• No results found

chapter13_physical_security.pdf

N/A
N/A
Protected

Academic year: 2020

Share "chapter13_physical_security.pdf"

Copied!
21
0
0

Loading.... (view fulltext now)

Full text

(1)

Computer Security:

Computer Security:

Principles and Practice

Principles and Practice

First Edition First Edition

by William Stallings and Lawrie Brown by William Stallings and Lawrie Brown

Chapter 13 – Physical and

Chapter 13 – Physical and

(2)

Agenda

Agenda

 AnnouncementsAnnouncements

 Mr. Vaislay – April 25Mr. Vaislay – April 25thth 10 AM 10 AM

Discuss management aspect of securityDiscuss management aspect of security

 Physical securityPhysical security  BreakBreak

(3)

Physical and Infrastructure

Physical and Infrastructure

Security

Security

 now consider physical / premises securitynow consider physical / premises security

 three elements of info system security:three elements of info system security:

 logical security - protect computer datalogical security - protect computer data

(4)

Physical Security

Physical Security

 protect physical assets that support the protect physical assets that support the storage and processing of information

storage and processing of information

 involves two complementary requirements:involves two complementary requirements:

 prevent damage to physical infrastructureprevent damage to physical infrastructure

information system hardwareinformation system hardware • physical facilityphysical facility

• supporting facilitiessupporting facilities

• personnelpersonnel

(5)
(6)

Physical Security Threats

Physical Security Threats

 look at physical situations / occurrences look at physical situations / occurrences that threaten information systems:

that threaten information systems:

 environmental threats (incl. natural disasters)environmental threats (incl. natural disasters)  technical threatstechnical threats

 human-caused threatshuman-caused threats

(7)

Natural Disasters

Natural Disasters

 tornadotornado

 hurricanehurricane  earthquakeearthquake

 ice storm / blizzardice storm / blizzard  lightninglightning

(8)

Environmental Threats

Environmental Threats

 inappropriate temperature and humidityinappropriate temperature and humidity

 fire and smokefire and smoke  waterwater

 chemical, radiological, biological hazardschemical, radiological, biological hazards  dustdust

(9)

Technical Threats

Technical Threats

 electrical power is essential to run equipmentelectrical power is essential to run equipment

 power utility problems: power utility problems:

• under-voltage - dips/brownouts/outages, interrupt serviceunder-voltage - dips/brownouts/outages, interrupt service

• over-voltage - surges/faults/lightening, can destroy chipsover-voltage - surges/faults/lightening, can destroy chips

• noise - on power lines, may interfere with device operationnoise - on power lines, may interfere with device operation

electromagnetic interference (EMI)electromagnetic interference (EMI)

 from line noise, motors, fans, heavy equipment, other from line noise, motors, fans, heavy equipment, other

computers, nearby radio stations & microwave relays

computers, nearby radio stations & microwave relays

(10)

Human-Caused Threats

Human-Caused Threats

 less predictable, may be targeted, harder less predictable, may be targeted, harder to deal with

to deal with

 include:include:

 unauthorized physical accessunauthorized physical access

leading to other threatsleading to other threats

 theft of equipment / datatheft of equipment / data

(11)

Mitigation Measures

Mitigation Measures

Environmental Threats

Environmental Threats

 inappropriate temperature and humidityinappropriate temperature and humidity

 environmental control equipment, powerenvironmental control equipment, power

 fire and smokefire and smoke

 alarms, preventative measures, fire mitigationalarms, preventative measures, fire mitigation

 smoke detectors, no smokingsmoke detectors, no smoking

waterwater

 manage lines, equipment location, cutoff sensorsmanage lines, equipment location, cutoff sensors

(12)

Mitigation Measures

Mitigation Measures

Technical Threats

Technical Threats

 electrical power for critical equipment useelectrical power for critical equipment use

 use uninterruptible power supply (UPS) use uninterruptible power supply (UPS)  emergency power generator emergency power generator

 electromagnetic interference (EMI)electromagnetic interference (EMI)

(13)

Mitigation Measures

Mitigation Measures

Human-Caused Threats

Human-Caused Threats

 physical access controlphysical access control

 IT equipment, wiring, power, comms, mediaIT equipment, wiring, power, comms, media

 have a spectrum of approacheshave a spectrum of approaches

 restrict building access, locked area, secured, restrict building access, locked area, secured,

power switch secured, tracking device power switch secured, tracking device

(14)

Recovery from Physical

Recovery from Physical

Security Breaches

Security Breaches

 redundancyredundancy

 to provide recovery from loss of datato provide recovery from loss of data

 ideally off-site, updated as often as feasibleideally off-site, updated as often as feasible  can use batch encrypted remote backupcan use batch encrypted remote backup

 extreme is remote hot-site with live dataextreme is remote hot-site with live data

 physical equipment damage recoveryphysical equipment damage recovery

(15)

Threat Assessment

Threat Assessment

1.

1. set up a steering committee set up a steering committee

2.

2. obtain information and assistance obtain information and assistance

3.

3. identify all possible threats identify all possible threats

4.

4. determine the likelihood of each threat determine the likelihood of each threat

5.

5. approximate the direct costs approximate the direct costs

6.

6. consider cascading costs consider cascading costs

7.

(16)

Planning and Implementation

Planning and Implementation

 after assessment then develop a plan for after assessment then develop a plan for threat prevention, mitigation, recovery

threat prevention, mitigation, recovery

 typical steps:typical steps:

1.

1. assess internal and external resourcesassess internal and external resources

2.

2. identify challenges and prioritize activitiesidentify challenges and prioritize activities

3.

3. develop a plandevelop a plan

4.

(17)
(18)

Physical / Logical Security

Physical / Logical Security

Integration

Integration

 have many detection / prevention deviceshave many detection / prevention devices

 more effective if have central controlmore effective if have central control

 hence desire to integrate physical and hence desire to integrate physical and logical security, esp access control

logical security, esp access control

 need standards in this areaneed standards in this area

 FIPS 201-1 “FIPS 201-1 “Personal Identity Verification Personal Identity Verification

(PIV) of Federal Employees and Contractors

(19)
(20)
(21)

Summary

Summary

 introduced physical security issuesintroduced physical security issues

 threats: environmental,technical, humanthreats: environmental,technical, human  mitigation measures and recoverymitigation measures and recovery

References

Related documents