Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

Information protection in digital communication systems. Textbook

.pdf
Скачиваний:
0
Добавлен:
07.09.2026
Размер:
2 Мб
Скачать
281
6.3.1. Turnkey preparation of the enterprise for certification of the
customer’s informatization objects for compliance with the requirements of
the Russian Federation.
6.3.2. Preparing an enterprise for CIS certification for compliance with the security requirements of international standards ISO 15408, ISO 17799, ISO 9001 standard while ensuring the information security requirements of the enterprise.
6.4. Development of organizational, administrative and technological documentation.
6.4.1. Development of an expanded list of restricted information as part of the security policy.
6.4.2. Development of a package of organizational and administrative documentation (OAD) in accordance with the recommendations of the
enterprise’s corporate information security policy at the organizational,
managerial and legal levels.
6.4.3. Supply of a set of standard organizational and administrative documentation in accordance with the recommendations of the corporate information security policy of the enterprise at the organizational, managerial and legal levels.
7. Advanced training and retraining of specialists.
Trainings in the field of organizational and legal components of information security.
• Training in the basics of economic security.
• Trainings in the field of information security technology.
Trainings on the use of information security products (technical
means).
Training in actions to take when attempting to hack information systems.
Education and training on restoring the system after a disruption in its normal operation, as well as on restoring data and programs from backup copies.
Maintenance of the information security system after a comprehensive analysis or analysis of the elements of the enterprises information security system.
282
Annual reassessment of the information security state
Here, the term information security audit of a corporate Internet/Intranet system is understood as a systemic process of obtaining objective qualitative and quantitative assessments of the current state of a
company’s information security in accordance with certain security criteria
and indicators at all main levels of security: methodological, organizational, managerial, technological and technical. Such assessments that allow us to develop practical recommendations for managing and ensuring the
company’s information security that are adequate to the set goals and
objectives of business development.
In general, regardless of its type, composition and volume, a security audit of a corporate Internet/Intranet system should allow solving the following urgent problems of each company being audited:
1) ensure (if necessary increase) the information security of the
enterprise;
2) reduce potential losses of the enterprise by increasing the stability
of the corporate network;
3) protect confidential information transmitted over open
communication channels;
4) protect information from intentional distortion (destruction),
unauthorized copying, access or use;
5) ensure control of user actions in the corporate network of the
enterprise;
6) timely assess and reassess the information risks of the company’s
business activities;
7) develop optimal plans for the development and management of the
enterprise.
Planning an authorized audit of a company’s information security
In accordance with the recommendations of international information security standards, the procedure for conducting a company security audit should be planned in advance. To do this, it is necessary to draw up an audit
283
plan, which should reflect all activities and procedures associated with initial and follow-up audits lasting more than one day. In addition, it is necessary to familiarize yourself with the relevant legislative and regulatory framework to identify information security requirements that can be used to ensure the company's information security.
To conduct an information security audit, a company must prepare all the necessary information about its own structure, business activities, current projects, the state of the information infrastructure, etc. In addition, you will need:
• documented concept and company security policy;
• list of system and application software used in the company;
• description of data processing technology;
• composition and structure of the information security subsystem;
• general map of the company’s computer network.
The audit plan should determine the audited areas of the companys activities and the time of their audit, indicating which specific requirements of international standards, for example ISO 17799, and the governing documents of the State Technical Commission of the Russian Federation will be audited. That is, the plan for preparing and conducting an audit should determine the company’s needs for assessing and objectively analyzing the state of information security, the need for appropriate hardware and software for information security, the need for training and retraining of the information security service, as well as highlight other questions that cannot be answered without an audit. In the future, the audit plan with changes made to it during the audits is attached to the audit report. In addition, it is necessary to remember to coordinate the audit plan with the Concept and Information Security Policy of the company.
It is recommended to distinguish four possible stages of audit
planning:
