case study 4-5 Pages + charts

profileMbab4
romney_ais14_inppt_08.pptx

Accounting Information Systems

Fourteenth Edition

Chapter 8

Controls for Information Security

Copyright © 2018 Pearson Education, Inc. All Rights Reserved

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

If this PowerPoint presentation contains mathematical equations, you may need to check that your computer has the following installed:

1) MathType Plugin

2) Math Player (free versions available)

3) NVDA Reader (free versions available)

1

Learning Objectives (1 of 2)

Explain how security and the other four principles in the Trust Services Framework affect systems reliability.

Explain two fundamental concepts; why information security is a management issue, and the time-based model of information security.

Discuss the steps criminals follow to execute a targeted attack against an organization’s information system.

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

2

Learning Objectives (2 of 2)

Describe the preventive, detective, and corrective controls that can be used to protect an organization’s information.

Describe the controls that can be used to timely detect that an organization’s information system is under attack.

Discuss how organizations can timely respond to attacks against their information system.

Explain how virtualization, cloud computing, and the Internet of Things affect information security.

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

3

COBIT Controls

210 controls for ensuring information integrity

Subset is relevant for external auditors

IT control objectives for Sarbanes-Oxley, 2nd Edition

AICPA and CICA information systems controls

Controls for system and financial statement reliability

8-4

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

Information for Management Should Be:

Effective

Information must be relevant and timely.

Efficient

Information must be produced in a cost-effective manner.

Confidential

Sensitive information must be protected from unauthorized disclosure.

Integrity

Information must be accurate, complete, and valid.

Available

Information must be available whenever needed.

Compliance

Controls must ensure compliance with internal policies and with external legal and regulatory requirements.

Reliable

Management must have access to appropriate information needed to conduct daily activities and to exercise its fiduciary and governance responsibilities.

8-5

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

Trust Services Framework

Security

Access to the system and data is controlled and restricted to legitimate users.

Confidentiality

Sensitive organizational data is protected.

Privacy

Personal information about trading partners, investors, and employees are protected.

Processing integrity

Data are processed accurately, completely, in a timely manner, and only with proper authorization.

Availability

System and information are available.

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

The trust services framework is a means to organize IT controls to help ensure systems reliability. At the foundation of this framework is security which is absolutely necessary for success and for achieving the other four principles.

Security procedures:

Restrict access to authorized users only

which protects confidentiality of sensitive organizational data and the privacy of personal

data collected from customers, suppliers, employees, and so on.

Security protects the processing integrity by preventing submission of unauthorized transactions or unauthorized changes to the data.

Security provides protection from unwanted attacks that could bring down the system and make it unavailable.

6

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

This is a good visual of the Trust Services Framework

Using an analogy of building a house, you need a good foundation; otherwise the house will fall apart. Then to keep the roof over your head, you need to have wel-constructed walls.

Similarly, for good systems reliability, you need a good foundation of security. The walls are the four pillars focused on maintaining good systems reliability.

7

Security Life Cycle

Security is a management issue

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

8

Security Approach

Time-based model, security is effective if:

P > D + C where

P is time it takes an attacker to break through preventive controls

D is time it takes to detect an attack is in progress

C is time it takes to respond to the attack and take corrective action

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

Organizations try to satisfy the time-based model by employing the strategy of defense-in-depth which is multiple layers of control (preventive and detective) to avoid a single point of failure.

9

Understanding Targeted Attacks

Conduct reconnaissance

Attempt social engineering

Scan and map the target

Research

Execute the attack

Cover tracks

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

These are the six basic steps criminals use to attack an organization’s information system:

Conduct reconnaissance—criminals will try to learn as much as possible about the target and to identify potential vulnerabilities.

Attempt social engineering—criminals will use deception to try and “trick” an unsuspecting employee into granting them access.

Scan and map the target—the attacker uses a variety of automated tools to identify computers that can be remotely accessed and the types of software they are running.

Research—attackers conduct research to find known vulnerabilities for those programs and learn how to take advantage of those vulnerabilities.

Execute the attack—criminal takes advantage of a vulnerability to obtain unauthorized access to the target’s information system.

Cover tracks—most attackers attempt to cover their tracks and create “back doors” that they can use to obtain access if their initial attack is discovered and controls are implemented to block that method of entry.

10

Steps in an IS System Attack

Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall

8-11

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

Conduct Reconnaissance

Attempt Social Engineering

Scan & Map Target

Research

Execute Attack

Cover Tracks

How to Mitigate Risk of Attack

Preventive Controls

Detective Controls

People

Process

IT Solutions

Physical security

Log analysis

Intrusion detection systems

Continuous monitoring

Response

Computer Incident Response Teams (CIRT)

Chief Information Security Officer (CISO)

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

Preventive: People

Culture of security

Tone set at the top with management

Training

Follow safe computing practices

Never open unsolicited e-mail attachments

Use only approved software

Do not share passwords

Physically protect laptops/cellphones

Protect against social engineering

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

Preventive Process: User Access Controls

Authentication—verifies the person

Something person knows

Something person has

Some biometric characteristic

Combination of all three

Authorization—determines what a person can access

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

These two concepts are related, to get into a system, you need to be authenticated, then authorization is where you are allowed to go once you are in the system.

