Case Study with full APA format and NO PLAGIARISM
Network Defense and
Countermeasures
by Chuck Easttom
Chapter 11: Security Policies
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 2
Objectives
Create effective user policies
Outline effective system administration
policies
Define effective access control
Generate effective developmental policies
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 3
Introduction
Technology is not effective if people do not
follow procedures. Policies designate how the
technology can be used, by whom, and for
what purpose. Through the policies, the
technology can be appropriately applied to
ensure business purposes and objectives are
met.
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 4
Defining User Policies
Areas that effective user policies must cover
include:
Passwords
Internet use
E-mail attachments
Software installation and removal
Instant messaging
Desktop configuration
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 5
Defining User Policies cont.
Passwords
Never write down passwords
Never share passwords with other people for any
reason
If compromised, the user should contact
administration to change the password
Trace login attempts on old passwords
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 6
Defining User Policies cont.
Internet Use
Internet access is necessary for businesses
There are legitimate business uses
There are also inappropriate uses of the Internet
on a company network
Then there are “gray” areas
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 7
Defining User Policies cont.
Legitimate uses:
Sales staff checking competitor web sites to see
what products and services are offered
Creditors checking a business’ AM Best or
Standard and Poor’s rating
Business travelers checking weather conditions
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 8
Defining User Policies cont.
Inappropriate uses:
Using the web to search for a job
Any pornographic use
Any use that violates local, state, or federal laws
Use of the web to conduct employee’s own
business
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 9
Defining User Policies cont.
Gray areas:
Online shopping during the employee’s lunch or
break time
Reading news articles online during lunch or
break time
Viewing humorous web sites
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 10
Defining User Policies cont.
E-mail attachments
Due to virus propagation through e-mail, it is
critical to have policies on how to handle
attachments
Open attachments only if they meet the following:
It was expected
If not expected, it has come from a known source
Appears to be a legitimate business document
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 11
Defining User Policies cont.
E-mail attachments (continued)
Never open an attachment if it meets the
following:
Comes from an unknown source
It is some active code or executable
It is an animation/movie
The e-mail does not appear legitimate
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 12
Defining User Policies cont.
Software installation and removal
Software installation should be prohibited
If allowed, IT department should scan and
approve first
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 13
Defining User Policies cont.
Instant messaging
If not necessary in the business, prohibit its use
If necessary, restrict use to business issues
No confidential or private business information
should be sent via instant messaging
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 14
Defining User Policies cont.
Desktop configuration
In itself may not be considered a security hazard
Some things to consider:
Where did the background come from
Viruses may be disguised as a jpg or gif file
Rights to configure the desktop also allow users to
configure other system settings
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 15
Defining User Policies cont.
Final thoughts on user policies
Policies must be clearly defined
Consequences must also be clearly defined in
relation to the policies
Examples of consequences:
First incident of violation will result in a verbal warning
Second incident will result in a written warning
Third incident will result in suspension or termination
Require employees to sign off on the user policies
when they join the organization
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 16
CAUTION
Termination or Expulsion
Any policy that can lead to expulsion from a
school or termination from a job should first be
cleared by legal advisors. If termination is
wrongfully imposed, there are serious
ramifications associated with this action.
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 17
Defining System Administration
Policies
New employees
Leaving employees
Change requests
Security breaches
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 18
Defining System Administration
Policies cont.
New employees
Document the granting of access in log or other
form
Request to add an employee should come from
the hiring business unit
Request must come from authorized manager
Request should be signed by IT authority
When complete, request should be filed for
documentation
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 19
Defining System Administration
Policies cont.
Leaving employees
All logon accounts are disabled (deleted)
All keys to the facility are returned
All accounts for e-mail, Internet access, wireless
Internet, cell phones, and such are shut off
Any accounts for mainframe resources are
canceled
Employee’s workstation hard drive is searched
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 20
Defining System Administration
Policies cont.
Change requests
The nature of IT is change
Change control process needs to be in place with
the following steps:
Manager approval on signed request
IT verifies the request can be fulfilled
Security issues relating to change are identified
IT formulates the plan to implement the change
Date and time is set and parties are notified of change
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 21
Defining System Administration
Policies cont.
Security breaches
Virus infection
Denial of service attacks
Intrusion by a hacker
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 22
Virus Infection
Quarantine files through antivirus software
After quarantine, take the following steps:
Scan and clean each infected machine
Log the incident
Bring online in stages when they are clean
Notify organization leaders of incident and actions
taken
Meet with IT staff to find out ways to prevent future
incidents
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 23
Denial of Service Attacks
Utilize firewall and IDS software
Deny originating IP address of the attack,
access to the network
Log all activities
Meet with IT staff to discuss the attack and
what can be done for future attacks
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 24
Intrusion by a Hacker
Immediately copy all logs of affected systems
Scan all systems for Trojan horses, system
changes, and so on
Document everything
Change all affected passwords
Inform appropriate leaders
Meet with IT staff
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 25
Defining Access Control
Complete lockdown of resources is not
practical
Unfettered access is also not feasible
Concept of “least privileges” should be
followed
There will always be trade-offs
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 26
Defining Developmental Policies
Software development within the company if
possible
All code must be checked for Trojan horses, and
such
Error handling must be addressed for buffers
Secure communication guidelines must be followed
Code that opens ports must be documented
Security flaws of vendor software must be provided
by vendors
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 27
Summary
Clear and specific policies coupled with
technology can secure your network
Policies must cover:
New employees
Outgoing employees
Access control
Emergency response procedures
Application and web site code security
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 28
Summary cont.
User policies must cover:
All aspects of use of company technology
Instant messaging
Web use
Consequences must be clearly outlined
These types of policies are difficult to enforce
but need to be in place
© 2014 by Pearson Education, Inc. Chapter 11 Security Policies 29
Summary cont.
IT staff policies must also be in place on how
to handle certain situations
New and exiting employees
Security breaches
Change management systems