• No results found

ch05 HumanFactorsandPolicy

N/A
N/A
Protected

Academic year: 2020

Share "ch05 HumanFactorsandPolicy"

Copied!
25
0
0

Loading.... (view fulltext now)

Full text

(1)

Computer Security:

Computer Security:

Principles and Practice

Principles and Practice

First Edition First Edition

by William Stallings and Lawrie Brown by William Stallings and Lawrie Brown

Lecture slides by Lawrie Brown Lecture slides by Lawrie Brown

Chapter 14 –

(2)

Human Factors

Human Factors

important, broad area

important, broad area

consider a few key topics:

consider a few key topics:

 security awareness, training, and educationsecurity awareness, training, and education

 organizational security policy organizational security policy

 personnel securitypersonnel security

(3)

Security Awareness, Training,

Security Awareness, Training,

and Education

and Education

prominent topic in various standards

prominent topic in various standards

provides benefits in:

provides benefits in:

 improving employee behaviorimproving employee behavior

 increasing employee accountabilityincreasing employee accountability

 mitigating liability for employee behaviormitigating liability for employee behavior

 complying with regulations and contractual complying with regulations and contractual

(4)
(5)

Awareness

Awareness

seeks to inform and focus an employee's

seeks to inform and focus an employee's

attention on security issues

attention on security issues

 threats, vulnerabilities, impacts, responsibilitythreats, vulnerabilities, impacts, responsibility

must be tailored to organization’s needs

must be tailored to organization’s needs

using a variety of means

using a variety of means

 events, promo materials, briefings, policy docevents, promo materials, briefings, policy doc

should have an employee security policy

should have an employee security policy

document

(6)

Training

Training

teaches what people should do and how

teaches what people should do and how

they do it to securely perform IS tasks

they do it to securely perform IS tasks

encompasses a spectrum covering:

encompasses a spectrum covering:

 general usersgeneral users

• good computer security practicesgood computer security practices

 programmers, developers, maintainersprogrammers, developers, maintainers

• security mindset, secure code developmentsecurity mindset, secure code development

 managersmanagers

• tradeoffs involving security risks, costs, benefitstradeoffs involving security risks, costs, benefits

 executivesexecutives

(7)

Education

Education

most in depth

most in depth

targeted at security professionals whose

targeted at security professionals whose

jobs require expertise in security

jobs require expertise in security

more employee career development

more employee career development

often provided by outside sources

often provided by outside sources

 college coursescollege courses

(8)

Organizational Security Policy

Organizational Security Policy

formal statement of rules by which people

formal statement of rules by which people

given access to organization's technology

given access to organization's technology

and information assets must abide”

and information assets must abide”

(9)

Organizational Security Policy

Organizational Security Policy

need written security policy document

need written security policy document

to define acceptable behavior, expected

to define acceptable behavior, expected

practices, and responsibilities

practices, and responsibilities

 makes clear what is protected and whymakes clear what is protected and why  articulates security procedures / controlsarticulates security procedures / controls  states responsibility for protectionstates responsibility for protection

 provides basis to resolve conflicts provides basis to resolve conflicts

must reflect executive security decisions

must reflect executive security decisions

(10)
(11)

Policy Document Responsibility

Policy Document Responsibility

security policy needs broad support

security policy needs broad support

especially from top management

especially from top management

should be developed by a team including:

should be developed by a team including:

 site security administrator, IT technical staff, site security administrator, IT technical staff,

user groups admins, security incident user groups admins, security incident

response team, user groups representatives, response team, user groups representatives,

(12)

Document Content

Document Content

 what is the reason for the policy?what is the reason for the policy?  who developed the policy?who developed the policy?

 who approved the policy?who approved the policy?

whose authority sustains the policy?whose authority sustains the policy?  which laws / regulations is it based on?which laws / regulations is it based on?  who will enforce the policy?who will enforce the policy?

 how will the policy be enforced?how will the policy be enforced?  whom does the policy affect?whom does the policy affect?

what information assets must be protected?what information assets must be protected?what are users actually required to do?what are users actually required to do?

 how should security breaches be reported?how should security breaches be reported?

(13)

Security Policy Topics

Security Policy Topics

 principlesprinciples

 organizational reporting structureorganizational reporting structurephysical securityphysical security

hiring, management, and firinghiring, management, and firing

data protectiondata protection

 communications securitycommunications securityhardwarehardware

softwaresoftware

(14)

Security Policy Topics cont.

Security Policy Topics cont.

 technical supporttechnical support  privacyprivacy

 accessaccess

 accountabilityaccountability  authenticationauthentication  availabilityavailability

 maintenancemaintenance

 violations reportingviolations reporting  business continuitybusiness continuity

(15)

Resources

Resources

ISO 17799

ISO 17799

 popular international standardpopular international standard

 has a comprehensive set of controls has a comprehensive set of controls

 a convenient framework for policy authorsa convenient framework for policy authors

COBIT

COBIT

 business-oriented set of standardsbusiness-oriented set of standards

 includes IT security and control practicesincludes IT security and control practices

Standard of Good Practice for Information

Standard of Good Practice for Information

Security

Security

(16)

