There is one specific control that comes to mind when I think of when taking
preventative measures, and that would be " Continuous Vulnerability Management".
This control monitors systems configurations, unauthorized access, and patching. It's
also integrated with tools anticipate the level of threats, facilitates data configuration,
special code for writing security checklist. Controls are necessary when addressing
network security concerns and should always be used as a robust approach. Another
important thing to remember is that controls normally depend on each other to be
more sufficient. Until this week I never knew how preventative controls could be, and
how they actually play a major role when it comes to securing networks. There are
more controls that have many different functions and I do think that it would be of a
great advantage to me to familiarize myself with these tools. Audit logs are very
important in the overall security of a network as it is the logs that tells you what is
going on within the network. There are a log of problems with logs, however. One
is that the logs have to be setup properly to assure you are getting what you need
without flooding your log servers with junk you will have problems monitoring. So,
finding the correct logging level is of utmost importance. zz Another issue with logging
is time. It is very important that all of your systems are set to the exact same time
so that the logs coming in from different systems will make sense. This is done, of
course, by enforcing NTP on all systems using the same time source. Another issue
with logging is correlation - taking logs from different servers and network equipment
for the same event and putting them together to get the big picture. For this, you will
need a SIEM tool. SIEM stands for Security Information and Event Management. I
chose to write about physical controls. physical controls are those things that we
physically put in place to make sure access is denied to anyone who is not supposed
to have it, while still giving access to those who need it. physical controls can range
from a security camera, keypad, security gaurd, ID badges, alarm systems and so
forth. physical controls break down into three categories deterrent, detective, and
preventative. all of this help to keep the bad guys out and keep giving the good guys
control. physical controls are just some of the controls that can be established in
protecting our technology and its systems. controls are important at every level of
security and should always be kept as a top priority because even the smallest slip up
can leave a system vulnerable to any type of attack. ACL's or Access Control Lists
protect and improve a network by controlling the flow and access or restrictions on a
given network. ACL's will perform their function based on a set of determined rules
that can automatically deny access to certain types of packets or IP addresses. ACL's
are emplaced on routers and switches and direct the flow of data while monitoring the
network, improving performance, and enhancing security. ACL's are most commonly
found on Windows and Linux server operating systems as these two OS's are most
commonly used on large networks.ACL's can also be used to protect and control
filesystems. These filesystem control measures can govern user accounts based on
privilege. "A filesystem ACL is a table that informs a computer operating system of
the access privileges a user has to a system object, including a single file or a file
directory. Each object has a security property that connects it to its access control list.
The list has an entry for every user with access rights to the system. Typical
privileges include the right to read a single file (or all the files) in a directory, to
execute the file, or to write to the file or files. Operating systems that use an ACL
include, for example, Microsoft Windows NT/2000, Novell’s Netware, Digital’s
OpenVMS, and UNIX-based systems." CAC is another form of two factor
authentication, with the card being "something you have" and the pin being
"something you know". There are three total factors of authentication, the third being
"something you are", such as fingerprints or iris scans and you can have three factor
authentication where the authentication system requires all three. There is also multi-
factor authentication where you use one or more of the factors more than one time.
