Добавил:
ivanov666
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз:
Предмет:
Файл:Information protection in digital communication systems. Textbook
.pdf
261
- level of authority of AS access subjects to access confidential
information;
- data processing mode in the AS — collective or individual.
Nine classes of AS security from unauthorized access to information
are established. Each class is characterized by a certain minimum set of
protection requirements.
The classes are divided into three groups, differing in the
characteristics of information processing in the AS. Within each group, a
hierarchy of protection requirements is observed depending on the value and
confidentiality of information and, consequently, a hierarchy of AS security
classes;
• RD “CE. Firewalls. Protection from unauthorized access to
information. Indicators of security from unauthorized access to
information.” When analyzing the protection system for the external
perimeter of a corporate network, it is advisable to use this document as the
main criteria. It determines the indicators of firewall security. Each security
indicator is a set of security requirements that characterize a specific area of
firewall operation. There are five security indicators in total:
1) access control;
2) identification and authentication;
3) event registration and notification;
4) integrity control;
5) restoration of performance.
Based on security indicators, the following five firewall security
classes are determined:
1) the simplest filtering routers — class 5;
2) network level packet filters — class 4;
3) the simplest firewall of the application level — class 3;
4) basic level firewall — class 2;
5) advanced firewall — class 1.
Firewalls of the first security class can be used in class 1A systems,
classes that process information of “special importance”. The second

262
security class of the firewall corresponds to security class AS 1B, intended
for processing “top secret” information, etc. [3].
7.1.2. Auditing Standards
Association for Information Systems Audit and Control
Information Systems Audit and Control Association — ISACA. The
approach to conducting an IP audit as a separate independent service has
been streamlined and standardized over time. Large and medium-sized audit
companies have formed associations: unions of professionals in the field of
IP auditing, which are engaged in the creation and maintenance of auditing
standards in the IT field. As a rule, these are closed standards.
ISACA is committed to open standardization of IP auditing.
The ISACA association currently unites about 20 thousand members
from more than 100 countries, including Russia. The association
coordinates the activities of more than 12 000 information systems auditors.
The main declared purpose of the association is to research, develop,
publish and promote a standardized set of information technology
management documents for daily use by information systems administrators
and auditors.
To help professional auditors, administrators and interested users, the
ISACA association and attracted specialists from the world's leading
consulting companies have developed the CoBiT standard.
CoBit. CoBiT (Control Objects of Information Technology) is an open
standard whose first edition in 1996 was sold in 98 countries around the
world and has made the work of professional information technology
auditors easier. The standard connects information technologies and the
actions of auditors, combines and harmonizes many other standards into a
single resource that allows you to authoritatively, at a modern level, gain
insight into and manage the goals and objectives solved by IS. CoBiT takes
into account all the features of information systems of any scale and
complexity.

263
The fundamental rule underlying CoBiT is that IS resources must be
managed by a set of naturally grouped processes to provide the organization
with the necessary and reliable information (Fig. 7.1).
Each of the elements shown in the block diagram is complex and
includes the following components.
Resources: human resources, applications, technology, equipment,
data. And now a little clarification about what resources and criteria for their
evaluation are used in the CoBiT standard.
Labor resources — labor resources mean not only the employees of
the organization, but also the management of the organization and contract
personnel. Staff skills, task understanding, and job performance are
reviewed.
Ресурсы
Критерии оценки
Планирование и организация
Комплектация и внедрение
Функционирование и обслуживание
Мониторинг, управление, конструирование
Бизнес-задачи
CoBiT
Fig. 7.1. Structure of the CoBiT standard
Applications are application software used in the operation of an
organization.
Technologies — operating systems, databases, control systems, etc.
Equipment — all hardware of the organization’s IS, taking into
account their maintenance.
Data — data in the broadest sense — external and internal, structured
and unstructured, graphic, audio, multimedia, etc.
Evaluation criteria: effectiveness, technical level, safety, integrity,
suitability, consistency, reliability.

264
All these resources are assessed by CoBiT at each stage of IS
construction or audit according to the following criteria.
Efficiency — a criterion that determines the relevance and compliance
of information with business objectives.
Technical level — a criterion for compliance with standards and
instructions.
Security — information protection.
Integrity — accuracy and completeness of information.
Suitability — the availability of information to required business
processes in the present and future. As well as the protection of necessary
and related resources.
Consistency — the implementation of laws, instructions and
agreements that affect the business process, that is, external requirements
for the business.
Reliability — the consistency of information provided to the
organization’s management, implementation of appropriate funding
management and consistency of job responsibilities.
Planning and organization:
P01 Strategic development plan.
P02 IS architecture.
P03 Technological direction.
P04 Internal organizational structure and relationships.
P05 Investment management.
P06 Goals and objectives of management.
P07 Users and maintenance personnel.
P08 Legislative and regulatory acts.
P09 Risk accounting and analysis.
P010 Project management.
P011 Quality management.
Complete set and implementation:
A1 Technological solution.
A2 Application software.
A3 Infrastructure.

