Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

Information protection in digital communication systems. Textbook

.pdf
Скачиваний:
0
Добавлен:
07.09.2026
Размер:
2 Мб
Скачать
181
Table 6.2
Requirements for security classes of automated systems
Subsystems and requirements
Classes
3B
2B
1E
1D
1C
1B
I. Access control subsystem
Identification, authentication and access control of subjects:
To the system
+ + + + + + + + +
to terminals, computers, computer network nodes, communication channels, external computer devices
+ + + + +
to programs
+ + + + +
to volumes, directories, files, records, record fields
+ + + + +
Information flow management
+ + + +
II. Registration and accounting subsystem
Registration and accounting
entry/exit of access subjects to/from the system (network node)
+ + + + + + + + +
issuance of printed (graphic) output documents
+ + + + + +
starting/ending programs and processes (tasks)
+ + + + +
access of programs of access subjects to protected files, including their creation and deletion, transmission over communication lines and channels
+ + + + +
access of programs of access subjects to terminals, computers, computer network nodes, communication channels, external computer devices, programs, volumes, directories, files, records, record fields
+ + + + +
182
Subsystems and requirements
Classes
3B
2B
1E
1D
1C
1B
changes in permissions of access subjects
+ + +
created protected access objects
+ + + +
Storage media accounting
+ + + + + + + + +
Clearing (zeroing, depersonalizing) freed areas of computer RAM and external storage devices
+ + + + + +
Alarm of security violation attempts
+ + +
III. Cryptographic subsystem
Encryption of confidential information
+ + +
Encryption of information belonging to different access subjects (groups of subjects) using different keys
+
Use of certified cryptographic tools
+ + +
IV. Integrity subsystem
Ensuring the integrity of software and processed information
+ + + + + + + + +
Physical security of computer equipment and storage media
+ + + + + + + + +
Availability of an information protection administrator (service) in the AS
+ + + +
Periodic testing of the information and information protection system from the UA
+ + + + + + + + +
Availability of means for restoring information and data protection equipment from the UA
+ + + + + + + + +
Use of certified protective equipment
+ + + + +
Designations:
“+” there is a requirement for this class.
183
Firewall security indicators
In the guiding document of the State Technical Commission of Russia [9] “Guiding document. Computer facilities. Firewalls. Protection against unauthorized access to information. Indicators of security against unauthorized access to information establishes a classification of firewalls according to the level of security against unauthorized access to information based on a list of security indicators and a set of requirements describing them.
In this document, computer networks distributed by AS are understood as data processing systems connected by communication channels and focused on a specific user.
Firewall is a local (single-component) or functionally distributed tool (complex) that implements control over information entering the AS and/or leaving the AS, and ensures protection of the AS by filtering information, i.e. analyzing it according to a set of criteria, and making a decision on its distribution to (from) the AS.
The guidance document was developed in addition to the Guidance
documents of the State Technical Commission of Russia “Computer
facilities. Protection against unauthorized access to information. Indicators of security against unauthorized access to information and Automated systems. Protection against unauthorized access to information. Classification of automated systems and requirements for information protection.”
The document is intended for customers and developers of firewalls, as well as computer networks, distributed automated systems for the purpose of use in the formulation and implementation of requirements for their protection from unauthorized access to information.
General provisions. These indicators contain requirements for security measures that ensure safe interaction between computer and AS networks by managing inter-network information flows and implemented in the form of the firewall.
184
Security metrics are applied to firewalls to determine the level of security they provide during internetwork communications.
Specific lists of indicators determine the security classes of the firewall.
Dividing firewalls into appropriate classes according to the levels of control of inter-network information flows from the point of view of information security is necessary in order to develop and apply reasonable and economically justified measures to achieve the required level of information protection in the interaction of computers and AS. The differentiation of the approach to the selection of protection functions in the firewall is determined by the AS for the protection of which this screen is used.
Five firewall security classes are established. Each class is characterized by a certain minimum set of requirements for information protection.
The lowest security class is the fifth, used for the safe intercommunion of class 1E with the external environment, the fourth 1D, the third 1C, the second 1B, the highest is the first, used for the safe intercommunion of class 1A with the external environment (Table 6.3).
