Assignment
1630 – Slav Konev
Lab 10- Aligning an IT Security Policy Framework to the Seven Domains of a Typical IT Infrastructure
Lab Assessment Questions & Answers
1. Define a policy statement (in two or three sentences maximum) for each of the following policy definitions that are needed to remediate identified gaps for an IT security policy framework:
1. Access control policy definition
0. The use of two-factor authentication, with logon timeouts after the third attempt. Attempts outside the network to gain internal access will have two-factor authentication to prevent unauthorized access.
1. Business continuity: Business impact analysis (BIA) policy definition
1. Determine the course of action to deal with ISP issues, power outages, and incidents within a facility. Determine the maximum amount of time allowed without services before costing data loss
1. Business continuity and disaster recovery policy definition
2. Defines plans and individuals responsible for the containment of business in the event of an incident. The amount of time allowed for outage of service before a DRP is enacted, with contact information for individuals responsible to restore services.
1. Data classification standard and encryption policy definition
3. All data sent over the Internet should be encrypted to prevent eavesdropping, or session hijacking. All personal or IP of the organization will be encrypted during storage and backup
1. Internet ingress/egress traffic and Web content filter policy definition
4. Filter all traffic into the internal organization, alerts sent when IP looks suspicious, multiple attempts for the same IP, logging of the information in and out of the organization with review daily for glitches
1. Production data backup policy definition
5. Data back up one hourly and nightly to an offsite facility. Production data backed up every hour on an automatic setting
1. Remote access Virtual Private Network (VPN) policy definition
6. VPN to access an internal server with authentication, before access will be granted to internal database server. Access controls on individuals with remote access, filtering and logging of use of the remote device
1. Wide Area Network (WAN) service availability policy definition
7. Should services not be restored within allowed time, the BCP will become activated by management. Should an outage last more than eight hours, the DRP will be activated by management
1. Internet ingress/egress availability (denial of service/distributed denial of service [DoS/DDoS]) policy definition
8. Filter violations both outbound and inbound based on IP address. In unique and unusual cases, all IP addresses that are attempting to access the Internet from inside of your network should bear and address that is assigned.
1. Wireless Local Area Network (WLAN) access control and authentication policy definition
9. Access to IT resources and information must be corresponding with the security requirements of that resource and classification of data it has to provide access. Access control rules must differentiate between roles.
1. Internet and e-mail acceptable use policy definition
10. Applies to all Internet users who access the Internet through the computing or networking resources. The company’s Internet users are expected to be familiar with and to comply with the policy, also using good judgement while using Internet services
1. Asset protection policy definition
11. Unauthorized physical assets, loss, damage or interference to the organization’s premises and infrastructure should be prevented using physical and environmental controls appropriate to the identified risks and the value of the assets protected
1. Audit and monitoring policy definition
12. Provide the authority for members to conduct a security audit on any system at the company. Ensure CIA of information and investigate security incidents.
1. Computer security incident response team (CSIRT) policy definition
13. The plan should support, complement, and provide input into existing business and IT policies that impact the security of an organization’s infrastructure, just like any other incident management processes.
1. Security awareness training policy definition
14. Security awareness programs are designed to educate users on the security policy of an organization. The goals for a security awareness program should include not only education about the organization’s security policy but should help to foster an understanding of how the policy protects the business, the employee, and customers
YZ Credit Union/Bank Incident Response Policy
Policy Statement
This policy is to help ABC Credit Union to establish a CIRT policy. It is being put in place to protect the organization’s equipment and allow the organization to know what to do when an incident occurs in order to get the systems up and running in the fastest amount of time possible.
Purpose/Objectives
Because there is risk in information security, management must have a proactive plan to address incidents where Availability, Integrity, and Confidentiality of information can possibly be breached. ABC Credit Union needs to ensure that this policy addresses violations of the AUP (Acceptable Use Policy).
Scope
This plan applies to ABC Credit Union’s team, along with all members of the IT team. These teams are responsible for overseeing the development, implementation, and maintenance of this plan. The plan should be reviewed, at minimum, semi-annually to ensure that relevant information is appropriately considered.
Standards
CIRT members have pre-defined roles and responsibilities; these can take priority over normal responsibilities.
The appropriate technical resources from the CIRT will be responsible for monitoring any damage from a security incident gets repaired or mitigated.
The appropriate technical resources from the CIRT will be responsible for communicating new issues or vulnerabilities to system’s vendors and work with the vendor to eliminate or mitigate the vulnerabilities.
The ISO (Information Security Officer) will responsible for coordinating communications with outside organizations and law enforcement agencies.
In a situation where law enforcement is involved, the ISO is to act as the liaison between law enforcement and ABC Credit Union.
Procedures
IT team members will be trained by the lead officers and report any potential issues that might be discovered to the CIRT for investigation as they troubleshoot and maintain the systems.
All incidents shall be carefully assessed by the Information Lead Officer to determine any appropriate actions and ensure that the necessary reporting requirements are being met.
Based on the nature and scope of an incident, IT staff and the information office shall determine whether the incident can be resolved locally, of if additional assistance is required by the CIRT.
Operating systems, user accounts, and application software audit logging process must be enabled on all hosts and server systems.
Guidelines
Based on the type of incident that occurs, it is at the IT officer’s discretion to determine what category the actual response to an event may fall into: Containment, Eradication, Recovery, or Follow-up.
Containment: To limit the extent of an attack
Eradication: Once contained, the cause of the issue to is be resolved
Recovery: Return the system to its normal functioning state
Follow-up: Includes regular status reports, describe new controls, and include “lessons learned” to improve future response time and performance