CMGT 582 Security Review - COMPUTER SCIENCE ONLY TUTORS

profilemsluvnmauh33
cmgt_582_week_6.docx

Smith Systems Consulting Security Audit Outline

CMGT 582

February 08, 2016

Running head: SECURITY AUDIT OUTLINE

1

SMITH SYSTEMS CONSULTING SECURITY AUDIT OUTLINE

2

Smith Systems Consulting Security Audit Outline

I. Smith Systems Consulting (SSC)

a. Overview - Smith Systems Consulting was founded in 1994 and delivers business application services, high value web design, and database solutions.

b. Clients - SSC serves companies of all sizes, in various industries, including a number of government and not-for-profit organizations.

c. Risks - This poses a number of security risks to the company and the customers making a security audit plan necessary for the company’s security assessment (Hardie, 2003).

II. Ethical Issues - ethical issues in price fixing and anti-trust laws. Also, ethical issues in addressing conflicts of interest, employee discrimination as well as bidding and award practices are common for security companies.

a. Data Security

b. Information Systems

c. Confidentiality

III. Governing Laws and Regulations

a. Data Protection Act

b. Health Insurance Portability and Accountability Act of 1996 (HIPAA)

c. Gramm-Leach-Bliley Act (GLBA) of 1999.

d. Privacy Act of 1974.

IV. Conclusion - The security audit plan ensures that Smith Systems Consulting has the best measures in place to maintain compliance to the set laws and deal with any issues that may arise.

Smith Systems Consulting Application for the Formula for Risk

The risk is the potential harm that may interfere with the performance of the system. There is a need for every system to have a risk mitigation plans that are achieved through the proper application of the formula for risk (Stoneburner, 2001). Risk results in the harm of information or the functioning of the system itself. Smith Systems Consulting operates with application services, high-value web design, and database solutions that are vulnerable to threats such as hackers. Risks are initiated by the presence of threats. Application of the formula for risk will involve identifying the possibility of threats that can become a problem to the system and having mitigation strategies to reduce the impacts of the harm that can be caused (Stoneburner, 2001).

V. To control risk, the following techniques can be used;

Technique

Description

Risk assessment questionnaire

The questionnaire should be designed to help in locating various risk.

Assessment tools

The security team should have testing tools to look for the vulnerability of the system.

Interviews

Interviews are tool to obtain information from other staffs for the information they may have connected to the risk of the system possibilities

Documentation review

Information system documentation can be examined for auditing, security and disaster recovery components.

Site Visit

The site visit of the data hub can provide information on environmental controls and physical contact

Vulnerability sources

The vulnerability of the sources needs to be reviewed for potential harm.

Risk Model

Application of the formula for risk involves using the risk model;

Risk = Likelihood of the risk * size of the impact. Likelihood of the risk can be high, medium or low. When the probability is high, it is not possible to control the vulnerability, when moderate there is the possibility of control, and when it is low, the available controls can easily impede the problems that can arise .To estimate the magnitude of the impact can be as follows;

Impact score

Description

High

There is lack of integrity leading to loopholes in the system

Medium

There are moderate losses that can result from the risk damage.

Low

There can be minor damage.

The next step is to calculate the threat by multiplying the impact with the likelihood potential, for example; medium risk (50 * 10) and a risk scale is obtained. The risk scale is divided into categories which can be High (> 500 to 100), Low (10 to 100) and the medium is (> 100 to 500).

System characterization can now be done where it is classified as components:

Component

Description

Security

Passwords and antivirus

Auditing

Databases

Disaster recovery

System backup

Threat statement is then produced to classify the source as hackers, computer criminal, insiders or the environment (Bennett, 2007). This sources can be used to analyze the risk effects that results and risk assessments results can now be produced as follows;

Item

Observation

Threat source

Existing controls

Likelihood

Impact-rate

control

Security

Password so easily to be guessed

Password masters

Alphanumeric passwords

medium

medium

Peculiar characters should be used

Auditing

Wrong use of SQL commands

SQL manipulation

Less validation

high

medium

All security rules should be followed

Disaster recovery

Storing data in backups

Hackers

Server passwords

medium

medium

Best Practice Mitigation Strategies

Once the organization has defined the policies that will guide its security program the next step is the implementation of best practices for risk mitigation strategies. The risk mitigation strategies are contained in a crisis management plan and describe the initial emergency measures to take, in order to contain and prevent the worsening of the damages caused by an incident or catastrophe (Cantoria, 2011).

