0% found this document useful (0 votes)
37 views115 pages

Security Assessment Types and Methods

Uploaded by

mywwbrba
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
37 views115 pages

Security Assessment Types and Methods

Uploaded by

mywwbrba
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Module 3

Information Security Management

Monitor systems and apply controls -


security assessment using automated tools
Security Assessment
Outline

• What is security assessment?


• What are the non-intrusive types?
• How do you choose between these types?
• What are the intrusive types?
• What are the types of risk reduction?
• What is effective security?
• What are the limitations to security assessment?
Security Assessment
Overview

• Definition
– Security assessment
• identifies existing IT vulnerabilities (weakness) and
• recommends countermeasures for mitigating potential risks
• Goal
– Make the infrastructure more secure
– Identify risks and reduce them
• Consequences of Failure
– Loss of services
– Financial loss
– Loss of reputation
– Legal consequences
Security Assessment
Types

• Non-Intrusive
1. Security Audit
2. Risk Assessment
3. Risk Analysis
• Intrusive
1. Vulnerability Scan
2. Penetration Testing / Ethical Hacking
• All have the goal of identifying vulnerabilities and
improving security
– Differ in rules of engagement and limited purpose of the
specific engagement (what is allowed, legal liability,
purpose of analysis, etc.).
Security Assessment: Non-Intrusive Types
1. Security Audit

• Security Audit- Independent review and examination of


system records & activities to determine adequacy of system
controls, ensure compliance of security policy & operational
procedures, detect breaches in security, and recommend
changes in these processes.1
• Features
– Formal Process
– Paper Oriented
• Review Policies for Compliance and Best Practices
– Review System Configurations
• Questionnaire, or console based
– Automated Scanning
– Checklists
Security Assessment: Non-Intrusive Types
2. Risk Assessment

• Risk Assessment (Vulnerability Assessment) is:


– determination of state of risk associated with a system based upon
thorough analysis
– includes recommendations to support subsequent security
controls/decisions.
– takes into account business, as well as legal constraints.
• Involves more testing than traditional paper audit
• Primarily required to identify weaknesses in the information
system
• Steps
– Identify security holes in the infrastructure
– Look but not intrude into the systems
– Focus on best practices (company policy is secondary)
Security Assessment: Non-Intrusive Types
3. Risk Analysis

• Risk Analysis is the identification or study of:


– an organization’s assets
– threats to these assets
– system’s vulnerability to the threats
• Risk Analysis is done in order to determine exposure
and potential loss.
• Computationally intensive and requires data to
– Compute probabilities of attack
– Valuation of assets
– Efficacy of the controls
• More cumbersome than audit or assessment and usually
requires an analytically trained person
Security Assessment
How to choose

• Security audit, risk assessment and risk analysis have


similar goals.
Security Assessment
Assessment vs. Analysis vs. Audit

Assessment Analysis Audit


Objective Baseline Determine Measure against a
Exposure and Standard
Potential Loss
Method Various (including Various (including Audit Program/
use of tools) tools) Checklist
Deliverables Gaps and Identification of Audit Report
Recommendations Assets, Threats &
Vulnerabilities
Performed by: Internal or External Internal or External Auditors

Value Focused Preparation for Compliance


Improvement Assessment
Security Assessment: Intrusive Types
1. Vulnerability Scan

• Definition
– Scan the network using automated tools to identify security
holes in the network
• Usually a highly automated process
– Fast and cheap
• Limitations
– False findings
– System disruptions (due to improperly run tools)
• Differences in regular scans can often identify new
vulnerabilities
Security Assessment: Intrusive Types
2. Penetration Testing

• Definition (Ethical Hacking)


– Simulated attacks on computer networks to identify
weaknesses in the network.
• Steps
– Find a vulnerability
– Exploit the vulnerability to get deeper access
– Explore the potential damage that the hacker can cause
• Example
– Scan web server: Exploit buffer overflow to get an account
– Scan database (from web server)
– Find weakness in database: Retrieve password
– Use password to compromise firewall
Security Assessment
Risk Reduction

There are three strategies for risk reduction:


• Avoiding the risk
– by changing requirements for security or other system
characteristics
• Transferring the risk
– by allocating the risk to other systems, people,
organizations assets or by buying insurance
• Assuming the risk
– by accepting it, controlling it with available resources
Security Assessment
Effective Security

• Effective security relies on several factors


– Security Assessments
– Policies & Procedures
– Education (of IT staff, users, & managers)
– Configuration Standards/Guidelines
• OS Hardening
• Network Design
• Firewall Configuration
• Router Configuration
• Web Server Configuration
– Security Coding Practices
Security Assessment
Limitations

• Often locates previously known issues


– Provides false sense of security
• Just the first step
– Needs due diligence in applying the
recommendation of the assessment
• Becomes obsolete rapidly
– Needs to be repeated periodically
What is Security Assessment?
Case

• Scenario to identify the suitable method


for application to the scenario
Risk Analysis
Concept Map

• Threats exploit system vulnerabilities which expose system assets.