For example, at my bank, you have to use a password to sign in and then once in
the website, you have to provide a pin. Both are something you know. I had one
multi-factor system that you would login with a password and you would receive a
phone call. When you answered you had to provide a pin as well, so it was two
factor (something you know - password and something you have - phone) with a
second factor for the pin input during the call. When it comes to countermeasures and
controls we are faced with many aspects. The control I would like to discuss this
week is password control. When it comes to securing a system and its data we are
met with one of its first lines of defense, Which is the password. according to NIST,
Allowing special characters and spaces can help to increase the password strength,
coupled with increasing the password length to further increase difficulty in cracking a
password. Permitting users to paste text is also another great way to help secure
passwords, because this allows a user to use a password manager. keep note that the
passwords should be hashed and salted in case of theft when using a password
manager. Multifactor authentication is another way we can defend our systems and our
data. The use of hardware and software tokens can reduce the chances of information
falling into the wrong hands tremendously. Most of all, we need to ensure that we
train users in these practices to increase their effectiveness. After considering the
discussions below from our classmates, I have decided to write my discussion piece
this week related to technical detective controls. Detection mainly relies on threat
identification or patterned behavior, which works great for a majority of threats. If a
threat type or style is recognized by a physical firewall or an antivirus/anti-malware
software, it can be immediately flagged, quarantined, and/or deleted with little-to-no
input nor confirmation from the end user. This works great in an enterprise/corporate
settings where end users have non-administrative roles, but still require wider system
access for tools, information, databases, etc. In case malicious activity such as a
suspicious process or port is called, the detection method is triggered and the
designated action is taken- usually automatically.The effectiveness of a technical
detective control is only as good as the implementation's definitions and rules. For
example, if the control were to have out-of-date virus definitions, what could be
considered a "common and highly detectable" infection to most could wreak havoc on
a system that does not recognize the threat as malicious. Processes may end up
running on your server, replicating and propagating along the way, and damaging or
stealing data in the process. Stolen passwords are one thing- a reset will remove
access from the bad actor- but stolen consumer information or other business data has
the potential to bring down a company from the loss of integrity & confidentiality.
ontrols are countermeasures used to treat risks. Within the categories of administrative
or technical controls, there can be preventative, detective, and responsive types of
controls. Technical Controls such as antivirus software, firewalls, and IPSs; and
Administrative Controls like separation of duties, data classification, and auditing.The
specific control I am going to talk about is the Administrative Control that is refer to
policies, procedures, or guidelines that define personnel or business practices in
accordance with the organization's security goals.Administrative Control involve some
manner of prior planning and avoidance. The Administrative Control is second lowest
control because they require workers to actively think and offer temporary solution to
a problem. Companies may need to continuous training or re-certificate for their
workers for the initial investment of the three more desirable hazard control in values.
An example of Administrative Control is a weekly set maintenance set by the
company. I work in an assisted living home where every Thursday at 11am there is a
beep, a trouble message display on the panel screen than the alarm company ADT
call with a warning to us that they have received a trouble warning coming from our
building. Because we as employees taught by the company that the generator set to
test itself every Thursday around this time therefore we don’t panic but give the pass
code when ask by the ADT operator. I decided to write about Physical Security
Controls this week after watching a program on TV about a laptop that was stolen
from a NASA employee and that laptop led to the hacking of the International Space
Station. Physical security controls are means and devices to control physical access to
sensitive information and to protect the availability of that information. Protecting all
of your equipment is a vital task in keeping data safe from others. These security
elements are necessary to ensure that unauthorized persons are kept away from
physical spaces and assets where they could represent a potential threat. All types of
computers, computing devices, and associated communications facilities must be
thought of as sensitive assets and places to be protected. Some examples of physical
security controls are physical access systems including guards and receptionists, door
access controls, restricted areas, closed-circuit television, physical intrusion detection
systems, and physical protection systems. Administrative and technical controls depend
on proper physical security controls being in place. You would need to protect your
equipment not only from those who would break in from the outside but also from
those who also have legitimate access to the facility. There will also be a need to
maintain the appropriate environmental conditions for your equipment to function
properly, such as power, temperature, and humidity. In the story of the NASA laptop
being stolen, it was actually stolen from the main NASA office building which has
some of the highest security measures in the world. So as you might see, you can
never have enough security.Password policies considered strong have followed the
same pattern with a minimum length of at least 7 characters, the requirement to be
complex, and the requirement to change it every 90 days or so. The Payment Card
Industry Data Security Standards have very well defined password requirements that
follow this pattern. There has always been the argument about having passwords so
complex that users write them down, which is a vulnerability as opposed to so easy
that they can be guessed a lot of the time. In mid-2016, the National Institute of
Science and Technology (NIST) released new guidance on passwords the drastically
reduced some of the more onerous requirements of "Best Practice". According to
NIST, passwords should not expire without a reason. There is no requirement for
password complexity. There are other things, of course, but for those of us with
complaints about password policies, the tide is starting to turn. Content filtering can
be a wide range of material on the world wide web. Gaming is content that can be
filter. Movies is content that can be filter. Gambling is content that can be filter.