Risk mitigation strategies are action plans formulated after making a thorough evaluation of the possible threats, hazards or detriments that threaten the continuity of each business unit (Cantoria, 2011). The purpose of such strategies is to lessen or reduce, if not totally eliminate the adverse impacts of the identified or perceived risks characteristic to SSC even before any damage or disaster takes place.

Best practices require that the known and perceived risks be analyzed according to the degree and likelihood of the adverse results that are anticipated to take place. Thereafter, all such risks analyzed shall be documented according to their levels of priority in a form known as the risk mitigation plan.

Each business department, unit, or division must be independently evaluated to determine how important its functions are to the organization as a whole. For example, recovery operations in the case of SSC should focus on the IT Department and network operation before turning to the Personnel Department's hiring activities. Managers in the IT and information security communities are usually called on to provide strategic planning to assure the continuous availability of information systems. Various types of contingency plans are available to respond to events, including incident response plans, disaster recovery plans, and business continuity plans (Whitman and Mattord, 2012). In SSC organization, these should be handled as a single integrated plan.

Information security is designed and implemented in three layers: policies, people (education, training, and awareness programs), and technology. Each layer contains controls and safeguards to protect the information and information system assets that the organization values. For example, the layer of training and education can help defend against attacks enabled by employee ignorance and social engineering (Whitman and Mattord, 2012). Technology is also implemented in layers, with detection equipment (IDS) working in tandem with reaction technology (IPS) behind access control mechanisms (firewalls).

While policy itself may not prevent attacks, it certainly prepares the organization to handle them. When coupled appropriately, information security layers will complement and support each other toward enhancing the overall level of efficiency provided by the instated security program.

Security Risk Assessment

Information Security Risk Assessments are required in order to allow a company or an organization to be complex and provide proper data integrity. Smith systems is a national and international RDMS Enterprise with a financial database that requires different modules for its accounting system. This has allowed Smith Systems to maintain a diversified roles and segregation of duties for its employees. Smith Systems will run its billing through a separate module that runs off the same system with an interface to the financial database. Security for this database will be highly monitored. User roles will be defined based on positions, tasks and duties. Each role will be enabled based on specific rights that will fall in line with the department for which the employee belongs to.

Application of network security technologies and methodologies

The application of security protocols and policies are needed to evaluate and measure the security of a company. Technologies such as antivirus, encryption, data loss protection, and firewalls are just a few example of specific technologies that can be used to control security. The design and implementation of these technologies need to be used in accordance with the methodology in which will be used.

The technology that will meet this will include the ability of the following:

· Traceability

· You should be able to see who accessed what, when, and what was done with the information.

· Practicality

· This is the ability to identify the scenario’s in which the technology will help protect the data.

· Accountability

· This is identifying the owners of the data and all personal who are accountable for its protection.

· Reusability

· The technology and method’s used should be reusable across the enterprise. By reusing technology and methods, results are predictable and cost efficient.

· Temporality:

· Temporality indicates the ability to gather and react to security issues in real time. Technologies and security policies should be capable of performing this for the fastest resolution and maximum amount of control.

· Holism:

· This is the view of the organization as s whole, This includes physical, virtual, and cyber assets. Technology and methods need to be able to account for the whole organization.

· Cost:

· Cost is always a factor. Not every budget can afford to correct everything therefore having a priority list of the most critical controls that need to be meet should be kept. This will allow a company to address security issues in a logical and manageable approach.