Table 6.3
List of indicators by firewall security classes
Security indicators
Security classes
5 4 3 2 1
Access control (data filtering and address translation)
+ + + + =
Identification and authentication
– – + = +
Registration
+ + + =
Administration: identification and authentication
+ = + + +
Administration: registration
+ + + = =
Administration: ease of use
– – + = +
Integrity
+ = + + +
185
Security indicators
Security classes
5 4 3 2 1
Recovery
+ = = + =
Testing
+ + + + +
Security administrator guide
+ = = = =
Test documentation
+ + + + +
Design (project) documentation
+ = + = +
Designations:
“–” — there are no requirements for this class;
“+” — new or additional requirements;
“=” — the requirements coincide with the requirements for the ME of the
previous class.
The requirements for firewall do not exclude the requirements for CE and AS in accordance with the governing documents of the State Technical
Commission of Russia “Computer facilities. Protection against
unauthorized access to information. Indicators of security against unauthorized access to information and Automated systems. Protection against unauthorized access to information. Classification of automated systems and requirements for information protection.”
When an firewall is included in an AS of a certain security class, the security class of the total AS obtained from the original one by adding an firewall to it should not be reduced. For 3B, 2B classes, firewalls of at least class 5 must be used. For 3A, 2A classes, depending on the importance of the information being processed, firewalls of the following classes should be used:
when processing information classified as “secret” — not lower than
class 3;
when processing information classified as “top secret” — not lower
than class 2;
when processing information classified as “special importance” —
not lower than class1.
186
Thus, in fact, this document does not provide for the exchange of information constituting a state secret between automated systems of classes 1D–1A or if such a system is available at only one end.
6.2. ADMINISTRATIVE LEVEL
The administrative level of information security includes general actions taken by the management of the organization. The administrative level is the basis for the practical construction of an integrated system that determines the general direction of work to ensure information security (IS).
The purpose of the administrative level is to develop a work program in the field of information security and ensure its implementation. The program presents a formal safety policy that reflects the organizations own conceptual approach to IS. The specification of the security policy is expressed in plans for information protection of the plant.
Practical activities for creating an IS system include the following steps:
1. Development of a security policy.
2. Conducting a risk analysis.
3. Information security planning.
4. Emergency planning.
5. Selection of mechanisms and means of ensuring information
security.
Actually, the first two stages are usually interpreted as the development of a security policy and constitute the administrative level of the enterprise security system.
The third and fourth stages are the development of security procedures; at these stages, the planning level of the IS system is formed; this level can also be called procedural.
At the last stage of practical activities, the software and hardware level of the IS system is determined.
187
6.2.1. Security policy
The Orange Book defines security policy as a set of rules, regulations, and practices that govern the management, protection, and distribution of valuable information. In practice, security policy (SP) is interpreted somewhat more broadly as a set of documented administrative decisions aimed at ensuring the security of an information resource. The result of the policy is a high-level document that represents a systematic statement of goals, objectives, principles and methods for achieving information security.
This document presents the methodological basis for practical measures (procedures) for the implementation of IS and contains the following groups of information:
1. Basic provisions of information security.
2. Scope of application.
3. Goals and objectives of ensuring information security.
4. Distribution of roles and responsibilities.
5. General responsibilities.
The main provisions define the importance of IS, general security problems, directions for solving them, the role of employees, and the legal framework.
The scope of application of the security policy is the main assets and subsystems of the AS that are subject to protection. Typical assets are software, hardware and information support of the plant, personnel, and, in some cases, the information infrastructure of the enterprise.
Goals, objectives, IS criteria follow from the functional purpose of the enterprise. For example, for security organizations, confidentiality is a top priority. For real-time information services, it is important to ensure the availability (operational readiness) of subsystems. For information warehouses, ensuring data integrity, etc. may be relevant. Laws and organizational rules that should be taken into account when carrying out work on IS are indicated here.
188
Typical goals could be the following:
1) ensuring a level of security that complies with the regulatory
documents of the enterprise;
2) following economic feasibility in choosing protective measures;
3) ensuring an appropriate level of safety in specific functional areas
of the plant;
4) ensuring accountability of all user actions with information
resources and analysis of registration information, etc.