Shopping sites is content that can be filter. Adult websites is content that can be filter.
Web Content is a large area to be controlled by a System Administrator. In the
previous paragraph, we just name a few that are popular among internet user.
Malware is designed to download in the background while the content is accessed at
the website.
Here are the different kind of Filters:
• Browse Base Filter
• Email Filter
• Client-Side Filter
• Network Based Filter
• Search Engine Filter
A System Administrator would purchase a content filter software that would block
certain websites and content.
One software that I have some experience working with is Barracuda. Barracuda is a
great software content for corporation. Barracuda will stop Sesame Street from coming
through.
Content Filtering is a very secure control design to put those protocols in place to
protect the network from malicious attacks. Administrative preventative controls is the
first line of defense. This particular control includes access reviews and audits.
Preventative controls are designed to be implemented prior to a threat event and
reduce and/or avoid the likelihood and potential impact of a successful threat event.
The goal of a preventative control is to decrease the unauthorized access and
unintentional errors. What makes this control effective in protecting a network is the
policies, processes, procedures, encryption, firewalls, and physical barriers that are
included with this particular control. Response, when you become vulnerable within
your environment you work toward making corrective actions, you may want to repair
any damages from broken physical items or if you have employees you may wish to
issue out new id cards. On the other hand you have various software within your
environment in which you would want to apply vulnerability patches either directly
issue within or from external vendors in which your partnering with. In some case
you may want to complete an emergency reboot during business hours or in some
cases do a reboot have hours. There are also resources that can be used to quarantine
a virus from your system. This can be a response that could be part of the response
along with the preventive like Symantec or Crowdstrike. To conclude all business
should implement a business continuity plan and have available at a moment notice a
incident response team.There is great blog by AWS: "In this post, I take that approach
a step further by introducing an example of a responsive control, which you can use
to automatically respond to a detected security event by applying a chosen security
mitigation. I demonstrate a solution that continuously monitors changes made to an
Amazon VPC security group, and if a new ingress rule (the same as an inbound rule)
is added to that security group, the solution removes the rule and then sends you a
notification after the changes have been automatically reverted." Often times technical
controls can be considered logical controls, which can include hardware and software
to protect any assets. Under that, detective controls can be described as any security
measure that is taken or a solution that was create to detect and often alert any
unauthorized activity that is in progress or even after the event has occurred. A
technical detective control would be an intrusion detection system (IDS) that monitors
a network for any harmful, unauthorized, and malicious activity or policy violations.
This is often reported after collected centrally using a security information and event
management system. Two common IDS types are network intrusion detection systems
(NIDS) and host-based intrusion detection systems (HIDS). Hackers are typically aware
of how IDSs work and will try and manipulate their attack method. Another example
of a technical detective control would be any anti-virus software. The reason being is
because an anti-virus software is software designed to protect an asset and notifies a
user in the event an intrusion has occurred or that the asset is out of compliance. Any
technical control will be hardware or software or solution implemented to detect and
alert any malicious activity. Another example of a technical detective control would be
a honeypot. Honeypots are designed to entice an attacker into attacking so the user
can gain information on the attacker and notify other defenders of the attempt(s) to
access the honeypot. Passwords are an ideal way for employees to maintain security
within their company’s computers. Each employee has their own specific password
that they only know. Some companies provide detailed guidance as to what their
password requirements are. These policies cover such topics as a minimum length
requirement, specific types of characters that must be used in creating the passwords,
and policy dictates how often the password should be changed. Along with these
requirements, the password policy also covers guidance on what employees should do
to keep their passwords safe, like not writing it down and keeping it near the
employee’s work desktop, or not to share passwords with other employees. From the
information I have researched, a password policy would be considered an access
control, which could fall under a preventative type of control. Passwords prevent any
unauthorized person from gaining access to an employee’s computer. One difficult
aspect of passwords is that they can be hard to remember, especially with the multiple
types of accounts that people have that require the use of a password for access. This
issue will persist, in my opinion, until we’ve come up with a means of making
passwords memorable. I like the idea of a password management system, but let’s
face it, those are protected by passwords as well. What does one do if they forget the
password to the password management application?
