Part I.
1. In your Lab Report file, document the non-profit organization that manages and
publishes the Controls.
A. The SANS Institute
4.
7. In the Lab Report file, summarize each section of the control’s description. –
a. Inventory of Authorized and Unauthorized Devices – Provides access control
to authorized devices
b. Unauthorized Software Inventory of Authorized and Unauthorized Software
– This manages software on the network to prevent unauthorized installs
c. Secure Configuration of End-User Devices – Actively manages security
configurations on laptops, servers, and workstations
d. Continuous Vulnerability Assessment & Remediation – Response to new
information to identify vulnerabilities, in order to remediate
e. Controlled Use of Administrative Privileges - Uses automated tools as a method
to inventory all administrative accounts and validate that each person with
administrative privileges on desktops, laptops, and servers is authorized by a
senior executive.
f. Maintenance, Monitoring, and Analysis of Audit Logs - Verifies audit log
settings for hardware and software installed on company devices, ensuring that
logs include a date, timestamp, source addresses, destination addresses, and
various other useful elements of each packet and/or transaction.
g. Email and Web Browser Protections - Ensure that only fully supported web
browsers and email clients are allowed to execute in the organization
h. Malware Defense - Deploy anti-malware software that provides a centralized
infrastructure that compiles information on file reputations.
i. Limitation & Control of Network Ports, Protocols, and Service - Operate
critical services on separate physical or logical host machines
j. Data Recovery Capability - Ensure that key systems have at least one backup
destination that is not continuously addressable through operating system
k. Secure Configuration of Network Devices - Manage network devices using
two-factor authentication and encrypted sessions.
l. Boundary Defense - Periodically scan for back-channel connections to the
Internet that bypass the DMZ,
m. Data Protection - Perform an assessment of data to identify sensitive information
that requires encryption and integrity controls
n. Controlled Access Based on Need to Know – Specifies that all communication
of sensitive information over less-trusted networks should be encrypted.
o. Wireless Access Control - Use wireless intrusion detection systems (WIDS) to
identify rogue wireless devices and detect attack attempts and successful
compromises.
p. Account Monitoring and Control - Review all system accounts and disable any
account that cannot be associated with a business process and owner.
q. Security Skills Assessment and Appropriate Training - Deliver training to fill
the skills gap.
r. Application Software Security - Maintain separate environments for production
and nonproduction systems.
s. Incident Response and Management - Assigns job titles and duties for handling
computer and network incidents to specific individuals.
t. Penetration Tests and Red Team Exercises - Plan clear goals of the penetration
test itself with blended attacks in mind
8. In the Lab Report file, describe each guideline for implementing this control.
A. Physical Security - The wireless station and its WLAN adaptor card should not be
physically exposed to prevent theft and unauthorized access to the WLAN.
B. Confidentiality and Integrity - Confidential or important information should not be
transmitted unprotected over the WLAN.
C. Key Management – The symmetric encryption keys, e.g. the WEP keys stored in the
access points and wireless stations, should be protected from unauthorized access.
D. User Authentication - The access control mechanisms supported by the WLAN
technology, e.g. using the ESSID, the MAC address and the WEP key, only verify
authorized wireless stations but not the users.
E. Access Control - The access point should be configured to allow only authorized
wireless stations to associate with the WLAN.
F. Client security - Access control and intrusion detection mechanisms should be installed
on the wireless station where possible to prevent and detect any unauthorized access to
the wireless station over the WLAN.
G. User Awareness - Where it is not required, the users should not be allowed to set up their
wireless stations in ad-hoc mode and communicate with each other without going
through the access point.
H. Administration of access points - The access to WLAN key distribution program should
be controlled and limited to the administrators only.
I. Availability - The WLAN is vulnerable to denial of service attacks such as network
jamming.
J. Logging and Audit Trails - Unauthorized network traffic and access to the WLAN
should be logged, e.g. using Intrusion Detection System, to detect attacks directed over
the WLAN.
