Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

Information protection in digital communication systems. Textbook

.pdf
Скачиваний:
0
Добавлен:
07.09.2026
Размер:
2 Мб
Скачать
261
- level of authority of AS access subjects to access confidential information;
- data processing mode in the AS collective or individual.
Nine classes of AS security from unauthorized access to information are established. Each class is characterized by a certain minimum set of protection requirements.
The classes are divided into three groups, differing in the characteristics of information processing in the AS. Within each group, a hierarchy of protection requirements is observed depending on the value and confidentiality of information and, consequently, a hierarchy of AS security classes;
RD “CE. Firewalls. Protection from unauthorized access to information. Indicators of security from unauthorized access to information. When analyzing the protection system for the external perimeter of a corporate network, it is advisable to use this document as the main criteria. It determines the indicators of firewall security. Each security indicator is a set of security requirements that characterize a specific area of firewall operation. There are five security indicators in total:
1) access control;
2) identification and authentication;
3) event registration and notification;
4) integrity control;
5) restoration of performance.
Based on security indicators, the following five firewall security
classes are determined:
1) the simplest filtering routers class 5;
2) network level packet filters class 4;
3) the simplest firewall of the application level class 3;
4) basic level firewall class 2;
5) advanced firewall class 1.
Firewalls of the first security class can be used in class 1A systems,
classes that process information of “special importance”. The second
262
security class of the firewall corresponds to security class AS 1B, intended for processing “top secret” information, etc. [3].
7.1.2. Auditing Standards
Association for Information Systems Audit and Control
Information Systems Audit and Control Association ISACA. The approach to conducting an IP audit as a separate independent service has been streamlined and standardized over time. Large and medium-sized audit companies have formed associations: unions of professionals in the field of IP auditing, which are engaged in the creation and maintenance of auditing standards in the IT field. As a rule, these are closed standards.
ISACA is committed to open standardization of IP auditing.
The ISACA association currently unites about 20 thousand members from more than 100 countries, including Russia. The association coordinates the activities of more than 12 000 information systems auditors.
The main declared purpose of the association is to research, develop, publish and promote a standardized set of information technology management documents for daily use by information systems administrators and auditors.
To help professional auditors, administrators and interested users, the ISACA association and attracted specialists from the world's leading consulting companies have developed the CoBiT standard.
CoBit. CoBiT (Control Objects of Information Technology) is an open standard whose first edition in 1996 was sold in 98 countries around the world and has made the work of professional information technology auditors easier. The standard connects information technologies and the actions of auditors, combines and harmonizes many other standards into a single resource that allows you to authoritatively, at a modern level, gain insight into and manage the goals and objectives solved by IS. CoBiT takes into account all the features of information systems of any scale and complexity.
263
The fundamental rule underlying CoBiT is that IS resources must be managed by a set of naturally grouped processes to provide the organization with the necessary and reliable information (Fig. 7.1).
Each of the elements shown in the block diagram is complex and includes the following components.
Resources: human resources, applications, technology, equipment, data. And now a little clarification about what resources and criteria for their evaluation are used in the CoBiT standard.
Labor resources labor resources mean not only the employees of the organization, but also the management of the organization and contract personnel. Staff skills, task understanding, and job performance are reviewed.
Ресурсы
Критерии оценки
Планирование и организация
Комплектация и внедрение
Функционирование и обслуживание
Мониторинг, управление, конструирование
Бизнес-задачи
CoBiT
Fig. 7.1. Structure of the CoBiT standard
Applications are application software used in the operation of an organization.
Technologies operating systems, databases, control systems, etc.
Equipment all hardware of the organizations IS, taking into account their maintenance.
Data — data in the broadest sense — external and internal, structured and unstructured, graphic, audio, multimedia, etc.
Evaluation criteria: effectiveness, technical level, safety, integrity, suitability, consistency, reliability.
264
All these resources are assessed by CoBiT at each stage of IS construction or audit according to the following criteria.
Efficiency a criterion that determines the relevance and compliance of information with business objectives.
Technical level a criterion for compliance with standards and instructions.
Security information protection.
Integrity accuracy and completeness of information.
Suitability the availability of information to required business processes in the present and future. As well as the protection of necessary and related resources.
Consistency the implementation of laws, instructions and agreements that affect the business process, that is, external requirements for the business.
