itself its environment

User applications One user must not be User files and Components of the Operating system
must not be able to able to access, modules must not be operating system should be able to
gain control of, or destroy, or corrupt allowed to destroy or should not be allowed maintain a controlled
damage in any way, the data or programs corrupt another to destroy or corrupt termination of
the operating system, of another user. module. other components. activities and recover
thus causing it to later in case of
cease running or fortuitous events.
destroy data.
OPERATING SYSTEM SECURITY CONTROLS:
ACCESS PRIVILEGE CONTROLS
• Management must ensure that user are not granted privileges that are
incompatible to their duties.

• Privileges should be carefully administered and closely monitored for


compliance with organizational policy and principles of internal control.
OPERATING SYSTEM SECURITY CONTROLS:
PASSWORD CONTROLS
• A password is a secret code the user enters to gain access to systems,
applications, datafiles, or a network server.

• Most common forms of contra-security behavior of password include:


• Forgetting passwords and being locked out of the system.
• Failing to change passwords on a frequent basis.
• “Post-it” syndrome (writing down and displaying the password)
• Simplistic passwords that can be easily anticipated.
OPERATING SYSTEM SECURITY CONTROLS:
PASSWORD CONTROLS
Types of password Common password controls

• Reusable password - The user defines • Automate password change protocols


the password to the system once and • Disallow weak passwords
then reuses it to gain future access.
• Utilize one-time passwords

• One-time password - the user’s


password changes continuously.
OPERATING SYSTEM SECURITY CONTROLS:
MALICIOUS PROGRAMS CONTROLS
• Purchase software from trusted sources only.
• Issue entity-wide policy prohibiting the use of unauthorized software.
• Examine new software installations or software upgrades for viruses.
• Use antivirus software to examine application and system programs.
• Limit user access to read and execute only if possible.
• Routine backup procedures of key files.
• Require protocols that explicitly invoke the operating system’s log-on procedures
to bypass Trojan horses
OPERATING SYSTEM SECURITY CONTROLS:
SYSTEM AUDIT TRAIL CONTROLS
• System audit trails are logs that record activity at the system, application, and user level.
• Audit trails typically consist of two types of audit logs:
• Keystroke Monitoring - involves recording both the user’s keystrokes and the system’s
responses. This is akin to wiretapping and may violate the user’s privacy.
• Event Monitoring - summarizes key activities related to system resources.
• Audit trails can be used to support security objectives in three ways:
• Detecting unauthorized access to the system;
• Facilitating the reconstruction of events; and
• Promoting personal accountability.
AUDITING OPERATING SYSTEM CONTROLS
AUDITING OBJECTIVES

• For access privilege controls, establish whether access privileges granted do not
include incompatible functions.
• For password controls, determine if the organization has an adequate and effective
password policy for controlling access to the operating system.
• For malicious program controls, verify that effective management policies and
procedures are in place to prevent the introduction and spread of destructive
programs.
• For system audit trail controls, ensure that the established system audit trail is
adequate for preventing and detecting abuses and errors.
AUDIT PROCEDURES ON ACCESS PRIVILEGE
CONTROLS
• Review the organization’s policies for separating incompatible functions.
• Review the privileges of a selection of user groups and individuals to determine if
their access rights are appropriate.
• Review personnel records to determine whether privileged employees undergo an
adequately intensive security clearance check in compliance with company policy.
• Review employee records to determine whether users have formally acknowledged
their responsibility to maintain the confidentiality of company data.
• Review the users’ permitted log-on times.
AUDIT PROCEDURES ON PASSWORD CONTROLS

• Verify that all users are required to have passwords.


• Verify that new users are instructed in the use of passwords and the importance of
password control.
• Review password control procedures to ensure that passwords are changed regularly.
• Review the password file to determine that weak passwords are identified and disallowed.
• Verify that the password file is encrypted and that the encryption key is properly secured.
• Assess the adequacy of password standards such as length and expiration interval.
• Review the account lockout policy and procedures.
AUDIT PROCEDURES ON MALICIOUS PROGRAMS
CONTROLS
• Through interviews, determine that operations personnel have been
educated about computer viruses and are aware of the risky computing
practices that can introduce and spread viruses and other malicious
programs.
• Verify that new software is tested for malicious programs before
implementation on the host or network server.
• Verify that the current version of antiviral software is installed on the server
and that upgrades are regularly downloaded to workstations.
AUDIT PROCEDURES ON SYSTEM AUDIT TRAIL
CONTROLS
• Verify that the audit trail has been activated according to organization
policy.
• Scan and/or check for unusual log activities.
• Select a sample of security violation cases and evaluate their disposition to
assess the effectiveness of the security group.

You might also like