1 of 32

KEY CONCEPTS AND PRINCIPLES

Chapter 3

2 of 32

Information Security

  • Information security refers to the processes and methodologies that are designed to protect sensitive information or data from unauthorized access, use and misuse, disclosure, modification, destruction, or disruption. �
  • In addition, it also covers the validity or genuineness of the information and rejection of false information received from others.

  • The terms “information security,” “computer security,” “data security,” and “information assurance” are frequently used interchangeably.

  • Their common goal is to protect the Confidentiality, Integrity, and Availability (CIA) of data.

3 of 32

Objectives of InfoSec

  • What is the purpose of Information Security?

  • What are we trying to protect?

4 of 32

Information Security Objectives

The objective of Information Security is to protect :

    • Information
    • People
    • Systems
    • Hardware that store, transmit & process data
    • Resources

5 of 32

What are the consequences of inadequate InfoSec?

  • What happens if a system is breached?

  • Was it just a password?
    • Whose was it? What access does account have? Is account still active?

  • An entire corporate database?
    • What data populates it? Who/What has access? Is it encrypted?

  • An electrical facility?
    • How fast do I have to drive away?!

6 of 32

Layers of security

  • Communications
  • Physical
  • Software
  • People

7 of 32

Requirements

  • The requirements of information security have undergone major changes in the last few decades. �
  • Used to be more restricted to physical access: guarded room, locked security cabinets, etc.

  • Now, automated tools became a necessity for protecting data as it is stored, transmitted and processed.

8 of 32

Communications Security

TCP/IP: Since it connects all the things …

  • Network Security became extremely essential to protect data that is being transmitted and guarantee that the data is not tampered with during the transmission. �

9 of 32

Physical Security

  • Physical Security is still a significant part of any security system and cannot be ignored
    • Insecure server room doors, keys, ID’s, no timeout on system, network devices open in a classroom …

  • Hardware Security can be primarily considered under Physical Security, even though some of the components of the hardware can be considered under other securities such as Network Security

10 of 32

Software Security

  • Deals with Operating System Security, Application Security, Software utilities/tools, including the very tools used to provide information security!

  • More devices == More Software == More things that can/do go boom.

  • In practice, secure design + development + deployment is lagging behind significantly.
    • “I’m looking at you, Java …”

11 of 32

Human/Personnel Security

Awareness of Risks

  • “But I always get .exe’s as attachments…”

Motivation

  • “We have a good security team, so I click stuff …”�

Training

  • “What’s a malware?”

12 of 32

Security Layers

13 of 32

Comprehensive Security

  • An effective Information Security Architecture should consider all layers without omitting any of them.

  • It should also consider the effectiveness and have an integrated view of all of them

  • This is Defense in Depth

14 of 32

Security Threats

  • What are some threats?
    • <class erupts with suggestions>

15 of 32

External Threats

16 of 32

Frameworks

Access/User : Authentication/Authorization, security clearance

Application controls over web servers, databases, encryption, identity management

Network Security: firewall, IDS, IPS

Platform/Host: IDS/IPS, anti-virus,

Hardening of servers

Physical: locks, fire protection

17 of 32

Terms

18 of 32

Security Frameworks

  • ISO/IEC 27001:2013: Specifies a management system that is intended to bring information security under management control and gives specific requirements.

  • NIST Special Publication 800-39: Managing Information Security Risk

  • NIST Special Publication 800-53 Revision 4: Security and Privacy Controls for Federal Information Systems and Organizations.

  • SABSA: “methodology for developing business-driven, risk and opportunity focused Security Architectures at both enterprise and solutions level that traceably support business objectives.”

*Pro Tip: None of them use the same layers, but all have core layering concepts in common.

19 of 32

Scenario:

  • Imagine you have a brand new network with 20 computers, a webserver, database server, and email server.

  • There is no security on any system other than default passwords.

  • The boss says you go live in 1 hour.

  • What do you do in that hour?

  • What are the next things you will try to do?

20 of 32

People, Procedures, Technology

If any one of these items are not supported nor enforced, then they are not effective.

21 of 32

Policies, Procedures & Processes … oh my!

Just a few policies …

  • Information Security Management Systems Policy
  • Access Control Policy
  • Information Classification and Handling Policy
  • Physical and Environmental Security Policy
  • Acceptable Use of Assets Policy
  • Clear Desk and Clear Screen Policy
  • Privacy and Protection of Personally Identifiable Information Policy
  • Mobile Devices and Teleworking Policy
  • Backup Policy
  • Restrictions on Software Installations and Use Policy
  • Protection from Malware Policy
  • Management of Technical Vulnerabilities Policy
  • Information Transfer Policy
  • Communications Security Policy
  • Cryptographic Controls Policy
  • Policy on Supplier Relationships

Procedures and processes describe how the intent of the policies is to be implemented. �

Question: What’s the point of all these policies?

22 of 32

CIA … and not the govt. agency kind

Confidentiality

  • Some information is secret, sensitive, or needs to be restricted as a disclosure to unintended sources can create such things as the compromise of a nation’s security or strategic installations, the loss of business opportunities, a first mover advantage, intellectual property rights, and privacy.

