Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

Введение в информационную безопасность и защиту информации. Учебное пособие

.pdf
Скачиваний:
0
Добавлен:
07.09.2026
Размер:
2 Мб
Скачать
Твердая копия документа – полу­ченная на устройствах вывода ЭВМ надлежащим образом удостоверенная форма внешнего представления элек­тронного документа, выполненная на бумажном носителе.
[ГОСТ 2.051-2006]
Тестирование – процесс испытания одного или нескольких объектов про­верки при определенных условиях, который проводится для сравнения реального поведения с ожидаемым. Результаты используются для под­держки решения о наличии, эффек­тивности, функциональных возмож­ностях, правильности, полноте мер и средств контроля и управления и воз­можности их совершенствования с течением времени.
Р 56045-2014/ISO/IEC TR
[ГОСТ 27008:2011]
Hard copy of document – duly certified form of external representation of elec­tronic document, made on paper, ob­tained on the output devices of the com­puter.
Test – A type of assessment method that is characterized by the process of exer­cising one or more assessment objects under specified conditions to compare actual with expected behavior, the re­sults of which are used to support the determination of security control effec­tiveness over time. SOURCE: SP 800-53A
testing (1) Evaluation of a resource to validate the achievement of objectives and aims. See exercise.
[ASIS/BSI BCM.01-2010] (2) Activities performed to evaluate the
effectiveness or capabilities of a plan relative to specified objectives or meas­urement criteria. Testing usually in­volves exercises designed to keep teams and employees effective in their duties and to reveal weaknesses in the Business Continuity Plan.
[ASIS GDL BC 01 2005] (3) Activities performed to evaluate the
effectiveness or capabilities of a plan relative to specified objectives or meas­urement criteria. Testing usually in­volves exercises designed to keep teams and employees effective in their duties, and to reveal weaknesses in the prepar­edness and response/continuity/recovery plans.
[ASIS GDL BC 01 2005] [ANSI/ASIS PAP.1-2012]
91
Тестирование функций СЗИ НСД
Техника защиты информации –
средства защиты информации, в том числе средства физической защиты информации, криптографические средства защиты информации, сред­ства контроля эффективности защиты информации, средства и системы управления, предназначенные для обеспечения защиты информации.
ГОСТ Р 50922 2006
Трансграничная передача персо­нальных данных – передача персо-
нальных данных оператором через Государственную границу Россий­ской Федерации органу власти ино­странного государства, физическому или юридическому лицу иностранно­го государства.
[Методические рекомендации по обеспечению с помощью крипто­средств безопасности персональных данных при их обработке в информа­ционных системах персональных данных с использованием
средств
автоматизации]
Требование по защите информа­ции – установленное правило или
норма, которая должна быть выпол­нена при организации и осуществле­нии защиты информации, или допу­стимое значение показателя эффек­тивности защиты информации.
ГОСТ Р 50922 2006
Security Testing – Process to determine
that an information system protects data and maintains functionality as intended.
SOURCE: CNSSI-4009
Information Security Program Plan –
Formal document that provides an over­view of the security requirements for an organization-wide information security program and describes the program management controls and common con­trols in place or planned for meeting those requirements.
SOURCE: SP 800-37; SP 800-53; SP 800-53A
Cross-border transfer of personal data – the transfer of personal data by
the operator through the state border of the Russian Federation to the authority of a foreign country, person or entity of a foreign country.
Security Requirements – Requirements levied on an information system that are derived from applicable laws, Executive Orders, directives, policies, standards, instructions, regulations, or procedures, or organizational mission/business case needs to ensure the confidentiality, in­tegrity, and availability of the infor­mation being processed, stored, or transmitted.
SOURCE: FIPS 200; SP 800-53; SP 800-53A; SP 800-37; CNSSI-4009
92
Угроза (безопасности информа­ции) – Совокупность условий и фак-
торов, создающих потенциальную или реально существующую опас­ность нарушения безопасности ин­формации.
