Добавил:
ivanov666
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз:
Предмет:
Файл:Information protection in digital communication systems. Textbook
.pdf
191
Roles and responsibilities. The “policy” document must include
information about the officials responsible for implementing the security
policy. For example, if employees need management permission to use
unofficial software, it should be known from whom and how it can be
obtained. If unofficial software cannot be used, you should know who is
enforcing this rule.
Law-abiding. The policy should contain a general description of
prohibited activities and the penalties for them.
Points of contact. It should be known where to go for clarification,
assistance and additional information. Typically, the “point of contact” is a
specific official, rather than a specific person currently occupying a given
position.
The head of the security service, AS security administrators, and the
corporate network administrator are responsible for the development and
implementation of security policies at the upper and middle levels.
The lower level of security policy refers to specific services or
departments of the organization and details the upper levels of security
policy. This level is necessary when security issues of specific subsystems
require solutions at the managerial, and not just at the technical level.
It is clear that at this level specific goals, criteria and indicators of
information security are determined, the rights of specific user groups are
determined, appropriate conditions for access to information are formulated,
etc. Here, from specific goals, (usually formal) security rules are derived
that describe who, what he can or cannot do and under what conditions.
More detailed and formal rules will simplify the implementation of the
system and configuration of IS tools.
At this level, information security mechanisms and the software and
hardware used for their implementation are described (within the
framework, of course, of the management level, but not the technical one).
System administrators are responsible for lower-level security
policies.

192
British Standard BS 7799:1995 recommends that an organization’s
security policy document include the following sections:
1) an introductory section confirming the concern of senior
management with information security issues;
2) an organizational section containing a description of divisions,
commissions, groups, etc., responsible for work in the field of information
security;
3) classification, describing the material and information resources
available in the organization and the required level of their protection;
4) standard, characterizing the security measures applied to personnel
(description of positions from the point of view of information security,
organization of training and retraining of personnel, procedure for
responding to security violations, etc.);
5) section covering issues of physical protection;
6) control section describing the approach to managing computers and
computer networks;
7) section describing the rules for restricting access to production
information;
8) section characterizing the procedure for developing and
maintaining systems;
9) section describing measures aimed at ensuring the continuous
operation of the organization;
10) legal section confirming the compliance of the security policy with
current legislation.
As part of developing a security policy, a risk analysis is carried out.
This is done in order to minimize IS costs. The basic principle of security:
the cost of protective equipment should not exceed the cost of the protected
objects. Moreover, if the security policy is drawn up in the form of a highlevel document describing the overall strategy, then the risk analysis (as an
application) is drawn up in the form of a list of assets that need protection.

193
6.2.2. Risk analysis
Risk management (or analysis) is considered at the administrative level
of information security, since only the management of the organization is
able to allocate the necessary resources, initiate and control the
implementation of relevant programs.
Risk management and development of one’s own safety precautions
are relevant only for those organizations whose information systems and/or
processed data can be considered non-standard. An ordinary organization
will be quite satisfied with a standard set of protective measures, selected
on the basis of an idea of typical risks or without any risk analysis at all (this
is especially true from a formal point of view, in the light of the Russian
legislation in the field of information security that we previously analyzed).
An analogy can be drawn between individual construction and obtaining an
apartment in a mass construction area. In the first case, it is necessary to
make many decisions and draw up a large number of papers; in the second,
it is enough to decide on only a few parameters.
The use of information systems is associated with a certain set of risks.
When the potential damage is unacceptably great, economically feasible
protective measures must be taken. Periodic risk assessment is necessary to
monitor the effectiveness of security activities and to account for changes in
the environment.
From a quantitative point of view, the level of risk is a function of the
likelihood of a particular threat (exploiting some vulnerabilities) occurring,
as well as the magnitude of possible damage.
Thus, the essence of risk management is to assess the size of the risk,
develop effective and cost-effective risk mitigation measures, and then
ensure that the risks are contained (and remain so) within acceptable limits.
Consequently, risk management includes two types of activities that
alternate cyclically:
1) risk assessment;
2) selection of effective and economical protective equipment
(neutralization of risks).

194
The following actions are possible in relation to the identified risks:
• risk elimination;
• risk reduction (through the use of additional protective equipment);
• acceptance of risk (and development of a plan of action in
appropriate conditions);
• risk transfer (for example, by concluding an insurance agreement).
The risk management process can be divided into several stages
(Fig. 6.2).
Выбор анализируемых объектов и степени детализации
Выбор методологии оценки рисков
Идентификация активов
Анализ угроз и уязвимости защиты
Оценка рисков
Выбор защитных мер
Реализация и проверка выбранных мер
Оценка остаточного риска
Fig. 6.2. Risk analysis algorithm
The last two stages (implementation and verification of selected
measures, residual risk assessment) relate to the selection of protective
equipment (risk neutralization), the rest — to risk assessment. Already
listing the stages shows that risk management is a cyclical process.
Essentially, the last step is an end-of-loop statement that instructs you to
return to the beginning. Risks must be constantly monitored, periodically
reassessed. Note that a conscientious and carefully documented first
assessment can significantly simplify subsequent activities.