• Security controls protect against threats by meeting security
requirements established on the basis of asset values.
Risk Analysis
Basic Definitions

• Assets- Something that the agency values and has to protect. Assets
include all information and supporting items that an agency requires to
conduct business.
• Vulnerability- A weak characteristic of an information asset or group of
assets which can be exploited by a threat.1 Consequence of weaknesses in
controls.
• Threat- Potential cause of an unwanted event that may result in harm to
the agency and its assets.1 A threat is a manifestation of vulnerability.

• Security Risk- is the probability that a specific threat will successfully


exploit a vulnerability causing a loss.

• Security Controls- Implementations to reduce overall risk and vulnerability.


Risk Analysis
Assets

• Assets: Something that the agency values and has to


protect. Assets include all information and supporting
items that an agency requires to conduct business.
• Data
– Breach of confidentiality • Organization
– Loss of data integrity – Loss of trust
– Embarrassment
– Denial of service
– Management failure
– Corruption of Applications • Personnel
– Disclosure of Data – Injury and death
– Sickness
– Loss of morale
Risk Analysis
Assets Cont’d

• Infrastructure • Legal
– Electrical grid failure – Use or acceptance of
– Loss of power unlicensed software
– Chemical leaks – Disclosure of Client
– Facilities & equipment Secrets
– Communications • Operational
– Interruption of services
– Loss/Delay in Orders
– Delay in Shipments
Risk Analysis
Vulnerabilities

• Vulnerabilities are flaws within an asset, such as an operating


system, router, network, or application, which allows the
asset to be exploited by a threat.
• Examples
– Software design flaws
– Software implementation errors
– System misconfiguration (e.g. misconfigured firewalls)
– Inadequate security policies
– Poor system management
– Lack of physical protections
– Lack of employee training (e.g. passwords on post-it
notes in drawers or under keyboards)
Risk Analysis
Threats

• Threats are potential causes of events which have a


negative impact.
– Threats exploit vulnerabilities causing impact to assets

• Examples
– Denial of Service (DOS) Attacks
– Spoofing and Masquerading
– Malicious Code
– Human Error
– Insider Attacks
– Intrusion
Risk Analysis
Sources of Threats

Source Examples of Reasons


• Espionage
External Hackers with Malicious Intent • Intent to cause damage
• Terrorism

External Hackers Seeking Thrill • Popularity

• Anger at company
Insiders with Malicious Intent
• Competition with co-worker(s)

Accidental Deletion of Files and Data • User errors

• Floods
Environmental Damage • Earthquakes
• Fires

Equipment and Hardware Failure • Hard disk crashes


Risk Analysis
Security Risk

• Risk is the probability that a specific threat will successfully


exploit a vulnerability causing a loss.
• Risks of an organization are evaluated by three distinguishing
characteristics:
– loss associated with an event, e.g., disclosure of confidential data, lost
time, and lost revenues.
– likelihood that event will occur, i.e. probability of event occurrence
– Degree that risk outcome can be influenced, i.e. controls that will
influence the event
• Various forms of threats exist
• Different stakeholders have various perception of risk
• Several sources of threats exist simultaneously
Risk Analysis
Physical Asset Risks

• Physical Asset Risks


– Relating to items with physical and tangible items
that have an associated financial value
Risk Analysis
Mission Risks

• Mission Risks
– Relating to functions, jobs or tasks that need to be
performed
Risk Analysis
Security Risks

• Security Risks
– Integrates with both asset and mission risks
Risk Analysis: Tools and Usage
Types

• Tools can speed up the security assessment and help in


automation of the risk analysis process.
• Several categories of tools exist:
– Asset Inventory
– Software Usage
– Vulnerability Assessment
– Configuration Validation
– Penetration Testing
– Password Auditing
– Documentation
Risk Analysis: Tools and Usage
Asset Inventory Tools

Name Description
Inventory software tool intended to audit software and hardware
Asset
components installed on computers over a network. It collects network
Tracker
inventory information, provides detailed comprehensive reports and
for
allows export of assets details to external storages, such as SQL
Networks
database or web site. [Link]
Peregrine Autodiscovery/inventory tool which maintains “an evolving
snapshot of IT infrastructure” and provides: what hardware and
Asset
software is available, asset connection to other assets, location of assets,
Center
access to assets, as well as financial and contractual information on
assets. [Link]
Computer Associates International asset management tool. It features:
Unicenter
“automated discovery, hardware inventory, network inventory, software
Access
inventory, configuration management, software usage monitoring,
Managem
license management and extensive cross-platform reporting.”
ent
[Link]
Tools
Asset Inventory Tools, cont’d.

