Добавил:
ivanov666
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз:
Предмет:
Файл:Information protection in digital communication systems. Textbook
.pdf
181
Table 6.2
Requirements for security classes of automated systems
Subsystems and requirements
Classes
3B
3А
2B
2А
1E
1D
1C
1B
1А
I. Access control subsystem
Identification, authentication and access control of subjects:
To the system
+ + + + + + + + +
to terminals, computers, computer network nodes, communication
channels, external computer devices
+ + + + +
to programs
+ + + + +
to volumes, directories, files, records, record fields
+ + + + +
Information flow management
+ + + +
II. Registration and accounting subsystem
Registration and accounting
entry/exit of access subjects to/from the system (network node)
+ + + + + + + + +
issuance of printed (graphic) output documents
+ + + + + +
starting/ending programs and processes (tasks)
+ + + + +
access of programs of access subjects to protected files, including their
creation and deletion, transmission over communication lines and
channels
+ + + + +
access of programs of access subjects to terminals, computers,
computer network nodes, communication channels, external computer
devices, programs, volumes, directories, files, records, record fields
+ + + + +

182
Subsystems and requirements
Classes
3B
3А
2B
2А
1E
1D
1C
1B
1А
changes in permissions of access subjects
+ + +
created protected access objects
+ + + +
Storage media accounting
+ + + + + + + + +
Clearing (zeroing, depersonalizing) freed areas of computer RAM and
external storage devices
+ + + + + +
Alarm of security violation attempts
+ + +
III. Cryptographic subsystem
Encryption of confidential information
+ + +
Encryption of information belonging to different access subjects
(groups of subjects) using different keys
+
Use of certified cryptographic tools
+ + +
IV. Integrity subsystem
Ensuring the integrity of software and processed information
+ + + + + + + + +
Physical security of computer equipment and storage media
+ + + + + + + + +
Availability of an information protection administrator (service) in the
AS
+ + + +
Periodic testing of the information and information protection system
from the UA
+ + + + + + + + +
Availability of means for restoring information and data protection
equipment from the UA
+ + + + + + + + +
Use of certified protective equipment
+ + + + +
Designations:
“+” — there is a requirement for this class.

183
Firewall security indicators
In the guiding document of the State Technical Commission of Russia
[9] “Guiding document. Computer facilities. Firewalls. Protection against
unauthorized access to information. Indicators of security against
unauthorized access to information” establishes a classification of firewalls
according to the level of security against unauthorized access to information
based on a list of security indicators and a set of requirements describing
them.
In this document, computer networks distributed by AS are
understood as data processing systems connected by communication
channels and focused on a specific user.
Firewall is a local (single-component) or functionally distributed tool
(complex) that implements control over information entering the AS and/or
leaving the AS, and ensures protection of the AS by filtering information,
i.e. analyzing it according to a set of criteria, and making a decision on its
distribution to (from) the AS.
The guidance document was developed in addition to the Guidance
documents of the State Technical Commission of Russia “Computer
facilities. Protection against unauthorized access to information. Indicators
of security against unauthorized access to information” and “Automated
systems. Protection against unauthorized access to information.
Classification of automated systems and requirements for information
protection.”
The document is intended for customers and developers of firewalls,
as well as computer networks, distributed automated systems for the purpose
of use in the formulation and implementation of requirements for their
protection from unauthorized access to information.
General provisions. These indicators contain requirements for
security measures that ensure safe interaction between computer and AS
networks by managing inter-network information flows and implemented in
the form of the firewall.

184
Security metrics are applied to firewalls to determine the level of
security they provide during internetwork communications.
Specific lists of indicators determine the security classes of the
firewall.
Dividing firewalls into appropriate classes according to the levels of
control of inter-network information flows from the point of view of
information security is necessary in order to develop and apply reasonable
and economically justified measures to achieve the required level of
information protection in the interaction of computers and AS. The
differentiation of the approach to the selection of protection functions in the
firewall is determined by the AS for the protection of which this screen is
used.
Five firewall security classes are established. Each class is
characterized by a certain minimum set of requirements for information
protection.
The lowest security class is the fifth, used for the safe intercommunion
of class 1E with the external environment, the fourth — 1D, the third — 1C,
the second — 1B, the highest is the first, used for the safe intercommunion
of class 1A with the external environment (Table 6.3).
Table 6.3
List of indicators by firewall security classes
Security indicators
Security classes
5 4 3 2 1
Access control (data filtering and address
translation)
+ + + + =
Identification and authentication
– – + = +
Registration
– + + + =
Administration: identification and authentication
+ = + + +
Administration: registration
+ + + = =
Administration: ease of use
– – + = +
Integrity
+ = + + +

