Добавил:
ivanov666
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз:
Предмет:
Файл:Information protection in digital communication systems. Textbook
.pdf
281
6.3.1. Turnkey preparation of the enterprise for certification of the
customer’s informatization objects for compliance with the requirements of
the Russian Federation.
6.3.2. Preparing an enterprise for CIS certification for compliance with
the security requirements of international standards ISO 15408, ISO 17799,
ISO 9001 standard while ensuring the information security requirements of
the enterprise.
6.4. Development of organizational, administrative and technological
documentation.
6.4.1. Development of an expanded list of restricted information as
part of the security policy.
6.4.2. Development of a package of organizational and administrative
documentation (OAD) in accordance with the recommendations of the
enterprise’s corporate information security policy at the organizational,
managerial and legal levels.
6.4.3. Supply of a set of standard organizational and administrative
documentation in accordance with the recommendations of the corporate
information security policy of the enterprise at the organizational,
managerial and legal levels.
7. Advanced training and retraining of specialists.
• Trainings in the field of organizational and legal components of
information security.
• Training in the basics of economic security.
• Trainings in the field of information security technology.
• Trainings on the use of information security products (technical
means).
• Training in actions to take when attempting to hack information
systems.
• Education and training on restoring the system after a disruption in
its normal operation, as well as on restoring data and programs from
backup copies.
• Maintenance of the information security system after a
comprehensive analysis or analysis of the elements of the enterprise’s
information security system.

282
Annual reassessment of the information security state
Here, the term information security audit of a corporate
Internet/Intranet system is understood as a systemic process of obtaining
objective qualitative and quantitative assessments of the current state of a
company’s information security in accordance with certain security criteria
and indicators at all main levels of security: methodological, organizational,
managerial, technological and technical. Such assessments that allow us to
develop practical recommendations for managing and ensuring the
company’s information security that are adequate to the set goals and
objectives of business development.
In general, regardless of its type, composition and volume, a security
audit of a corporate Internet/Intranet system should allow solving the
following urgent problems of each company being audited:
1) ensure (if necessary increase) the information security of the
enterprise;
2) reduce potential losses of the enterprise by increasing the stability
of the corporate network;
3) protect confidential information transmitted over open
communication channels;
4) protect information from intentional distortion (destruction),
unauthorized copying, access or use;
5) ensure control of user actions in the corporate network of the
enterprise;
6) timely assess and reassess the information risks of the company’s
business activities;
7) develop optimal plans for the development and management of the
enterprise.
Planning an authorized audit of a company’s information security
In accordance with the recommendations of international information
security standards, the procedure for conducting a company security audit
should be planned in advance. To do this, it is necessary to draw up an audit

283
plan, which should reflect all activities and procedures associated with
initial and follow-up audits lasting more than one day. In addition, it is
necessary to familiarize yourself with the relevant legislative and regulatory
framework to identify information security requirements that can be used to
ensure the company's information security.
To conduct an information security audit, a company must prepare all
the necessary information about its own structure, business activities,
current projects, the state of the information infrastructure, etc. In addition,
you will need:
• documented concept and company security policy;
• list of system and application software used in the company;
• description of data processing technology;
• composition and structure of the information security subsystem;
• general map of the company’s computer network.
The audit plan should determine the audited areas of the company’s
activities and the time of their audit, indicating which specific requirements
of international standards, for example ISO 17799, and the governing
documents of the State Technical Commission of the Russian Federation
will be audited. That is, the plan for preparing and conducting an audit
should determine the company’s needs for assessing and objectively
analyzing the state of information security, the need for appropriate
hardware and software for information security, the need for training and
retraining of the information security service, as well as highlight other
questions that cannot be answered without an audit. In the future, the audit
plan with changes made to it during the audits is attached to the audit report.
In addition, it is necessary to remember to coordinate the audit plan with the
Concept and Information Security Policy of the company.
It is recommended to distinguish four possible stages of audit
planning:
1. Preparation of a security audit.
2. Analysis of requirements and source data.
3. Calculation of labor intensity and cost of work performed.
4. Documentation of the audit procedure.