Name Description
Tally Systems offers three tools which can be used for IT asset
inventory. These are: TS Census Asset Inventory, WebCensus and
Tally PowerCensus. These products provide unparalleled IT asset inventory
Systems and tracking, hosted PC inventory and reporting, and enhanced
inventory for Microsoft SMS respectively.
[Link]
Isogon offers multiple tools. SoftAudit gathers software inventory and
usage data from your z/OS, OS/390, or UNIX server. Asset insight
offers PC, PDA, & network device auto-discovery software & captures
Isogon
data. Vista manages and organizes details from contracts, contract
addenda/attachments, and maintenance
agreements. [Link]
Risk Analysis: Tools and Usage
Software Usage

• Software usage tools monitor the use of software


applications in an organization
• Several uses of such tools
– Track usage patterns and report on trends to assist with server load balancing
and license negotiation to prevent costly overbuying or risk-laden under
buying.
– Used to monitor and control the use of unauthorized applications (for
example, video games and screen savers).
– Important for vendor auditing the customers especially for monitoring clients
for subscription-based pricing
Risk Analysis: Tools and Usage
Software Usage Tools

Name Description
Designed to help detect and identify pirated software through
Software Audit tracking licenses. It is a suite of tools used by the Business
Tool (GASP) Software Alliance and is freely available at:
[Link]
Risk Analysis: Tools and Usage
Vulnerability Assessment

• Vulnerability Assessment helps determine vulnerabilities in


computer networks at any specific moment in time.
• Deliverables:
– List of exploits and threats to which systems and networks are
vulnerable. (Ranked according to risk levels)
– Specific information about exploits and threats listed. (name of
exploit or threat, how the threat/exploit works)
– Recommendations for mitigating risk from these threats and exploits.
• Tools used can be:
– Commercial or open source (decide based on staff skills)
– Perform analysis such as:
– Host-based or network-based
Risk Analysis: Tools and Usage
Vulnerability Assessment (Host or Network Based)

Host-based Tools Network-Based Tools


Pros Pros
Can provide rich security information, Once deployed, have limited impact on
such as by checking user access logs. network traffic.
Can give a quick look at what weaknesses Available as software, appliances and
hackers and worms can exploit. managed services.

Cons Cons
Costs can add up when deploying agents Deployment can be time-consuming.
across many desktops and servers.
Requires careful planning to avoid Generates considerable network traffic.
conflict with security systems.

Source: [Link]
Risk Analysis: Tools and Usage
Vulnerability Assessment
Name Description
Windows web server vulnerability tester designed to help administrators locate and fix
Cerberus Internet security holes in their computer systems
Scanner
[Link]
This is a web vulnerability scanner which searches interesting directories and files on a site.
Cgichk Looks for interesting and hidden directories such as logs, scripts, restricted code, etc.
[Link]
Server and client software vulnerability assessment tool which provides remote and local
Nessus security checking.
[Link]
SAINT (Security Administrator's Integrated Network Tool) is a security assessment tool. It
scans through a firewall updated security checks from CERT & CIAC bulletins. Also, it
SAINT features 4 levels of severity (red, yellow, brown, & green) through an HTML interface. Based
on SATAN model.
[Link]
SARA (Security Auditor's Research Assistant) Third generation UNIX-based security analysis
tool. It contains: SANS/ISTS Certified, CVE standards support, an enterprise search
SARA module, standalone or daemon mode, user extension support and is based on the SATAN
model
[Link]
A web server scanner which performs comprehensive tests against web servers for multiple
Nikto items, including over 2200 potentially dangerous files/CGIs, versions on over 140 servers,
and problems on over 210 servers [Link]
Risk Analysis: Tools and Usage
Penetration Testing

• Penetration Testing is the evaluation of a system for weaknesses through


attempting to exploit vulnerabilities.
• Can be done in-house or by a neutral 3rd party
• “Black-box” (no knowledge) or “White-box” (complete knowledge)
• Steps
– Define scope (External: servers, infrastructure, underlying software; Internal:
network access points; Application: proprietary applications and/or systems;
Wireless/Remote Access; Telephone/Voice Technologies; Social Engineering)
– Find correct tools (freeware or commercial software)
– Properly configure tools to specific system
– Gather information/data to narrow focus (“white-box”)
– Scan using proper tools
• Penetration Testing tools can include:
– Network exploration (ping, port scanning, OS fingerprinting)
– Password cracking
– IDS, Firewall, Router, Trusted System, DOS, Containment Measures Testing
– Application Testing and Code Review
Source: [Link]
Risk Analysis: Tools and Usage
Penetration Testing

