Computer Security:
Computer Security:
Principles and Practice
Principles and Practice
First Edition First Edition
by William Stallings and Lawrie Brown by William Stallings and Lawrie Brown
Chapter 13 – Physical and
Chapter 13 – Physical and
Physical and Infrastructure
Physical and Infrastructure
Security
Security
now consider physical / premises securitynow consider physical / premises security
three elements of info system security:three elements of info system security:
logical security - protect computer datalogical security - protect computer data
Physical Security
Physical Security
protect physical assets that support the protect physical assets that support the storage and processing of information
storage and processing of information
involves two complementary requirements:involves two complementary requirements:
prevent damage to physical infrastructureprevent damage to physical infrastructure
• information system hardwareinformation system hardware
• physical facilityphysical facility
• supporting facilitiessupporting facilities
• personnelpersonnel
Physical Security Threats
Physical Security Threats
look at physical situations / occurrences look at physical situations / occurrences that threaten information systems:
that threaten information systems:
environmental threats (incl. natural disasters)environmental threats (incl. natural disasters) technical threatstechnical threats
human-caused threatshuman-caused threats
Natural Disasters
Natural Disasters
tornadotornado
hurricanehurricane earthquakeearthquake
ice storm / blizzardice storm / blizzard
Environmental Threats
Environmental Threats
inappropriate temperature and humidityinappropriate temperature and humidity
fire and smokefire and smoke waterwater
chemical, radiological, biological hazardschemical, radiological, biological hazards
dustdust
Technical Threats
Technical Threats
electrical power is essential to run equipmentelectrical power is essential to run equipment
power utility problems: power utility problems:
• under-voltage - dips/brownouts/outages, interrupt serviceunder-voltage - dips/brownouts/outages, interrupt service
• over-voltage - surges/faults/lightening, can destroy chipsover-voltage - surges/faults/lightening, can destroy chips
• noise - on power lines, may interfere with device operationnoise - on power lines, may interfere with device operation
electromagnetic interference (EMI)electromagnetic interference (EMI)
from line noise, motors, fans, heavy equipment, other from line noise, motors, fans, heavy equipment, other
computers, nearby radio stations & microwave relays
computers, nearby radio stations & microwave relays
Human-Caused Threats
Human-Caused Threats
less predictable, may be targeted, harder less predictable, may be targeted, harder to deal with
to deal with
include:include:
unauthorized physical accessunauthorized physical access
• leading to other threatsleading to other threats
theft of equipment / datatheft of equipment / data
Mitigation Measures
Mitigation Measures
Environmental Threats
Environmental Threats
inappropriate temperature and humidityinappropriate temperature and humidity
environmental control equipment, powerenvironmental control equipment, power
fire and smokefire and smoke
alarms, preventative measures, fire mitigationalarms, preventative measures, fire mitigation
smoke detectors, no smokingsmoke detectors, no smoking
waterwater
manage lines, equipment location, cutoff sensorsmanage lines, equipment location, cutoff sensors
other threatsother threats
appropriate technical counter-measures, limit dust appropriate technical counter-measures, limit dust
entry, pest control
Mitigation Measures
Mitigation Measures
Technical Threats
Technical Threats
electrical power for critical equipment useelectrical power for critical equipment use
use uninterruptible power supply (UPS) use uninterruptible power supply (UPS) emergency power generator emergency power generator
electromagnetic interference (EMI)electromagnetic interference (EMI)
Mitigation Measures
Mitigation Measures
Human-Caused Threats
Human-Caused Threats
physical access controlphysical access control
IT equipment, wiring, power, comms, mediaIT equipment, wiring, power, comms, media
have a spectrum of approacheshave a spectrum of approaches
restrict building access, locked area, secured, restrict building access, locked area, secured,
power switch secured, tracking device power switch secured, tracking device
Recovery from Physical
Recovery from Physical
Security Breaches
Security Breaches
redundancyredundancy
to provide recovery from loss of datato provide recovery from loss of data
ideally off-site, updated as often as feasibleideally off-site, updated as often as feasible can use batch encrypted remote backupcan use batch encrypted remote backup
extreme is remote hot-site with live dataextreme is remote hot-site with live data
physical equipment damage recoveryphysical equipment damage recovery
Threat Assessment
Threat Assessment
1.
1. set up a steering committee set up a steering committee
2.
2. obtain information and assistance obtain information and assistance
3.
3. identify all possible threats identify all possible threats
4.
4. determine the likelihood of each threat determine the likelihood of each threat
5.
5. approximate the direct costs approximate the direct costs
6.
6. consider cascading costs consider cascading costs
7.
7. prioritize the threatsprioritize the threats
8.
Planning and Implementation
Planning and Implementation
after assessment then develop a plan for after assessment then develop a plan for threat prevention, mitigation, recovery
threat prevention, mitigation, recovery
typical steps:typical steps:
1.
1. assess internal and external resourcesassess internal and external resources
2.
2. identify challenges and prioritize activitiesidentify challenges and prioritize activities
3.
3. develop a plandevelop a plan
4.
Physical / Logical Security
Physical / Logical Security
Integration
Integration
have many detection / prevention deviceshave many detection / prevention devices
more effective if have central controlmore effective if have central control hence desire to integrate physical and hence desire to integrate physical and
logical security, esp access control
logical security, esp access control
need standards in this areaneed standards in this area
FIPS 201-1 “FIPS 201-1 “Personal Identity Verification Personal Identity Verification
(PIV) of Federal Employees and Contractors
Summary
Summary
introduced physical security issuesintroduced physical security issues
threats: environmental,technical, humanthreats: environmental,technical, human mitigation measures and recoverymitigation measures and recovery
assessment, planning, implementationassessment, planning, implementation