1. Preparation of a security audit.
2. Analysis of requirements and source data.
3. Calculation of labor intensity and cost of work performed.
4. Documentation of the audit procedure.
284
Preparatory stage. At this stage, the contractor determines the general order of work, establishing the sequence of execution and possible resource costs, and coordinates it with the customer. At this stage the following are considered:
purpose and goals of the upcoming audit, the procedure for achieving
them;
• principles for establishing the audit framework;
functions, structure and composition of the corporate
Internet/Intranet system, bottlenecks and potential vulnerabilities in the information security management system;
methods for assessing the qualifications of specialists and employees
of the information security service;
methods of categorizing information processed in a corporate information system, for example, into public, confidential and strictly confidential;
methods and tools for estimating the time and resource costs of a company for an information security audit. The ability to use the results of a previously conducted audit, including analysis of information risks and analysis of compliance with the requirements of international standards and governing documents of the State Technical Commission of the Russian Federation;
composition of a group of experts in the field of security of corporate Internet/Intranet systems and distribution of responsibilities between them;
parameters of the companys corporate information network and its operating environment, which have a significant impact on the quality of the security audit;
a set of requirements of international, state, interdepartmental and internal standards taken into account when conducting a safety audit;
internal reporting documentation, preparation and, if necessary, adjustment of the company’s information security concept and policy;
prospects and trends in the development of the companys corporate
information security system, issues of developing strategies and tactics for its development.
285
The general procedure for conducting a company security audit, agreed upon with the customer, can be reflected in the corresponding technical specifications.
Stage of analysis of requirements and source data. This stage forms a major part of audit planning. The analysis process considers:
information security requirements. The purpose of the audit is to
objectively and quickly evaluate and verify the compliance of the
company’s corporate security system under investigation with the
information security requirements imposed on it. Therefore, for such an assessment it is necessary to first consider information security requirements. The main information security requirements for domestic enterprises and companies are the requirements of the governing documents of the State Technical Commission of the Russian Federation, laws of the Russian Federation, intradepartmental, interdepartmental, national and international standards. In addition, for each corporate information system it is necessary to take into account special requirements for internal use, consistent with the companys security concept and policy. It is recommended to formulate such internal requirements based on the results
of an analysis of the company’s information risks, taking into account the
specifics of a particular company;
initial data for the audit. The guiding document of the State
Technical Commission “Regulations on the certification of informatization objects according to information security requirements” provides a standard
list of initial data necessary for the development of a program and methodology for certification tests. In addition to standard source data, additional source data specific to each specific company can be used, for
example, statistics of violations of the company’s security policy, statistics
of external and internal attacks, vulnerabilities of the most critical corporate information resources, etc. It should also be taken into account that, as a rule, Company management has its own views on the information provided as input for a security audit. Therefore, it is recommended to conclude a special confidentiality agreement or a corresponding letter of intent between the customer and the information security audit performer;
286
scope of the audit. When determining the scope of the audit, it is necessary to equally take into account the organizational, technological and software and hardware levels of information security. Otherwise, the audit results will not objectively reflect the real level of information security of the company. For example, expensive hardware and software information security tools may be useless if measures and measures at the organizational and technological levels are incorrectly defined and implemented. When determining the scope of the audit, it is necessary to record the standard operating conditions of the companys corporate information security
system. Such recording can be reflected in the “Certificate of Compliance” or “Company Passport” and is a necessary condition for ensuring the
required level of information security of the company and developing action plans in the event of abnormal operating conditions of the corporate Internet/Intranet system;
areas of detailed study. When conducting an audit, the main attention should be paid to the components and subsystems that process confidential company information. At the same time, it is necessary to be able to calculate the possible damage that could be caused to the company in the event of disclosure of confidential information and violation of the Security Policy. This should be reflected in the relevant company documents regulating its information security policy. To determine possible damage, a variety of formal methods, such as expert assessment methods, can be used. The initial data for making a decision on areas of detailed study can be the results of a previously conducted, ongoing comprehensive security audit of
the company, the results of an analysis of the company’s information risks
and other data. In addition, if necessary, vulnerabilities can be additionally examined by special instrumental checks using so-called scanners and systems for checking the level of security;
required level of detail and completeness. In most cases, to obtain adequate results, it is enough to conduct a basic analysis of the corporate information security system, which allows us to determine the overall level of information security of the company and check it for compliance with certain security requirements. In some cases, it is additionally required to
287
conduct a detailed analysis, the purpose of which is to quantify the level of information security of the company based on special quantitative metrics and information security measures. To do this, first all the necessary quantitative indicators are determined, and then the level of information security of the company is assessed. It is important that in this case it
becomes possible to compare the company’s security level with a certain
standard, determine trends and prospects for the development of the corporate security system, necessary investments, etc.
Stage of calculating labor intensity and cost. At the stage of calculating the labor intensity and cost of the work carried out, based on the analysis performed, the time, financial, technical, information and other resources necessary for the information security audit are assessed. It is recommended to allocate resources taking into account possible emergency situations that could increase the complexity of a security audit.