Name Description
Domain name lookup to find administrative, technical, and billing
Whois contacts. It also provides name servers for the domain.
[Link]

Utility for network exploration or security auditing. Can scan large


networks or single hosts. It uses raw IP packets to determine hosts
Nmap
available on network, services those hosts are running, OS and OS version
they are running, type of packet filters/firewalls being used, etc.
[Link]
Network Reconnaissance Tool. Supports various TCP port & filter scans,
MingSweeper UDP scans, OS detection (NMAP and ICMP style), Banner grabbing etc.
[Link]
Network mapping tool with graphical user interface (GUI).
Cheops
[Link]
Remote OS detector. Sends obscure TCP packets to determine remote
QueSO OS.
[Link]
Risk Analysis: Tools and Usage
Password Auditing

• Used for testing passwords for weaknesses which lead to vulnerable


systems
• Reasons for password weakness
– Poor encryption
– Social engineering (e.g. password is spouse’s, pet’s or child’s name)
– Passwords less than 6 characters
– Passwords do not contain special characters and numbers in addition to lower
and uppercase letters.
– Passwords from any dictionary
• Software tools might perform these tasks:
– Extracting hashed passwords / encrypted passwords
– Dictionary attack (cracks passwords by trying entries in a pre-installed
dictionary)
– Brute force attack (cracks passwords by trying all possible combinations of
characters)
• Deliverables
– Recommendations for future password policies
Risk Analysis: Tools and Usage
Password Auditing

Name Description OS
Detects weak UNIX passwords. “Uses highly optimized modules to decrypt
John the All
different ciphertext formats and architectures” Can be modified to crack LM
Ripper hashes in Windows. [Link]
platforms

Brutus Remote password cracker. [Link] Windows


Audits the AppleTalk users file for weak passwords using brute force methods.
Magic Key Macintosh
[Link]
Assesses, recovers, and remediates Windows and Unix account passwords from Windows
L0phtcrack multiple domains and systems. [Link] & UNIX
Extracts information about users from SAM-files and performs brute force
SAMInside attack of Windows NT/2000/XP. Breaks defense of Syskey. Windows
[Link]
Cracks weakly encrypted Cisco IOS type 7 passwords once encrypted password
Cisco
GetPass! file is obtained.
Router IOS
[Link]

Brute force utility that will try to crack web authentication. Can use a word file
or try all possible combinations, and by trial-and-error, will attempt to find a
wwwhack correct username/password combination.
Windows
[Link]
Backups of security devices,
Performance Analysis
Backup
Why Backup?

“If you are not backing up your files


regularly, you deserve to lose them.”

Average user experiences loss once a year


Backup
What Can Cause Data Loss?
• Incorrect software use
• Input data incorrectly
• Software may harm data
• Hard disk malfunctions
• Accidentally delete files
• Virus infection
Backup

Methods Media
Full backup Diskette
Differential backup Tape
Incremental backup Zip disk
CD-R / CR-RW
DVD-RAM
Mirrored hard drive
Full Backup

• Complete type of backup operation


• make a copy of all the data including files,
folders, settings, applications
• On - storage devices like hard drive, SSD,
HDD, etc.
• files and folders will be backed up again
entirely in any subsequent backup operations
– redundant copies of data
• Needs much disk space
Incremental Backup

• backing up all the files that have changed


since the last backup operation
Differential Backup

• backing up the only changed files since the


last full backup
Mirror Backup

• mirror of source is being supported up


• when record is erased from source, that
document - erased in Mirror Backup too
Full PC Backup

• whole picture of PC’s hard drive


Local Backup

• backup where capacity medium is kept close


within reach or in structure with source
• second inward hard drive, connected outer
hard drive, CD/DVD-More, Network
Attached storage (NAS)
Offsite Backup

• Backup - set in an alternate topographical


area from source

• Cloud Backup
• FTP Backup
Hardware and

Software
Desktops and laptops – Computer equipment can be damaged, lost, stolen.

• Removable media – Media degrades over time. Software programs to read the media
change and can become obsolete. Hardware changes over time, and is not always
backward compatible.

• Cloud storage

– Cloud providers go out of business


– Data formats change (what you upload may not be
useable when you download it)
– Accidents happen. Data is corrupted, or stolen.
File
Formats
• Think about the ability to use and re-use data in the future. Both for you, and for
others.

• Accessibility of future data because of technology changes - proactively plan for


hardware and software obsolescence.

• Think about who needs access to your data. Are you collaborating with someone
within the University, or outside of it?

• Conducting funded research - be aware of any data storage and data sharing
requirements.

• Think about data security.