Integrity

  • Information is useful and reliable only if it is accurate and not modified against the intentions wanted of the originator. “Integrity” needs to be protected appropriately by means such as appropriate authentication, routing protocols, appropriate configuration of systems, and application security

Availability

  • Information today is stored in systems, databases, storage units, or, most recently, on the Cloud. In today’s fast-paced world where opportunities can be lost fast and the speed of decision making is important, the availability of crucial information at all times has become necessary

23 of 32

Security Implementation Cycle

This is similar to other Design and Implementation Cycles: Software Development, Network Design, Architecture.

24 of 32

Risk Assessment�

  • There are various risk management methodologies available for ensuring effective risk assessment.
    • Risk Management – Principles and guidelines (ISO/IEC 31000:2009);
    • Operationally Critical Threat, Asset and Vulnerability Evaluation SM (OCTAVE)
    • Risk assessment methodology specified by NIST (SP 30, 39 & 53)
    • Risk IT framework by Information Systems Audit and Control Association (COBIT)

  • Regardless of the method, risk assessment as a process has to be carried out methodically and effectively to derive the required benefits.

    • Risks in the context of the entire organization
    • Vulnerabilities and Threats to information assets
    • Current controls that are in place
    • Quantification of the risk to understand risk exposure

25 of 32

Planning and Architecture�

  • In an existing organization, planning may commence with the planning for effective risk assessment involving all the stakeholders as relevant.
  • In a new organization, the planning may be carried out to effectively approach achievement of information security using relevant steps as suggested by appropriate frameworks or methodologies.

  • Plans:
    • Identify the owners for various activities, roles, and responsibilities for the effective execution of these plans.
    • Schedules used also clearly depicts the timelines, keeping in mind various dependencies and constraints
    • Integrated, methodical, and well-coordinated approach, leading to effective information security infrastructure or architecture rather than an ad-hoc approach that can create side effects or make the implementation ineffective.
    • Effective information security infrastructure or architecture provides ease of use and generates confidence to all the stakeholders including business users.

26 of 32

Mind the Gap Analysis

  • Reveals unknown vulnerabilities
    • Example: Bob used to work in accounting, but now works in sales. She still is authorized to access the accounting system.

  • Ensures our protection systems continue to work after changes.

  • Periodical gap analysis to check on:
    • Implementation of policies, procedures, and processes
    • Effectiveness of existing protective mechanisms�
  • This may be done through periodical risk re-assessments leading to additional controls to be implemented through new risk treatment plans

27 of 32

Implementation and Deployment

Implementation done in silos rather than organization-wide does not provide adequate protection

  • Efforts related to information security need to be thought of in an integrated manner by involving all the relevant stakeholders
  • Implemented based on their dependencies

  • What would be the impact of requiring Champlain student users to change their password every month?�
  • What would be the impact of requiring Champlain staff users to change their password every month?

  • Are the risks different for these situations?

28 of 32

Operations

  • Operations (day-to-day activities) carried out according to established policies, procedures and processes. �
  • Violations to speed up the activities or ignorance can lead to serious consequences. �
  • Examples:
    • Backups are taking up too much space so person responsible starts doing weekly backups, instead of nightly
    • Big Box Store: It is easier to keep one person logged in than to re-login every time a new cashier takes over.

29 of 32

Monitoring�

  • Integral part of any activity whether it is business-related or information security-related.
    • Monitoring threats so we can react to the them effectively and timely
    • Time-consuming … finding all intruder activities manually through logs is a humungous activity. #Ugh!
    • There are many tools available to monitor, filter, detect, and/or alert:
      • Firewalls and IDS/IPS
      • Resource usage monitoring�
  • If not done on a timely basis, may lead to systems not being usable or available.
  • Log Analysis carried out to understand causes better and may create newer defensive mechanisms.

30 of 32

Legal Compliance and Audit�

  • One of the biggest threats to an organization’s existence is non-compliance to legal requirements… Organizations can be permanently shut down if the non-compliance is severe!
    • Laws enacted to prevent the misuse of IT and those need to be adhered to. May require special skills to understand the compliance in the context of information technology.
    • Periodic audits by knowledgeable independent or internal experts

  • Compliance check on various policies, procedures, or processes
    • Context changes, but these policies and processes are not modified.
    • New employees join, but are not trained on policies and processes.
    • Requisite focus on effective implementation of policies and processes gets low priority.
    • Organizations should have strong periodic internal audits coupled with external audits by independent experts occasionally.
    • Management should provide necessary focus on these so that even if the organization wades off a little, it is again brought back to the right path.

31 of 32

Crisis Management

    • Crisis Management Plan, Business Continuity Plan, or Disaster Recovery Plan are interchangeably

    • Organizations can face crisis because of natural disasters, mistakes of employees, senior management, or because of the external attacks like the attacks from the hackers.

    • Need to respond effectively and also restore their business back to normalcy after such attacks.

    • Well-planned business continuity and crisis management plan should be put in place by every organization.

    • Disaster recovery and business continuity should become an integral part of the planning process of every organization.

    • Organization should carry out the business impact analysis to identify the critical businesses for which continuity is essential and also the tolerance time frame up to which the organization can wait before the business need to be commenced.

    • A business continuity plan should be put in place clearly identifying the roles and responsibilities of all the concerned stakeholders.

    • Stakeholders need to be trained and the business continuity plan should be tested to check that it works as required when actually it has to be put into action.

    • As every event or incident is not a crisis, a senior person should be empowered to identify a crisis when it arises, as he has the maturity and knowledge to declare a situation a crisis.

32 of 32

Principles of Information Security

  • Homework 🡪
    • Read chapter 3
    • Review section “Principles of Information Security”