Personnel Security

Personnel Security

 hiring, training, monitoring behavior, and hiring, training, monitoring behavior, and

handling departure handling departure

 employees security violations occur:employees security violations occur:

 unwittingly aiding commission of violationunwittingly aiding commission of violation  knowingly violating controls or proceduresknowingly violating controls or procedures

 threats include:threats include:

 gaining unauthorized access, altering data,gaining unauthorized access, altering data, deleting deleting

production and back up data,

production and back up data, crashing systems,crashing systems, destroying systems,

destroying systems, misusing systems ,misusing systems , holding data holding data hostage,

hostage, stealing strategic or customer data for stealing strategic or customer data for corporate espionage or fraud schemes

(17)

Security in Hiring Process

Security in Hiring Process

objective:

objective:

 ““to ensure that employees, contractors and third to ensure that employees, contractors and third party users understand their responsibilities, and

party users understand their responsibilities, and

are suitable for the roles they are considered for,

are suitable for the roles they are considered for,

and to reduce the risk of theft, fraud or misuse of

and to reduce the risk of theft, fraud or misuse of

facilities”

facilities”

need appropriate background checks,

need appropriate background checks,

screening, and employment agreements

(18)

Background Checks & Screening

Background Checks & Screening

 issues:issues:

 inflated resumesinflated resumes

 reticence of former employers to give good or bad reticence of former employers to give good or bad

references due to fear of lawsuits

references due to fear of lawsuits

employers do need to make significant effort to employers do need to make significant effort to

do background checks / screening do background checks / screening

 get detailed employment / education historyget detailed employment / education history  reasonable checks on accuracy of detailsreasonable checks on accuracy of details  have experienced staff members interviewhave experienced staff members interview

 for some sensitive positions, additional intensive for some sensitive positions, additional intensive

(19)

Employment Agreements

Employment Agreements

employees should agree to and sign the

employees should agree to and sign the

terms and conditions of their employment

terms and conditions of their employment

contract, which should include:

contract, which should include:

 information on their and the organization’s information on their and the organization’s

security responsibilities security responsibilities

 confidentiality and non-disclosure agreementconfidentiality and non-disclosure agreement

 agreement to abide by organization's security agreement to abide by organization's security

(20)

During Employment

During Employment

current employee security objectives:

current employee security objectives:

• ensure employees, contractors, third party users ensure employees, contractors, third party users are aware of info security threats & concerns

are aware of info security threats & concerns • know their responsibilities and liabilitiesknow their responsibilities and liabilities

• are equipped to support organizational security are equipped to support organizational security policy in their work, and reduce human error risks policy in their work, and reduce human error risks

need security policy and training

need security policy and training

security principles:

security principles:

 least privilegeleast privilege

 separation of dutiesseparation of duties

(21)

Termination of Employment

Termination of Employment

 termination security objectives: termination security objectives:

• ensure employees, contractors, third party users ensure employees, contractors, third party users

exit organization or change employment in an

exit organization or change employment in an

orderly manner

orderly manner

• that the return of all equipment and the removal of that the return of all equipment and the removal of

all access rights are completed

all access rights are completed

 critical actions:critical actions:

 remove name from authorized access listremove name from authorized access list

 inform guards that general access not allowedinform guards that general access not allowed  remove personal access codes, change lock remove personal access codes, change lock

combinations, reprogram access card systems, etc

(22)

Email & Internet Use Policies

Email & Internet Use Policies

E-mail & Internet access for employees is

E-mail & Internet access for employees is

common in office and some factories

common in office and some factories

increasingly have e-mail and Internet use

increasingly have e-mail and Internet use

policies in organization's security policy

policies in organization's security policy

due to concerns regarding

due to concerns regarding

 work time lostwork time lost

 computer / comms resources consumedcomputer / comms resources consumed  risk of importing malwarerisk of importing malware

(23)

Suggested Policies

Suggested Policies

 business use onlybusiness use only  policy scopepolicy scope

 content ownershipcontent ownershipprivacyprivacy

 standard of conductstandard of conduct

 reasonable personal usereasonable personal use  unlawful activity prohibitedunlawful activity prohibited  security policysecurity policy

(24)

Example

Example

(25)

Summary

Summary

introduced some important topics relating

introduced some important topics relating

to human factors

to human factors

security awareness, training & education

security awareness, training & education

organizational security policy

organizational security policy

personnel security

personnel security

References

Related documents

This program is ideal for tribal leaders, tribal managers, tribal directors, and other officials who work in Indian Country and who wish to hone or acquire the leadership,

Division of Water Quality Engineer Jennifer Robinson has earned two prestigious awards from the Water Environment Association of Utah (WEAU) for outstanding work in her field

The DTaP/IPV/Hib vaccine (diphtheria, tetanus, acellular pertussis, inactivated polio vaccine, Hib) is a combined vaccine that contains the following active ingredients:.. •

and I experience no condemnation today is that all our sins have been punished and condemned, but in the body of another — in the body of Jesus Christ. WHAT IT MEANS TO OVERCOME THE

c) List below: expert keywords and/or phrases, author(s) of article, name of the journal in which the article appears, the volume, issue number, month, year and page numbers (or

"the man who invented management" (New York Times). „He was saying that

Emi rates Air Line te Ma p North G ree nwich Plantation Wharf W ands w orth Ri ve rside St Geor ge Wharf (V auxhall) Cadogan Chelsea Harbour Blackfria rs Millbank London Brid

[r]