195
Preliminary stage of risk analysis. At the initial stage, general issues
of risk analysis are resolved using the expert assessment method. The first
step is to select the components of the AS and the degree of detail of their
consideration. A comprehensive analysis requires consideration of the entire
information infrastructure. But in practice, based on the principle of
reasonable sufficiency, individual most important components and services
can be isolated and subjected to greater detail, first of all, where the risks
are high or unknown. New and modified AS components, as well as
components where new incidents and security breaches have occurred, are
subject to more thorough analysis.
Next, risk assessment methodologies are selected as the process of
obtaining a quantitative or qualitative assessment of the damage that may
occur in the event of threats to AS safety. Methodologies are of a private
nature, inherent to the organization and the plant, and depend on a specific
set of destabilizing factors and operating conditions of the plant, the
possibility of their quantitative assessment, the degree of their inaccuracy,
incompleteness, vagueness, etc. In practice, taking into account the
acceptable approximate risk assessment, simple visual methods based on
elements of probability theory and mathematical statistics.
Asset identification. The basis of the risk analysis process is the
determination of what needs to be protected, from whom and how. To do
this, assets (AS components) that need protection are identified. Below are
the main categories of AS assets of the enterprise:
1. Hardware (computers, peripheral devices, communication lines,
network equipment and their components).
2. Software (source, object and boot modules of operating systems,
auxiliary system and communication programs, development tools,
application software packages).
3. Information support (input and processed, stored, transmitted and
backup (safety copies) data and metadata).
4. Personnel (operators and users).
5. Documentation (design, technical, user and other documentation).
6. Consumables (paper, magnetic media, cartridges, etc.).

196
In some specific AS, assets unique to the organization can be separated
into separate groups, for example: communication, algorithmic or linguistic
support. In addition, parts of the infrastructure may be subject to protection,
in particular power supply subsystems, etc.
The main outcome of the asset identification process is to obtain a
detailed information structure of the organization and how the information
will be used. Further stages of risk analysis are based precisely on this
information recorded at a certain point in time.
Threat analysis. After identifying AS assets, all possible threats to
these assets should be considered, risks assessed and ranked according to
the degree of possible damage.
A threat is usually understood as any event (action) that could
potentially damage the AS by violating the confidentiality, integrity or
availability of information. Threats can be intentional, resulting from
deliberate (malicious) actions of people, and unintentional, caused by
human errors, or failures and errors of hardware and software, or natural
actions. Currently, there are a huge number of threats that can lead to
violation of the confidentiality, integrity and availability of information.
When analyzing threats, it is necessary to identify their sources and
conditions for their implementation. This will help in choosing additional
means of protection. Often, some threats can be a consequence or condition
for the manifestation of a number of other threats. For example,
unauthorized access (in various forms of its manifestation) to resources
facilitates the implementation of almost any threat: from damage to
magnetic media to a complex remote attack.
Risk assessment. Once a threat has been identified, it is necessary to
assess the risk of the threat occurring. In most cases it is possible to obtain
a quantitative risk assessment. It can be obtained on the basis of an expert
survey, estimated statistically, or calculated using some mathematical
relationship (adequate to a specific threat to a specific asset).
In addition to the probability of the threat being carried out, the size of
the expected losses is important. In general, expected losses are calculated
using the following formula:

197
E = P × V, (6.1)
where P — a probabilistic assessment of the risk of a threat; V — damage
when the threat is realized.
However, both threat probabilities and expected losses cannot always
be quantified. For example, it is quite simple to calculate the replacement of
a computer, but it is difficult to assess the potential damage in the event of
a delay in issuing data, distortion of information, disclosure of certain
information, etc. Some incidents can damage the reputation of the company,
cause social tension in the team, and lead to legal prosecution of the
enterprise from outside users, etc.
There are several simple ways to assess the likelihood of threats and
possible losses:
1. Expert assessment of events. Expert assessment methods are used
to assess difficult-to-predict threats, such as natural disasters, and are the
most inaccurate.
2. Methodology for determining the acceptability of the risk level on
a three-point scale. According to the methodology, the assessed risks and
damages are rated on a three-point scale: 1, 2, 3. The resulting two sets of
risk and damage assessments are multiplied. The set of possible values will
be as follows: 1, 2, 3, 4, 6, 9. It is assumed that the first two values
characterize a low level of risk, the third and fourth — medium, the last
two — high.
Methodology for determining the acceptability of the level of risk,
taking into account the visibility of threats and their consequences. Here the
concept of threat visibility to the outside world is introduced — a measure
of information about the system that is accessible to an attacker (and arouses
unhealthy interest). According to this methodology, the assessed risks,
visibility, physical damage and moral damage are rated on a three-point
scale — 1, 2, 3. The risk values are multiplied by the values for visibility,
and the values for physical damage are multiplied by the values for moral
damage. The resulting two numbers are then added together. The risk level

