Computer Security:
Computer Security:
Principles and Practice
Principles and Practice
First Edition First Edition
by William Stallings and Lawrie Brown by William Stallings and Lawrie Brown
Lecture slides by Lawrie Brown Lecture slides by Lawrie Brown
Chapter 14 –
Human Factors
Human Factors
important, broad area
important, broad area
consider a few key topics:
consider a few key topics:
security awareness, training, and educationsecurity awareness, training, and education
organizational security policy organizational security policy
personnel securitypersonnel security
Security Awareness, Training,
Security Awareness, Training,
and Education
and Education
prominent topic in various standards
prominent topic in various standards
provides benefits in:
provides benefits in:
improving employee behaviorimproving employee behavior
increasing employee accountabilityincreasing employee accountability
mitigating liability for employee behaviormitigating liability for employee behavior
complying with regulations and contractual complying with regulations and contractual
Awareness
Awareness
seeks to inform and focus an employee's
seeks to inform and focus an employee's
attention on security issues
attention on security issues
threats, vulnerabilities, impacts, responsibilitythreats, vulnerabilities, impacts, responsibility
must be tailored to organization’s needs
must be tailored to organization’s needs
using a variety of means
using a variety of means
events, promo materials, briefings, policy docevents, promo materials, briefings, policy doc
should have an employee security policy
should have an employee security policy
document
Training
Training
teaches what people should do and how
teaches what people should do and how
they do it to securely perform IS tasks
they do it to securely perform IS tasks
encompasses a spectrum covering:
encompasses a spectrum covering:
general usersgeneral users
• good computer security practicesgood computer security practices
programmers, developers, maintainersprogrammers, developers, maintainers
• security mindset, secure code developmentsecurity mindset, secure code development
managersmanagers
• tradeoffs involving security risks, costs, benefitstradeoffs involving security risks, costs, benefits
executivesexecutives
Education
Education
most in depth
most in depth
targeted at security professionals whose
targeted at security professionals whose
jobs require expertise in security
jobs require expertise in security
more employee career development
more employee career development
often provided by outside sources
often provided by outside sources
college coursescollege courses
Organizational Security Policy
Organizational Security Policy
“
“
formal statement of rules by which people
formal statement of rules by which people
given access to organization's technology
given access to organization's technology
and information assets must abide”
and information assets must abide”
Organizational Security Policy
Organizational Security Policy
need written security policy document
need written security policy document
to define acceptable behavior, expected
to define acceptable behavior, expected
practices, and responsibilities
practices, and responsibilities
makes clear what is protected and whymakes clear what is protected and why articulates security procedures / controlsarticulates security procedures / controls states responsibility for protectionstates responsibility for protection
provides basis to resolve conflicts provides basis to resolve conflicts
must reflect executive security decisions
must reflect executive security decisions
Policy Document Responsibility
Policy Document Responsibility
security policy needs broad support
security policy needs broad support
especially from top management
especially from top management
should be developed by a team including:
should be developed by a team including:
site security administrator, IT technical staff, site security administrator, IT technical staff,
user groups admins, security incident user groups admins, security incident
response team, user groups representatives, response team, user groups representatives,
Document Content
Document Content
what is the reason for the policy?what is the reason for the policy? who developed the policy?who developed the policy?
who approved the policy?who approved the policy?
whose authority sustains the policy?whose authority sustains the policy? which laws / regulations is it based on?which laws / regulations is it based on? who will enforce the policy?who will enforce the policy?
how will the policy be enforced?how will the policy be enforced? whom does the policy affect?whom does the policy affect?
what information assets must be protected?what information assets must be protected? what are users actually required to do?what are users actually required to do?
how should security breaches be reported?how should security breaches be reported?
Security Policy Topics
Security Policy Topics
principlesprinciples
organizational reporting structureorganizational reporting structure physical securityphysical security
hiring, management, and firinghiring, management, and firing
data protectiondata protection
communications securitycommunications security hardwarehardware
softwaresoftware
Security Policy Topics cont.