Implementing a perimeter defense is a countermeasure that can detect and prevent
attacks that occur over the internet. Having a multiple layered perimeter defense is the
best strategy a firewall is one layer that greatly assists.
Firewalls set up boundaries inspecting and identifying suspicious behavior. By filtering
traffic and blocking outsiders from gaining access. Defending the network from
external intrusion attempts. Acting as a barrier from your computer to the internet. A
firewall can filter wanted and undesirable traffic safeguarding the computers entry
point.
Network based firewalls monitor interactions across a wireless or local area network.
Used to protect a large network. This firewall can observe interactions of computers
across the network. As well as limit certain websites, restricting certain services, or
denying access. A network based firewall has many uses to protect a large
infrastructure .
Host based firewalls is software stored locally on a computer. Individually installed on
each device this firewall protects its isolated component.
Perimeter defense is a crucial layer of protection. Denying access and restricting
certain entry points has been a proven way of detecting and eliminating
threats.Administrative preventative control is where your employer or school keeps you
from logging on to certain web sites. it is a preventative measure to keep you from
downloading spam, malware, or spyware. where i am employed we have this measure
in place to keep you "honest" about what you are doing during your work day. it is
also in place to make sure that people's private information is not exposed
unmeaningly to the outside world. it is also in place, as i work at a financial
institution, to make sure what is private stays private. we have a certain expectation
that we must obtain in all matters, private or public. we make sure that all employees
know that we are watching what they are surfing on the internet. Defense in Depth is
a term that all Information Security, Data Security, and Cyber Security professionals
should know very well. The concept is simple - there is no single silver bullet that
makes everything secure. Instead there are layers of security much like the layers of
an onion. The bad actors may get past one layer, but there is another right behind it.
Some of the layers are preventative, some are detective, and some are corrective or
reactive (depending on which version you ascribe). zz Ideally, they are designed so that
each layer complements the next. Security controls are not chosen or implemented
arbitrarily. They typically flow out of an organization’s risk management process,
which begins with defining the overall IT security strategy, then goals. This is
followed by defining specific control objectives; statements about how the organization
plans to effectively manage risk. For example, “Our controls provide reasonable
assurance that physical and logical access to databases and data records is restricted to
authorized users” is a control objective. “Our controls provide reasonable assurance
that critical systems and infrastructure are available and fully functional as scheduled”
is another example.A control type: Administrative controls refer to policies, procedures,
or guidelines that define personnel or business practices in accordance with the
organization's security goals. These can apply to employee hiring and termination,
equipment and Internet usage, physical access to facilities, separation of duties, data
classification, and auditing. Security awareness training for employees also falls under
the umbrella of administrative controls.A control function: Preventative controls
describe any security measure that’s designed to stop unwanted or unauthorized
activity from occurring. Examples include physical controls such as fences, locks, and
alarm systems; technical controls such as antivirus software, firewalls, and IPS's; and
administrative controls like separation of duties, data classification, and auditing.
Intrusion Detection Systems have been around for several decades. One of the best
around has been Snort, which is an open source IDS. Many years ago now, the
Intrusion Prevention Systems (IPS) came out prompting a Gartner Analyst to proclaim
that IDS is dead and there is no longer any reason to use IDS. He could not have
been more wrong. There is a time and place for IPS and there is a time and place
where IPS should not be used. It does not matter how well you are able to tune an
IPS, it is still subject to false positives. When you have a false positive on an IPS,
you block legitimate traffic. If you are in a critical industry like medical or financial
and legitimate traffic gets blocked, it can be catastrophic. In these instances, you use
IDS and not IPS. I have chosen to research and acquire more information about
firewall control plus discuss how effective it is in protecting a network. According to
Microsoft Press Store (2012), a firewall is considered a technical preventive control
due to the ability of malicious traffic prevention from accessing a network. (Par. 12)
There are multiple types of Firewalls used by companies to protect their data and
information against security breaches. According to Norton (2020), a firewall can be
either hardware or software used for the sake of security preserve and protection. In
addition, firewalls can be very effective in the data protection process, however, there
is a need to decide how much protection is required based on each system and uses.