Evaluation of security technologies and methodologies

Some of the well-known standards used in evaluating security methodologies are founded on evaluation criteria models such as the Information Technology System Evaluation Criteria, the Information Technology System Evaluation Criteria, and the Common Criteria. The later models, such as Bell-LaPadula (Confidentiality Model), Biba (Integrity Model), Clark-Wilson (Integrity Model), Graham-Denning (Access Control Model), Harrison-Ruzzo-Ullman, and Brewer-Nash models demonstrate the effects of implementing computer security systems on the confidentiality, integrity, and availability of information. The role of all these models is to ensure that privacy of information is protected by controlling the access of one part of a system on another. (Whitman & Mattord, 2012)

The Trusted Computer System Evaluation Criteria (TCSEC) is an older DoD standard that defines the criteria for assessing the access controls in a computer system. This standard is part of a larger series of standards collectively referred to as the Rainbow Series

The Information Technology System Evaluation Criteria (ITSEC) is an international set of criteria for evaluating computer systems which is very similar to TCSEC. Both TCSEC and ITSEC have been functionally replaced by the Common Criteria, in 2005. The Common Criteria for Information Technology Security Evaluation (CC) is an international standard (ISO/IEC 15408) for computer security certification. The CC process assures that the specification, implementation, and evaluation of computer security products are performed in a rigorous and standard manner, regardless of the IT product or the market environment. (Whitman and Mattord, 2012)

CC terminology includes the process of determining the Evaluation Assurance Levels (EALs) associated with a computer security product. EAL is typically rated on a seven levels scale: EAL1 – Functionally Tested, EAL2 – Structurally Tested, EAL3 – Methodically Tested and Checked, EAL4 – Methodically Designed, Tested, and Reviewed, EAL5 – Semiformally Designed and Tested, EAL6 – Semiformally Verified Design and Tested, and EAL7 – Formally Verified Design and Tested. (Whitman & Mattord, 2012)

Access controls technologies

After the establishment and implementation of mitigation practices to keeps systems safe as well as security risk assessment is done, the Smith Systems put in place access controls. However, it is necessary and utmost important to understand that the Smith securities only installs access control technologies to systems that have been placed on mitigation strategies and security assessment risk done. Access controls help in limiting the number of users who can access a system, and this acts as a major protection from threats like hackers. Access control denies any person without the access code an opportunity to access the information stored in the system. For the Smith Securities, the company has come up with different technologies for the purpose of enabling access controls. Different technologies apply in different circumstances and depending on the type of system being protected.

The use of the password is the major technology that the Smiths Security systems use to protect different clients systems. The company has established a system that recognizes different passwords, and this means that when a particular password in the input, the system can recognize the user hence allow access (Yee, 2012). Any wrong password, the system automatically denies access displaying a wrong password notification to the user. The latter means that the Smiths Systems provides every employee with a different password which every employee is entitled to keep a secret. Upon turning on the system, the system demands the users’ password, and it is only after a correct password is granted that access is allowed.

In other instances, the Smiths Systems have established small gadgets that are used to swipe cards. The company also designs cards that go along with the gadget being swiped. The latter means that every authorized person allowed to access is provided with a card that he/she is supposed to swipe for the system to recognize the user. The system acknowledges the user since every card has a serial number and the name of the user which when swiped automatically identifies the user and hence access is allowed. However, over the years cases of cards being stolen have been on the rise and unauthorized persons accessing protected systems hence causing harm and damage. It is for this reason that the Smiths Systems come up with an extra idea of increasing and tightening the card swiping security idea (Yee, 2012). The company established the application of passwords or thumb fingerprints into the system to go along with the card swiping. Hence, when a user swipes his/her card, he/she has to place his/her thumb finger in a special design feature where the prints are electronically identified, and access is allowed. Apart from the finger thumb, the system also allows password after card swiping.

