Showing posts with label assessment. Show all posts
Showing posts with label assessment. Show all posts

Friday, July 22, 2011

Network Security Essentials


In a perfect world, probably you just install some security hardware and software to protect your business network. In the real world, you would be frustrated you think you have taken the necessary precautions but you don’t make too much of a scene when the inevitable business security breach occurs. Understanding network security essentials will help protect the business network against any security breaches.
There is more to Network security essentials than technology; real network security requires understanding the inherent people and corporate policy issues as well. Therefore corporate realize the need of developing the management of information security that must be enforced to the workforce.
According to Cisco there are three network security essentials issue that face a corporate network today:
  1. Security is not just a technology problem. Many researches found that administrators and users are the cause of many of the security problems that corporations face today.
  2. Network administrators tend to buy technology from a random advertisement they happen to read in a networking magazine or networking websites. Actually spending money at the corporate security problems might not be a good solution. Predictably, many vendors would absolutely love it if they could succeed in making you believe otherwise.
  3. Many organizations lack of well-defined network security policy even some corporations don’t even have security policy. Even if they have such kind of security policy, each department has created their own security policy independently of the others. This is highly ineffective because it creates a myriad of security holes, leaving the network wide open to attacks in a number of places.
An effective network security policy involves a strategic combination of both hardware implementation and a proper information security management.
Speaking about network security essentials, there are four primary threats to network security that define the type of attacker you could be dealing with some day:
Unstructured threats
Probably your users have downloaded information from the internet and want to feel the sense of power this provides them. They don’t know that some of them commonly referred to as Script Kiddies—can be pretty nasty, but most of them are just doing it for the rush and for bragging rights. This is categorized as unstructured threats which typically originate from those curious users. They’re untalented, inexperienced hackers, and they’re really just motivated by the thrill of seeing what they can do.
Structured threats
Hackers who create structured threats are much more sophisticated than Script Kiddies. They are technically competent and calculating in their work, they usually understand network system design, and they are well versed in how to exploit routing and network vulnerabilities. They can and often do create hacking scripts that allow them to penetrate deep into a network’s systems at will. They tend to be repeat offenders. Both structured and unstructured threats typically come from the Internet.
External threats
External threats typically come from people on the Internet or from someone who has found a hole in your network from the outside. These serious threats have become ubiquitous in the last 10 to 15 years, during which time most companies began to show their presence on the Internet. External threats generally make their insidious way into your network via the Internet or via a dial-up server, where they try to gain access to your computer systems or network.
Internal threats
Internal threats come from users on your network, typically employees. These are probably the scariest of all threats because they’re extremely tough to both catch and stop.
And because these hackers are authorized to be on the network, they can do some serious damage in less time because they’re already in and they know their way around. Plus, the profile of an internal threat is that of the disgruntled, angry, and vengeful former or current employee, or even a contractor who wants nothing more than to cause some real pain and suffering! Although most users know this type of activity is illegal, some users also know it’s fairly easy to cause a lot of damage—fast—and that they have a shake at getting away with it. That can be a huge, irresistible temptation to those with the right modus operandi or the wrong temperament!
Suggested readings:

Security Risk Assessment


Identifying IT security requirements for the organization is very important as part of the development of the disaster recovery and business continuity plan of the information system in an organization. One of the areas the organization needs to identify its security requirements is security risk assessment.
IT Security risk assessment is the process of identifying IT risks, analyze the potential impact, and then implement the measures to prevent the risk when it is realized. One of the sources that can help in identifying the security requirements of the organization is security risk assessment. With security risk assessment, we can identify the threats to the assets and identify the vulnerabilities of the systems. Thus, we can evaluate and estimate the potential impact.
With security risk assessment, all the business harm likely to result from a security failure can be considered. All the potential consequences of a loss of confidentiality, integrity or availability of the information and other assets can be taken into account too. And then we can make the necessary controls where the expenditure should be balanced against the business harm likely to result from security failures. Basically we can apply this technique to the whole organization, or only parts of it, as well as to individual information systems, specific system components or services where this is practicable, realistic and helpful.
The results of this Security Risk Assessment will help guide and determine the appropriate management action and priorities for managing information security risks, and for implementing controls selected to protect against these risks. The process of assessing risks and selecting controls may need to be performed a number of times to cover different parts of the organization or individual information systems.
Periodic reviews of the security risk assessment and implemented controls should be carried out to help take action:
  • If any changes to business requirements and priorities
  • If any new threats and vulnerabilities should be taken into account
  • Assure that controls remain effective and appropriate
Reviews should be performed at different levels of depth depending on the results of previous security risk assessments and the changing levels of risk that management is prepared to accept. Security risk assessments are often carried out first at a high level, as a means of prioritizing resources in areas of high risk, and then at a more detailed level, to address specific risks.
Selecting controls
Once security requirements have been identified, controls should be selected and implemented to ensure security risk are reduced to an acceptable level. However, it is necessary to recognize that some of the controls are not applicable to every information system or environment, and might not be practicable for all organizations.
As an example, segregation of duties describes how duties may be segregated to prevent fraud and error. It may not be possible for smaller organizations to segregate all duties and other ways of achieving the same control objective may be necessary.
Segregation of duties is a method for reducing the risk of accidental or deliberate system misuse. Separating the management or execution of certain duties or areas of responsibility, in order to reduce opportunities for unauthorized modification or misuse of information or services, should be considered.
Small organizations may find this method of control difficult to achieve, but the principle should be applied as far as is possible and practicable. Whenever it is difficult to segregate, other controls such as monitoring of activities, audit trails and management supervision should be considered. It is important that security audit remains independent.
Controls should be selected based on the cost of implementation in relation to the risks being reduced and the potential losses if a security breach occurs. Non-monetary factors such as loss of reputation should also be taken into account.
Information security starting point
A number of controls can be considered as guiding principles providing a good starting point for implementing information security. They are either based on essential legislative requirements or considered to be common best practice for information security.
Controls considered to be essential to an organization from a legislative point of view include:
  1. Data protection and privacy of personal information.
  2. Safeguarding of organizational records
  3. Intellectual property rights
  4. Controls considered to be common best practice for information security include:
    1. Information security policy document
    2. Allocation of information security responsibilities
    3. Information security education and training
    4. Reporting security incidents
    5. Business continuity management
These controls apply to most organizations and in most environments. It should be noted any control should be determined in the light of the specific risks an organization is facing. Hence, although the above approach is considered a good starting point, it does not replace selection of controls based on a security risk assessment.
Critical success factors
Experience has shown that the following factors are often critical to the successful implementation of information security within an organization:
  1. Security policy, objectives and activities that reflect business objectives;
  2. An approach to implementing security that is consistent with the organizational culture;
  3. Visible support and commitment from management;
  4. A good understanding of the security requirements, security risk assessment and security risk management;
  5. Effective marketing of security to all managers and employees;
  6. Distribution of guidance on information security policy and standards to all employees and contractors;
  7. Providing appropriate training and education;
  8. A comprehensive and balanced system of measurement which is used to evaluate performance in information security management and feedback suggestions for improvement.
By: IT Security Consultant Group