ГОСТ Р 53114-2008
Угроза (безопасности информации):
Совокупность условий и факторов, создающих потенциальную или ре­ально существующую опасность нарушения безопасности информа­ции. [ГОСТ Р 50922-2006, 2.6.1]
Инцидент информационной без­опасности: Любое непредвиденное
или нежелательное событие, которое
Threat – Any circumstance or event
with the potential to adversely impact organizational operations (including mission, functions, image, or reputa­tion), organizational assets, individuals, other organizations, or the Nation through an information system via unau­thorized access, destruction, disclosure, modification of information, and/or de­nial of service.
SOURCE: SP 800-53; SP 800-53A; SP 800-27; SP 800-60; SP 800-37; CNSSI-4009
Threat – The potential source of an ad­verse event. SOURCE: SP 800-61
Threat – Any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputa­tion), organizational assets, or individu­als through an information system via unauthorized access, destruction, disclo­sure, modification of information, and/or denial of service. Also, the potential for a threat-source to successfully exploit a particular information system vulnera­bility.
SOURCE: FIPS 200
Threat Any circumstance or event with the potential to adversely impact agency operations (including mission, functions, image, or reputation), agency assets, or individuals through an information sys­tem via unauthorized access, destruction, disclosure, modification of information, and/or Denial of Service (DOS). [Glos­sary TOC]
93
может нарушить деятельность или информационную безопасность.
Примечание. Инцидентами информа­ционной безопасности являются:
– утрата услуг, оборудования или устройств;
системные сбои или перегрузки; – ошибки пользователей; – несоблюдение политики или реко­мендаций по ИБ; – нарушение физических мер защиты; – неконтролируемые изменения си-
стем; – сбои программного обеспечения и
отказы технических средств; – нарушение
правил доступа. [ГОСТ Р ИСО/МЭК 27001-2006, ста­тья 3.6]
Управление рисками: Координиро- ванные действия по направлению и контролю над деятельностью органи­зации в связи с рисками.
[ГОСТ Р 53114-2008 3.2.16]
Risk Management – The process of
managing risks to organizational opera­tions (including mission, functions, im­age, reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation of an information system, and includes: (i) the conduct of a risk assessment; (ii) the implementation of a risk mitigation strategy; and (iii) employment of tech­niques and procedures for the continu­ous monitoring of the security state of the information system.
SOURCE: SP 800-53; SP 800-53A; SP 800-37 Risk Management – The process of managing risks to organizational opera­tions (including mission, functions, im­age, or reputation), organizational assets, or individuals resulting from the opera­tion of an information system, and in­cludes:
94
1) the conduct of a risk assessment;
2) the implementation of a risk mitiga­tion strategy; and
3) employment of techniques and proce­dures for the continuous monitoring of the security state of the information sys­tem.
SOURCE: FIPS 200 Risk Management – The process of
managing risks to agency operations (including mission, functions, image, or reputation), agency assets, or individuals resulting from the operation of an infor­mation system. It includes risk assess­ment; cost-benefit analysis; the selec­tion, implementation, and assessment of security controls; and the formal author­ization to operate the system. The pro­cess considers effectiveness, efficiency, and constraints due to laws, directives, policies, or regulations.
SOURCE: SP 800-82; SP 800-34 The process of managing risks to organ-
izational operations (including mission, functions, image, or reputation), organi­zational assets, individuals, other organ­izations, or the nation resulting from the operation or use of an information sys­tem, and includes: (1) the conduct of a risk assessment; (2) the implementation of a risk mitigation strategy; (3) em­ployment of techniques and procedures for the continuous monitoring of the security state of the information system; and (4) documenting the overall risk management program.
SOURCE: CNSSI-4009 The program and supporting processes
to manage information security risk to organizational operations (including mission, functions, image, reputation),
95
Уровень: – защиты информации;
конфиденциальности; – полномочий – cовокупность прав
доступа субъекта доступа. [Руково­дящий документ Защита от несанкци­онированного доступа к информации Термины и определения, пункт 9]
Успешная атака – атака, достигшая своей цели.