198
is considered low if the total number is less than 7, high if the total number
is more than 11, otherwise — medium.
Statistical assessment of events and the use of statistical models
(reflecting the laws of distribution of specific types of threats). This method
allows one to obtain acceptable results for assessing frequently detected
threats, such as failures and failures of a computing process.
Use of analytical models (possibly in the form of tables) of potential
damage depending on predetermined coefficients.
It should be noted that risk analysis methods are usually not highly
accurate. The fact is that the main task of risk analysis (as a planning tool)
is to assess the level of possible losses and the level of protection costs. For
practice, when heterogeneous initial data have an approximate or subjective
nature of assessment, high calculation accuracy is not required. Sometimes
it is completely impossible to assess the accuracy of the result.
Selection and verification of protective measures. To reduce the
amount of damage, it is necessary to select appropriate protective measures:
organizational, physical, software and hardware, etc. Each threat can be
prevented in various ways. Therefore, at this stage, the task of analyzing and
synthesizing measures, methods and means of protection according to the
efficiency/cost criterion is solved, taking into account, of course, the
technical policy of the organization and other vital characteristics of the
plant.
After selecting methods of protecting the AS, their effectiveness is
checked. If residual risks have again become unacceptable, it is very
reasonable to repeat the risk analysis steps.
Concluding this subsection, it should be noted that developing a
security policy and conducting risk analysis are painstaking scientific and
technical tasks. Therefore, it is important to choose the right development
team. This is usually done professionally by the enterprise information
security group. However, it is possible to involve administrators and
developers of systems and networks, audit and management specialists,
psychologists, and representatives of the regime service.

199
6.3. PROCEDURAL LEVEL
Main classes of procedural level measures
These safety measures are people-oriented. It is people who form the
information security regime, and they also turn out to be the main threat, so
the “human factor” deserves special attention.
Russian companies have accumulated a wealth of experience in
regulating and implementing procedural (organizational) measures, but the
fact is that they came from the “pre-computer” past, and therefore require
re-evaluation.
It is necessary to realize the degree of dependence on computer data
processing into which modern society has fallen. Without any exaggeration,
we can say that informational civil defense is necessary. Calmly, without
stirring up passions, it is necessary to explain to society not only the
advantages, but also the dangers associated with the use of information
technologies. The emphasis should not be on the military or criminal side of
the matter, but on the civilian aspects associated with maintaining the
normal functioning of hardware and software, that is, focusing on issues of
data availability and integrity.
At the procedural level, the following classes of measures can be
distinguished:
1) personnel management;
2) physical protection;
3) maintaining performance;
4) responding to security violations;
5) planning of restoration work.
Personnel Management
Human resource management begins with the hiring of a new
employee and even earlier — with the preparation of a job description.

200
Already at this stage, it is advisable to involve an information security
specialist in the work to determine the computer privileges associated with
the position. There are two general principles to keep in mind:
• segregation of duties;
• minimization of privileges.
The principle of separation of duties prescribes the distribution of roles
and responsibilities so that one person cannot disrupt a process critical to
the organization. For example, it is undesirable for one person to make large
payments on behalf of an organization. It is safer to instruct one employee
to process applications for such payments, and another to certify these
applications. Another example is procedural restrictions on superuser
actions. You can artificially “split” the superuser password by sharing the
first part of it with one employee and the second with another. Then they
will be able to perform critical IS administration tasks only together, which
reduces the likelihood of errors and abuse.
The principle of least privilege requires that users be given only those
access rights that they need to perform their job responsibilities. The
purpose of this principle is obvious — to reduce damage from accidental or
deliberate incorrect actions.
Preliminary preparation of a job description allows you to assess its
criticality and plan the procedure for screening and selecting candidates. The
more responsible the position, the more carefully you need to check
candidates: make inquiries about them, perhaps talk with former colleagues,
etc. Such a procedure can be lengthy and expensive, so there is no point in
complicating it further. At the same time, it is unreasonable to completely
refuse pre-screening in order to avoid accidentally hiring someone with a
criminal record or mental illness. Once a candidate has been identified, he
or she will likely need to undergo training; at the very least, he should be
thoroughly familiarized with job responsibilities and information security
regulations and procedures. It is advisable that he understand the security
measures before taking office and before establishing his system account
with login name, password and privileges.
Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]
