KEY CONCEPTS AND PRINCIPLES
Chapter 3
Information Security
Objectives of InfoSec
Information Security Objectives
The objective of Information Security is to protect :
What are the consequences of inadequate InfoSec?
Layers of security
Requirements
Communications Security
TCP/IP: Since it connects all the things …
Physical Security
Software Security
Human/Personnel Security
Awareness of Risks
Motivation
Training
Security Layers
Comprehensive Security
Security Threats
External Threats
Frameworks
Access/User : Authentication/Authorization, security clearance
Application controls over web servers, databases, encryption, identity management
Network Security: firewall, IDS, IPS
Platform/Host: IDS/IPS, anti-virus,
Hardening of servers
Physical: locks, fire protection
Security Frameworks
*Pro Tip: None of them use the same layers, but all have core layering concepts in common.
Scenario:
People, Procedures, Technology
If any one of these items are not supported nor enforced, then they are not effective.
Policies, Procedures & Processes … oh my!
Just a few policies … �
Procedures and processes describe how the intent of the policies is to be implemented. �
Question: What’s the point of all these policies?
CIA … and not the govt. agency kind
Confidentiality
Integrity
Availability
Security Implementation Cycle
This is similar to other Design and Implementation Cycles: Software Development, Network Design, Architecture.
Risk Assessment�
Planning and Architecture�
Mind the Gap Analysis
Implementation and Deployment
Implementation done in silos rather than organization-wide does not provide adequate protection
Operations
Monitoring�
Legal Compliance and Audit�
Crisis Management
Principles of Information Security