In the case of an attempt to access the system using a recognized card but wrong password, the Smiths Systems has an internal alarm that informs the system control unit about someone trying to access the system using the wrong access codes or strategies. In the case of continued persistence on accessing the system using the wrong code or card, the Smith Systems automatically disenables the point from where forceful access is being attempted. The disabled access point is only enabled by the central system controlling unit, and this makes it impossible for any person without a password or the thumbprints is not identified by the system to access a system protected by Smiths Securities.

Security Audit

Security Policies

Definition: Security policy refers to what it entails for a system or organization to be secure.

Issues addressed by security policies in organizations, in particular, Smith Consulting Inc.

Constraints on the behaviors of the members of the organization (employees, business owners, and clients), constraints imposed by various adversaries including doors, keys, locks and walls.

Examples of security policies offered by Smith Consulting Inc: Information security policy, content security policy

Information security policy

Scope: Addresses all information facilities, systems, data, networks, and technology users in the organization.

Information Classification: Content –specific definitions as opposed to generic “restricted” or “confidential”.

Management goals (for securing handling of information in each classification): Application of legislations and regulations of Smith Consulting Inc.

Contractual Security Obligations: Customer privacy, no authorization to access customer data.

Information integrity: No outside access to customers’ information. Aimed at preventing loss of assets.

Placement of policy (context of supplementary documents and other management directives): Consulting executive level, consistency in the information handling documents.

References to the support documents: Responsibilities and roles, technology standards, process, guidelines, and procedures.

Explicit instruction: Requirements for access to organization’s computers (identity verification and authentication).

Specific designation of responsibilities: All the responsibilities of the various departments clearly outlined. For instance, technology department as the sole provider of the telecommunication lines.

Consequences for non-compliance: Contract termination, dismissal, among others.

Content security policy

The security policies apply to various resources. Other providing directives to script resources that are more prone to security than other resources, content security policy offers policy directives that control all the resources that can be loaded into a page.

Rest of the resource directives: base-URI, child-src, connect-src, font-src, form-action, frame-src, img-src, media-src, object-src, media-src, object-src, plugin-types, report-URI, style-src, and upgrade-insecure-requests.

Brief descriptions of the above-listed resource directives as well as their functions in security and the implementation details

Sandboxing: Relatively more special than the other directives. A brief explanation on this directive and how it works.

Key Factors To Consider When Offering Security Risk Consultant Services To Clients

Status of employee or consultant: Certainty of a legal relationship with the customers. Consider controls including behavioral control (control and direction of the business over the clients regarding working hours, equipment and tools, and sequence of actions), financial control, (terms of payment), type of relationship (permanent or temporary).

Self-employment and income taxes: Clear distinction between the independent contractors and the employees.

Sales tax on the firm’s fees: Determining whether the fee Smith Consulting Inc charges clients is subjected to tax or not.

Intellectual property: Copyright protection to the security services.

Exclusive vs. non-exclusive license: Possibility of granting licensing rights to other parties and the necessary procedures to be followed.

Insurance: Protection from evil actions and decisions that Smith Consulting Inc may be involved in while offering the security services to their clients. Two types of insurance should be considered namely general and professional liability.

Business organization option: Smith Consulting Inc to consider the amount of legal protection as well as the quantity of reporting required depending on the level of their services. More reports on security services offered in case of partnership and fewer reports in sole-proprietorship.

Business liability: Both internal and external liability to the services provided. In unlimited liability, Smith Consulting provides compensation to clients for resulting damages on their behalf. No compensations in case of limited liability.