15. Describe the various components that make up a typical IT security policy.
A. Purpose - To establish a general approach to information security. To detect and
forestall the compromise of information security such as misuse, etc.
B. Scope - Address all data, programs, systems, facilities, other tech infrastructure,
users of technology and third parties in each organization.
C. Information security objectives – Attempts to compose a working ISP that have
well-defined objectives concerning security and strategy on which management
could agree with.
D. Authority & Access Control Policy – The hierarchical pattern.
E. Classification of Data - Data classification determines the exact measures data
custodian needs to take to preserve the integrity of data.
F. Data Support & Operations – This is a way to regulate general system
mechanisms responsible for data protection, data backups, and movement of data.
Part II.
G. Security Awareness Sessions – In this step you ensure that the staff is familiar
with the document, as well as understands it.
H. Responsibilities, Rights and Duties of Personnel – This section covers who is
responsible for carrying out the implementation, education, incident response,
user access reviews, and periodic updates of an ISP.
I. User Authentication Policy Statement
The purpose of this policy is to provide an authentication method for all users to
authenticate against a centralized database. This security framework will ensure
that the company is protected, from unauthorized access, data loss or damage
while supporting availability for all clients. This data could be on a stand-alone
network, digital, shared or used for other purposes. Additional standards and
procedures will be published separately.
Failure to comply with this policy statement could be subject to disciplinary
action or other potential penalties.
II. Authorized Networked Devices Policy Statement
Access to and use of ABC Holdings INC. network services are privileges
accorded at the discretion of the ABC Holdings INC. Devices connected to the
ABC Holdings INC. network must comply with the minimum standards for
security set by the International Organization for Standardization (ISO) and the
International Electrotechnical Commission (IEC). ABC Holdings or service
providers may develop stricter standards for themselves. Devices that do not meet
minimum standards for networked host security configurations may be
disconnected.
III. Email Acceptable Use Policy Statement
ABC Holdings INC. intent for establishing an Email Acceptable Use Policy are
not to impose guidelines that are contradictory with ABC Holdings INC.
established culture of openness, trust and integrity. ABC Holdings INC. is
dedicated to protecting ABC Holdings INC. employees, partners and the company
from illegal or damaging actions by individuals, either knowingly or
unknowingly.
Internet/Intranet/Extranet-related systems, including but not limited to computer
equipment, software, operating systems, storage media, network accounts
providing electronic mail, WWW browsing, and FTP, are the property of ABC
Holdings INC. All systems are to be used solely for purposes in serving the
business interests of the company, and of our clients and customers in the course
of normal operations. Please review ABC Holdings INC. Information Systems
Security Policy for further details. Effective security is the responsibility of the
whole, which involves the participation and support of every ABC Holdings INC.
employee and affiliate who deals with information and/or information systems. It
is the responsibility of every computer user to know and understand these
guidelines, and to conduct their activities accordingly.
Part III.
2. The Lab Topology does meet the necessary requirements, for confidentiality and
integrity, client security, availability, logging and audit trails, access control, and
administration of access points. However, it does not meet the requirements for key
management, user authentication, or physical security requirements.
3. The main requirement that would need to be added to the Tzami-7, PFSense, Accounting,
BestBuy Web Server, and Tzanagi-K machines, would be some user authentication for
each machine. At the present time these machine are able to be access with no type of
authentication. Logging and audit trails was satisfied for those machines.
14.
ttpsi//mmw.draw.io/#LHampton_SecurityPolicies
p-o|
Ei
Horpton
x
Google|
©
£8
serch
~|
BW
Share
Hampton_SecurityPolicies
File
Edit
View
Arrange
Extras
Help
Ail
Fix
100%
QQ
wow
z
Pp
sy py $e
a
Set
r
AD
"
»
Cisco
/
Modems
and
Phones
»
Cisco
/
People
»
Cisco
Routers,
2
»
Cisco
/
Security
Ror
ta
>
Cisco
/
Servers
»
Cisco//
Storage
>
Cisco
/
Switches
~
Cisco/
Wireless