265
A4 Procedures.
A5 Installation and accreditation of IS.
A6 Performance assessment.
Operation and maintenance:
DS1 Levels of Service.
DS2 Third Party Services.
DS3 Performance and scalability.
DS4 Continuity of service.
DS5 Information security in IS.
DS6 Determination and accounting of costs.
DS7 User training.
DS8 Help and advice to service personnel.
DS9 Configuration of IS elements.
DS10 Problem and Incident Resolution.
DS11 Operation, transmission, storage and protection of data.
DS12 Operational safety.
DS13 Carrying out and documenting work.
Monitoring, management, control:
M1 Monitoring of ongoing processes.
M2 Adequacy of control.
M3 Control of independent service.
M4 Conducting an independent audit.
CoBiT is based on the ISA and ISACF auditing standards, but also
includes other international standards, including taking into account
previously approved standards and regulations:
• technical standards;
• codes;
• IP criteria and description of processes;
• professional standards;
• requirements and recommendations;
• requirements for banking services, e-commerce systems and
production.

266
The standard was developed and analyzed by employees of the
relevant departments of leading consulting companies and is used in their
work along with their own developments.
The use of the CoBiT standard is possible both for conducting an audit
of an organization’s IS and for the initial design of an IS. The usual version
of direct and inverse problems. If in the first case it is the compliance of the
current state of the IS with the best practice of similar organizations and
enterprises, then in the other it is an initially correct project and, as a
consequence, upon completion of the design, an IS striving for the ideal.
Despite its small size, the developers tried to ensure that the standard
was pragmatic and responsive to business needs, while maintaining
independence from specific manufacturers, technologies and platforms.
The basic block diagram of CoBiT shows the sequence, composition
and relationships of the basic groups. Business processes (at the top of the
diagram) place their requirements on IS resources, which are analyzed using
the CoBiT assessment criteria at all stages of construction and audit.
Four basic groups (domains) contain thirty-four subgroups, which, in
turn, consist of three hundred and two control objects. Objects of control
provide the auditor with all reliable and relevant information about the
current state of the IS.
Distinctive features of CoBiT:
1. Large coverage area (all tasks from strategic planning and
fundamental documents to analysis of the operation of individual IS
elements).
2. Cross-audit (overlapping areas of inspection of critical elements).
3. Adaptable, scalable standard.
4. The standard is easily scaled and expanded. CoBiT allows you to
use any developments from hardware and software manufacturers and
analyze the data obtained without changing the general approaches and its
own structure.

267
Requirements for submission of information
The ISACA Association has developed and adopted requirements for
the presentation of information during an audit. The application of the
CoBiT standard guarantees compliance with these requirements.
The main requirement: usefulness of information. For information to
be useful, it must have certain characteristics, including:
1. Clarity. Information should be understandable to a user who has a
certain level of knowledge, which does not mean, however, that complex
information should be excluded if it is necessary.
2. Relevance. Information is relevant or relevant if it influences users’
decisions and helps them evaluate past, present, future events or confirm
and correct past assessments. The relevance of information is influenced by
its content and materiality. Information is material if its absence or incorrect
assessment could influence the user’s decision. Another characteristic of
relevance is the timeliness of information, which means that all relevant
information is included in the report in a timely manner without delay and
that the report is provided on time. A certain analogue of the principle of
appropriateness in Russian practice can be the requirement for the complete
reflection of transactions for the accounting period, although the
requirement for the reflection of all information is not identical to the
requirement for the reflection of essential information.
3. Credibility, reliability. Information is reliable if it does not contain
significant errors or biased assessments and truthfully reflects business
activities. To be reliable, information must meet the following
characteristics:
• truthfulness;
• neutrality: information should not contain one-sided assessments,
that is, information should not be provided selectively in order to achieve a
certain result;
• prudence: readiness to take into account potential losses rather than
potential profits and, as a result, the creation of reserves; this approach is

