case study 4-5 Pages + charts
Accounting Information Systems
Fourteenth Edition
Chapter 8
Controls for Information Security
Copyright © 2018 Pearson Education, Inc. All Rights Reserved
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
If this PowerPoint presentation contains mathematical equations, you may need to check that your computer has the following installed:
1) MathType Plugin
2) Math Player (free versions available)
3) NVDA Reader (free versions available)
1
Learning Objectives (1 of 2)
Explain how security and the other four principles in the Trust Services Framework affect systems reliability.
Explain two fundamental concepts; why information security is a management issue, and the time-based model of information security.
Discuss the steps criminals follow to execute a targeted attack against an organization’s information system.
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
2
Learning Objectives (2 of 2)
Describe the preventive, detective, and corrective controls that can be used to protect an organization’s information.
Describe the controls that can be used to timely detect that an organization’s information system is under attack.
Discuss how organizations can timely respond to attacks against their information system.
Explain how virtualization, cloud computing, and the Internet of Things affect information security.
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
3
COBIT Controls
210 controls for ensuring information integrity
Subset is relevant for external auditors
IT control objectives for Sarbanes-Oxley, 2nd Edition
AICPA and CICA information systems controls
Controls for system and financial statement reliability
8-4
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
Information for Management Should Be:
Effective
Information must be relevant and timely.
Efficient
Information must be produced in a cost-effective manner.
Confidential
Sensitive information must be protected from unauthorized disclosure.
Integrity
Information must be accurate, complete, and valid.
Available
Information must be available whenever needed.
Compliance
Controls must ensure compliance with internal policies and with external legal and regulatory requirements.
Reliable
Management must have access to appropriate information needed to conduct daily activities and to exercise its fiduciary and governance responsibilities.
8-5
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
Trust Services Framework
Security
Access to the system and data is controlled and restricted to legitimate users.
Confidentiality
Sensitive organizational data is protected.
Privacy
Personal information about trading partners, investors, and employees are protected.
Processing integrity
Data are processed accurately, completely, in a timely manner, and only with proper authorization.
Availability
System and information are available.
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
The trust services framework is a means to organize IT controls to help ensure systems reliability. At the foundation of this framework is security which is absolutely necessary for success and for achieving the other four principles.
Security procedures:
Restrict access to authorized users only
which protects confidentiality of sensitive organizational data and the privacy of personal
data collected from customers, suppliers, employees, and so on.
Security protects the processing integrity by preventing submission of unauthorized transactions or unauthorized changes to the data.
Security provides protection from unwanted attacks that could bring down the system and make it unavailable.
6
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
This is a good visual of the Trust Services Framework
Using an analogy of building a house, you need a good foundation; otherwise the house will fall apart. Then to keep the roof over your head, you need to have wel-constructed walls.
Similarly, for good systems reliability, you need a good foundation of security. The walls are the four pillars focused on maintaining good systems reliability.
7
Security Life Cycle
Security is a management issue
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
8
Security Approach
Time-based model, security is effective if:
P > D + C where
P is time it takes an attacker to break through preventive controls
D is time it takes to detect an attack is in progress
C is time it takes to respond to the attack and take corrective action
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
Organizations try to satisfy the time-based model by employing the strategy of defense-in-depth which is multiple layers of control (preventive and detective) to avoid a single point of failure.
9
Understanding Targeted Attacks
Conduct reconnaissance
Attempt social engineering
Scan and map the target
Research
Execute the attack
Cover tracks
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
These are the six basic steps criminals use to attack an organization’s information system:
Conduct reconnaissance—criminals will try to learn as much as possible about the target and to identify potential vulnerabilities.
Attempt social engineering—criminals will use deception to try and “trick” an unsuspecting employee into granting them access.
Scan and map the target—the attacker uses a variety of automated tools to identify computers that can be remotely accessed and the types of software they are running.
Research—attackers conduct research to find known vulnerabilities for those programs and learn how to take advantage of those vulnerabilities.
Execute the attack—criminal takes advantage of a vulnerability to obtain unauthorized access to the target’s information system.
Cover tracks—most attackers attempt to cover their tracks and create “back doors” that they can use to obtain access if their initial attack is discovered and controls are implemented to block that method of entry.
10
Steps in an IS System Attack
Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall
8-11
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
Conduct Reconnaissance
Attempt Social Engineering
Scan & Map Target
Research
Execute Attack
Cover Tracks
How to Mitigate Risk of Attack
Preventive Controls
Detective Controls
People
Process
IT Solutions
Physical security
Log analysis
Intrusion detection systems
Continuous monitoring
Response
Computer Incident Response Teams (CIRT)
Chief Information Security Officer (CISO)
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
Preventive: People
Culture of security
Tone set at the top with management
Training
Follow safe computing practices
Never open unsolicited e-mail attachments
Use only approved software
Do not share passwords
Physically protect laptops/cellphones
Protect against social engineering
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
Preventive Process: User Access Controls
Authentication—verifies the person
Something person knows
Something person has
Some biometric characteristic
Combination of all three
Authorization—determines what a person can access
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
These two concepts are related, to get into a system, you need to be authenticated, then authorization is where you are allowed to go once you are in the system.
