Добавил:
ivanov666
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз:
Предмет:
Файл:Information protection in digital communication systems. Textbook
.pdf
251
Classification section
This section describes the material and information resources available
in the organization and the required level of their protection.
The elements described above can act as material resources. When
projected onto an organization with an information network security model
(Fig. 6.9), this list can take the form:
Hardware:
• computers;
• printers;
• scanners;
• faxes and telephones;
• communication lines;
• network equipment (network cards) and their components.
Software:
• operating systems: Windows 2000, Server, NT, 98/95 (for
workstations);
• application programs: office applications (MS Word, MS Excel, ...),
databases (1C, MS Access, Oracle, ...), other (...);
• mail protocols POP3, SMTP;
• network protocols: TCP/IP stack;
• security analysis system (Internet Scanner);
• IDS attack detection system, etc.
Information support (input and processed, stored, transmitted and
backup (safety copies) data and metadata):
• information about employees (personal information (full name, ...),
position held, rights of access to information, salary, ...);
• data about clients/partners;
• data on agreements/contracts with clients/partners;
• intermediate data (when processing any information);
• data on the system configuration, equipment and programs used, etc.
Staff:
• service personnel (IT administrators, security administrators);

252
• users (administration of the organization, top managers, economists,
lawyers, storekeepers, clients, ...).
Documentation (design, technical, user, ...).
Consumables:
• paper;
• magnetic media;
• cartridges, etc.
Staff section
This section characterizes the security measures applied to personnel,
in other words, these documents operate at the procedural level of
information protection.
Standard documents:
1. Description of positions from an information security point of view.
2. Organization of training and retraining of personnel.
3. The procedure for responding to security violations, etc.
List of standard instructions:
1. Password protection rules.
2. Rules for protection against viruses and malicious software.
3. Physical access control requirements.
4. Requirements for physical protection of equipment.
5. Instructions for the safe destruction of information or equipment.
6. Instructions for workplace safety (documents on the desktop and on
the monitor screen).
7. Rules for remote access.
8. Rules for local access.
9. Requirements for backup information storage.
10. Requirements for monitoring and maintaining diagnostic log files.
11. Requirement to monitor access and use of systems and maintain
log files.
12. Requirements for handling data media.
13. Requirements for non-electronic information exchange.

253
14. Requirements for user registration.
15. Requirements for checking user rights.
16. Requirements for access control to the operating system.
17. Requirement for the log on procedure.
18. Rules for using system utilities.
19. Rules for remote work of mobile users.
The following requirements must be met:
1. The requirement to distribute responsibility when ensuring security.
2. Safety rules when selecting personnel.
3. Requirements for control of operational changes.
4. Requirements for checking input data.
5. Requirements for the use of cryptographic controls.
6. Requirements for monitoring operating system programs.
7. Requirements for controlling access to source codes of programs
and libraries.
8. Requirements for control of changes made.
9. Business continuity requirement.
10. Software copyright requirements.
11. Requirements for ensuring the safety of evidence.
12. Requirements for system audit management.
Instructions:
1. On hiring and admitting new employees to work in the AS and
providing them with the necessary powers to access system resources.
2. By dismissing employees and depriving them of their rights to
access the system.
3. On the actions of various categories of personnel, including
employees of the information security department, to eliminate the
consequences of crisis (emergency or emergency) situations if they occur.
4. Actions of personnel to eliminate the consequences of crisis
(emergency or abnormal) situations in the event of their occurrence.
5. Incident control procedures.

254
CHAPTER 7. INFORMATION SYSTEM
SECURITY CONTROL4
7.1. REGULATORY FRAMEWORK FOR AUDIT
7.1.1. Review of legislation in the field of security auditing
The most significant regulatory documents in the field of information
security, which define the criteria for assessing the security of the AS and
the requirements for protection mechanisms, are:
1. The Common Criteria for Information Technology Security
Evaluation/ISO 15408;
2. Practical rules for information security management (Code of
practice for Information Security Management/ISO 17799).
In addition, in our country, the Guiding Documents (RD) of the State
Technical Commission of Russia are of paramount importance. In other
countries, their place is taken by the corresponding national standards
(where they exist).
ISO 15408:
Common Criteria for Information Technology Security Evaluation
The most complete criteria for assessing security mechanisms at the
software and hardware level are presented in the international standard ISO
15408: Common Criteria for Information Technology Security Evaluation,
adopted in 1999.
“Common Criteria for assessing the security of information
technologies” (hereinafter referred to as the “Common Criteria”) define
security functional requirements and requirements for the adequacy of the
implementation of security functions (security assurance requirements).
4
All figures in this chapter are taken from « Защита информации в цифровых системах
связи».