An Example Of Risk Assessment


Risk Assessment Form or Risk Assessment Template must be created as a standard form used to assess the security risk. The results of the risks assessment must be registered together with the control the management need to take action to. The following paragraphs explains the Sample Risk Assessment.
A methodical security risk assessment is used to identify the security requirements. Before discussing the Sample Risk Assessment using common Risk Assessment Form, the following is short description about the systematic consideration in assessing the risk security in the organization.
  1. The business harm likely to result from a security failure, taking into account the potential consequences of a loss of confidentiality, integrity or availability of the information and other assets;
  2. The realistic likelihood of such a failure occurring in the light of prevailing threats and vulnerabilities, and the controls currently implemented.
The results of this security risk assessment must be registered using the following Risk Assessment Form (as a Sample Risk Assessment) that will help guide and determine the appropriate management action and priorities for managing information security risks, and for implementing controls selected to protect against these risks. The process of assessing risks and selecting controls may need to be performed a number of times to cover different parts of the organization or individual information systems.
To provide a sample risk assessment, the previous scenario about networking connection between the Mining office and the HR building in Guinea Smelter as in the networking diagram below.
Sample risk assessment - network diagram
Sample risk assessment - network diagram
For the purpose of this sample risk assessment using the above network diagram, the security risks that will likely impact to the business continuity need to be identified. All of the risks must be registered in the following Risk assessment form.
Sample Risk Assessment - Table
Sample Risk Assessment - Table
click for larger image Or Click the disaster recovery plan template in pdf file here.
The risks
Identify all the possible risks that will likely impact to the business and in this sample risk assessment using the above network diagram the risks can be identified as follows:
Risk #1 the uplink cable
  1. Business function: Single uplink backbone cable connecting both Mine office and HR buildings.
  2. The threat: Backbone Cable Failure
  3. Consequences: The computers in the Mine building will be disconnected from all the network resources and network application
  4. Likelihood: Possible.
  5. Existing controls: Protecting the network cable with a metal pipe and run underground buried around 30 cm depth.
You still need to fill-in the other columns: Consequence rating; Likelihood rating; Level of Risk and Risk Priority. However, the following legends should be defined that should fit to your business environment:
Consequence
LikelihoodLevel of RiskRisk Priority
High: $2M impact on the organization or serious strategy impact1 Highly possibleHighLarge degree of impactHigh Risk
Medium: $500K – $2M impact on the organization or significant operating impact2 PossibleMediumMedium degree of impactMedium risk
Low: $500K impact on the organization, tactical impact on the operations3 LikelyLowMinimal impactLow Risks
4 Not very likely
5 Never
In this sample risk assessment, the “Possible” entry is in the Likelihood column in (refer to the above Risk Assessment Form) and “Medium Risk” entry is in the Consequence column.
The “adequacy of existing control” column must describe the current control, in this sample risk assessment the control is not good enough to protect network cabling from damage since the cable is only protected inside the metal pipe that is run underground with only 30 cm depth. Besides, above the cable is a roadway for light vehicles.
Beside the control, the consequence will result a significant operating impact to all users in Mine building. This will disrupt the business continuity with the possible impact of disconnecting all the network resources and network applications.
You can assess the risks of other critical items based on the above network diagram such as WAN connection link; the LAN switches, andperimeter routerActive directory DC serverdomain name serversDHCP server and other file servers in HR building. By applying this sample risk assessment you can also develop security risk assessment for your LAN networking (including your wireless LAN) as well as WAN networking(including frame relay networkor ISDN network, or even your PPP connection between remote sites) critical assets and take appropriate control to eliminate the risks or at least minimize the impact. All the possible risks must be registered using sample risk assessment form above.