Case Study with full APA format and NO PLAGIARISM

profileShrikaa
easttom_netd_ppt_11F.pdf

Network Defense and

Countermeasures

by Chuck Easttom

Chapter 11: Security Policies

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 2

Objectives

 Create effective user policies

 Outline effective system administration

policies

 Define effective access control

 Generate effective developmental policies

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 3

Introduction

Technology is not effective if people do not

follow procedures. Policies designate how the

technology can be used, by whom, and for

what purpose. Through the policies, the

technology can be appropriately applied to

ensure business purposes and objectives are

met.

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 4

Defining User Policies

 Areas that effective user policies must cover

include:

 Passwords

 Internet use

 E-mail attachments

 Software installation and removal

 Instant messaging

 Desktop configuration

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 5

Defining User Policies cont.

 Passwords

 Never write down passwords

 Never share passwords with other people for any

reason

 If compromised, the user should contact

administration to change the password

 Trace login attempts on old passwords

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 6

Defining User Policies cont.

 Internet Use

 Internet access is necessary for businesses

 There are legitimate business uses

 There are also inappropriate uses of the Internet

on a company network

 Then there are “gray” areas

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 7

Defining User Policies cont.

 Legitimate uses:

 Sales staff checking competitor web sites to see

what products and services are offered

 Creditors checking a business’ AM Best or

Standard and Poor’s rating

 Business travelers checking weather conditions

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 8

Defining User Policies cont.

 Inappropriate uses:

 Using the web to search for a job

 Any pornographic use

 Any use that violates local, state, or federal laws

 Use of the web to conduct employee’s own

business

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 9

Defining User Policies cont.

 Gray areas:

 Online shopping during the employee’s lunch or

break time

 Reading news articles online during lunch or

break time

 Viewing humorous web sites

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 10

Defining User Policies cont.

 E-mail attachments

 Due to virus propagation through e-mail, it is

critical to have policies on how to handle

attachments

 Open attachments only if they meet the following:

 It was expected

 If not expected, it has come from a known source

 Appears to be a legitimate business document

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 11

Defining User Policies cont.

 E-mail attachments (continued)

 Never open an attachment if it meets the

following:

 Comes from an unknown source

 It is some active code or executable

 It is an animation/movie

 The e-mail does not appear legitimate

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 12

Defining User Policies cont.

 Software installation and removal

 Software installation should be prohibited

 If allowed, IT department should scan and

approve first

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 13

Defining User Policies cont.

 Instant messaging

 If not necessary in the business, prohibit its use

 If necessary, restrict use to business issues

 No confidential or private business information

should be sent via instant messaging

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 14

Defining User Policies cont.

 Desktop configuration

 In itself may not be considered a security hazard

 Some things to consider:

 Where did the background come from

 Viruses may be disguised as a jpg or gif file

 Rights to configure the desktop also allow users to

configure other system settings

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 15

Defining User Policies cont.

 Final thoughts on user policies

 Policies must be clearly defined

 Consequences must also be clearly defined in

relation to the policies

 Examples of consequences:

 First incident of violation will result in a verbal warning

 Second incident will result in a written warning

 Third incident will result in suspension or termination

 Require employees to sign off on the user policies

when they join the organization

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 16

CAUTION

 Termination or Expulsion

 Any policy that can lead to expulsion from a

school or termination from a job should first be

cleared by legal advisors. If termination is

wrongfully imposed, there are serious

ramifications associated with this action.

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 17

Defining System Administration

Policies

 New employees

 Leaving employees

 Change requests

 Security breaches

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 18

Defining System Administration

Policies cont.

 New employees

 Document the granting of access in log or other

form

 Request to add an employee should come from

the hiring business unit

 Request must come from authorized manager

 Request should be signed by IT authority

 When complete, request should be filed for

documentation

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 19

Defining System Administration

Policies cont.

 Leaving employees

 All logon accounts are disabled (deleted)

 All keys to the facility are returned

 All accounts for e-mail, Internet access, wireless

Internet, cell phones, and such are shut off

 Any accounts for mainframe resources are

canceled

 Employee’s workstation hard drive is searched

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 20

Defining System Administration

Policies cont.

 Change requests

 The nature of IT is change

 Change control process needs to be in place with

the following steps:

 Manager approval on signed request

 IT verifies the request can be fulfilled

 Security issues relating to change are identified

 IT formulates the plan to implement the change

 Date and time is set and parties are notified of change

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 21

Defining System Administration

Policies cont.

 Security breaches

 Virus infection

 Denial of service attacks

 Intrusion by a hacker

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 22

Virus Infection

 Quarantine files through antivirus software

 After quarantine, take the following steps:

 Scan and clean each infected machine

 Log the incident

 Bring online in stages when they are clean

 Notify organization leaders of incident and actions

taken

 Meet with IT staff to find out ways to prevent future

incidents

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 23

Denial of Service Attacks

 Utilize firewall and IDS software

 Deny originating IP address of the attack,

access to the network

 Log all activities

 Meet with IT staff to discuss the attack and

what can be done for future attacks

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 24

Intrusion by a Hacker

 Immediately copy all logs of affected systems

 Scan all systems for Trojan horses, system

changes, and so on

 Document everything

 Change all affected passwords

 Inform appropriate leaders

 Meet with IT staff

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 25

Defining Access Control

 Complete lockdown of resources is not

practical

 Unfettered access is also not feasible

 Concept of “least privileges” should be

followed

 There will always be trade-offs

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 26

Defining Developmental Policies

 Software development within the company if

possible

 All code must be checked for Trojan horses, and

such

 Error handling must be addressed for buffers

 Secure communication guidelines must be followed

 Code that opens ports must be documented

 Security flaws of vendor software must be provided

by vendors

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 27

Summary

 Clear and specific policies coupled with

technology can secure your network

 Policies must cover:

 New employees

 Outgoing employees

 Access control

 Emergency response procedures

 Application and web site code security

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 28

Summary cont.

 User policies must cover:

 All aspects of use of company technology

 Instant messaging

 Web use

 Consequences must be clearly outlined

These types of policies are difficult to enforce

but need to be in place

© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 29

Summary cont.

 IT staff policies must also be in place on how

to handle certain situations

 New and exiting employees

 Security breaches

 Change management systems