C7 Information Security

Systems reliability ← (Confidentiality + Privacy + Processing integrity + Availability) ← Security

Fundamental Concepts

  1. Security is a management issue, rather than a technology one
  • Policy development
  • Effective communication of policies
  • Design and employment of appropriate control procedures
  • Monitoring & taking remedial action
  1. The time-based model of security
  • Focusing on the relationship of preventive, detective, and corrective controls
  • P>D+C → Effective
  1. Defense-in-depth
  • To employ multiple layers of controls to avoid single failures

Targeted Attacks

  1. Reconnaissance
  2. Attempt social engineering
  3. Scan & map the target
  4. Research
  5. Execute
  6. Cover tracks

Preventive Controls

  • Authentication controls: while accessing, verify the identify
  • Authorization controls: restricting specific portions and what actions permitted to perform
  • Access control matrix, compatibility test
  • Both for users and devices
  • Training
  • Importance of security, anti-social engineering, IS professionals, keep abreast, top-management support
  • Controlling physical access
  • Controlling remote access
  • Border router, firewall, DMZ (demilitarized zone), TCP / IP, routers
  • ACL (access control list), static / stateful packet filtering
  • Deep packet inspection, IPS (intrusion prevention systems)
  • Host & application hardening
  • Encryption: transforming plaintext to ciphertext (decryption)
  • Symmetric / asymmetric (private and public key)

Detective Controls

  • Log analysis
  • Intrusion detection systems
  • Managerial reports
  • Security testing

Corrective Controls

  • CERT (computer emergency response team)
  • CISO (chief information security officer)
  • Patch management
最后編輯于
?著作權歸作者所有,轉載或內容合作請聯系作者
平臺聲明:文章內容(如有圖片或視頻亦包括在內)由作者上傳并發布,文章內容僅代表作者本人觀點,簡書系信息發布平臺,僅提供信息存儲服務。

推薦閱讀更多精彩內容

  • PLEASE READ THE FOLLOWING APPLE DEVELOPER PROGRAM LICENSE...
    念念不忘的閱讀 13,528評論 5 6
  • 番石榴(番石榴,又名芭樂、拔子、雞矢果、雞屎拔、黃肚子。因其種殼極硬,且不怕禽胃而隨糞便排至鳥跡所到之處萌發生長,...
    小蟲_6c80閱讀 285評論 0 0
  • 有大半年了,日子過得稀里糊涂,總沒頭緒,總忙不清楚,心里總是很焦慮。 暑假了,決定理理頭緒。 我知道自己的焦慮源自...
    山鬼_碧芳閱讀 299評論 0 0
  • 很喜歡日本的動畫電影,也的確看過不少,有的堪稱經典,有的看完就忘,而《螢火蟲之墓》,是在諸多電影中,為數不多的一部...
    千千子衿閱讀 1,572評論 0 1
  • 北角,North Point,是一個非常適合來港吃住行的地方。沒有尖沙咀、銅鑼灣那么擁擠,也盡享地鐵、叮叮車、碼頭...
    339da1fbd744閱讀 1,690評論 0 0