255
When carrying out work to analyze the security of the AS, as well as
CE, it is advisable to use the “Common Criteria” as the main criteria that
allow us to assess the level of security of the AS (CE) in terms of the
completeness of the safety functions implemented in it and the reliability of
the implementation of these functions.
Although the Common Criteria are limited in their applicability to
software-level security mechanisms, they provide a specific set of
requirements for organizational-level security mechanisms and physical
security requirements that are directly related to the security functions
described.
The first part of the “Common Criteria” contains a definition of
general concepts, common concepts, a description of the model and
methodology for assessing IT security. It introduces the conceptual
apparatus and defines the principles of formalization of the subject area.
Requirements for the functionality of protective equipment are given
in the second part of the “Common Criteria” and can be directly used in
security analysis to assess the completeness of the security functions
implemented in the AS (CE).
The third part of the “Common Criteria” contains classes of
assessment assurance requirements, including a class of requirements for
analyzing the vulnerabilities of security tools and mechanisms called AVA:
Vulnerability Assessment. This class of requirements defines the methods
that must be used to prevent, identify and eliminate the following types of
vulnerabilities:
• presence of side channels of information leakage;
• configuration errors or incorrect use of the system, leading to a
transition to an unsafe state;
• insufficient reliability (robustness) of security mechanisms that
implement the corresponding security functions;
• the presence of vulnerabilities (“holes”) in information security tools
that enable users to obtain access to information bypassing existing security
mechanisms.

256
The corresponding assessment assurance requirements are contained
in the following four families of requirements:
1. AVA_CCA family: Covert Channel Analysis.
2. AVA_MSU family: Misuse (errors in configuration or incorrect use
of the system, leading to the system entering an unsafe state).
3. AVA_SOF family: Strength of TOE Security Functions (Strength
of security functions provided by their implementation).
4. AVA_VLA family: Vulnerability Analysis.
When conducting security audits, the listed families of requirements
can be used as guidelines and criteria for analyzing AS vulnerabilities (CE).
ISO 17799:
Code of Practice for Information Security Management
The most complete criteria for assessing organizational level security
mechanisms are presented in the international standard ISO 17799: Code of
Practice for Information Security Management, adopted in 2000. ISO 17799
is nothing more than the international version of the British standard BS
7799.
ISO 17799 provides practical guidelines for information security
management and can be used as criteria for assessing organizational level
security controls, including administrative, procedural and physical controls
(mentioned in the first section).
The rules of thumb are divided into the following 10 sections:
1. Security policy.
2. Organization of protection.
3. Classification of resources and their control.
4. Personnel safety.
5. Physical security.
6. Administration of computer systems and computer networks.
7. Access control.
8. Development and maintenance of information systems.

257
9. Planning the smooth operation of the organization.
10. Monitoring compliance with security policy requirements.
These sections describe the organizational-level security mechanisms
currently implemented by government and commercial organizations in
many countries around the world.
The ten controls proposed in ISO 17799 (identified as key controls)
are considered particularly important. Controls in this context refer to
mechanisms for managing an organization’s information security.
Some controls, such as data encryption, may require a risk assessment
to determine whether they are needed and how they should be implemented.
To provide a higher level of protection for particularly valuable assets or to
counter particularly serious security threats, stronger controls may be
required in some cases that go beyond the scope of ISO 17799.
The ten key controls listed below are either mandatory requirements,
such as legal requirements, or are considered fundamental building blocks
of information security, such as security training. These controls are relevant
for all organizations and AS operating environments and form the basis of
the information security management system. They serve as primary
guidance for organizations embarking on the implementation of information
security controls.
The following controls are key:
1. Information security policy document.
2. Distribution of responsibilities for ensuring information security.
3. Training and preparation of personnel to maintain the information
security regime.
4. Notification of security breaches.
5. Virus protection.
6. Planning the smooth operation of the organization.
7. Control over copying of software protected by copyright law.
8. Protection of the organization’s documentation.
9. Data protection.
10. Monitoring compliance with security policy.

