Discussion: Mapping Business Challenges to Types of Control

profiledonman555
Week4Slideschapts78.pdf

© ITT Educational Services, Inc. All rights reserved.Page 1IS404 Access Control, Authentication and PKI (PKI) © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Access Control, Authentication, and Public Key Infrastructure

Lesson 4 Human Nature and Organizational

Behavior Access Control for Information Systems

Page 2Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Dealing with Human Nature

The unintentional threat

Hackers and motivation

Social engineering

Page 3Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Pre-Employment Checks

What Information Can Be Considered

What Information Cannot be Considered

Applicant’s Rights

Consequences of a Bad Hiring Decision

Page 4Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Ongoing Observation of Personnel

Identify Potentially Disgruntled Employees

Proper Ways to Revoke Access upon Employee Termination

Page 5Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Organizational Structure and Access Control Strategy  Access control model based on organizational

structure is designed to prevent social engineering attacks  Employees are given access based on tasks they

must complete as part of their job  Access rules are based on balance of

confidentiality and necessity Organizational structure model is similar to the

role-based access control (RBAC) model

Page 6Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Job Rotation and Position Sensitivity  Job rotation minimizes effects of dishonesty Often used for sensitive positions, especially

those that are directly responsible for crucial information and assets

Page 7Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Requirement for Periodic Vacation  Periodic vacations act as a security measure  Requiring person to take time off from work

provides time for evidence of dishonesty to surface  Can also reduce the success of social engineers

Page 8Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Separation of Duties

 Ensures that a single person does not handle all crucial decisions and activities, especially those involving a high level of trust Goal is to avoid the temptation to commit fraud or

other illegal activities

Two-person control Collusion

Monitoring and

oversight

Page 9Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Responsibilities of Access Owners Disclosing to users any relevant legal,

regulatory, or ethical issues surrounding the use or disclosure of the information  Implementing a data classification system

and rating the data according to its sensitivity, confidentiality, inherent value, and other factors

Page 10Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Responsibilities of Access Owners (Cont.) Maintaining a list of authorized users  Implementing procedures to safeguard

information from unauthorized use, disclosure, alteration, or accidental or intentional destruction Developing a policy governing data retention

and disposition  • Providing users with adequate training in the

use and protection of the information

Page 11Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Training Employees

Be ongoing

Include multiple formats

Be interactive

Include multiple points of contact

Page 12Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Security Awareness Training Facts Information technology (IT) security surveys conducted by well-known accounting firms found the following: Many organizations have some awareness

training. Most awareness programs omitted important

elements.  Less than 25% of organizations had no way to

track awareness program effectiveness. Source: http://www.lumension.com/Resources/Resource-Center/Protect-Vital-Information-Minimize-Insider-Risks.aspx

Page 13Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Ethics

What is right and what is wrong

Enforcing policies

Human resources involvement

Page 14Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Defining appropriate policies and procedures governing employee behavior  Educating employees about the policies and

procedures relevant to them Discovering and addressing behavioral

shortcomings  Encouraging create risk-taking

Best Practices for Managing Human Nature

Page 15Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

User Domain Access Control Management

Page 16Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

The Three States of Data • Stored on some device • Archived records

Data at Rest (DAR)

• Sending an e-mail • Retrieving a Web page

Data in Motion (DIM)

• Creating a new document • Processing a paymentData in Process

Page 17Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Use encryption to protect stored data: • Elements in databases • Files on network and shared drives • Files on portable or movable drives,

Universal serial bus (USB), and flash drives • Files and shared drives accessible from the

Internet • Personal computers (PCs), laptop hard

drives, and full disk encryption

Protecting DAR

Page 18Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

DIM

Page 19Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Difficult to protect since it is being operated on by the central processing unit (CPU)

Protecting DIP

Page 20Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Object: An item or a distinct group of information in a data storage system Group information as an object, set controls

at the object level Allows you to manage groups of related

data Helps with DAR and DIM security

Object-Level Security

Page 21Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

A security identifier (SID) that identifies what the ACE applies to—the specific user, group or system An access mask that lists the specific rights

granted or denied  Flags to indicate the type of ACE and

whether child objects can inherit the rights from the object that the ACE is attached to

Access Control List Properties

Page 22Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

access-denied

access-allowed

system-audit

Access Control List Types

Page 23Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

DACL and SACL

• Controls access to an object

Discretionary Access Control

List (DACL)

• Handles the information assurance aspect of access controls

System Access Control List

(SACL)

Page 24Access Control, Authentication, and PKI © 2015 Jones and Bartlett Learning, LLC, an Ascend Learning Company www.jblearning.com All rights reserved.

Best Practices for Access Controls for Information Systems Create a baseline for access Segregate users’ rights by role Automate user creation Tie access controls to the environment Have a clear standard for decommissioning

data storage devices

  • Slide Number 1
  • Slide Number 2
  • Slide Number 3
  • Slide Number 4
  • Slide Number 5
  • Slide Number 6
  • Slide Number 7
  • Slide Number 8
  • Slide Number 9
  • Slide Number 10
  • Slide Number 11
  • Slide Number 12
  • Slide Number 13
  • Slide Number 14
  • Slide Number 15
  • The Three States of Data
  • Protecting DAR
  • DIM
  • Protecting DIP
  • Object-Level Security
  • Access Control List Properties
  • Access Control List Types
  • DACL and SACL
  • Best Practices for Access Controls for Information Systems