[Методические рекомендации по обеспечению с помощью крипто­средств безопасности персональных данных при их обработке в информа­ционных системах персональных данных с использованием средств автоматизации]
Устройства (Устройство – кон­структивно законченный технический элемент, имеющий определенное функциональное назначение в ин­формационной системе
[Методический документ. Меры за­щиты информации в государствен­ных информационных системах. Утвержден ФСТЭК России 11 фев­раля 2014 г.]):
organizational assets, individuals, other organizations, and the Nation, and in­cludes: (i) establishing the context for risk-related activities; (ii) assessing risk; (iii) responding to risk once determined; and (iv) monitoring risk over time. SOURCE: SP 800-39
Level: – of information security;
– of confidentiality; – of powers – the aggregate subject ac-
cess permissions..
Successful attack – attack, which has reached its goal.
Devices
1) In general, a device is a machine de­signed for a purpose. In a general con­text, a computer can be considered a device.
2) In the context of computer technolo­gy, a device is a unit of hardware, out­side or inside the case or housing for the essential computer (processor, memory, and data paths) that is capable of provid­ing input to the essential computer or of receiving output or of both.
96
Утечка информации: Неконтроли­руемое распространение защищаемой информации в результате ее разгла­шения, несанкционированного досту-
Data Loss – The exposure of proprie­tary, sensitive, or classified information through either data theft or data leakage.
SOURCE: SP 800-137
па к информации и получения защи­щаемой информации иностранными разведками.
[ГОСТ Р 53114-2008 3.3.10]
Учетные данные Credentials
Credential – An object or data structure
that authoritatively binds an identity (and optionally, additional attributes) to a token possessed and controlled by a Subscriber. SOURCE: SP 800-63 Credential – Evidence attesting to one’s right to credit or authority. SOURCE: FIPS 201
Credential – Evidence or testimonials that support a claim of identity or asser­tion of an attribute and usually are in­tended to be used more than once.
SOURCE: CNSSI-4009
Уязвимость (информационной си­стемы); брешь: Свойство информа-
ционной системы, обусловливающее возможность реализации угроз без­опасности обрабатываемой в ней ин­формации.
[ГОСТ Р 50922-2006, 2.6.4]
Vulnerability – Weakness in an infor-
mation system, system security proce­dures, internal controls, or implementa­tion that could be exploited or triggered by a threat source. SOURCE: SP 800­53; SP 800-53A; SP 800-37; SP 800-60; SP 800- 115; FIPS 200
A weakness in a system, application, or network that is subject to exploitation or misuse. SOURCE: SP 800-61 Weakness in an information system, system securi­ty procedures, internal controls, or im­plementation that could be exploited by a threat source. SOURCE: CNSSI-4009
97
Фактор, воздействующий на защи­щаемую информацию: Явление, дей-
ствие или процесс, результатом кото­рого могут быть утечка, искажение, уничтожение защищаемой информа­ции, блокирование доступа к ней. [ГОСТ Р 50922-2006, 2.6.2]
Характеристика безопасности объ­екта – требование к объекту, или к
условиям его создания и существова­ния, или к информации об объекте и условиях его создания и существова­ния, выполнение которого необходи­мо для обеспечения защищенности жизненно важных интересов лично­сти, общества или государства.
[Методические рекомендации по обеспечению с помощью крипто­средств
безопасности персональных данных при их обработке в информа­ционных системах персональных данных с использованием средств автоматизации]
Целостность информации – устой- чивость информации к несанкциони­рованному или случайному воздей­ствию на нее в процессе обработки техническими средствами, результа­том которого может быть уничтоже­ние и искажение информации.
СТРК-2001
Incident An assessed event of attempted entry, unauthorized entry, and/or attack against a facility, operation, or Automat­ed Information System (AIS).