Stage of formalization and documentation. Audit planning ends with the formalization and documentation of the audit, which first of all implies the preparation and approval of an audit plan. The audit plan generally includes the following sections:
1. Brief description of the work. Includes all necessary information
about the work procedure.
2. Introduction. The relevance of conducting a security audit, features and requirements for the procedure for conducting an audit, characteristics of the object under study, the scope of the audit, the general procedure, requirements for recording the results of the audit are indicated. Additionally, information is provided on the categorization of corporate information, such as confidential and strictly confidential. The main tasks to be solved, restrictions, functions performed and criteria for assessing the level of information security of the company, the requirements of regulatory documents of the Russian Federation, international standards and internal requirements of the company are also listed.
3. Distribution of responsibilities. The staff and functional responsibilities of the group of specialists who will conduct the security audit are determined.
288
4. Information security requirements. A reasonable choice of information security requirements is recorded, criteria and indicators for
assessing the company’s information security are determined, and
quantitative metrics and security measures are selected. In addition to the regulatory and legislative framework of the Russian Federation, it is additionally recommended to use the requirements of international and internal company standards that are relevant for each individual company. It is recommended to evaluate investments in modernizing the corporate information security system based on the results of an analysis of the company’s information risks.
5. Formalization of assessments of the company’s security level. Qualitative and quantitative parameters are determined to obtain objective assessments of the company’s information security level. The tasks performed when conducting basic and detailed information risk analysis are listed. The scope of tasks depends on what stage of the life cycle the security of the corporate Internet/Intranet system is at: the design stage, operation stage, etc. This section reflects the company’s critical information resources, an assessment of the economic efficiency of its activities, the models used, methods, and audit tools security, initial data.
6. Work schedule. The deadlines, calendar plan of work performed, completion time, forms of reporting documents, requirements for acceptance and delivery of work, etc. are determined.
7. Support and support. The requirements for administrative, technological and technical support for an information security audit are listed.
8. Reporting documents. The main reporting documents are a report on the results of a security audit, an information security concept and policy, and a company protection plan.
9. Applications. The appendices contain inspection protocols, as well as information on audit methods and tools, identified comments, recommendations, etc.
289
7.2.3. Security analysis technique [2]
Currently, there are no standardized methods for analyzing the security of AS, therefore, in specific situations, the algorithms of actions of auditors may vary significantly. However, it is still possible to propose a standard methodology for analyzing the security of a corporate network. And although this technique does not claim to be universal, its effectiveness has been repeatedly tested in practice.
A typical methodology for analyzing the security of a corporate network includes the use of the following methods:
1. Study of initial data on AS.
2. Assessment of risks associated with the implementation of security
threats in relation to AS resources.
3. Analysis of security mechanisms at the organizational level, the
organization’s security policy and organizational and administrative
documentation to ensure the information security regime and assessment of their compliance with the requirements of existing regulatory documents, as well as their adequacy to existing risks.
4. Manual analysis of configuration files of routers, firewalls and proxy servers that manage internetwork interactions, mail and DNS servers, as well as other critical elements of the network infrastructure.
5. Scanning external LAN network addresses from the Internet.
6. Scanning LAN resources from the inside.
7. Analysis of the configuration of servers and LAN workstations using specialized software.
Initial data on the examined AS
In accordance with the requirements of the State Technical Commission RD, when carrying out work on AS safety certification, including a preliminary examination and analysis of the security of the informatization object, the customer of the work must provide the following initial data:
290
1. Full and exact name of the informatization object and its purpose.
2. The nature (scientific, technical, economic, industrial, financial, military, political) of information and the level of secrecy (confidentiality) of the processed information are determined in accordance with which lists (state, industry, departmental, enterprise).
3. Organizational structure of the informatization object.
4. List of premises, composition of the complex of technical means (main and auxiliary) included in the informatization object, in which (on which) the specified information is processed.
5. Features and layout of the informatization object indicating the boundaries of the controlled area.
6. The structure of the software (general system and application) used on the certified information object and intended for processing protected information, the information exchange protocols used.
7. General functional diagram of an informatization object, including a diagram of information flows and modes of processing protected information.
8. The presence and nature of interaction with other objects of informatization.
9. Composition and structure of the information security system at the certified informatization object.
10. List of hardware and software in a protected design, protection and control means used at the certified information technology object and having the appropriate certificate and instructions for operation.
11. Information about the developers of the information security system, whether third-party developers (in relation to the enterprise where the certified information technology object is located) have licenses to carry out such work.
12. Availability at the informatization facility (at the enterprise where the informatization facility is located) of an information security service and an administrator service (automated system, network, databases).