Best Practices for File
Formats
Formats most likely to be accessible in the future are:

• non-proprietary
• open
• documented standard commonly used by a discipline-specific
research community
• standard representation (ASCII, Unicode)
• unencrypted and uncompressed

Remember that comprehensive documentation (metadata) is


essential to accurate use, and reuse, of all data.
Data Security and Access
Control
• Network security
– Keep confidential or highly sensitive data off
computers or servers connected to the internet
• Physical security
– Access to buildings and rooms
• Computer systems & files
– Use strong passwords on files and systems
– Virus protection (updated continuously and running!)
– Encryption
Data
Backups
• Reduces the risk of damage or loss
• Use multiple locations (here-near-far or 3-2-1)
-Keep at least 3 copies of data
- Store 2 backup copies on different storage media.
- Store 1 backup copy offsite.
• Create a backup schedule and put someone dependable in charge
• Use reliable backup medium
• Test your backup system (test file recovery, data consistency, data
accuracy)
Performance Analysis
 The performance of the Information Security Management System (ISMS) must
be continuously monitored and analysed. If necessary, appropriate preventive
and/or corrective actions should be taken.
 Although information security (ISec) performance measurement is recognised as
an important element of the ISMS, many challenges and issues persist and hinder
the development of ISec in organisations.
 The current state-of-play in ISec metrics does not seem sufficiently advanced in
practice since it remains mostly ad-hoc due to its inherent complexity.
• Since information security is a complex and multidimensional system with an
enormous scope and volume of relevant data, ISec professionals are often
overwhelmed and unable to develop effective assessment processes. Hence,
security managers mostly focus on technical goals and controls, while only few
are capable of performing comprehensive multidimensional ISMS assessments
down to the last level.
CONT.
 Two types of quantitative approaches related to information security performance
are being developed that differ in terms of their measurement focus and
orientation.
 Firstly, assessments that evaluate the ISMS performance in terms of ISec risks
are based on threats and technical vulnerabilities, however, it is difficult to
ensure the sustainability of such approaches due to the changing nature of
threat landscape and constant technological advancements. In such
circumstances, dynamic threat values and manoeuvrable frameworks are
necessary.
 Secondly, control-centric metrics based on established standards are proposed
as an alternative. Such an approach, which enables assessments against
various requirements, has been recognised as an efficient, flexible, and
sustainable mean of measuring ISec effectiveness. Herein, the effectiveness of
ISMS is evaluated in terms of the level of security measures implementation
strength (i.e. development level), which in turn enables a control-gap analysis
and produces quantifiable and operable results.
• To develop an instrument (SECURQUAL) that enables an assessment of the
effectiveness of enterprise information security programs, the COBIT framework was
used in it.
F1: Physical information security controls

Fire, voltage and flood protection of buildings and premises

Adequate installation and management of communication and power network

Support systems for critical services – power supply, cooling, communication

Control of third-party access to buildings and premises


Control of employee access to buildings and premises

Adequate installation and physical protection of hardware

Regular maintenance of hardware

Protection of ICT located outside organizations’ premises (MDM systems)

Adequate building architecture and security plan in place – defined security areas

Protection of buildings and premises against break-ins and wiretapping


F2: Technical and logical security controls
Malware protection

Logical security of programs, systems and databases – identification/authorization

Technical protection of local networks (LAN) and network devices

Technical measures aimed at protecting information during their storage

Technical measures aimed at protecting communications and information during


transfer
Access control – log management, activity monitoring
Adequate system capabilities and capacities for information processing – system
reliability
Standardization of workstations
Change management – analyses of impacts that technology changes have on existing
systems

Regular (automatic) security updates of software and systems


F3: Information resources management

Security categorization of information

Defined administration and other responsibilities related to information


management

User guidelines for handling information


Implementation of the “need-to-know” principle

Control over the exercise of administrator and system rights

Definition and protection of organization’s intellectual property

Definition and protection of personal data


Provision of data processing traceability – audit trails

Adequate deletion of data, destruction of equipment and physical documentation

Information archiving and regular back-ups


F4: Employee management

Raising employees’ awareness regarding information risks and policies

Defined user responsibilities related to the use of confidential systems and


data

Defined disciplinary proceedings, sanctions and infringement proceedings

User rights management throughout employment – before, during, after


employment
Security vetting of employees
Employee agreements and declarations concerning the protection of
confidentiality

Provision of technical and consultative support to employees

Defined remote access and teleworking procedures


Protection of employee rights during information security control
procedures – protection of privacy
Professional training of security and technical personnel
F5: Information risk management and incident handling
Business continuity plan and policy
Automated early warning systems – IDS, IPS, SIEM