Security Requirements – Require­ments – Requirements levied on an in­formation system that are derived from applicable laws, Executive Orders, di­rectives, policies, standards, instructions, regulations, or procedures, or organiza­tional mission/business case needs to ensure the confidentiality, integrity, and availability of the information being processed, stored, or transmitted. SOURCE: FIPS 200; SP 800-53; SP 800-53A; SP 800-37; CNSSI- 4009
Integrity – Guarding against improper information modification or destruction, and includes ensuring information non­repudiation and authenticity.
SOURCE: SP 800-53; SP 800-53A; SP 800-18; SP 800-27; SP 800-37;
SP 800-60; FIPS 200; FIPS 199; 44 U.S.C., Sec. 3542
Integrity – The property that sensitive data has not been modified or deleted in an unauthorized and undetected manner.
SOURCE: FIPS 140-2 Integrity – The property whereby an
entity has not been modified in an unau­thorized manner.
SOURCE: CNSSI-4009
98
Цель защиты информации: Заранее намеченный результат защиты ин­формации.
[ГОСТ Р 50922-2006, 2.4.2]
Target – a detailed performance re-
quirement applicable to the organization (or parts thereof) that arises from the objectives and that needs to be set and met in order to achieve those objectives. [ASIS SPC.1-2009] [ANSI/ASIS PAP.1-2012] [ANSI/ASIS PSC.1-2012]
Штамп.
Технологическая оснастка, посред­ством которой заготовка приобрета­ет форму и (или) размеры, соответ­ствующие поверхности или контуру
Stamp.
Industrial equipment, by means of which the workpiece acquires the shape or size, the corresponding surface or the contour of the working elements of a stamp
рабочих элементов штампа [ГОСТ 15830 84]
Эффективность защиты информа­ции – степень соответствия результа-
тов защиты информации цели защиты информации.
ГОСТ Р 50922 2006
Security Control Effectiveness – The
measure of correctness of implementa­tion (i.e., how consistently the control implementation complies with the secu­rity plan) and how well the security plan meets organizational needs in accord­ance with current risk tolerance. SOURCE: SP 800-137
НСД – несанкционированный доступ – unauthorized access
99
Компьютерная защита информации
Web-сервер – общедоступный в Сети
информационный сервер, использу­ющий гипертекстовую технологию.
СТРК-2001
Автоматизированные системы (АС) – автоматизированная система:
Система, состоящая из персонала и комплекса средств автоматизации его деятельности, реализующая инфор­мационную технологию выполнения установленных функций.
[ГОСТ 34.003 90, пункт 1.1], [СТР-К, 2001, пункт 1.3]
в которых работает один пользова- тель;
многопользовательские.
Администратор АС – лицо, ответ­ственное за функционирование авто­матизированной системы в установ­ленном штатном режиме работы. [СТР-К, 2001, пункт 1.4]
Администратор защиты информа­ции (в АС) – это субъект доступа,
ответственный за защиту автоматизи­рованной системы от несанкциониро­ванного доступа к информации. [Ру­ководящий документ Защита от не­санкционированного доступа к ин­формации Термины и определения, пункт 29], [СТР-К, 2001, пункт 1.5]
Web Server – A software process that runs on a host computer connected to the Internet to respond to HTTP requests for documents from client web browsers.
Automated Information system (AS)
A generic term applied to all electronic computing systems. Automated Infor­mation Systems (AIS) collect, store, process, create, disseminate, communi­cate, or control data or information.
AIS are composed of computer hard­ware (e.g., automated data processing equipment and associated devices that may include communication equipment), firmware, an operating system (OS), and other applicable software. – single-user; – multiuser.
System Administrator – A person who manages the technical aspects of a sys­tem. SOURCE: SP 800-40
Administrator of information security (in AS) – it is the subject responsible for
protection of the automated system from unauthorized access to information.
100
Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]