500 word Security Questions
Week 5 - Weekly Lecture
|
|
Weekly Lecture |
Week 5 – Network Management, Security Risks, and Policies
First, let’s discuss network management and the expectations from the end users’ perspective. End users expect networks to be reliable and to work at an optimum level 24/7, 365 days a year. Networks are viewed as a utility like electricity or water service; networks cannot be merely adequate, the network must work at its optimum levels at all times because that is the expectation of a utility service. As with all utilities, there are common metrics which are provided with quality assurance tools that are used for appropriate management and health of the utility, and one of these is QoS (Quality of Service). QoS metrics are generally combined with SLAs (Service Level Agreements) which come into play when a network provider takes on the responsibility of managing communications for a business entity. Or, in the case of very large organizations, SLAs may even be used when IT provides specific services to business units within the organization.
Security risks come in many forms. Some of the most obvious are hackers, viruses, Trojans, key-loggers, root kits, server and software misconfigurations, and unpatched network vulnerabilities, all of which can compromise a network. Most of the previous elements are introduced into the network through user error such as a misconfigured server, or an unsuspecting user who clicks a link with malware or visiting a site compromised with malware. Less frequent than might be assumed is the unethical employee who willfully compromises data or network security. There are many ways to detect these breaches, including a number of intrusion detection methods such as anomaly and signature based techniques (Stallings & Case, 2013). Generally, most intrusion detection methods require specialized hardware, server-based software, or a combination of these in order to provide effective intrusion prevention and detection.
However, there are other not so obvious security risks in today’s business environments. There are also the security risks associated with access that employees have to company data. One way to mitigate too much data access would be to use the principle of ‘least privilege’, which is where user access to data is limited to only that which allow the completion of the user’s tasks and no more (Hoelzer, 2010). Company data includes but is not limited to, customer data, intellectual property, and employee data.
While we often assume that the biggest risks to a network are the hackers trying to get in, this is not always the case. In most cases, internal data breaches and compromised networks happen through ignorance or error. In other words, any these data stores can be compromised inadvertently by the people who have access to the data. For example, an employee may inadvertently send sensitive data via email which goes to the wrong person because of a mistyped email address.
The second area of network management is security of the electronic resources, including data access and security, and information management. It is understood that part of this responsibility includes the prevention of data breaches, malware, and viruses from compromising the network. The following links can give you more details on these elements and many other aspects of this topic.
· Busting the 10 Myths about Data Protection
· Information Security Best Practices
· Network Security Best Practices
Because security and risk prevention are critical aspects of network management, electronic resource usage security policies are an essential element for providing governance for the network resource. These security policies identify the end user behaviors that put electronic resources at risk and provide sanctions or penalties for violating the policy. Electronic usage security policies also provide best practices as they relate to data security and data loss prevention.
You’ll notice that electronic resource security policies generally have nothing to do with the specifics of the software used or what IT uses to manage or monitor these elements on the network. Be sure to recognize that organizational security policies govern behaviors, not risk mitigation execution strategies, or implementation of security products, which fall under the category of a ‘plan’ rather than a policy.
Notice too, that with the exception of the hacker, the risks mentioned in previous paragraphs are dependent upon a person who takes an action that compromises data or introduces a risk into the network. A person who may have avoided the action if there were guidelines in place to address these possibilities. If there were guidelines in place that educated employees about data sensitivity and avoiding certain behaviors, then these incidents could have been mitigated.
Because security is completely reliant on the people who have access to the network and access to the company’s data, end users are the first line of defense in an organization’s security plan. No amount of capital investment into the best security tools and equipment will prevent a network or data breach if the end users do not understand the importance of security through education and policy. For these reasons, security is a management issue – not a technological one.
One final thought, keep in mind that policy is not the same as implementation. Policy identifies the broad risks of security and defines behaviors which are then categorized as acceptable or unacceptable behaviors. Implementation is the method of execution for the policy. This is where elements such as leveraging the principle of least access, the type of virus protection that will be implemented for servers versus PCs, or network monitoring software would be defined.
References: Hoelzer, D. (2010, April 8) Translating Security Principles to Management: Least Privilege. [Web log post] Retrieved from http://it-audit.sans.org/blog/2010/04/08/translating-security-principles-management-privilege/ Stallings, W., & Case, T. (2013). Business Data Communications: Infrastructure, Networking and Security (7th ed.). Upper Saddle River, NJ: Prentice Hall.