Defined procedures for reporting and handling detected irregularities

Crisis management – plans for responding to critical security risks

An alternative location (i.e. hot spot) for the most important parts of
information systems

Incident monitoring, recording and analysis – experiential learning

Forensic procedures and evidence gathering for incident investigations

Information risk management – analysis and evaluation


Analyses of former information incidents’ impacts on business operation –
damage assessment
Assessment of existing security controls’ efficiency – performance
measurement
F6: Organizational culture and top management support
Ethical, socially responsible and transparent security management
Pursuing the principle of efficiency in information security – economy/cost
optimization
Good relations and constructive debates regarding security controls between
organizational departments
Inclusion of information security in the planning of organizational projects and
changes
Leadership familiarity with security needs – direct communication channels

Users’ general satisfaction and confidence with respect to information security

Organizations’ innovativeness, excellence and continuous development in the field of


information technology

Adequate staffing and financial support to information security

Clearly defined organizational hierarchy and job classification regarding


management of organizational security

Leadership involvement in information security planning


F7: Information security policy and compliance
Adoption of a formal information security policy

Policy’s breakdown into sub-areas and orderly documentation

Monitoring the respect of policies among users during their everyday work

Compliance with international standards and recommendations

Continuous development and upgrading of information security – control


of risks and conformity
Regular management reviews and internal audits
Compliance with relevant legislation
Fulfillment of contractual security obligations
Use of licensed products and services

Analysis of examples of information security best practices – benchmarking


F8: Security management maturity
Strategic and long-term planning of information security – proactive
approach
Development of information security as a business function or special
department/service within an organization

Adequate personnel structure – recruitment of qualified staff

Formal authority of security personnel – ability of decision-making

Division between system-related and security tasks – separation between IT


and security division
Cooperation with other organizational authorities in information security
planning
Regular vertical and horizontal security meetings

Team decision-making regarding management of critical security risks

Management of employees’ security culture and motivational activities

Legitimacy of information security – compliance with user requirements


F9: Third-party relationships
Formalized contractual relationships with partners and suppliers regarding
information security

Defined security responsibilities with respect to customers

Involvement of third parties in the implementation of information security


measures

Good customer relations – building trust and reputation/organizations’ goodwill

Testing ICT before acquisition – defined acceptability criteria and quality

Security vetting of business partners and suppliers


Defined and regulated security of e-business

Adequate technical protection of inter – organizational information systems

Formalized contractual relationships for the processing and exchange of personal


data
Liability insurance covering information security events and incidents
F10: External environment connections

Flexibility of organizations – adapting to changes in the sector and the environment

Successful management of competitive and external pressures

Cooperation with other sectoral organizations – inter-organizational strategic


security ties

Participation in economic and business associations, societies and groups

Cooperation with competent authorities when dealing with information incidents

Cooperation with security consultant groups and external audits of information


security

Active participation in foreign/international environments – international


cooperation for knowledge sharing

Defined rules governing communication with the public and competitive


organizations

Monitoring technological developments and implementing innovations regularly

Monitoring and analyzing security trends – development of threats and


vulnerabilities
Root cause analysis and Resolution

• Root cause analysis (RCA) is a method of problem-


solving used to investigate known problems and
identify their antecedent and underlying causes.
• While root cause analysis seems to imply that
issues have a singular cause, this is not always the
cause.
• Problems may have a singular cause or multiple
causes stemming from deficiencies in products,
people, processes or other factors.
types of root causes
• Root cause analysis is implemented as an investigative tool in a variety of industries.

• For IT organizations, root cause analysis is a key aspect of the cyber security incident
response process. When a security breach occurs, SecOps teams must collaborate
quickly to determine where the breach originated, isolate the vulnerability that
caused the breach and initiate corrective and preventive actions to prevent
exploiting the vulnerability again. Root causes can be divided into three types.
1. Physical - when a physical part of a system breaks down. These include hardware
failures, system errors from booting up, issues with tools not functioning, or other
tangible components breaking down.
2. Human - arise from human errors or mistakes. If a person does not have the
necessary skills to operate systems properly, does not know the tools, creates a
programming error, or tries to perform tasks with incorrect tools.
3. Organizational - arise from administrative issues. For example, suppose a team lead
provides incorrect instructions to team members. In that case, organizations make
the incorrect selection of people to perform tasks, or the organization does not
handle or maintain staff correctly.
Benefits of root cause analysis

• There are many benefits to conducting a root cause


analysis:
• Reduce the number of errors that occur from the same root causes.
• Implement tools and solutions to address future issues.
• Implement tools to log and monitor for potential future issues.
• Enable your team to address issues faster.
How to do root cause analysis
When investigating a cyber security incident, security operations teams must act
quickly to identify and isolate the event's root cause. The basic outline of the RCA
process is identical across industries, regardless of the tools that individual
practitioners choose to implement:

