Discussion: Mapping Business Challenges to Types of Control
© ITT Educational Services, Inc. All rights reserved.Page 1IS404 Access Control, Authentication and PKI (PKI) © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Access Control, Authentication, and Public Key Infrastructure
Lesson 4 Human Nature and Organizational
Behavior Access Control for Information Systems
Page 2Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Dealing with Human Nature
The unintentional threat
Hackers and motivation
Social engineering
Page 3Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Pre-Employment Checks
What Information Can Be Considered
What Information Cannot be Considered
Applicant’s Rights
Consequences of a Bad Hiring Decision
Page 4Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Ongoing Observation of Personnel
Identify Potentially Disgruntled Employees
Proper Ways to Revoke Access upon Employee Termination
Page 5Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Organizational Structure and Access Control Strategy Access control model based on organizational
structure is designed to prevent social engineering attacks Employees are given access based on tasks they
must complete as part of their job Access rules are based on balance of
confidentiality and necessity Organizational structure model is similar to the
role-based access control (RBAC) model
Page 6Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Job Rotation and Position Sensitivity Job rotation minimizes effects of dishonesty Often used for sensitive positions, especially
those that are directly responsible for crucial information and assets
Page 7Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Requirement for Periodic Vacation Periodic vacations act as a security measure Requiring person to take time off from work
provides time for evidence of dishonesty to surface Can also reduce the success of social engineers
Page 8Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Separation of Duties
Ensures that a single person does not handle all crucial decisions and activities, especially those involving a high level of trust Goal is to avoid the temptation to commit fraud or
other illegal activities
Two-person control Collusion
Monitoring and
oversight
Page 9Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Responsibilities of Access Owners Disclosing to users any relevant legal,
regulatory, or ethical issues surrounding the use or disclosure of the information Implementing a data classification system
and rating the data according to its sensitivity, confidentiality, inherent value, and other factors
Page 10Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Responsibilities of Access Owners (Cont.) Maintaining a list of authorized users Implementing procedures to safeguard
information from unauthorized use, disclosure, alteration, or accidental or intentional destruction Developing a policy governing data retention
and disposition • Providing users with adequate training in the
use and protection of the information
Page 11Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Training Employees
Be ongoing
Include multiple formats
Be interactive
Include multiple points of contact
Page 12Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Security Awareness Training Facts Information technology (IT) security surveys conducted by well-known accounting firms found the following: Many organizations have some awareness
training. Most awareness programs omitted important
elements. Less than 25% of organizations had no way to
track awareness program effectiveness. Source: http://www.lumension.com/Resources/Resource-Center/Protect-Vital-Information-Minimize-Insider-Risks.aspx
Page 13Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Ethics
What is right and what is wrong
Enforcing policies
Human resources involvement
Page 14Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Defining appropriate policies and procedures governing employee behavior Educating employees about the policies and
procedures relevant to them Discovering and addressing behavioral
shortcomings Encouraging create risk-taking
Best Practices for Managing Human Nature
Page 15Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
User Domain Access Control Management
Page 16Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
The Three States of Data • Stored on some device • Archived records
Data at Rest (DAR)
• Sending an e-mail • Retrieving a Web page
Data in Motion (DIM)
• Creating a new document • Processing a paymentData in Process
Page 17Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Use encryption to protect stored data: • Elements in databases • Files on network and shared drives • Files on portable or movable drives,
Universal serial bus (USB), and flash drives • Files and shared drives accessible from the
Internet • Personal computers (PCs), laptop hard
drives, and full disk encryption
Protecting DAR
Page 18Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
DIM
Page 19Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Difficult to protect since it is being operated on by the central processing unit (CPU)
Protecting DIP
Page 20Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Object: An item or a distinct group of information in a data storage system Group information as an object, set controls
at the object level Allows you to manage groups of related
data Helps with DAR and DIM security
Object-Level Security
Page 21Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
A security identifier (SID) that identifies what the ACE applies to—the specific user, group or system An access mask that lists the specific rights
granted or denied Flags to indicate the type of ACE and
whether child objects can inherit the rights from the object that the ACE is attached to
Access Control List Properties
Page 22Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
access-denied
access-allowed
system-audit
Access Control List Types
Page 23Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
DACL and SACL
• Controls access to an object
Discretionary Access Control
List (DACL)
• Handles the information assurance aspect of access controls
System Access Control List
(SACL)
Page 24Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.
Best Practices for Access Controls for Information Systems Create a baseline for access Segregate users’ rights by role Automate user creation Tie access controls to the environment Have a clear standard for decommissioning
data storage devices
- Slide Number 1
- Slide Number 2
- Slide Number 3
- Slide Number 4
- Slide Number 5
- Slide Number 6
- Slide Number 7
- Slide Number 8
- Slide Number 9
- Slide Number 10
- Slide Number 11
- Slide Number 12
- Slide Number 13
- Slide Number 14
- Slide Number 15
- The Three States of Data
- Protecting DAR
- DIM
- Protecting DIP
- Object-Level Security
- Access Control List Properties
- Access Control List Types
- DACL and SACL
- Best Practices for Access Controls for Information Systems