14

Preventive Process: Change Controls and Change Management

Formal process used to ensure that modifications to hardware, software, or processes do not reduce systems reliability

Good change management and control requires

Documentation

Approval

Testing

Develop “backout” plan

Monitoring

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

Characteristics of a well-designed change control and change management process include:

 

Documentation of all change requests, identifying the nature of the change, its rationale, date of request, and outcome of request.

Documented approval of all change requests by management.

Testing of all changes in a separate system, not the one used for daily business processes.

Conversion controls to ensure that data is accurately and completely transferred from the old to the new system.

Updating of all documentation (program instructions, system descriptions, procedures manuals, etc.) to reflect the newly implemented changes.

A special process for timely review, approval, and documentation of emergency changes as soon after the crisis as is practical.

Development and documentation of “backout” plans to facilitate reverting to previous configurations if the new change creates unexpected problems.

Careful monitoring and review of user rights and privileges during the change process to ensure that proper segregation of duties is maintained.

15

Preventive: IT Solutions

Antimalware controls

Network access controls

Device and software hardening controls

Encryption

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

Network Access Control (Perimeter Defense)

Border router

Connects an organization’s information system to the Internet

Firewall

Software or hardware used to filter information

Demilitarized Zone (DMZ)

Separate network that permits controlled access from the Internet to selected resources

Intrusion Prevention Systems (IPS)

Monitors patterns in the traffic flow, rather than only inspecting individual packets, to identify and automatically block attacks

8-17

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

Internet Information Protocols

8-18

Information travels the internet and LAN in the form of packets

Transmission Control Protocol (TCP) specifies the procedures for dividing files into packets and the method for reassembly when it reaches its destination

Specifies the size of the header and information field sequence

Internet Protocol (IP) specifies the structure of the packets and how to route them to their destination

IP contains a header (origin and destination) and body

Access Control Lists (ACL) is a list of rules that determines which packets are allowed entry

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

Device and Software Hardening (Internal Defense)

End-Point Configuration

Disable unnecessary features that may be vulnerable to attack on:

Servers, printers, workstations e.g. a buffer-overflow attack

User Account Management

Software Design

Programmers must be trained to treat all input from external users as untrustworthy and to carefully check it before performing further actions.

8-19

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

Preventive: Physical Security: Access Controls

Physical security access controls

Limit entry to building

Restrict access to network and data

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

Detecting Attacks

Log Analysis—examining logs to identify evidence of possible attacks

Intrusion Detection Systems (IDSs) —system that creates logs of network traffic that was permitted to pass the firewall and then analyzes those logs for signs of attempted or successful intrusions

Continuous Monitoring—employee compliance with organization’s information security policies and overall performance of business processes

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

Responding to Attacks

Computer Incident Response Team (CIRT)

Chief Information Security Officer (CISO)

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

Security Implications of Virtualization, Cloud Computing, and the Internet of Things

Virtualization and Cloud Computing

Positive impact on security

Implementing strong access controls is good security over all the systems

Negative impact on security

Reliability issues

Risk of theft or destruction if unsupervised physical access

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

Virtualization and Cloud computing can increase risks possibly by:

Unsupervised physical access in virtualization environment exposes the entire virtual network to risk of theft or destruction

Public clouds may have reliability issues because the organization is outsourcing control of its data and computing resources to a third party

However, there are opportunities to improve overall security by:

Implementing strong access controls in the cloud and use multifactor authentication.

 

Internet of Things (IoT) refers to embedding sensors in a multitude of devices so they can connect to the Internet. Again there is a net effect of positive and negative effects.

The major issue is that since these devices are connected to the Internet, there are more ways to gain access to the corporate network and must be secured.

23

Key Terms

Time-based model of security

Defense-in-depth

Social engineering

Authentication

Biometric identifier

Multifactor authentication

Multimodal authentication

Authorization

Access control matrix

Compatibility test

Penetration test

Change control and change management

Border router

Firewall

Demilitarized zone (DMZ)

Routers

Access control list (ACL)

Packet filtering

Deep packet inspection

Intrusion prevention system

Endpoints

Vulnerabilities

Vulnerability scanners

Exploit

Patch

Patch management

Hardening

Log analysis

Intrusion detection system (IDS)

Computer incident response team (CIRT)

Virtualization

Cloud Computing

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

24

Copyright © 2018 Pearson Education, Inc.

Chapter 8: Controls for Information Security

Slide 1 - ‹#›

25