Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

Information protection in digital communication systems. Textbook

.pdf
Скачиваний:
0
Добавлен:
07.09.2026
Размер:
2 Мб
Скачать
251
Classification section
This section describes the material and information resources available in the organization and the required level of their protection.
The elements described above can act as material resources. When projected onto an organization with an information network security model (Fig. 6.9), this list can take the form:
Hardware:
• computers;
• printers;
• scanners;
• faxes and telephones;
• communication lines;
• network equipment (network cards) and their components.
Software:
operating systems: Windows 2000, Server, NT, 98/95 (for
workstations);
• application programs: office applications (MS Word, MS Excel, ...),
databases (1C, MS Access, Oracle, ...), other (...);
mail protocols POP3, SMTP;
• network protocols: TCP/IP stack;
• security analysis system (Internet Scanner);
• IDS attack detection system, etc.
Information support (input and processed, stored, transmitted and backup (safety copies) data and metadata):
information about employees (personal information (full name, ...),
position held, rights of access to information, salary, ...);
• data about clients/partners;
• data on agreements/contracts with clients/partners;
• intermediate data (when processing any information);
• data on the system configuration, equipment and programs used, etc.
Staff:
• service personnel (IT administrators, security administrators);
252
• users (administration of the organization, top managers, economists,
lawyers, storekeepers, clients, ...).
Documentation (design, technical, user, ...).
Consumables:
paper;
• magnetic media;
• cartridges, etc.
Staff section
This section characterizes the security measures applied to personnel, in other words, these documents operate at the procedural level of information protection.
Standard documents:
1. Description of positions from an information security point of view.
2. Organization of training and retraining of personnel.
3. The procedure for responding to security violations, etc.
List of standard instructions:
1. Password protection rules.
2. Rules for protection against viruses and malicious software.
3. Physical access control requirements.
4. Requirements for physical protection of equipment.
5. Instructions for the safe destruction of information or equipment.
6. Instructions for workplace safety (documents on the desktop and on
the monitor screen).
7. Rules for remote access.
8. Rules for local access.
9. Requirements for backup information storage.
10. Requirements for monitoring and maintaining diagnostic log files.
11. Requirement to monitor access and use of systems and maintain
log files.
12. Requirements for handling data media.
13. Requirements for non-electronic information exchange.
253
14. Requirements for user registration.
15. Requirements for checking user rights.
16. Requirements for access control to the operating system.
17. Requirement for the log on procedure.
18. Rules for using system utilities.
19. Rules for remote work of mobile users.
The following requirements must be met:
1. The requirement to distribute responsibility when ensuring security.
2. Safety rules when selecting personnel.
3. Requirements for control of operational changes.
4. Requirements for checking input data.
5. Requirements for the use of cryptographic controls.
6. Requirements for monitoring operating system programs.
7. Requirements for controlling access to source codes of programs
and libraries.
8. Requirements for control of changes made.
9. Business continuity requirement.
10. Software copyright requirements.
11. Requirements for ensuring the safety of evidence.
12. Requirements for system audit management.
Instructions:
1. On hiring and admitting new employees to work in the AS and
providing them with the necessary powers to access system resources.
2. By dismissing employees and depriving them of their rights to
access the system.
3. On the actions of various categories of personnel, including employees of the information security department, to eliminate the consequences of crisis (emergency or emergency) situations if they occur.
4. Actions of personnel to eliminate the consequences of crisis (emergency or abnormal) situations in the event of their occurrence.
5. Incident control procedures.
254
CHAPTER 7. INFORMATION SYSTEM
SECURITY CONTROL4
7.1. REGULATORY FRAMEWORK FOR AUDIT
7.1.1. Review of legislation in the field of security auditing
The most significant regulatory documents in the field of information security, which define the criteria for assessing the security of the AS and the requirements for protection mechanisms, are:
1. The Common Criteria for Information Technology Security
Evaluation/ISO 15408;
2. Practical rules for information security management (Code of
practice for Information Security Management/ISO 17799).
In addition, in our country, the Guiding Documents (RD) of the State Technical Commission of Russia are of paramount importance. In other countries, their place is taken by the corresponding national standards (where they exist).
