People, Process and Technology
Download
Report
Transcript People, Process and Technology
Current Strategies for protecting the ICT
Infrastructure, including lessons Learnt
from recent threats, successful mitigation
and failures
Presented by:
Thomas Bbosa,CISSP
BitWork Consult Ltd
www.bitworkconsult.com
“ICT advisory services”
Introduction
There is increased dependence worldwide on
information and communication technology (ICT) and
ICT-based services for public and private sectors.
The modern ICT Infrastructure as
we know it today, has evolved
over the years.
-
In the mid 1940s huge computers could not even
do what our small calculators can do today
-
We then moved on to the mainframe technology
www.bitworkconsult.com
“ICT advisory services”
Internet access increased
-
-
Shift of focus from centralized to decentralized, distributed, network
computing
Drop in hardware prices ,desktop computers with fast processors, more
memory, high capacity
Cloud computing, mobile computing etc... we are talking about Software as
a service (SaaS), technologies like web 2.0 and enterprise 2.0
Brought myriad of issues
-
Exposure to Cyber threats also increases
-
Complexity in managing security: Confidentiality, Integrity, and availability
(C.I.A)
www.bitworkconsult.com
“ICT advisory services”
What are the Components of an
Enterprise ICT Infrastructure?
www.bitworkconsult.com
“ICT advisory services”
People
“ who we are”
“The best run companies function much like a flock of birds, in which individuals following fairly
simple rules interact with each other to form a cohesive and dynamic whole” - Lewin
People who use or interact with the ICT Infrastructure
include:
Share Holders / Owners
Management
Employees
Business Partners
Service providers
Contractors
Customers / Clients
Regulators etc…
www.bitworkconsult.com
“ICT advisory services”
Process
“what we do”
The processes refer to "work practices" or workflow.
Processes are the repeatable steps to accomplish
business objectives. Typical process in our ICT
Infrastructure could include:
Helpdesk / Service management
Incident Reporting and Management
Change Requests process
Request fulfillment
Access management
Identity management
Service Level / Third-party Services Management
IT procurement process
etc……...
www.bitworkconsult.com
“ICT advisory services”
Technology “what we use to improve what we do”
The ICT infrastructure today could consist of the
following components:
Physical Security components:
CCTV Cameras
Clock in systems / Biometrics
Environmental management Systems: Humidity Control, Ventilation , Air
Conditioning, Fire Control systems
Electricity / Power backup
Access devices:
Desktop computers
Laptops, ultra-mobile laptops and PDAs
Thin client computing.
Digital cameras, Printers, Scanners, Photocopier etc.
www.bitworkconsult.com
“ICT advisory services”
Technology ………………….
Network Infrastructure:
Cabling, Data/Voice Networks and equipment
Telecommunications services (PABX), including VoIP services , ISDN , Video
Conferencing
Server computers and associated storage devices
Operating software for server computers
Communications equipment and related hardware.
Intranet and Internet connections
VPNs and Virtual environments
Remote access services
Wireless connectivity
Application software:
Finance and assets systems, including Accounting packages, Inventory
management, HR systems, Assessment and reporting systems
Software as a service (Sass) - instead of software as a packaged or custom-made
product. Etc..
www.bitworkconsult.com
“ICT advisory services”
What are the Challenges &
Current Threats ?
www.bitworkconsult.com
“ICT advisory services”
Challenges
Globalization and Jurisdiction issues on Cyber crime
- There are no borders, no need for “Visas”
- Conflicting or Non-existing regulations
- cultural differences and varying degrees of technological maturity
IT security arms race - the bad guy is motivated
- with the adversary able to focus time and money on attacks while the target
has to prioritize spending on IT security among other budget items.
Blended Cyber Threats – changing attacks
- Technology and methods of attack always changing. Can combine several
methods of attack
www.bitworkconsult.com
“ICT advisory services”
The Bad guy is focused
www.bitworkconsult.com
“ICT advisory services”
The Threats
People
Process
Technology
www.bitworkconsult.com
“ICT advisory services”
The Threats - People
IT security threats and attacks caused by the Human
factor :
“Security is a chain, and People are the weakest link in the chain ”
Social Engineering: This is the act of tricking someone into giving
sensitive or confidential info that may be used against the company.