Reliability the consistency of information provided to the organizations management, implementation of appropriate funding management and consistency of job responsibilities.
Planning and organization:
P01 Strategic development plan.
P02 IS architecture.
P03 Technological direction.
P04 Internal organizational structure and relationships.
P05 Investment management.
P06 Goals and objectives of management.
P07 Users and maintenance personnel.
P08 Legislative and regulatory acts.
P09 Risk accounting and analysis.
P010 Project management.
P011 Quality management.
Complete set and implementation:
A1 Technological solution.
A2 Application software.
A3 Infrastructure.
265
A4 Procedures.
A5 Installation and accreditation of IS.
A6 Performance assessment.
Operation and maintenance:
DS1 Levels of Service.
DS2 Third Party Services.
DS3 Performance and scalability.
DS4 Continuity of service.
DS5 Information security in IS.
DS6 Determination and accounting of costs.
DS7 User training.
DS8 Help and advice to service personnel.
DS9 Configuration of IS elements.
DS10 Problem and Incident Resolution.
DS11 Operation, transmission, storage and protection of data.
DS12 Operational safety.
DS13 Carrying out and documenting work.
Monitoring, management, control:
M1 Monitoring of ongoing processes.
M2 Adequacy of control.
M3 Control of independent service.
M4 Conducting an independent audit.
CoBiT is based on the ISA and ISACF auditing standards, but also includes other international standards, including taking into account previously approved standards and regulations:
• technical standards;
• codes;
• IP criteria and description of processes;
professional standards;
• requirements and recommendations;
requirements for banking services, e-commerce systems and
production.
266
The standard was developed and analyzed by employees of the relevant departments of leading consulting companies and is used in their work along with their own developments.
The use of the CoBiT standard is possible both for conducting an audit of an organization’s IS and for the initial design of an IS. The usual version of direct and inverse problems. If in the first case it is the compliance of the current state of the IS with the best practice of similar organizations and enterprises, then in the other it is an initially correct project and, as a consequence, upon completion of the design, an IS striving for the ideal.
Despite its small size, the developers tried to ensure that the standard was pragmatic and responsive to business needs, while maintaining independence from specific manufacturers, technologies and platforms.
The basic block diagram of CoBiT shows the sequence, composition and relationships of the basic groups. Business processes (at the top of the diagram) place their requirements on IS resources, which are analyzed using the CoBiT assessment criteria at all stages of construction and audit.
Four basic groups (domains) contain thirty-four subgroups, which, in turn, consist of three hundred and two control objects. Objects of control provide the auditor with all reliable and relevant information about the current state of the IS.
Distinctive features of CoBiT:
1. Large coverage area (all tasks from strategic planning and fundamental documents to analysis of the operation of individual IS elements).
2. Cross-audit (overlapping areas of inspection of critical elements).
3. Adaptable, scalable standard.
4. The standard is easily scaled and expanded. CoBiT allows you to use any developments from hardware and software manufacturers and analyze the data obtained without changing the general approaches and its own structure.
267
Requirements for submission of information
The ISACA Association has developed and adopted requirements for the presentation of information during an audit. The application of the CoBiT standard guarantees compliance with these requirements.
The main requirement: usefulness of information. For information to be useful, it must have certain characteristics, including:
1. Clarity. Information should be understandable to a user who has a certain level of knowledge, which does not mean, however, that complex information should be excluded if it is necessary.
2. Relevance. Information is relevant or relevant if it influences users decisions and helps them evaluate past, present, future events or confirm and correct past assessments. The relevance of information is influenced by its content and materiality. Information is material if its absence or incorrect assessment could influence the users decision. Another characteristic of relevance is the timeliness of information, which means that all relevant information is included in the report in a timely manner without delay and that the report is provided on time. A certain analogue of the principle of appropriateness in Russian practice can be the requirement for the complete reflection of transactions for the accounting period, although the requirement for the reflection of all information is not identical to the requirement for the reflection of essential information.
3. Credibility, reliability. Information is reliable if it does not contain significant errors or biased assessments and truthfully reflects business activities. To be reliable, information must meet the following characteristics:
• truthfulness;
• neutrality: information should not contain one-sided assessments,
that is, information should not be provided selectively in order to achieve a certain result;
• prudence: readiness to take into account potential losses rather than
potential profits and, as a result, the creation of reserves; this approach is
268
appropriate in a state of uncertainty and does not mean the creation of hidden reserves or distortion of information;
sufficiency of information: includes such a characteristic as the requirement for completeness of information in terms of both its materiality and the costs of its preparation.