ISO 15408:
Common Criteria for Information Technology Security Evaluation
The most complete criteria for assessing security mechanisms at the software and hardware level are presented in the international standard ISO 15408: Common Criteria for Information Technology Security Evaluation, adopted in 1999.
“Common Criteria for assessing the security of information technologies” (hereinafter referred to as the “Common Criteria”) define security functional requirements and requirements for the adequacy of the implementation of security functions (security assurance requirements).
4
All figures in this chapter are taken from « Защита информации в цифровых системах
связи».
255
When carrying out work to analyze the security of the AS, as well as CE, it is advisable to use the “Common Criteria” as the main criteria that allow us to assess the level of security of the AS (CE) in terms of the completeness of the safety functions implemented in it and the reliability of the implementation of these functions.
Although the Common Criteria are limited in their applicability to software-level security mechanisms, they provide a specific set of requirements for organizational-level security mechanisms and physical security requirements that are directly related to the security functions described.
The first part of the “Common Criteria” contains a definition of general concepts, common concepts, a description of the model and methodology for assessing IT security. It introduces the conceptual apparatus and defines the principles of formalization of the subject area.
Requirements for the functionality of protective equipment are given in the second part of the “Common Criteria” and can be directly used in security analysis to assess the completeness of the security functions implemented in the AS (CE).
The third part of the “Common Criteria” contains classes of assessment assurance requirements, including a class of requirements for analyzing the vulnerabilities of security tools and mechanisms called AVA: Vulnerability Assessment. This class of requirements defines the methods that must be used to prevent, identify and eliminate the following types of vulnerabilities:
• presence of side channels of information leakage;
configuration errors or incorrect use of the system, leading to a
transition to an unsafe state;
insufficient reliability (robustness) of security mechanisms that
implement the corresponding security functions;
the presence of vulnerabilities (“holes”) in information security tools that enable users to obtain access to information bypassing existing security mechanisms.
256
The corresponding assessment assurance requirements are contained
in the following four families of requirements:
1. AVA_CCA family: Covert Channel Analysis.
2. AVA_MSU family: Misuse (errors in configuration or incorrect use of the system, leading to the system entering an unsafe state).
3. AVA_SOF family: Strength of TOE Security Functions (Strength of security functions provided by their implementation).
4. AVA_VLA family: Vulnerability Analysis.
When conducting security audits, the listed families of requirements
can be used as guidelines and criteria for analyzing AS vulnerabilities (CE).
ISO 17799:
Code of Practice for Information Security Management
The most complete criteria for assessing organizational level security mechanisms are presented in the international standard ISO 17799: Code of Practice for Information Security Management, adopted in 2000. ISO 17799 is nothing more than the international version of the British standard BS
7799.
ISO 17799 provides practical guidelines for information security management and can be used as criteria for assessing organizational level security controls, including administrative, procedural and physical controls (mentioned in the first section).
The rules of thumb are divided into the following 10 sections:
1. Security policy.
2. Organization of protection.
3. Classification of resources and their control.
4. Personnel safety.
5. Physical security.
6. Administration of computer systems and computer networks.
7. Access control.
8. Development and maintenance of information systems.
257
9. Planning the smooth operation of the organization.
10. Monitoring compliance with security policy requirements.
These sections describe the organizational-level security mechanisms currently implemented by government and commercial organizations in many countries around the world.
The ten controls proposed in ISO 17799 (identified as key controls) are considered particularly important. Controls in this context refer to mechanisms for managing an organizations information security.
Some controls, such as data encryption, may require a risk assessment to determine whether they are needed and how they should be implemented. To provide a higher level of protection for particularly valuable assets or to counter particularly serious security threats, stronger controls may be required in some cases that go beyond the scope of ISO 17799.
The ten key controls listed below are either mandatory requirements, such as legal requirements, or are considered fundamental building blocks of information security, such as security training. These controls are relevant for all organizations and AS operating environments and form the basis of the information security management system. They serve as primary guidance for organizations embarking on the implementation of information security controls.
The following controls are key:
1. Information security policy document.
2. Distribution of responsibilities for ensuring information security.
3. Training and preparation of personnel to maintain the information
security regime.