Insider threats: perhaps the most difficult category of threats, since the
perpetrators are already inside the organization. For example a
disgruntled employee could sell Company’s clients’ database to the
Competition. Includes as well outsourcing vendors, employees
introducing malware.
Application and Infrastructure Abuse: Employees continue to misuse
and abuse IT resources
- Instant messaging (IM) e.g. yahoo messenger, msn, skype etc..
- P2P File Sharing Applications e.g Kaaza, BitTorrent, BearShare, Limewire etc..
- Employees Internet / misuse e.g facebook, Twitter, youtube etc..
www.bitworkconsult.com
“ICT advisory services”
The Threats – People
Data Diddling: is the act of modifying information, programs, or
documents to commit fraud, tampers with INPUT data.
“Security is a chain, and People are the weakest link in the chain ”
For example if a cashier enters an amount of Ugx. 40,000/= into the cash register,
but really charges the customer Ugx. 60, 000/= and keeps the extra Ugx.
20,000/=.
Salami attack: one in which an attacker commits several small crimes
with the hope that the overall larger crime will go unnoticed.
For example, a bank employee may alter a banking software program to subtract
5 cents from each of the bank’s customers’ accounts once a month such as a
debit could be represented as service charge, and moved to the perpetrator’s
bank account. If this happened to all of the bank’s 50,000 customer accounts, the
intruder could make up to US$30,000 a year.
Trap Door/ Maintenance hooks: An undocumented access path through
a system usually made by Application Developers. This typically bypasses
the normal security mechanisms and can be used to gain access later on.
www.bitworkconsult.com
“ICT advisory services”
The Threats – People
Hackers / Crackers / phreakers: Hackers sometimes break into networks for
the thrill of the challenge (Script Kiddies), or for bragging rights in the hacker
community. Crackers aim at financial gain, Phreakers break into
telecommunication infrastructure like Public telephone systems or company
PBX.
Publication of illegal content: Involves dissemination of unacceptable
content online, include Racist material, terrorist literature, porn etc..
Shoulder Surfing: Is a technique in which the attacker looks over someone's
shoulder to obtain passwords, Information, PINs and other security codes
being entered. Shoulder surfing can also be done long distance with the aid of
binoculars or other vision-enhancing devices.
Wire tapping: Most communication signals can be vulnerable to some type
wire tapping or eaves dropping, using tools like cellular scanners, radio
receivers; telephone tapping devices etc.
Dumpster diving: practice of sifting through commercial or residential trash
to find items, documents or records that have been discarded by their owners,
but which may be useful to the dumpster diver.
www.bitworkconsult.com
“ICT advisory services”
The Threats – People
www.bitworkconsult.com
“ICT advisory services”
The Threats
People
Process
Technology
www.bitworkconsult.com
“ICT advisory services”
The Threats - Process
This section looks at weaknesses in the business
processes which could lead to attacks on the
Infrastructure:
“Security is a chain, and People are the weakest link in the chain ”
Failure to develop an Information Systems security Program:
Organizations should develop an Information Systems Security program
that documents the policy, procedures, standards etc… for protecting the
concerned assets. Issues that arise due to lack of a proper security
program could include:
1.
Lack of security awareness
2.
Concentration of duties
3.
Lack of ways to detect fraud
4.
Security through obscurity: Idea that attacker might fail to see
loopholes
www.bitworkconsult.com
“ICT advisory services”
The Threats – Process
“Security
Excessive
Userand
Rights/
Excessive
user
rights
is a chain,
Peopleprivileges:
are the weakest
link in the
chain
” or privileges,
is a very common security issue that has become increasingly hard to
control. It occurs if a user has more access rights than necessary, beyond
the necessary “need to know”.
Unencrypted Laptops and Removable Media: Loss of laptops and
removable media has become a major liability for corporations and
government agencies as well as for general consumers. All too frequently,
a major loss of personal or identifying information is traced back to the
loss of a single laptop or piece of removable media.
www.bitworkconsult.com
“ICT advisory services”
www.bitworkconsult.com
“ICT advisory services”
The Threats
People
Process
Technology
www.bitworkconsult.com
“ICT advisory services”
The Threats - