Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

Information protection in digital communication systems. Textbook

.pdf
Скачиваний:
0
Добавлен:
07.09.2026
Размер:
2 Мб
Скачать
191
Roles and responsibilities. The “policy” document must include information about the officials responsible for implementing the security policy. For example, if employees need management permission to use unofficial software, it should be known from whom and how it can be obtained. If unofficial software cannot be used, you should know who is enforcing this rule.
Law-abiding. The policy should contain a general description of prohibited activities and the penalties for them.
Points of contact. It should be known where to go for clarification,
assistance and additional information. Typically, the “point of contact” is a
specific official, rather than a specific person currently occupying a given position.
The head of the security service, AS security administrators, and the corporate network administrator are responsible for the development and implementation of security policies at the upper and middle levels.
The lower level of security policy refers to specific services or departments of the organization and details the upper levels of security policy. This level is necessary when security issues of specific subsystems require solutions at the managerial, and not just at the technical level.
It is clear that at this level specific goals, criteria and indicators of information security are determined, the rights of specific user groups are determined, appropriate conditions for access to information are formulated, etc. Here, from specific goals, (usually formal) security rules are derived that describe who, what he can or cannot do and under what conditions. More detailed and formal rules will simplify the implementation of the system and configuration of IS tools.
At this level, information security mechanisms and the software and hardware used for their implementation are described (within the framework, of course, of the management level, but not the technical one).
System administrators are responsible for lower-level security policies.
192
British Standard BS 7799:1995 recommends that an organizations security policy document include the following sections:
1) an introductory section confirming the concern of senior
management with information security issues;
2) an organizational section containing a description of divisions, commissions, groups, etc., responsible for work in the field of information security;
3) classification, describing the material and information resources available in the organization and the required level of their protection;
4) standard, characterizing the security measures applied to personnel (description of positions from the point of view of information security, organization of training and retraining of personnel, procedure for responding to security violations, etc.);
5) section covering issues of physical protection;
6) control section describing the approach to managing computers and computer networks;
7) section describing the rules for restricting access to production information;
8) section characterizing the procedure for developing and maintaining systems;
9) section describing measures aimed at ensuring the continuous operation of the organization;
10) legal section confirming the compliance of the security policy with current legislation.
As part of developing a security policy, a risk analysis is carried out. This is done in order to minimize IS costs. The basic principle of security: the cost of protective equipment should not exceed the cost of the protected objects. Moreover, if the security policy is drawn up in the form of a high­level document describing the overall strategy, then the risk analysis (as an application) is drawn up in the form of a list of assets that need protection.
193
6.2.2. Risk analysis
Risk management (or analysis) is considered at the administrative level of information security, since only the management of the organization is able to allocate the necessary resources, initiate and control the implementation of relevant programs.
Risk management and development of one’s own safety precautions are relevant only for those organizations whose information systems and/or processed data can be considered non-standard. An ordinary organization will be quite satisfied with a standard set of protective measures, selected on the basis of an idea of typical risks or without any risk analysis at all (this is especially true from a formal point of view, in the light of the Russian legislation in the field of information security that we previously analyzed). An analogy can be drawn between individual construction and obtaining an apartment in a mass construction area. In the first case, it is necessary to make many decisions and draw up a large number of papers; in the second, it is enough to decide on only a few parameters.
The use of information systems is associated with a certain set of risks. When the potential damage is unacceptably great, economically feasible protective measures must be taken. Periodic risk assessment is necessary to monitor the effectiveness of security activities and to account for changes in the environment.
From a quantitative point of view, the level of risk is a function of the likelihood of a particular threat (exploiting some vulnerabilities) occurring, as well as the magnitude of possible damage.
Thus, the essence of risk management is to assess the size of the risk, develop effective and cost-effective risk mitigation measures, and then ensure that the risks are contained (and remain so) within acceptable limits. Consequently, risk management includes two types of activities that alternate cyclically:
1) risk assessment;
2) selection of effective and economical protective equipment
(neutralization of risks).
194
The following actions are possible in relation to the identified risks:
• risk elimination;
• risk reduction (through the use of additional protective equipment);
acceptance of risk (and development of a plan of action in
appropriate conditions);
risk transfer (for example, by concluding an insurance agreement).
The risk management process can be divided into several stages (Fig. 6.2).
Выбор анализируемых объектов и степени детализации
Выбор методологии оценки рисков
Идентификация активов
Анализ угроз и уязвимости защиты
Оценка рисков
Выбор защитных мер
Реализация и проверка выбранных мер
Оценка остаточного риска
Fig. 6.2. Risk analysis algorithm
The last two stages (implementation and verification of selected measures, residual risk assessment) relate to the selection of protective equipment (risk neutralization), the rest to risk assessment. Already listing the stages shows that risk management is a cyclical process. Essentially, the last step is an end-of-loop statement that instructs you to return to the beginning. Risks must be constantly monitored, periodically reassessed. Note that a conscientious and carefully documented first assessment can significantly simplify subsequent activities.
195
Preliminary stage of risk analysis. At the initial stage, general issues of risk analysis are resolved using the expert assessment method. The first step is to select the components of the AS and the degree of detail of their consideration. A comprehensive analysis requires consideration of the entire information infrastructure. But in practice, based on the principle of reasonable sufficiency, individual most important components and services can be isolated and subjected to greater detail, first of all, where the risks are high or unknown. New and modified AS components, as well as components where new incidents and security breaches have occurred, are subject to more thorough analysis.
Next, risk assessment methodologies are selected as the process of obtaining a quantitative or qualitative assessment of the damage that may occur in the event of threats to AS safety. Methodologies are of a private nature, inherent to the organization and the plant, and depend on a specific set of destabilizing factors and operating conditions of the plant, the possibility of their quantitative assessment, the degree of their inaccuracy, incompleteness, vagueness, etc. In practice, taking into account the acceptable approximate risk assessment, simple visual methods based on elements of probability theory and mathematical statistics.
Asset identification. The basis of the risk analysis process is the determination of what needs to be protected, from whom and how. To do this, assets (AS components) that need protection are identified. Below are the main categories of AS assets of the enterprise:
1. Hardware (computers, peripheral devices, communication lines,
network equipment and their components).
2. Software (source, object and boot modules of operating systems, auxiliary system and communication programs, development tools, application software packages).
3. Information support (input and processed, stored, transmitted and backup (safety copies) data and metadata).
4. Personnel (operators and users).
5. Documentation (design, technical, user and other documentation).
6. Consumables (paper, magnetic media, cartridges, etc.).
196
In some specific AS, assets unique to the organization can be separated into separate groups, for example: communication, algorithmic or linguistic support. In addition, parts of the infrastructure may be subject to protection, in particular power supply subsystems, etc.
The main outcome of the asset identification process is to obtain a detailed information structure of the organization and how the information will be used. Further stages of risk analysis are based precisely on this information recorded at a certain point in time.
Threat analysis. After identifying AS assets, all possible threats to these assets should be considered, risks assessed and ranked according to the degree of possible damage.
A threat is usually understood as any event (action) that could potentially damage the AS by violating the confidentiality, integrity or availability of information. Threats can be intentional, resulting from deliberate (malicious) actions of people, and unintentional, caused by human errors, or failures and errors of hardware and software, or natural actions. Currently, there are a huge number of threats that can lead to violation of the confidentiality, integrity and availability of information.
When analyzing threats, it is necessary to identify their sources and conditions for their implementation. This will help in choosing additional means of protection. Often, some threats can be a consequence or condition for the manifestation of a number of other threats. For example, unauthorized access (in various forms of its manifestation) to resources facilitates the implementation of almost any threat: from damage to magnetic media to a complex remote attack.
Risk assessment. Once a threat has been identified, it is necessary to assess the risk of the threat occurring. In most cases it is possible to obtain a quantitative risk assessment. It can be obtained on the basis of an expert survey, estimated statistically, or calculated using some mathematical relationship (adequate to a specific threat to a specific asset).
In addition to the probability of the threat being carried out, the size of the expected losses is important. In general, expected losses are calculated using the following formula:
197
E = P × V, (6.1)
where P a probabilistic assessment of the risk of a threat; V damage when the threat is realized.
However, both threat probabilities and expected losses cannot always be quantified. For example, it is quite simple to calculate the replacement of a computer, but it is difficult to assess the potential damage in the event of a delay in issuing data, distortion of information, disclosure of certain information, etc. Some incidents can damage the reputation of the company, cause social tension in the team, and lead to legal prosecution of the enterprise from outside users, etc.
There are several simple ways to assess the likelihood of threats and possible losses:
1. Expert assessment of events. Expert assessment methods are used to assess difficult-to-predict threats, such as natural disasters, and are the most inaccurate.
2. Methodology for determining the acceptability of the risk level on a three-point scale. According to the methodology, the assessed risks and damages are rated on a three-point scale: 1, 2, 3. The resulting two sets of risk and damage assessments are multiplied. The set of possible values will be as follows: 1, 2, 3, 4, 6, 9. It is assumed that the first two values characterize a low level of risk, the third and fourth medium, the last two high.