1. Identification and description


• The first step to a successful root cause analysis is the accurate characterization of a
problem. If the problem is poorly understood, it may be difficult to isolate the
underlying causes correctly. Accurate event descriptions also play an important role
in RCA. The starting point for a successful analysis should be a collection of accurate
event descriptions detailing everything that happened in connection with the
problem.
2. Chronology
• Once IT operators have identified the problem and associated events, they should
be arranged chronologically, as in a timeline or sequence of events. This makes
establishing and identifying causal relationships between events connected to the
problem easy. Organizations that leverage security analytics software can automate
the collection of event logs and integrate logs from multiple sources into a single,
standardized format and platform. This streamlines the RCA process, helping these
organizations get to step three of RCA at lightning speed.
CONT.
3. Differentiation
• Investigators incorporate additional contextual data surrounding the events to
understand how events are correlated. When a cyber security event is
detected, security operators must analyze dependencies between events to
distinguish between root causes, causal factors and non-causal factors within
the system. ​Enterprise security analytics tools use an event correlation data
analysis technique, which filters through high volumes of computer logs from
various sources and pinpoints the most likely to be connected to the problem.
4. Causal graphing
• In the final step of the RCA process, investigators are encouraged to produce a
causal graph, diagram or another visual interpretation of the result of the RCA
process. Causal graphing illustrates a sequence of key events that begins with
the root causes and ends with the problem. This exercise demonstrates the
logical pathway to determine how the problem occurred.
MODULE 3

Information Security Policies,


Procedures, Standards and
Guidelines
Policies, Procedures, Standards and
Guidelines
• Policy: formal statements produced and
supported by senior management.
• Standards: mandatory courses of action or rules
that give formal policies support and direction.
• Procedure: detailed step-by-step instructions to
achieve a given goal or mandate.
• Guidelines: recommendations to users when
specific standards do not apply.
Policies, Procedures, Standards and
Guidelines
Information Security Policies
Information Security Policies

• Security policies are the foundation of your


security infrastructure.
• A security policy is a document or set of
documents that describes, at a high level, the
security controls that will be implemented by
the company.
Basic Rules in Shaping a Policy

• Policy should never conflict with law


• Policy must be able to stand up in court, if
challenged
• Policy must be properly supported and
administered
Why Policy?
• A quality information security program begins
and ends with policy
• Although information security policies are the
least expensive means of control to execute, they
are often the most difficult to implement
• Policy controls cost - time and effort that the
management team spends to create, approve and
communicate them, and that employees spend
integrating the policies into their daily activities
Why Policy?

Policies are important reference documents


– For internal audits
– For the resolution of legal disputes about
management's due diligence
– Policy documents can act as a clear statement of
management's intent
Information Security Policies

• Two types of basic security policies:


Technical security policies: these include how
technology should be configured and used.
 Administrative security policies: these include
how people (both end users and management)
should behave/ respond to security.
Information Security Policies

• Policies are not technology specific.


• Do 3 things for an organization:
Reduce or eliminate legal liability to employees
and third parties.
 Protect confidential, proprietary information
from theft, misuse, unauthorized disclosure or
modification.
Prevent waste of company computing resources.
Information Security Policies

• Persons responsible for the implementation


of the security policies are:
Director of Information Security
 Chief Security Officer
Director of Information Technology
Chief Information Officer
Information Security Policies

Types of information security policy


– Enterprise Information Security Policy (EISP)
– Issue-specific information security policies
– Systems-specific policies
Enterprise Information Security Policy
(EISP)
• EISP sets the strategic direction, scope, and tone for
all of an organization’s security efforts
• EISP assigns responsibilities for the various areas of
information security including maintenance of
information security policies and the practices and
responsibilities of other users.
• EISP guides the development, implementation, and
management requirements of the information security
program
• EISP should directly support the mission and vision
statements
EISP Elements
• An overview of the corporate philosophy on
security
• Information on the structure of the InfoSec
organization and individuals who fulfill the
InfoSec role
• Fully articulated responsibilities for security that
are shared by all members of the organization
• Fully articulated responsibilities for security that
are unique to each role within the organization
Issue-Specific Security Policy (ISSP)
• Provides a common understanding of the
purposes for which an employee can and
cannot use a technology
– Should not be presented as a foundation for legal
prosecution
• Protects both the employee and organization
from inefficiency and ambiguity
ISSP Topics
• Use of Internet, e-mail, phone, and office
equipment
• Incident response
• Disaster/business continuity planning
• Minimum system configuration requirements
• Prohibitions against hacking/testing security
controls
• Home use of company-owned systems
• Use of personal equipment on company
networks
Example Policy
ISSP Implementation
• Three common approaches for creating/managing
ISSP
– Create individual independent ISSP documents,
tailored for specific issues
– Create a single ISSP document covering all issues
– Create a modular ISSP document unifying overall
policy creation/management while addressing
specific details with respect to individual issues
System Specific Security Policy (SysSPs)

• SysSPs provide guidance and procedures for configuring


specific systems, technologies, and applications
– Intrusion detection systems
– Firewall configuration
– Workstation configuration
• SysSPs are most often technical in nature, but can also
be managerial
– Guiding technology application to enforce higher
level policy (e.g. firewall to restrict Internet access)
Information Security Policies
• A security policy should determine rules and
regulations for the following systems:
– Encryption mechanisms
– Access control devices
– Authentication systems
– Firewalls
– Anti-virus systems
– Websites
– Gateways
– Routers and switches
– Necessity of a security policy
Information Security Policies
Information Security Policies
Guidelines for Effective Policy

• Developed using industry-accepted practices


• Distributed using all appropriate methods
• Reviewed or read by all employees
• Understood by all employees
• Formally agreed to by act or assertion
• Uniformly applied and enforced
Developing Information Security Policy

• Investigation Phase
• Analysis Phase
• Design Phase
• Implementation Phase
• Maintenance Phase
Investigation Phase
• Support from senior management
• Support and active involvement of IT
management
• Clear articulation of goals
• Participation by the affected communities of
interest
• Detailed outline of the scope of the policy
development project

98
Analysis Phase

• The analysis phase should produce the


following:
– A new or recent risk assessment or IT audit
documenting the information security needs of
the organization.
– Gathering of key reference materials – including
any existing policies

99
Design Phase

• Users or organization members acknowledge


they have received and read the policy
– Signature and date on a form
– Banner screen with a warning

100
Implementation Phase

• Policy development team writes policies


• Resources:
– The Web
– Government sites such as NIST
– Professional literature
– Peer networks
– Professional consultants

101
Maintenance Phase

• Policy development team responsible for


monitoring, maintaining, and modifying the
policy

102
Policy Distribution

• Hand policy to employees


• Post policy on a public bulletin board
• E-mail
• Intranet
• Document management system

103
Policy Comprehension

• Language
– At a reasonable reading level
– With minimal technical jargon and management
terminology
• Understanding of issues
– Quizzes

104
Policy Compliance

• Policies must be agreed to by act or


affirmation
• Corporations incorporate policy confirmation
statements into employment contracts, annual
evaluations

105
Bull’s Eye Model
• Proven mechanism for prioritizing complex
changes
• Issues are addressed by moving from general
to specifics
• Focus of systemic solutions instead of
individual problems

10
106
6
Bull’s Eye Model (Contd)

10
107
7
Bull’s Eye Model Layers
• Policies – the outer layer in the bull’s eye diagram
• Networks – the place where threats from public networks meet the
organization’s networking infrastructure; in the past, most information
security efforts have focused on networks, and until recently information
security was often thought to be synonymous with network security
• Systems – computers used as servers, desktop computers, and systems
used for process control and manufacturing systems
• Application – all applications systems, ranging from packed applications
such as office automation and e-mail programs, to high-end ERP
packages and custom application software developed by the organization

10
108
8
Automated Tools

• VigilEnt Policy Center – a centralized policy


approval and implementation center
– Manage the approval process
– Reduces need to distribute paper copies
– Manage policy acknowledgement forms

109
VigilEnt Policy Center Architecture
User Site Company Intranet
Users view policies and quizzes.

User information Administrators


Users read to the company receive policy
policy docs intranet. docs and
Policy docs and
and complete quizzes.
quizzes and news
quizzes.
items to the Intranet.

Administrators publish policy docs and


quizzes. VPC server sends published
policy docs and quizzes to the server
VPC Server Administration Site
for distribution to the user sites.

110
Policy Management

• Policy administrator
• Review schedule
• Review procedures and practices
• Policy and revision dates

111
Policy Administrator

• Policy administrator
– Champion
– Mid-level staff member
– Solicits input from business and information
security communities
– Makes sure policy document and subsequent
revisions are distributed

112
Review Schedule

• Periodically reviewed for currency and


accuracy, and modified to keep current
– Organized schedule of review
– Reviewed at least annually
– Solicit input from representatives of all affected
parties, management, and staff

113
Review Procedures and Practices

• Easy submission of recommendations


• All comments examined
• Management approved changes implemented

114
Policy and Revision Date

• Often published without a date


– Legal issue – are employees “complying with an
out-of-date policy
• Should include date of origin, revision dates
– don’t use “today’s date” in the document
• Sunset clause (expiration date)

115

You might also like