Showing posts with label risk. Show all posts
Showing posts with label risk. Show all posts
Thursday, August 4, 2011
Friday, July 22, 2011
Network Security Essentials
In a perfect world, probably you just install some security hardware and software to protect your business network. In the real world, you would be frustrated you think you have taken the necessary precautions but you don’t make too much of a scene when the inevitable business security breach occurs. Understanding network security essentials will help protect the business network against any security breaches.
There is more to Network security essentials than technology; real network security requires understanding the inherent people and corporate policy issues as well. Therefore corporate realize the need of developing the management of information security that must be enforced to the workforce.
According to Cisco there are three network security essentials issue that face a corporate network today:
- Security is not just a technology problem. Many researches found that administrators and users are the cause of many of the security problems that corporations face today.
- Network administrators tend to buy technology from a random advertisement they happen to read in a networking magazine or networking websites. Actually spending money at the corporate security problems might not be a good solution. Predictably, many vendors would absolutely love it if they could succeed in making you believe otherwise.
- Many organizations lack of well-defined network security policy even some corporations don’t even have security policy. Even if they have such kind of security policy, each department has created their own security policy independently of the others. This is highly ineffective because it creates a myriad of security holes, leaving the network wide open to attacks in a number of places.
An effective network security policy involves a strategic combination of both hardware implementation and a proper information security management.
Speaking about network security essentials, there are four primary threats to network security that define the type of attacker you could be dealing with some day:
Unstructured threats
Probably your users have downloaded information from the internet and want to feel the sense of power this provides them. They don’t know that some of them commonly referred to as Script Kiddies—can be pretty nasty, but most of them are just doing it for the rush and for bragging rights. This is categorized as unstructured threats which typically originate from those curious users. They’re untalented, inexperienced hackers, and they’re really just motivated by the thrill of seeing what they can do.
Structured threats
Hackers who create structured threats are much more sophisticated than Script Kiddies. They are technically competent and calculating in their work, they usually understand network system design, and they are well versed in how to exploit routing and network vulnerabilities. They can and often do create hacking scripts that allow them to penetrate deep into a network’s systems at will. They tend to be repeat offenders. Both structured and unstructured threats typically come from the Internet.
External threats
External threats typically come from people on the Internet or from someone who has found a hole in your network from the outside. These serious threats have become ubiquitous in the last 10 to 15 years, during which time most companies began to show their presence on the Internet. External threats generally make their insidious way into your network via the Internet or via a dial-up server, where they try to gain access to your computer systems or network.
Internal threats
Internal threats come from users on your network, typically employees. These are probably the scariest of all threats because they’re extremely tough to both catch and stop.
And because these hackers are authorized to be on the network, they can do some serious damage in less time because they’re already in and they know their way around. Plus, the profile of an internal threat is that of the disgruntled, angry, and vengeful former or current employee, or even a contractor who wants nothing more than to cause some real pain and suffering! Although most users know this type of activity is illegal, some users also know it’s fairly easy to cause a lot of damage—fast—and that they have a shake at getting away with it. That can be a huge, irresistible temptation to those with the right modus operandi or the wrong temperament!
Suggested readings:
Security Risk Assessment
Identifying IT security requirements for the organization is very important as part of the development of the disaster recovery and business continuity plan of the information system in an organization. One of the areas the organization needs to identify its security requirements is security risk assessment.
IT Security risk assessment is the process of identifying IT risks, analyze the potential impact, and then implement the measures to prevent the risk when it is realized. One of the sources that can help in identifying the security requirements of the organization is security risk assessment. With security risk assessment, we can identify the threats to the assets and identify the vulnerabilities of the systems. Thus, we can evaluate and estimate the potential impact.
With security risk assessment, all the business harm likely to result from a security failure can be considered. All the potential consequences of a loss of confidentiality, integrity or availability of the information and other assets can be taken into account too. And then we can make the necessary controls where the expenditure should be balanced against the business harm likely to result from security failures. Basically we can apply this technique to the whole organization, or only parts of it, as well as to individual information systems, specific system components or services where this is practicable, realistic and helpful.
The results of this Security Risk Assessment will help guide and determine the appropriate management action and priorities for managing information security risks, and for implementing controls selected to protect against these risks. The process of assessing risks and selecting controls may need to be performed a number of times to cover different parts of the organization or individual information systems.
Periodic reviews of the security risk assessment and implemented controls should be carried out to help take action:
- If any changes to business requirements and priorities
- If any new threats and vulnerabilities should be taken into account
- Assure that controls remain effective and appropriate
Reviews should be performed at different levels of depth depending on the results of previous security risk assessments and the changing levels of risk that management is prepared to accept. Security risk assessments are often carried out first at a high level, as a means of prioritizing resources in areas of high risk, and then at a more detailed level, to address specific risks.