258
The AS safety audit procedure includes checking the presence of the
listed key controls, assessing the completeness and correctness of their
implementation, as well as analyzing their adequacy to the risks existing in
the given operating environment. An integral part of the AS safety audit
work also includes risk analysis and management.
RD State Technical Commission of Russia
In general, in our country, when solving problems of information
security, compliance with the following decrees of the President, federal
laws, decrees of the Government of the Russian Federation, RD of the State
Technical Commission of Russia and other regulatory documents must be
ensured (see also section 1):
• Doctrine of information security of the Russian Federation (approved
by Decree of the President of the Russian Federation of December 5, 2016
No. 646);
• Decree of the President of the Russian Federation of March 6, 1997
No. 188 “On approval of the list of confidential information”;
• Federal Law “On Information, Information Technologies and
Information Protection” dated July 27, 2006 No. 149-FZ;
• Federal Law “On Communications” dated July 7, 2003 No. 126-FZ;
• Federal Law “On the introduction into force of part four of the Civil
Code of the Russian Federation” dated December 18, 2006 No. 231-FZ;
• Federal Law “On Licensing of Certain Types of Activities” dated
May 4, 2011 No. 99-FZ;
• Law of the Russian Federation “On State Secrets” dated July 21,
1993 No. 5485-I;
• GOST R 51583 “Information protection. Sequence of protected
operational system formation. General provisions”;
• Guiding document “Regulations on the certification of
informatization objects according to information security requirements”
(State Technical Commission of Russia, 1994);

259
• Guiding document “Automated systems. Protection against
unauthorized access to information. Classification of automated systems
and requirements for information protection” (State Technical Commission
of Russia, 1992);
• Guiding document “Computer facilities. Protection against
unauthorized access to information. Indicators of security against
unauthorized access to information” (State Technical Commission of
Russia, 1992);
• Guiding document “Concept for protecting computer equipment and
automated systems from unauthorized access to information” (State
Technical Commission of Russia, 1992);
• Guiding document “Protection against unauthorized access to
information. Terms and definitions” (State Technical Commission of
Russia, 1992);
• Guiding document “Temporary regulations on organizing the
development, production and operation of software and hardware for
protecting information from unauthorized access in automated systems and
computer equipment” (State Technical Commission of Russia, 1992);
• Guiding document “Computer facilities. Firewalls. Protection
against unauthorized access to information. Indicators of security against
unauthorized access to information” (State Technical Commission of
Russia, 1997);
• Guiding document “Protection against unauthorized access to
information. Part 1. Information security software. Classification according
to the level of control over the absence of undeclared capabilities” (State
Technical Commission of Russia, 1999);
• Guiding document “Special requirements and recommendations for
the technical protection of confidential information” (State Technical
Commission of Russia, 2001).
The RDs of the State Technical Commission of Russia form the basis
of the regulatory framework in the field of protection against unauthorized
access to information in our country. The most significant of them are the
defining criteria for assessing the security of the nuclear power plant (CE).

260
The criteria for assessing the protection mechanisms at the software
and hardware level, used in the analysis of the security of AS and CE, are
expressed in the RD of the State Technical Commission of the Russian
Federation:
• “AS. Protection from unauthorized access to information.
Classification of AS and requirements for information protection” and “CE.
Protection from unauthorized access to information. Indicators of security
from unauthorized access to information”;
• RD “CE. Protection from unauthorized access to information.
Indicators of security from unauthorized access to information.” Establishes
a classification of electronic equipment according to the level of security
against unauthorized access to information based on a list of security
indicators and a set of requirements describing them. (The main source for
the development of this document was the American Orange Book). Seven
classes of CE security from unauthorized access to information are
established. The lowest class is seventh, the highest is first. The classes are
divided into four groups, differing in the level of protection:
1. The first group contains only one seventh class, which includes all
CE that do not meet the requirements of higher classes.
2. The second group is characterized by discretionary protection and
contains the sixth and fifth grades.
3. The third group is characterized by mandatory protection and
contains the fourth, third and second classes.
4. The fourth group is characterized by verified protection and
contains only the first class;
• RD “AS. Protection from unauthorized access to information.
Classification of AS and requirements for information protection.”
Establishes a classification of automated systems subject to protection from
unauthorized access to information, and requirements for the protection of
information in automated systems of various classes. The defining
characteristics by which speakers are grouped into various classes include:
- availability of information of various levels of confidentiality
in the AS;
Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]