Security Policy Topics cont.
technical supporttechnical support privacyprivacy
accessaccess
accountabilityaccountability authenticationauthentication availabilityavailability
maintenancemaintenance
violations reportingviolations reporting business continuitybusiness continuity
Resources
Resources
ISO 17799
ISO 17799
popular international standardpopular international standard
has a comprehensive set of controls has a comprehensive set of controls
a convenient framework for policy authorsa convenient framework for policy authors
COBIT
COBIT
business-oriented set of standardsbusiness-oriented set of standards
includes IT security and control practicesincludes IT security and control practices
Standard of Good Practice for Information
Standard of Good Practice for Information
Security
Security
Personnel Security
Personnel Security
hiring, training, monitoring behavior, and hiring, training, monitoring behavior, and
handling departure handling departure
employees security violations occur:employees security violations occur:
unwittingly aiding commission of violationunwittingly aiding commission of violation knowingly violating controls or proceduresknowingly violating controls or procedures
threats include:threats include:
gaining unauthorized access, altering data,gaining unauthorized access, altering data, deleting deleting
production and back up data,
production and back up data, crashing systems,crashing systems, destroying systems,
destroying systems, misusing systems ,misusing systems , holding data holding data hostage,
hostage, stealing strategic or customer data for stealing strategic or customer data for corporate espionage or fraud schemes
Security in Hiring Process
Security in Hiring Process
objective:
objective:
““to ensure that employees, contractors and third to ensure that employees, contractors and third party users understand their responsibilities, and
party users understand their responsibilities, and
are suitable for the roles they are considered for,
are suitable for the roles they are considered for,
and to reduce the risk of theft, fraud or misuse of
and to reduce the risk of theft, fraud or misuse of
facilities”
facilities”
need appropriate background checks,
need appropriate background checks,
screening, and employment agreements
Background Checks & Screening
Background Checks & Screening
issues:issues:
inflated resumesinflated resumes
reticence of former employers to give good or bad reticence of former employers to give good or bad
references due to fear of lawsuits
references due to fear of lawsuits
employers do need to make significant effort to employers do need to make significant effort to
do background checks / screening do background checks / screening
get detailed employment / education historyget detailed employment / education history reasonable checks on accuracy of detailsreasonable checks on accuracy of details have experienced staff members interviewhave experienced staff members interview
for some sensitive positions, additional intensive for some sensitive positions, additional intensive
Employment Agreements
Employment Agreements
employees should agree to and sign the
employees should agree to and sign the
terms and conditions of their employment
terms and conditions of their employment
contract, which should include:
contract, which should include:
information on their and the organization’s information on their and the organization’s
security responsibilities security responsibilities
confidentiality and non-disclosure agreementconfidentiality and non-disclosure agreement
agreement to abide by organization's security agreement to abide by organization's security
During Employment
During Employment
current employee security objectives:
current employee security objectives:
• ensure employees, contractors, third party users ensure employees, contractors, third party users are aware of info security threats & concerns
are aware of info security threats & concerns • know their responsibilities and liabilitiesknow their responsibilities and liabilities
• are equipped to support organizational security are equipped to support organizational security policy in their work, and reduce human error risks policy in their work, and reduce human error risks
need security policy and training
need security policy and training
security principles:
security principles:
least privilegeleast privilege
separation of dutiesseparation of duties
Termination of Employment
Termination of Employment
termination security objectives: termination security objectives:
• ensure employees, contractors, third party users ensure employees, contractors, third party users
exit organization or change employment in an
exit organization or change employment in an
orderly manner
orderly manner
• that the return of all equipment and the removal of that the return of all equipment and the removal of
all access rights are completed
all access rights are completed
critical actions:critical actions:
remove name from authorized access listremove name from authorized access list
inform guards that general access not allowedinform guards that general access not allowed remove personal access codes, change lock remove personal access codes, change lock
combinations, reprogram access card systems, etc
Email & Internet Use Policies
Email & Internet Use Policies
E-mail & Internet access for employees is
E-mail & Internet access for employees is
common in office and some factories
common in office and some factories
increasingly have e-mail and Internet use
increasingly have e-mail and Internet use
policies in organization's security policy
policies in organization's security policy
due to concerns regarding
due to concerns regarding
work time lostwork time lost
computer / comms resources consumedcomputer / comms resources consumed risk of importing malwarerisk of importing malware
Suggested Policies
Suggested Policies
business use onlybusiness use only policy scopepolicy scope
content ownershipcontent ownership privacyprivacy
standard of conductstandard of conduct
reasonable personal usereasonable personal use unlawful activity prohibitedunlawful activity prohibited security policysecurity policy
Example
Example
Summary
Summary
introduced some important topics relating
introduced some important topics relating
to human factors
to human factors
security awareness, training & education
security awareness, training & education
organizational security policy
organizational security policy
personnel security
personnel security