4. Notification of security breaches.
5. Virus protection.
6. Planning the smooth operation of the organization.
7. Control over copying of software protected by copyright law.
8. Protection of the organization’s documentation.
9. Data protection.
10. Monitoring compliance with security policy.
258
The AS safety audit procedure includes checking the presence of the listed key controls, assessing the completeness and correctness of their implementation, as well as analyzing their adequacy to the risks existing in the given operating environment. An integral part of the AS safety audit work also includes risk analysis and management.
RD State Technical Commission of Russia
In general, in our country, when solving problems of information security, compliance with the following decrees of the President, federal laws, decrees of the Government of the Russian Federation, RD of the State Technical Commission of Russia and other regulatory documents must be ensured (see also section 1):
Doctrine of information security of the Russian Federation (approved by Decree of the President of the Russian Federation of December 5, 2016 No. 646);
Decree of the President of the Russian Federation of March 6, 1997 No. 188 “On approval of the list of confidential information”;
• Federal Law “On Information, Information Technologies and Information Protection” dated July 27, 2006 No. 149-FZ;
• Federal Law “On Communications” dated July 7, 2003 No. 126-FZ;
Federal Law “On the introduction into force of part four of the Civil Code of the Russian Federation” dated December 18, 2006 No. 231-FZ;
• Federal Law “On Licensing of Certain Types of Activities” dated
May 4, 2011 No. 99-FZ;
Law of the Russian Federation “On State Secrets” dated July 21, 1993 No. 5485-I;
• GOST R 51583 “Information protection. Sequence of protected operational system formation. General provisions”;
• Guiding document “Regulations on the certification of
informatization objects according to information security requirements”
(State Technical Commission of Russia, 1994);
259
Guiding document “Automated systems. Protection against unauthorized access to information. Classification of automated systems and requirements for information protection (State Technical Commission of Russia, 1992);
Guiding document “Computer facilities. Protection against unauthorized access to information. Indicators of security against unauthorized access to information (State Technical Commission of Russia, 1992);
• Guiding document “Concept for protecting computer equipment and
automated systems from unauthorized access to information” (State
Technical Commission of Russia, 1992);
Guiding document “Protection against unauthorized access to information. Terms and definitions (State Technical Commission of Russia, 1992);
Guiding document “Temporary regulations on organizing the development, production and operation of software and hardware for protecting information from unauthorized access in automated systems and
computer equipment” (State Technical Commission of Russia, 1992);
• Guiding document “Computer facilities. Firewalls. Protection
against unauthorized access to information. Indicators of security against unauthorized access to information (State Technical Commission of Russia, 1997);
Guiding document “Protection against unauthorized access to information. Part 1. Information security software. Classification according to the level of control over the absence of undeclared capabilities” (State Technical Commission of Russia, 1999);
• Guiding document “Special requirements and recommendations for
the technical protection of confidential information” (State Technical
Commission of Russia, 2001).
The RDs of the State Technical Commission of Russia form the basis of the regulatory framework in the field of protection against unauthorized access to information in our country. The most significant of them are the defining criteria for assessing the security of the nuclear power plant (CE).
260
The criteria for assessing the protection mechanisms at the software and hardware level, used in the analysis of the security of AS and CE, are expressed in the RD of the State Technical Commission of the Russian Federation:
“AS. Protection from unauthorized access to information. Classification of AS and requirements for information protection and CE. Protection from unauthorized access to information. Indicators of security
from unauthorized access to information”;
• RD “CE. Protection from unauthorized access to information.
Indicators of security from unauthorized access to information. Establishes a classification of electronic equipment according to the level of security against unauthorized access to information based on a list of security indicators and a set of requirements describing them. (The main source for the development of this document was the American Orange Book). Seven classes of CE security from unauthorized access to information are established. The lowest class is seventh, the highest is first. The classes are divided into four groups, differing in the level of protection:
1. The first group contains only one seventh class, which includes all CE that do not meet the requirements of higher classes.
2. The second group is characterized by discretionary protection and contains the sixth and fifth grades.
3. The third group is characterized by mandatory protection and contains the fourth, third and second classes.
4. The fourth group is characterized by verified protection and contains only the first class;
• RD “AS. Protection from unauthorized access to information.
Classification of AS and requirements for information protection.”
Establishes a classification of automated systems subject to protection from unauthorized access to information, and requirements for the protection of information in automated systems of various classes. The defining characteristics by which speakers are grouped into various classes include:
- availability of information of various levels of confidentiality in the AS;