Information Security Assessment Standards
based on the “Common Criteria
The project “Common Criteria” became the basis for the “Common Criteria for Assessing Information Technology Security” and is not only technical, but also economic and political in nature. Its purpose is, in particular, to simplify, reduce the cost and speed up the path of certified information technology products to the world market.
This goal is close and understandable to Russian specialists. In 2014, GOST R ISO/IEC 15408-2-2013 “Information technology. Security techniques. Evaluation criteria for IT security. Part 2. Security functional components)” was officially published. Thus, Russia actually lives according to the “Common Criteria” with all the consequences arising from this fact.
According to the approach adopted in the “Common Criteria”, based on security assumptions, taking into account threats and security policy provisions, security goals are formulated for the object being assessed. To achieve them, security requirements are imposed on the object and its environment.
Common Criteria” in its main part is a catalog (library) of safety requirements. The range of standardized requirements is extremely wide, which contributes to the universality of CC. A high level of detail makes them specific, allowing for unambiguous verification, and contributes to the repeatability of assessment results. The requirements are parameterized, making them flexible.
The “Common Criteria contain two main types of safety requirements:
269
1) functional, corresponding to the active aspect of protection, required for the security functions of the object being assessed and the mechanisms that implement them;
2) trust requirements corresponding to the passive aspect, imposed on the technology and process of development and operation of the object being assessed.
The library of functional requirements constitutes the second part of the “Common Criteria”, and the catalog of assurance requirements constitutes the third part (the first contains a statement of the main concepts of CC).
In addition, general requirements for security services are highlighted. One of the most important types of functional requirements is security audit analysis (FAU_SAA).
Of the components of the FAU class “Security Audit” that are essential
for an active audit, the “Common Criteria” lacks analysis for compliance
with the security policy (threshold, statistical and signature analyzes are provided in the FAU_SAA family), storage for descriptions of controlled objects and for analyzed information, as well as all interface Components.
Two new components are proposed to be included in the FAU_GEN (Security Audit Data Generation) family:
FAU_GEN.3 association of the object, the operation with which caused the event, with the inclusion of the name (identifier) of this object in the registration records. At the minimum level, the opening/closing of an object (connection establishment/breakdown, etc.) should be logged; at the basic level, all intermediate operations should be logged. At a granular level, the registration records must include all operands of an operation on an object. The FAU_GEN.3 component was added for two reasons. First, symmetry must be maintained between subjects and objects. Secondly, it is advisable to build statistical profiles not for subjects, but for objects, but for this you need to have the appropriate information.
FAU_GEN.4 is intended to ensure that a service using the services of the FAU_GEN family does not refuse to register an event.
270
The standard component FAU_SAR.3 makes it possible to search and sort registration information by specifying logical expressions as criteria.
Similar expressions are also useful for specifying filters that control the operation of sensors.
Automatic analysis of registration information to identify suspicious activity is presented in the “Common Criteria” by four components of the FAU_SAA family.
FAU_SAA.1 is focused on detecting exceedance of thresholds defined by a fixed set of rules.
FAU_SAA.2 serves to identify atypical activity by analyzing behavior profiles. The “Common Criteria” suggests subject profiles, although object profiles may be preferable. The “Common Criteria” allows for both real­time and post-facto analysis. Support for real-time analysis should be considered the most important differentiating feature of active auditing tools.
FAU_SAA.3 aims to detect simple attacks by performing signature analysis.
FAU_SAA.4 allows you to detect complex, multi-stage attacks carried out by a group of attackers. All four components can be customized by adding, modifying, or removing rules, monitored subjects, and signatures.
Another component, FAU_SAA.5, is introduced to detect security policy violations. It is proposed to set policies using first-order predicates.
In terms of automatic response to suspicious activity, the “Common Criteria”, in fact, limited themselves to stating such a possibility. The decisive element, which, after receiving recommendations from the analysis components, determines whether suspicious activity is actually occurring and, if necessary, responds appropriately (choosing the form of response depending on the severity of the detected violations).
This means that the solver (decisive element) must be able to:
• rank suspicious activity;
• react in accordance with the rank of the violation.
Both aspects must be managed by the security administrator.