268
appropriate in a state of uncertainty and does not mean the creation of hidden
reserves or distortion of information;
• sufficiency of information: includes such a characteristic as the
requirement for completeness of information in terms of both its materiality
and the costs of its preparation.
Information Security Assessment Standards
based on the “Common Criteria”
The project “Common Criteria” became the basis for the “Common
Criteria for Assessing Information Technology Security” and is not only
technical, but also economic and political in nature. Its purpose is, in
particular, to simplify, reduce the cost and speed up the path of certified
information technology products to the world market.
This goal is close and understandable to Russian specialists. In 2014,
GOST R ISO/IEC 15408-2-2013 “Information technology. Security
techniques. Evaluation criteria for IT security. Part 2. Security functional
components)” was officially published. Thus, Russia actually lives
according to the “Common Criteria” with all the consequences arising from
this fact.
According to the approach adopted in the “Common Criteria”, based
on security assumptions, taking into account threats and security policy
provisions, security goals are formulated for the object being assessed. To
achieve them, security requirements are imposed on the object and its
environment.
“Common Criteria” in its main part is a catalog (library) of safety
requirements. The range of standardized requirements is extremely wide,
which contributes to the universality of CC. A high level of detail makes
them specific, allowing for unambiguous verification, and contributes to the
repeatability of assessment results. The requirements are parameterized,
making them flexible.
The “Common Criteria” contain two main types of safety
requirements:

269
1) functional, corresponding to the active aspect of protection,
required for the security functions of the object being assessed and the
mechanisms that implement them;
2) trust requirements corresponding to the passive aspect, imposed on
the technology and process of development and operation of the object being
assessed.
The library of functional requirements constitutes the second part of
the “Common Criteria”, and the catalog of assurance requirements
constitutes the third part (the first contains a statement of the main concepts
of CC).
In addition, general requirements for security services are highlighted.
One of the most important types of functional requirements is security audit
analysis (FAU_SAA).
Of the components of the FAU class “Security Audit” that are essential
for an active audit, the “Common Criteria” lacks analysis for compliance
with the security policy (threshold, statistical and signature analyzes are
provided in the FAU_SAA family), storage for descriptions of controlled
objects and for analyzed information, as well as all interface Components.
Two new components are proposed to be included in the FAU_GEN
(Security Audit Data Generation) family:
FAU_GEN.3 — association of the object, the operation with which
caused the event, with the inclusion of the name (identifier) of this object in
the registration records. At the minimum level, the opening/closing of an
object (connection establishment/breakdown, etc.) should be logged; at the
basic level, all intermediate operations should be logged. At a granular level,
the registration records must include all operands of an operation on an
object. The FAU_GEN.3 component was added for two reasons. First,
symmetry must be maintained between subjects and objects. Secondly, it is
advisable to build statistical profiles not for subjects, but for objects, but for
this you need to have the appropriate information.
FAU_GEN.4 is intended to ensure that a service using the services of
the FAU_GEN family does not refuse to register an event.

270
The standard component FAU_SAR.3 makes it possible to search and
sort registration information by specifying logical expressions as criteria.
Similar expressions are also useful for specifying filters that control
the operation of sensors.
Automatic analysis of registration information to identify suspicious
activity is presented in the “Common Criteria” by four components of the
FAU_SAA family.
FAU_SAA.1 is focused on detecting exceedance of thresholds defined
by a fixed set of rules.
FAU_SAA.2 serves to identify atypical activity by analyzing behavior
profiles. The “Common Criteria” suggests subject profiles, although object
profiles may be preferable. The “Common Criteria” allows for both realtime and post-facto analysis. Support for real-time analysis should be
considered the most important differentiating feature of active auditing
tools.
FAU_SAA.3 aims to detect simple attacks by performing signature
analysis.
FAU_SAA.4 allows you to detect complex, multi-stage attacks carried
out by a group of attackers. All four components can be customized by
adding, modifying, or removing rules, monitored subjects, and signatures.
Another component, FAU_SAA.5, is introduced to detect security
policy violations. It is proposed to set policies using first-order predicates.
In terms of automatic response to suspicious activity, the “Common
Criteria”, in fact, limited themselves to stating such a possibility. The
decisive element, which, after receiving recommendations from the analysis
components, determines whether suspicious activity is actually occurring
and, if necessary, responds appropriately (choosing the form of response
depending on the severity of the detected violations).
This means that the solver (decisive element) must be able to:
• rank suspicious activity;
• react in accordance with the rank of the violation.
Both aspects must be managed by the security administrator.
Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]