Security Planning

Security planning is founded on established security policies and the data resulted from the Asset Inventory & Risk Assessment analysis. Security policies direct how problems should be addressed and how technologies should be used. Security planning represents the first step of SecSDLC’s implementation stage and describes how the CISO and various elements of the organization will implement the objectives of the information security charter. Security plans are used to create security tactical plans, which in turn are used to develop security operational plans. Those plans assign responsibilities in reference to various areas of security, including systems administration, maintenance of the information security policies, and the practices and responsibilities of users. Security planning also addresses the legal compliance of each unit of the organization. (Whitman and Mattord, 2012)

Evaluation of Security Planning

With these processes that have been developed, Smith Systems will be able to address vulnerabilities and performance measures to include security tools. Creating tactical plans will ensure that Smith Systems maintains good quality control as well as good internal controls. Addressing hardware and software issues’ is also included as part of the security planning. Department hardware will be assessed and evaluated every 3 years in order to maintain them up to date with current market. Software will be monitored as well and up dates will be handled according to current releases or updates. Segregation of duties will be handled by system administrators and will ensure good audit control. System administrators will be able to deploy any system updates via secure connections to all work stations, devices and mobile devices. User security will be monitored and security measures are set in place by deploying password lock, user cards and personal identification such as utilizing the thumb. All of the above will ensure that Smith Systems uphold a higher standard of security and maintain a credible database.

Multilevel or Defense Security Elements in Security Planning

The multilevel security process is the application of a computer system that processes information of incompatible classifications (i.e. unclassified, confidential, secret, and top secret) permitting access by users with different levels of security clearances and a need to know. There are two threat levels that must be considered when developing multilevel defense processes and they are internal and external threats. To combat external threats a security perimeter must be established. A security perimeter is a border of security that protects internal systems from outside threats and can be established both as an electronic perimeter as well as a physical one. Security perimeters can effectively be implemented as multiple technologies that segregate the protected information from potential attackers. (Whitman, 2014) The internal threats are typically combatted with the use of policies, training, awareness, hardware and software. The creation of internal security domains each with differing levels of security can help compartmentalize threats as the traffic between domains must be screened. The key components of the security perimeter are firewalls, DMZs (demilitarized zones), proxy servers, and IDPSs. “To achieve defense in depth, an organization must establish multiple layers of security controls and safeguards, which can be organized into policy, training and education, and technology.” (Whitman, 2014) Although, a policy, training and education, or piece of technology in itself is not going to prevent attacks the implementation of all these layers can deter an attack. With strong policies in place along with thorough training and up to date hardware and software such as, a firewall, intrusion detection system, antivirus, and malware protection the effects of any attack can be limited and compartmentalized. Technology is also implemented in layers, with detection equipment working in tandem with reaction technology behind access control mechanisms. (Whitman, 2014)

References

Bennett, M., & Waltz, E. (2007). Counter-deception Principles and Applications for National Security. Norwood, MA: Artech House, Inc.

Cantoria, C. S. (2011). Risk Mitigation Strategies and Risk Mitigation Plan. Retrieved from http://www.brighthubpm.com/risk-management/47934-risk-mitigation-strategies-and-risk-mitigation-plan/#imgn_1

Goggi, C. (2012). The Ultimate Network Security Checklist. Retrieved from http://www.gfi.com/blog/the-ultimate-network-security-checklist/

Hardie, C. (2003, April 21). Computer Security Audit Checklist. Retrieved from https://chrishardie.com/2003/04/computer-security-audit-checklist/

Rochester Institute of Technology. (2015, January 20). FORMS, CHECKLISTS, AND TEMPLATES. Retrieved from http://www.rit.edu/security/content/forms-checklists-and-templates

Stoneburner, G., Hayden, C., & Feringa, A. (2001). Engineering Principles for Information Technology Security (A Baseline for Achieving Security): Recommendations of the National Institute of Standards and Technology. Gaithersburg, Md.: U.S. Dept. of Commerce, Technology Administration, National Institute of Standards and Technology

Whitman, M. E. and Mattord, H. J. (2012). Principles of Information Security (5th ed.). Retrieved from The University of Phoenix eBook Collection database.

Willie, K. (2013, January 16). Physical Security Audit Checklist. Retrieved from http://locknet.com/lockbytes/excerpts/physical-security-audit-checklist/

Yee, G. (2012). Privacy protection measures and technologies in business Organizations: Aspects and Standards. Hershey, PA: Information Science Reference.