185
Security indicators
Security classes
5 4 3 2 1
Recovery
+ = = + =
Testing
+ + + + +
Security administrator guide
+ = = = =
Test documentation
+ + + + +
Design (project) documentation
+ = + = +
Designations:
“–” — there are no requirements for this class;
“+” — new or additional requirements;
“=” — the requirements coincide with the requirements for the ME of the
previous class.
The requirements for firewall do not exclude the requirements for CE
and AS in accordance with the governing documents of the State Technical
Commission of Russia “Computer facilities. Protection against
unauthorized access to information. Indicators of security against
unauthorized access to information” and “Automated systems. Protection
against unauthorized access to information. Classification of automated
systems and requirements for information protection.”
When an firewall is included in an AS of a certain security class, the
security class of the total AS obtained from the original one by adding an
firewall to it should not be reduced. For 3B, 2B classes, firewalls of at least
class 5 must be used. For 3A, 2A classes, depending on the importance of
the information being processed, firewalls of the following classes should
be used:
• when processing information classified as “secret” — not lower than
class 3;
• when processing information classified as “top secret” — not lower
than class 2;
• when processing information classified as “special importance” —
not lower than class1.

186
Thus, in fact, this document does not provide for the exchange of
information constituting a state secret between automated systems of classes
1D–1A or if such a system is available at only one end.
6.2. ADMINISTRATIVE LEVEL
The administrative level of information security includes general
actions taken by the management of the organization. The administrative
level is the basis for the practical construction of an integrated system that
determines the general direction of work to ensure information security (IS).
The purpose of the administrative level is to develop a work program
in the field of information security and ensure its implementation. The
program presents a formal safety policy that reflects the organization’s own
conceptual approach to IS. The specification of the security policy is
expressed in plans for information protection of the plant.
Practical activities for creating an IS system include the following
steps:
1. Development of a security policy.
2. Conducting a risk analysis.
3. Information security planning.
4. Emergency planning.
5. Selection of mechanisms and means of ensuring information
security.
Actually, the first two stages are usually interpreted as the
development of a security policy and constitute the administrative level of
the enterprise security system.
The third and fourth stages are the development of security
procedures; at these stages, the planning level of the IS system is formed;
this level can also be called procedural.
At the last stage of practical activities, the software and hardware level
of the IS system is determined.

187
6.2.1. Security policy
The Orange Book defines security policy as a set of rules, regulations,
and practices that govern the management, protection, and distribution of
valuable information. In practice, security policy (SP) is interpreted
somewhat more broadly — as a set of documented administrative decisions
aimed at ensuring the security of an information resource. The result of the
policy is a high-level document that represents a systematic statement of
goals, objectives, principles and methods for achieving information
security.
This document presents the methodological basis for practical
measures (procedures) for the implementation of IS and contains the
following groups of information:
1. Basic provisions of information security.
2. Scope of application.
3. Goals and objectives of ensuring information security.
4. Distribution of roles and responsibilities.
5. General responsibilities.
The main provisions define the importance of IS, general security
problems, directions for solving them, the role of employees, and the legal
framework.
The scope of application of the security policy is the main assets and
subsystems of the AS that are subject to protection. Typical assets are
software, hardware and information support of the plant, personnel, and, in
some cases, the information infrastructure of the enterprise.
Goals, objectives, IS criteria follow from the functional purpose of the
enterprise. For example, for security organizations, confidentiality is a top
priority. For real-time information services, it is important to ensure the
availability (operational readiness) of subsystems. For information
warehouses, ensuring data integrity, etc. may be relevant. Laws and
organizational rules that should be taken into account when carrying out
work on IS are indicated here.