14
Preventive Process: Change Controls and Change Management
Formal process used to ensure that modifications to hardware, software, or processes do not reduce systems reliability
Good change management and control requires
Documentation
Approval
Testing
Develop “backout” plan
Monitoring
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
Characteristics of a well-designed change control and change management process include:
Documentation of all change requests, identifying the nature of the change, its rationale, date of request, and outcome of request.
Documented approval of all change requests by management.
Testing of all changes in a separate system, not the one used for daily business processes.
Conversion controls to ensure that data is accurately and completely transferred from the old to the new system.
Updating of all documentation (program instructions, system descriptions, procedures manuals, etc.) to reflect the newly implemented changes.
A special process for timely review, approval, and documentation of emergency changes as soon after the crisis as is practical.
Development and documentation of “backout” plans to facilitate reverting to previous configurations if the new change creates unexpected problems.
Careful monitoring and review of user rights and privileges during the change process to ensure that proper segregation of duties is maintained.
15
Preventive: IT Solutions
Antimalware controls
Network access controls
Device and software hardening controls
Encryption
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
Network Access Control (Perimeter Defense)
Border router
Connects an organization’s information system to the Internet
Firewall
Software or hardware used to filter information
Demilitarized Zone (DMZ)
Separate network that permits controlled access from the Internet to selected resources
Intrusion Prevention Systems (IPS)
Monitors patterns in the traffic flow, rather than only inspecting individual packets, to identify and automatically block attacks
8-17
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
Internet Information Protocols
8-18
Information travels the internet and LAN in the form of packets
Transmission Control Protocol (TCP) specifies the procedures for dividing files into packets and the method for reassembly when it reaches its destination
Specifies the size of the header and information field sequence
Internet Protocol (IP) specifies the structure of the packets and how to route them to their destination
IP contains a header (origin and destination) and body
Access Control Lists (ACL) is a list of rules that determines which packets are allowed entry
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
Device and Software Hardening (Internal Defense)
End-Point Configuration
Disable unnecessary features that may be vulnerable to attack on:
Servers, printers, workstations e.g. a buffer-overflow attack
User Account Management
Software Design
Programmers must be trained to treat all input from external users as untrustworthy and to carefully check it before performing further actions.
8-19
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
Preventive: Physical Security: Access Controls
Physical security access controls
Limit entry to building
Restrict access to network and data
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
Detecting Attacks
Log Analysis—examining logs to identify evidence of possible attacks
Intrusion Detection Systems (IDSs) —system that creates logs of network traffic that was permitted to pass the firewall and then analyzes those logs for signs of attempted or successful intrusions
Continuous Monitoring—employee compliance with organization’s information security policies and overall performance of business processes
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
Responding to Attacks
Computer Incident Response Team (CIRT)
Chief Information Security Officer (CISO)
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
Security Implications of Virtualization, Cloud Computing, and the Internet of Things
Virtualization and Cloud Computing
Positive impact on security
Implementing strong access controls is good security over all the systems
Negative impact on security
Reliability issues
Risk of theft or destruction if unsupervised physical access
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
Virtualization and Cloud computing can increase risks possibly by:
Unsupervised physical access in virtualization environment exposes the entire virtual network to risk of theft or destruction
Public clouds may have reliability issues because the organization is outsourcing control of its data and computing resources to a third party
However, there are opportunities to improve overall security by:
Implementing strong access controls in the cloud and use multifactor authentication.
Internet of Things (IoT) refers to embedding sensors in a multitude of devices so they can connect to the Internet. Again there is a net effect of positive and negative effects.
The major issue is that since these devices are connected to the Internet, there are more ways to gain access to the corporate network and must be secured.
23
Key Terms
Time-based model of security
Defense-in-depth
Social engineering
Authentication
Biometric identifier
Multifactor authentication
Multimodal authentication
Authorization
Access control matrix
Compatibility test
Penetration test
Change control and change management
Border router
Firewall
Demilitarized zone (DMZ)
Routers
Access control list (ACL)
Packet filtering
Deep packet inspection
Intrusion prevention system
Endpoints
Vulnerabilities
Vulnerability scanners
Exploit
Patch
Patch management
Hardening
Log analysis
Intrusion detection system (IDS)
Computer incident response team (CIRT)
Virtualization
Cloud Computing
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
24
Copyright © 2018 Pearson Education, Inc.
Chapter 8: Controls for Information Security
Slide 1 - ‹#›
25