Basically, firewalls work as gatekeepers who monitor and check any attempt to access
the system preventing unauthorized or suspicious traffic from entering the system.
(Par. 3)
Firewall types include hardware/ physical such as broadband router while a software
firewall is inside the computer such as applications that monitor the traffic and
activities. Also, there is a cloud firewall which is also known as Firewall as a Service
(FaaS), such a firewall can increase functionality similar to a broadband router based
on the company side and requirements.
Detective controls is considered an internal control that can uncover problems. It is
also designed to detect errors or wrongdoings that may have occurred. Detective
controls can identify problem that already exist. Some examples of detective controls
could include reconciliation, physical inventory check and internal audits. With
reconciliation you can compare different sets of data to one another, identify and
examine the differences and take corrective actions. Reconciliations are vital to ensure
data integrity. Physical inventory checks can ensure an accurate inventory tally.
Inventory systems can be vulnerable to theft, fraud, or mismanagement. Physical
inventory can protect a network by making sure goods are not being lost or stolen
and ensure that the inventory system is accurate. Internal audits assure activity
designed to add value and improve a network. According to
www.journalofaccountancy.com “internal auditors pay close attention to areas such as
cybersecurity, data privacy, and social media.” Internal audits help protect against
fraud and reduce risks. It also works from within to watch over a network protect
against fraud, errors and risks. With internal audits you can look for vulnerabilities in
your digital systems and network and advise on how to close any gaps. Preventative
administration control watches out for danger, and tries to prevent it before it occurs.
For example, a firewall would be considered a preventative control, because it is
blocking any malware or harmful viruses from getting to your computer. It is putting
something in place before anything has ever even happened. With these things in
place before anything has happened, it is setting you up for success because you will
already be one step ahead. Preventative administration also has the ability to view
access reviews and perform audits to make sure everything is working properly. In my
opinion, preventative administration is one of the most important of the three, because
it is showing that you have acknowledged the risks you have, and you are taking
steps to make your security stronger, and also know exactly what to do in a moment
of attack. Whereas the others are more reactive, acting after the fact of the attack.
Another important thing we use often that preventative administration helps us with is
encryption, which we all just talked about the importance of last week. Everyone
should really focus on the preventative side, it would be very beneficial to many
people and businesses. Security of data and information is not one single step to do,
software to install, or a single security level to increase. As you mentioned, the whole
security is about building layers of defense. As a System Security Analyst at a
financial institution, part of my regular tasks is to perform system audits and double-
check that accesses are granted only to authorized users. I have read before that the
security preserving process in a system such as Macintosh grants access to the system
based on the level of security of the grated party. Meaning that a top-secret account
or user will be granted medium and low-risk access, yet not vice versa. While
password managers are protected by passwords, you also have to think that they can
also be protected in other ways, which can be biometric scanning as well. Password
managers allow us to copy and paste our passwords without having to remember
them, simply encrypt the passwords in your manager and set up a finger print or
facial recognition scan. The password for the manager is one password to remember,
as apposed to possible hundreds. If some companies did not provide some type of
physical control on their equipment companies would report major loss. I remember
working at a career college and someone was taking the student laptops from the
resource center. I would suggest to the LRC teacher that some type of security is
needed to secure each laptop. She didn't think that it was a big enough threat until
her computer came up missing. Physical control is needed to stop corporate loss from
not having some type of physical control.
Using multi-factor authentication allows for weaker passwords to be utilized, while
still maintaining a proper security posture. I'm not making excuses for the use of
ineffective passwords, but 2FA does provide some relief from todays robust password
policy. Most organizations that utilize 2FA still require a strong password. However,
GMAIL and other personal cloud based services that offer 2FA, have relaxed
password requirements.