If the enterprise is not isolated, goals and objectives are considered in a broader context: issues of safe mutual influence of local and remote subsystems must be discussed.
The document under consideration may specify some strategic security principles (arising from the goals and objectives of IS). These are strategies for action in the event of a violation of the security policy of the enterprise and third-party organizations, interaction with external organizations, law enforcement agencies, the press, etc. As an example, two strategies for responding to a security violation can be cited:
1. “Track and Convict,” when the attacker is allowed to continue his actions with the goal of compromising him and punishing him (this strategy is approved by law enforcement agencies).
2. “Protect and continue” when the organization fears for the vulnerability of information resources and provides maximum resistance to the violation.
The security policy affects all computer users in the organization. Therefore, it is important to resolve the so-called political issues of vesting all categories of users with appropriate rights, privileges and responsibilities.
For this purpose, the circle of persons who have access to the subsystems and services of the AS is determined. For each category of user, the correct and incorrect ways to use resources are described what is prohibited and allowed. Here the levels and regulation of access of various user groups are specified. It should be indicated which of the default rules for the use of resources is accepted in the organization, namely:
• what is not expressly prohibited is permitted or
189
• what is not clearly permitted is prohibited.
One of the most vulnerable points in IS is the distribution of access rights. The security policy must approve a scheme for managing the distribution of access rights to services centralized, or decentralized, or otherwise. It must be clearly defined who has access rights to services and what rights they have. It is advisable to describe in detail the practical procedures for assigning rights to users. Here you should indicate officials who have administrative privileges and passwords for certain services.
The rights and obligations of users are determined in relation to the safe use of AS subsystems and services. When defining the rights and responsibilities of administrators, some balance should be sought between users right to privacy and the administrators responsibility to control security breaches.
An important element of policy is the distribution of responsibilities. Politics cannot provide for everything, but it must find someone responsible for each type of problem.
There are usually several levels of responsibility. At the first level, each user is obliged to work in accordance with the security policy (protect his account), obey the orders of those responsible for certain aspects of security, and notify management about all suspicious situations. System administrators are responsible for protecting the relevant information and computing subsystems. Network administrators must ensure the implementation of organizational and technical measures necessary to implement the AS security policy. Higher level department heads, who are responsible for communicating and monitoring the provisions of the security policy.
From a practical point of view, it is advisable to divide the security policy into several levels (usually two or three levels are distinguished).
The top level is general in nature and determines the policy of the organization as a whole. Here the focus is on: the procedure for creating and reviewing security policies; the goals pursued by the organization in the field of information security; issues of resource allocation and distribution; principles of technical policy in the field of selection of methods and means
190
of information security; coordinating security measures; strategic planning and control; external interactions and other issues of an organization-wide nature.
At this level, the main goals in the field of information security (determined by the field of activity of the enterprise) are formulated: ensuring confidentiality, integrity and/or availability [2]. Generally speaking, the minimum number of issues should be raised to the top level. Such a provision is advisable when it promises significant cost savings or when it is simply impossible to do otherwise.
The average level of security policy is allocated in case of structural complexity of the organization or if it is necessary to identify specific subsystems of the organization. This concerns the attitude towards promising, not yet sufficiently proven technologies. For example, the use of new Internet services, the organization of communications and information processing on home and laptop computers, the degree of compliance with the provisions of computer law, etc. In addition, at the average level of security policy, particularly significant contours of the organization’s AS can be identified, for example, those processing secret or critically important information. That is, the average level includes issues related to individual aspects of information security, but important for various systems operated by the organization.
The mid-level policy should cover the following topics for each aspect.
Description of the aspect. For example, if we consider the use of unofficial software by users, the latter can be defined as software that has not been approved and/or purchased at the organizational level.
Application area. It is necessary to determine where, when, how, to whom and to what this security policy applies.
The position of the organization on this aspect. Continuing the example with unofficial software, one can imagine the positions of a complete ban, the development of a procedure for accepting such software, etc. The position can be formulated in a much more general form as a set of goals that the organization pursues in this aspect.