1 / 7100%
CSCI 601\Lab 2
Lab Deliverable Files
1. In your Lab Report file, document the non-profit organization that manages and
publishes the Controls.
The Center for Strategic and International Studies (CSIS)
2. Make a screen capture showing the complete list of Critical Security Controls and paste
it into your Lab Report file.
3. In the Lab Report file, summarize each section of the control’s description.
The processes and tools used to track/control/prevent/correct the security use of wireless local
area networks (LANS), access points, and wireless client systems.
4. In the Lab Report file, describe each guideline for implementing this control.
CSC 15: Wireless Access Control
- Ensure that each wireless device connected to the network matches an authorized configuration and
security profile, with a documented owner of the connection and a defined business need. Organizations
should deny access to those wireless devices that do not have such a configuration and profile
- Configure network vulnerability scanning tools to detect wireless access points connected to the wired
network. Identified devices should be reconciled against a list of authorized wireless access points.
Unauthorized (i.e., rogue) access points should be deactivated.
- Use wireless intrusion detection systems (WIDS) to identify rogue wireless devices and detect attack
attempts and successful compromises. In addition to WIDS, all wireless traffic should be monitored by
WIDS as traffic passes into the wired network.
- Where a specific business need for wireless access has been identified, configure wireless access on
client machines to allow access only to authorized wireless networks. For devices that do not have an
essential wireless business purpose, disable wireless access in the hardware configuration (basic
input/output system or extensible firmware interface).
- Ensure that all wireless traffic leverages at least Advanced Encryption Standard (AES) encryption used
with at least Wi-Fi Protected Access 2 (WPA2) protection.
- Ensure that wireless networks use authentication protocols such as Extensible Authentication Protocol
Transport Layer Security (EAP/TLS), which provide credential protection and mutual authentication.
- Disable peer-to-peer wireless network capabilities on wireless clients.
- Disable wireless peripheral access of devices (such as Bluetooth), unless such access is required for a
documented business need.
- Create separate virtual local area networks (VLANs) for BYOD systems or other untrusted devices.
Internet access from this VLAN should go through at least the same border as corporate traffic. Enterprise
access from this VLAN should be treated as untrusted and filtered and audited accordingly.
5. In your Lab Report file, describe the various components that make up a typical IT
security policy.
The security policy’s components include: overview, purpose, scope, policy, policy compliance,
exceptions, non-compliance, related standards, policies and procedures, definitions and terms,
and revision history.
6. In your Lab Report file, write a sample requirement statement that would be a part of
each of the following policies.
User Authentication Policy: All users at Liberty Beverages will have a network account created upon
employment. They will be issued a Common Access Card (CAC) that will house the authentication
certificate in order to log into the network. They will have a six digit PIN that will have to be used in
conjunction the CAC that will verify they have the authority to access the network and computer systems.
Authorized Networked Devices Policy: All networked devices will be approved through the Chief
Information Security Officer and the Network Administrators. All devices will have to be pre-approved,
configured, and maintained by the net admins. Only company purchased IT equipment is authorized on
the network. There is no bring your own device (BYOD) program at Liberty Beverages.
Email Acceptable Use Policy: All employees that require and email account will use it for official use
and business purposed only. Email will not be used for monetary gain (example: to sell your car),
harassment, explicit content, or any form of joke emails. Personal identifiable information or sensitive
information can be sent, only if it is encrypted.
7. In your Lab Report file describe how the existing lab topology meets or fails to meet the
conditions in the standard you defined in Part 2 of this lab.
There are no firewalls or intrusion detection set up. There is no separate VLAN for BYOD
options. This topology fails to meet the conditions.
8. In your Lab Report file describe what you would add, modify, or delete to fulfill the
requirements of that standard.
I would add a firewall, intrusion detection, proxy server, a separate VLAN for BYOD. I would
make sure that all the switches and access points and wireless routers passwords were changed as
well as the default admin accounts on all the systems on the network to include servers.
9. Make a screen capture showing your completed network diagram and paste it into your
Lab Report file.
Lab Assessment Questions & Answers
1. Describe the Critical Security Controls and identify the organization that manages
them.
Critical Security Controls are a set of actionable controls to cover nearly all areas of
information security. The SANS Institute manages the critical security controls.
2. What is the difference between a policy and a standard?
Policy contains roles and responsibilities and defines what is covered as the company
law. The policy answers questions pertaining to why and who.
Standards define what should be the normal or acceptable way to implement a policy.
Standards answer the question of what, most commonly about the technology to be used.
3. Describe how business travelers are vulnerable to exploitation of their laptops or
workstations. How might hackers use that vulnerability?
A standard that allows employees in the field access to the corporate network while
traveling could expose the company to access from unauthorized personnel. If an
employee uses a laptop and it is not properly updated regularly by the sys admins, the
vulnerabilities could be exploited by a hacker. Telework can introduce a lot of threats to a
network, if the system is not patched or updated regularly.
4. According to the SANS Institute, what is a control system?
A control system is hardware and software that monitor and control physical equipment
and processes for critical infrastructures.
5. Describe the system entity relationship diagram for the Wireless Access Control.
6. *OMITTED**How does the SANS Institute categorize the guidelines for
implementation of a security control? For example, what categories appear in the
implementation controls for the Wireless Access Control? *OMITTED*
7. What are the two kinds of metrics offered with most of the Critical Security
Controls?
Critical Security Controls include two sets of metrics: effectiveness and automation
metrics.
8. What Critical Security Control might be most related to security information and
event management (SIEM)?
CSC 6: Maintenance, Monitoring, and Analysis of Audit Logs
Challenge Questions
1. Conduct additional research about the Critical Security Controls. What is another
name commonly associated with this same set of controls?
Another name associated with the Critical Security Controls is the Center for Strategic &
International Studies or CSIS. In the fall of 2008, the Center for Strategic and
International Studies had convened a bipartisan panel, at the request two leading
members of Congress, called the Commission on Cybersecurity for the 44th Presidency.
The Commission's report made CSIS a respected source of guidance on cyber security. As
a continuation of the Commission's work, it was natural for CSIS to become the first
publisher of the CIS Critical Controls.
2. Download the Wireless Communication Policy template from the
http://www.sans.org/ security-resources/policies/ Web site. Customize the policy
components for the Liberty Beverages Corporation. Save the file as
lastname_WirelessPolicy, where lastname is your own last name.
Students also viewed