Methodology for determining the acceptability of the level of risk, taking into account the visibility of threats and their consequences. Here the concept of threat visibility to the outside world is introduced a measure of information about the system that is accessible to an attacker (and arouses unhealthy interest). According to this methodology, the assessed risks, visibility, physical damage and moral damage are rated on a three-point scale 1, 2, 3. The risk values are multiplied by the values for visibility, and the values for physical damage are multiplied by the values for moral damage. The resulting two numbers are then added together. The risk level
198
is considered low if the total number is less than 7, high if the total number is more than 11, otherwise medium.
Statistical assessment of events and the use of statistical models (reflecting the laws of distribution of specific types of threats). This method allows one to obtain acceptable results for assessing frequently detected threats, such as failures and failures of a computing process.
Use of analytical models (possibly in the form of tables) of potential damage depending on predetermined coefficients.
It should be noted that risk analysis methods are usually not highly accurate. The fact is that the main task of risk analysis (as a planning tool) is to assess the level of possible losses and the level of protection costs. For practice, when heterogeneous initial data have an approximate or subjective nature of assessment, high calculation accuracy is not required. Sometimes it is completely impossible to assess the accuracy of the result.
Selection and verification of protective measures. To reduce the amount of damage, it is necessary to select appropriate protective measures: organizational, physical, software and hardware, etc. Each threat can be prevented in various ways. Therefore, at this stage, the task of analyzing and synthesizing measures, methods and means of protection according to the efficiency/cost criterion is solved, taking into account, of course, the technical policy of the organization and other vital characteristics of the plant.
After selecting methods of protecting the AS, their effectiveness is checked. If residual risks have again become unacceptable, it is very reasonable to repeat the risk analysis steps.
Concluding this subsection, it should be noted that developing a security policy and conducting risk analysis are painstaking scientific and technical tasks. Therefore, it is important to choose the right development team. This is usually done professionally by the enterprise information security group. However, it is possible to involve administrators and developers of systems and networks, audit and management specialists, psychologists, and representatives of the regime service.
199
6.3. PROCEDURAL LEVEL
Main classes of procedural level measures
These safety measures are people-oriented. It is people who form the information security regime, and they also turn out to be the main threat, so the “human factor” deserves special attention.
Russian companies have accumulated a wealth of experience in regulating and implementing procedural (organizational) measures, but the fact is that they came from the “pre-computer” past, and therefore require re-evaluation.
It is necessary to realize the degree of dependence on computer data processing into which modern society has fallen. Without any exaggeration, we can say that informational civil defense is necessary. Calmly, without stirring up passions, it is necessary to explain to society not only the advantages, but also the dangers associated with the use of information technologies. The emphasis should not be on the military or criminal side of the matter, but on the civilian aspects associated with maintaining the normal functioning of hardware and software, that is, focusing on issues of data availability and integrity.
At the procedural level, the following classes of measures can be distinguished:
1) personnel management;
2) physical protection;
3) maintaining performance;
4) responding to security violations;
5) planning of restoration work.
Personnel Management
Human resource management begins with the hiring of a new employee and even earlier with the preparation of a job description.
200
Already at this stage, it is advisable to involve an information security specialist in the work to determine the computer privileges associated with the position. There are two general principles to keep in mind:
segregation of duties;
• minimization of privileges.
The principle of separation of duties prescribes the distribution of roles and responsibilities so that one person cannot disrupt a process critical to the organization. For example, it is undesirable for one person to make large payments on behalf of an organization. It is safer to instruct one employee to process applications for such payments, and another to certify these applications. Another example is procedural restrictions on superuser
actions. You can artificially “split” the superuser password by sharing the
first part of it with one employee and the second with another. Then they will be able to perform critical IS administration tasks only together, which reduces the likelihood of errors and abuse.
The principle of least privilege requires that users be given only those access rights that they need to perform their job responsibilities. The purpose of this principle is obvious to reduce damage from accidental or deliberate incorrect actions.
Preliminary preparation of a job description allows you to assess its criticality and plan the procedure for screening and selecting candidates. The more responsible the position, the more carefully you need to check candidates: make inquiries about them, perhaps talk with former colleagues, etc. Such a procedure can be lengthy and expensive, so there is no point in complicating it further. At the same time, it is unreasonable to completely refuse pre-screening in order to avoid accidentally hiring someone with a criminal record or mental illness. Once a candidate has been identified, he or she will likely need to undergo training; at the very least, he should be thoroughly familiarized with job responsibilities and information security regulations and procedures. It is advisable that he understand the security measures before taking office and before establishing his system account with login name, password and privileges.