284
Preparatory stage. At this stage, the contractor determines the
general order of work, establishing the sequence of execution and possible
resource costs, and coordinates it with the customer. At this stage the
following are considered:
• purpose and goals of the upcoming audit, the procedure for achieving
them;
• principles for establishing the audit framework;
• functions, structure and composition of the corporate
Internet/Intranet system, bottlenecks and potential vulnerabilities in the
information security management system;
• methods for assessing the qualifications of specialists and employees
of the information security service;
• methods of categorizing information processed in a corporate
information system, for example, into public, confidential and strictly
confidential;
• methods and tools for estimating the time and resource costs of a
company for an information security audit. The ability to use the results of
a previously conducted audit, including analysis of information risks and
analysis of compliance with the requirements of international standards and
governing documents of the State Technical Commission of the Russian
Federation;
• composition of a group of experts in the field of security of corporate
Internet/Intranet systems and distribution of responsibilities between them;
• parameters of the company’s corporate information network and its
operating environment, which have a significant impact on the quality of the
security audit;
• a set of requirements of international, state, interdepartmental and
internal standards taken into account when conducting a safety audit;
• internal reporting documentation, preparation and, if necessary,
adjustment of the company’s information security concept and policy;
• prospects and trends in the development of the company’s corporate
information security system, issues of developing strategies and tactics for
its development.

285
The general procedure for conducting a company security audit,
agreed upon with the customer, can be reflected in the corresponding
technical specifications.
Stage of analysis of requirements and source data. This stage forms
a major part of audit planning. The analysis process considers:
• information security requirements. The purpose of the audit is to
objectively and quickly evaluate and verify the compliance of the
company’s corporate security system under investigation with the
information security requirements imposed on it. Therefore, for such an
assessment it is necessary to first consider information security
requirements. The main information security requirements for domestic
enterprises and companies are the requirements of the governing documents
of the State Technical Commission of the Russian Federation, laws of the
Russian Federation, intradepartmental, interdepartmental, national and
international standards. In addition, for each corporate information system
it is necessary to take into account special requirements for internal use,
consistent with the company’s security concept and policy. It is
recommended to formulate such internal requirements based on the results
of an analysis of the company’s information risks, taking into account the
specifics of a particular company;
• initial data for the audit. The guiding document of the State
Technical Commission “Regulations on the certification of informatization
objects according to information security requirements” provides a standard
list of initial data necessary for the development of a program and
methodology for certification tests. In addition to standard source data,
additional source data specific to each specific company can be used, for
example, statistics of violations of the company’s security policy, statistics
of external and internal attacks, vulnerabilities of the most critical corporate
information resources, etc. It should also be taken into account that, as a
rule, Company management has its own views on the information provided
as input for a security audit. Therefore, it is recommended to conclude a
special confidentiality agreement or a corresponding letter of intent between
the customer and the information security audit performer;

286
• scope of the audit. When determining the scope of the audit, it is
necessary to equally take into account the organizational, technological and
software and hardware levels of information security. Otherwise, the audit
results will not objectively reflect the real level of information security of
the company. For example, expensive hardware and software information
security tools may be useless if measures and measures at the organizational
and technological levels are incorrectly defined and implemented. When
determining the scope of the audit, it is necessary to record the standard
operating conditions of the company’s corporate information security
system. Such recording can be reflected in the “Certificate of Compliance”
or “Company Passport” and is a necessary condition for ensuring the
required level of information security of the company and developing action
plans in the event of abnormal operating conditions of the corporate
Internet/Intranet system;
• areas of detailed study. When conducting an audit, the main attention
should be paid to the components and subsystems that process confidential
company information. At the same time, it is necessary to be able to
calculate the possible damage that could be caused to the company in the
event of disclosure of confidential information and violation of the Security
Policy. This should be reflected in the relevant company documents
regulating its information security policy. To determine possible damage, a
variety of formal methods, such as expert assessment methods, can be used.
The initial data for making a decision on areas of detailed study can be the
results of a previously conducted, ongoing comprehensive security audit of
the company, the results of an analysis of the company’s information risks
and other data. In addition, if necessary, vulnerabilities can be additionally
examined by special instrumental checks using so-called scanners and
systems for checking the level of security;
• required level of detail and completeness. In most cases, to obtain
adequate results, it is enough to conduct a basic analysis of the corporate
information security system, which allows us to determine the overall level
of information security of the company and check it for compliance with
certain security requirements. In some cases, it is additionally required to

287
conduct a detailed analysis, the purpose of which is to quantify the level of
information security of the company based on special quantitative metrics
and information security measures. To do this, first all the necessary
quantitative indicators are determined, and then the level of information
security of the company is assessed. It is important that in this case it
becomes possible to compare the company’s security level with a certain
standard, determine trends and prospects for the development of the
corporate security system, necessary investments, etc.
Stage of calculating labor intensity and cost. At the stage of
calculating the labor intensity and cost of the work carried out, based on the
analysis performed, the time, financial, technical, information and other
resources necessary for the information security audit are assessed. It is
recommended to allocate resources taking into account possible emergency
situations that could increase the complexity of a security audit.
Stage of formalization and documentation. Audit planning ends
with the formalization and documentation of the audit, which first of all
implies the preparation and approval of an audit plan. The audit plan
generally includes the following sections:
1. Brief description of the work. Includes all necessary information
about the work procedure.
2. Introduction. The relevance of conducting a security audit, features
and requirements for the procedure for conducting an audit, characteristics
of the object under study, the scope of the audit, the general procedure,
requirements for recording the results of the audit are indicated.
Additionally, information is provided on the categorization of corporate
information, such as confidential and strictly confidential. The main tasks
to be solved, restrictions, functions performed and criteria for assessing the
level of information security of the company, the requirements of regulatory
documents of the Russian Federation, international standards and internal
requirements of the company are also listed.
3. Distribution of responsibilities. The staff and functional
responsibilities of the group of specialists who will conduct the security
audit are determined.

