Altona Manufacturing Case

profileramtech0888
week_2_slides_operations_security.pptx

Operations Security

Week 2

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© (ISC)2 ® 2010, All Rights Reserved

For Personal Use of (ISC)2 Seminar Attendee Only

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

CISSP-ISSEP® Bootcamp Seminar v10

Technical Management

Initial Program Load (IPL)

Monitoring system execution

Control job flow

Mount I/O volumes

Bypass Label Processing (BLP)

Renaming/relabeling resources

Reassigning ports/lines

Operator and Administrator Privileges

Page 462

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

System Administrator Duties and Responsibilities

Server startup and shutdown

System configurations reset

Data backups

System maintenance

Customer service

Network Administrators duties

Page 462-463

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

Security Administrator Duties and Responsibilities

Policy

Vulnerability assessments

Incident response

User-oriented activity management

Information classification implementation

Audit log monitoring and review

Security tool oversight and management

Page 463

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

Backup Types

What should operations ensure they are backing up?

Page 463

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

Example

Over the years, the networks and IT infrastructure at Altona Manufacturing have grown through individual projects, acquisitions of other companies, and replacement of systems on an as-needed basis. Altona Manufacturing has hired you and your team to begin developing the type of backup system that it needs. Currently, 20 servers are in operation and only five are backed up using a tape backup system.

What are the key backup considerations in the scenario?

Page 464

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

Backup Type Matrix

Page 464

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

Backup Concepts

File image

System image

Data mirroring

Electronic vaulting

Remote journaling

Database shadowing

Redundant servers

Standby services

Page 464-465

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

Backup Integrity

Backup storage locations

Backups must be tested

Alternate site recovery plan

Site-specific software

Page 465

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

Configuration Management

Configuration Management means to maintain the systems’ integrity with respect to the approved settings.

Policy

Defines a process for authorized change

Patch management

Software licensing management

Hardware inventory

Deployment

Documentation requirements

Page 467-468

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

Baselining

Organizations should implement comprehensive security and controls to mitigate risks due to misuse or inappropriate use

Organizations should consider an enterprise-wide, standard-build workstation rollout that locks down and baselines system capabilities.

Page 468

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

System Recovery – Trusted Recovery

As defined in the Trusted Computer Security Evaluation Criteria (TCSEC, aka “The Orange Book”), the assurance control objective is that:

“Systems that are used to process or handle classified or other sensitive information must be designed to guarantee correct and accurate interpretation of the security policy and must not distort the intent of that policy. Assurance must be provided that correct implementation and operation of the policy exists throughout the system’s life cycle.”

Page 468

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

System Recovery – Trusted Recovery

This objective affects trusted recovery in two important ways:

First, the design and implementation of the recovery mechanisms and procedures must satisfy the life cycle assurance requirements of correct implementation and operation.

Second, the system’s administrative procedures and recovery mechanisms should ensure correct enforcement of the system security policy in the face of system failures and discontinuities of operation.

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

Trusted Path

A trusted path is a secure link from the management console directly to the equipment, often to an administrator port on the device

This provides a level of protection since the person desiring to change any administrative settings must have physical access to the management console or equipment itself

Page 468-469

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

Types of Trusted Recovery

Page 469-470

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

Types of Trusted Recovery

System Reboot – Is performed after shutting down the system in a controlled manner in response to a Trusted Computer Base (TCB) failure.

Emergency System Restart – Is done after a system fails in an uncontrolled manner in response to a TCB or media failure. In such cases, TCB and user objects on nonvolatile storage belonging to processes active at the time of TCB or media failure may be left in an inconsistent state.

System Cold Start – Takes place when unexpected TCB or media failures take place and the recovery procedures cannot bring the system to a consistent state. TCB and user objects may remain in an inconsistent state following attempts to recover automatically. Intervention of administrative personnel will be required in order to bring the system to a consistent state from maintenance mode.

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

Control Fail Modes

Fail secure (fail closed) – It is important that when a system fails, it fails in a secure manner rather than leaving everything open. Should firewall software crash, for example, all traffic should be disallowed rather than allowed. Fail closed is a synonym for fail secure — in the event of a failure, the system reverts to a closed or secure condition.

Fail soft – Selective termination of affected non-essential system functions and processes when a failure occurs or is detected in the system.

Fail safe – A system that, in the event of failure, responds in a way that will cause no harm, or at least a minimum of harm, to other devices or danger to personnel.

Page 470

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

System Resilience and Fault Tolerance Requirements

System resilience – Computer networking community defines it as the combination of trustworthiness (dependability, security, and perform ability) and tolerance (survivability, disruption tolerance, and traffic tolerance).

Fault tolerance – Fault-tolerant computing is the art and science of building computing systems that continue to operate satisfactorily in the presence of faults. A fault-tolerant system may be able to tolerate one or more fault-types, including:

Transient, intermittent, or permanent hardware faults

Software and hardware design errors

Operator errors

Externally induced upsets or physical damage

Page 470

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

Configuration Management Example

Altona Manufacturing has hired you and your team to begin developing the Configuration Management Controls that are needed.

Page 465-466

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

Example Review

What is the purpose of a change management process?

What is the risk to Altona Manufacturing due to a lack of a change management process?

Should Altona Manufacturing have a change control board?

Who should be on the change control board?

Page 466

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

This week

Complete the Altona Manufacturing Change Control Case outlined in the previous slides.

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances

© Copyright 2012 – 2013 (ISC)², Inc. All Rights Reserved.

For Personal Use of (ISC)2 Seminar Attendee Only.

Contents May Not Be Copied or Otherwise Distributed Under Any Circumstances