Selecting controls
Once security requirements have been identified, controls should be selected and implemented to ensure security risk are reduced to an acceptable level. However, it is necessary to recognize that some of the controls are not applicable to every information system or environment, and might not be practicable for all organizations.
As an example, segregation of duties describes how duties may be segregated to prevent fraud and error. It may not be possible for smaller organizations to segregate all duties and other ways of achieving the same control objective may be necessary.
Segregation of duties is a method for reducing the risk of accidental or deliberate system misuse. Separating the management or execution of certain duties or areas of responsibility, in order to reduce opportunities for unauthorized modification or misuse of information or services, should be considered.
Small organizations may find this method of control difficult to achieve, but the principle should be applied as far as is possible and practicable. Whenever it is difficult to segregate, other controls such as monitoring of activities, audit trails and management supervision should be considered. It is important that security audit remains independent.
Controls should be selected based on the cost of implementation in relation to the risks being reduced and the potential losses if a security breach occurs. Non-monetary factors such as loss of reputation should also be taken into account.
Information security starting point
A number of controls can be considered as guiding principles providing a good starting point for implementing information security. They are either based on essential legislative requirements or considered to be common best practice for information security.
Controls considered to be essential to an organization from a legislative point of view include:
- Data protection and privacy of personal information.
- Safeguarding of organizational records
- Intellectual property rights
- Controls considered to be common best practice for information security include:
- Information security policy document
- Allocation of information security responsibilities
- Information security education and training
- Reporting security incidents
- Business continuity management
These controls apply to most organizations and in most environments. It should be noted any control should be determined in the light of the specific risks an organization is facing. Hence, although the above approach is considered a good starting point, it does not replace selection of controls based on a security risk assessment.
Critical success factors
Experience has shown that the following factors are often critical to the successful implementation of information security within an organization:
- Security policy, objectives and activities that reflect business objectives;
- An approach to implementing security that is consistent with the organizational culture;
- Visible support and commitment from management;
- A good understanding of the security requirements, security risk assessment and security risk management;
- Effective marketing of security to all managers and employees;
- Distribution of guidance on information security policy and standards to all employees and contractors;
- Providing appropriate training and education;
- A comprehensive and balanced system of measurement which is used to evaluate performance in information security management and feedback suggestions for improvement.
By: IT Security Consultant Group
Network Security Best Practices | Minimum Requirements
Unlike small network in homes where security becomes the last thing to consider by mostly home users, network security in business class networks must be considered as serious tasks by the network administrators and IT managers. Network security can be achieved by implementing network security best practices including the security policy and following a defense in depth procedures. See also management of information security.
Network security best practices as a minimum should encompass physical access to critical assets; access controls over the switches and routers, VLANs support, encryptions, as well asrouter connections and packet filtering.
Implementing the network security best practices, you must identify all the components that must be addressed to deliver a secure network environment. The following lists best practices of the minimum requirements for network security:
- Physical Security: You must secure all physical access points and network equipmentsincluding network routers, server infrastructure, LAN Switches, and Satellite discs. Physical security is imperative in providing a solid foundation for all other security and is often overlooked. All networking infrastructure must be securely located and access only granted to authorized-personnel. Any device can be compromised if physical access is permitted.
- All the OSs and devices firmware must be patched regularly as soon as the patches are released by the Vendors. For Windows server, see also WSUS management system.
- All the networking devices including the routers, Switches, Access points, must be protected by assigning strong passwords. See also thebest practice in secure passwords.
- Allowing remote access to the network devices by using Telnet and SNMP must be restricted based on the IP address and granted to only authorized IT support personnel
- You should provide Logon banners such as Message of the Day (MOTD) for networking devices (such as Cisco routers, Switches) with legal warning message to any unauthorized users attempting to access the device. This is required to deter unauthorized access to these devices. See also Cisco device passwords.
- All the Telnet and Console on all networking devices must be configured with the Session timeouts limited to less than 10 minutes when unattended. This way you can prevent security breaches via unattended management terminals. Session timeouts can be used to close vacant management sessions.
- Providing passwords and community names on network devices must be strong enough consisting alphanumeric, character, and symbols.
- You should disabled all the management services such as SNMP if not required
- Internet and Wireless communications must be encrypted and the encryption keys must be regularly changed in a secure fashion to prevent eavesdropping and data manipulation based attacks. Wireless LAN connections must also be secured via encryption and preferably connected via firewalled network segment.
- Routers and firewalls that face the internet must be configured securely using packet filter (extended access-lists for Cisco devices). Routers should be configured securely to ensure only authorized business intended traffic flows exist. Access-lists must be used to restrict network traffic in environments where network security threats may exist. Packet filters should be used to prevent unauthorized access to key business resources, but should not stop registered network traffic. Packet filters (inbound extended access-list) as a minimum should be configured on perimeter routers to provide protection from the Internet (or other public networks).