188
Typical goals could be the following:
1) ensuring a level of security that complies with the regulatory
documents of the enterprise;
2) following economic feasibility in choosing protective measures;
3) ensuring an appropriate level of safety in specific functional areas
of the plant;
4) ensuring accountability of all user actions with information
resources and analysis of registration information, etc.
If the enterprise is not isolated, goals and objectives are considered in
a broader context: issues of safe mutual influence of local and remote
subsystems must be discussed.
The document under consideration may specify some strategic
security principles (arising from the goals and objectives of IS). These are
strategies for action in the event of a violation of the security policy of the
enterprise and third-party organizations, interaction with external
organizations, law enforcement agencies, the press, etc. As an example, two
strategies for responding to a security violation can be cited:
1. “Track and Convict,” when the attacker is allowed to continue his
actions with the goal of compromising him and punishing him (this strategy
is approved by law enforcement agencies).
2. “Protect and continue” when the organization fears for the
vulnerability of information resources and provides maximum resistance to
the violation.
The security policy affects all computer users in the organization.
Therefore, it is important to resolve the so-called political issues of vesting
all categories of users with appropriate rights, privileges and responsibilities.
For this purpose, the circle of persons who have access to the
subsystems and services of the AS is determined. For each category of user,
the correct and incorrect ways to use resources are described — what is
prohibited and allowed. Here the levels and regulation of access of various
user groups are specified. It should be indicated which of the default rules
for the use of resources is accepted in the organization, namely:
• what is not expressly prohibited is permitted or

189
• what is not clearly permitted is prohibited.
One of the most vulnerable points in IS is the distribution of access
rights. The security policy must approve a scheme for managing the
distribution of access rights to services — centralized, or decentralized, or
otherwise. It must be clearly defined who has access rights to services and
what rights they have. It is advisable to describe in detail the practical
procedures for assigning rights to users. Here you should indicate officials
who have administrative privileges and passwords for certain services.
The rights and obligations of users are determined in relation to the
safe use of AS subsystems and services. When defining the rights and
responsibilities of administrators, some balance should be sought between
users’ right to privacy and the administrator’s responsibility to control
security breaches.
An important element of policy is the distribution of responsibilities.
Politics cannot provide for everything, but it must find someone responsible
for each type of problem.
There are usually several levels of responsibility. At the first level,
each user is obliged to work in accordance with the security policy (protect
his account), obey the orders of those responsible for certain aspects of
security, and notify management about all suspicious situations. System
administrators are responsible for protecting the relevant information and
computing subsystems. Network administrators must ensure the
implementation of organizational and technical measures necessary to
implement the AS security policy. Higher level — department heads, who
are responsible for communicating and monitoring the provisions of the
security policy.
From a practical point of view, it is advisable to divide the security
policy into several levels (usually two or three levels are distinguished).
The top level is general in nature and determines the policy of the
organization as a whole. Here the focus is on: the procedure for creating and
reviewing security policies; the goals pursued by the organization in the
field of information security; issues of resource allocation and distribution;
principles of technical policy in the field of selection of methods and means

190
of information security; coordinating security measures; strategic planning
and control; external interactions and other issues of an organization-wide
nature.
At this level, the main goals in the field of information security
(determined by the field of activity of the enterprise) are formulated:
ensuring confidentiality, integrity and/or availability [2]. Generally
speaking, the minimum number of issues should be raised to the top level.
Such a provision is advisable when it promises significant cost savings or
when it is simply impossible to do otherwise.
The average level of security policy is allocated in case of structural
complexity of the organization or if it is necessary to identify specific
subsystems of the organization. This concerns the attitude towards
promising, not yet sufficiently proven technologies. For example, the use of
new Internet services, the organization of communications and information
processing on home and laptop computers, the degree of compliance with
the provisions of computer law, etc. In addition, at the average level of
security policy, particularly significant contours of the organization’s AS
can be identified, for example, those processing secret or critically important
information. That is, the average level includes issues related to individual
aspects of information security, but important for various systems operated
by the organization.
The mid-level policy should cover the following topics for each aspect.
Description of the aspect. For example, if we consider the use of
unofficial software by users, the latter can be defined as software that has
not been approved and/or purchased at the organizational level.
Application area. It is necessary to determine where, when, how, to
whom and to what this security policy applies.
The position of the organization on this aspect. Continuing the
example with unofficial software, one can imagine the positions of a
complete ban, the development of a procedure for accepting such software,
etc. The position can be formulated in a much more general form as a set of
goals that the organization pursues in this aspect.
Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]