288
4. Information security requirements. A reasonable choice of
information security requirements is recorded, criteria and indicators for
assessing the company’s information security are determined, and
quantitative metrics and security measures are selected. In addition to the
regulatory and legislative framework of the Russian Federation, it is
additionally recommended to use the requirements of international and
internal company standards that are relevant for each individual company.
It is recommended to evaluate investments in modernizing the corporate
information security system based on the results of an analysis of the
company’s information risks.
5. Formalization of assessments of the company’s security level.
Qualitative and quantitative parameters are determined to obtain objective
assessments of the company’s information security level. The tasks
performed when conducting basic and detailed information risk analysis are
listed. The scope of tasks depends on what stage of the life cycle the security
of the corporate Internet/Intranet system is at: the design stage, operation
stage, etc. This section reflects the company’s critical information resources,
an assessment of the economic efficiency of its activities, the models used,
methods, and audit tools security, initial data.
6. Work schedule. The deadlines, calendar plan of work performed,
completion time, forms of reporting documents, requirements for
acceptance and delivery of work, etc. are determined.
7. Support and support. The requirements for administrative,
technological and technical support for an information security audit are
listed.
8. Reporting documents. The main reporting documents are a report
on the results of a security audit, an information security concept and policy,
and a company protection plan.
9. Applications. The appendices contain inspection protocols, as well
as information on audit methods and tools, identified comments,
recommendations, etc.

289
7.2.3. Security analysis technique [2]
Currently, there are no standardized methods for analyzing the security
of AS, therefore, in specific situations, the algorithms of actions of auditors
may vary significantly. However, it is still possible to propose a standard
methodology for analyzing the security of a corporate network. And
although this technique does not claim to be universal, its effectiveness has
been repeatedly tested in practice.
A typical methodology for analyzing the security of a corporate
network includes the use of the following methods:
1. Study of initial data on AS.
2. Assessment of risks associated with the implementation of security
threats in relation to AS resources.
3. Analysis of security mechanisms at the organizational level, the
organization’s security policy and organizational and administrative
documentation to ensure the information security regime and assessment of
their compliance with the requirements of existing regulatory documents, as
well as their adequacy to existing risks.
4. Manual analysis of configuration files of routers, firewalls and
proxy servers that manage internetwork interactions, mail and DNS servers,
as well as other critical elements of the network infrastructure.
5. Scanning external LAN network addresses from the Internet.
6. Scanning LAN resources from the inside.
7. Analysis of the configuration of servers and LAN workstations
using specialized software.
Initial data on the examined AS
In accordance with the requirements of the State Technical
Commission RD, when carrying out work on AS safety certification,
including a preliminary examination and analysis of the security of the
informatization object, the customer of the work must provide the following
initial data:

290
1. Full and exact name of the informatization object and its purpose.
2. The nature (scientific, technical, economic, industrial, financial,
military, political) of information and the level of secrecy (confidentiality)
of the processed information are determined in accordance with which lists
(state, industry, departmental, enterprise).
3. Organizational structure of the informatization object.
4. List of premises, composition of the complex of technical means
(main and auxiliary) included in the informatization object, in which (on
which) the specified information is processed.
5. Features and layout of the informatization object indicating the
boundaries of the controlled area.
6. The structure of the software (general system and application) used
on the certified information object and intended for processing protected
information, the information exchange protocols used.
7. General functional diagram of an informatization object, including
a diagram of information flows and modes of processing protected
information.
8. The presence and nature of interaction with other objects of
informatization.
9. Composition and structure of the information security system at the
certified informatization object.
10. List of hardware and software in a protected design, protection and
control means used at the certified information technology object and
having the appropriate certificate and instructions for operation.
11. Information about the developers of the information security
system, whether third-party developers (in relation to the enterprise where
the certified information technology object is located) have licenses to carry
out such work.
12. Availability at the informatization facility (at the enterprise where
the informatization facility is located) of an information security service and
an administrator service (automated system, network, databases).
Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]