- If security segregations for users and network resources are required, VLANs must be used. You can implement Layer 3 Switches tocontrol inter-VLAN traffic. Switches may use VLANs to define separate security boundaries based on groups of users or location settings. MAC-based port restrictions on LAN switches can be used to further restrict network access in hostile public access environments.
- To provide device access restriction for the computers in high risk public access environments, must use Switch-based port level security (MAC address security)
- To prevent 3rd party devices from route infecting the network, all dynamic protocols should only be enabled on router links, and should not be run on user access links.
- To ensure only valid routing sources exchange path updates, routing protocols should use a secure authentication mechanism (MD-5 hash) to protect routing update messages
- For all the key devices, access logging (and also packet logging if necessary) must be used to record device access and configuration changes
- Sensitive data traversing a public link such as the Internet must be encrypted using VPNs. Network device configuration over public links should also be encrypted.
Any public Internet connection must be secured with a perimeter router and a firewall. The router functions as a 1st level defensive packet screener and the firewall functions as a last-line of defense from the public network.
The figure below shows the conceptual connection diagram by deploying network security best practices.
By not following a basic security policy, unauthorized network access is possible. This includes access to sensitive resources that have a high security risk. Having a basic security policy on the network ensures that resources are not readily compromised. Network components such as switches and routers are core to the operational integrity of the network and as such should be adequately protected.
An Example Of Risk Assessment
Risk Assessment Form or Risk Assessment Template must be created as a standard form used to assess the security risk. The results of the risks assessment must be registered together with the control the management need to take action to. The following paragraphs explains the Sample Risk Assessment.
A methodical security risk assessment is used to identify the security requirements. Before discussing the Sample Risk Assessment using common Risk Assessment Form, the following is short description about the systematic consideration in assessing the risk security in the organization.
- The business harm likely to result from a security failure, taking into account the potential consequences of a loss of confidentiality, integrity or availability of the information and other assets;
- The realistic likelihood of such a failure occurring in the light of prevailing threats and vulnerabilities, and the controls currently implemented.
The results of this security risk assessment must be registered using the following Risk Assessment Form (as a Sample Risk Assessment) that will help guide and determine the appropriate management action and priorities for managing information security risks, and for implementing controls selected to protect against these risks. The process of assessing risks and selecting controls may need to be performed a number of times to cover different parts of the organization or individual information systems.
To provide a sample risk assessment, the previous scenario about networking connection between the Mining office and the HR building in Guinea Smelter as in the networking diagram below.
Sample risk assessment - network diagram
For the purpose of this sample risk assessment using the above network diagram, the security risks that will likely impact to the business continuity need to be identified. All of the risks must be registered in the following Risk assessment form.
click for larger image Or Click the disaster recovery plan template in pdf file here.
The risks
Identify all the possible risks that will likely impact to the business and in this sample risk assessment using the above network diagram the risks can be identified as follows:
Risk #1 the uplink cable
- Business function: Single uplink backbone cable connecting both Mine office and HR buildings.
- The threat: Backbone Cable Failure
- Consequences: The computers in the Mine building will be disconnected from all the network resources and network application
- Likelihood: Possible.
- Existing controls: Protecting the network cable with a metal pipe and run underground buried around 30 cm depth.
You still need to fill-in the other columns: Consequence rating; Likelihood rating; Level of Risk and Risk Priority. However, the following legends should be defined that should fit to your business environment:
| Consequence | Likelihood | Level of Risk | Risk Priority | |
| High: $2M impact on the organization or serious strategy impact | 1 Highly possible | High | Large degree of impact | High Risk |
| Medium: $500K – $2M impact on the organization or significant operating impact | 2 Possible | Medium | Medium degree of impact | Medium risk |
| Low: $500K impact on the organization, tactical impact on the operations | 3 Likely | Low | Minimal impact | Low Risks |
| 4 Not very likely | ||||
| 5 Never | ||||
In this sample risk assessment, the “Possible” entry is in the Likelihood column in (refer to the above Risk Assessment Form) and “Medium Risk” entry is in the Consequence column.
The “adequacy of existing control” column must describe the current control, in this sample risk assessment the control is not good enough to protect network cabling from damage since the cable is only protected inside the metal pipe that is run underground with only 30 cm depth. Besides, above the cable is a roadway for light vehicles.
Beside the control, the consequence will result a significant operating impact to all users in Mine building. This will disrupt the business continuity with the possible impact of disconnecting all the network resources and network applications.
You can assess the risks of other critical items based on the above network diagram such as WAN connection link; the LAN switches, andperimeter router; Active directory DC server; domain name servers; DHCP server and other file servers in HR building. By applying this sample risk assessment you can also develop security risk assessment for your LAN networking (including your wireless LAN) as well as WAN networking(including frame relay network, or ISDN network, or even your PPP connection between remote sites) critical assets and take appropriate control to eliminate the risks or at least minimize the impact. All the possible risks must be registered using sample risk assessment form above.
Subscribe to:
Posts (Atom)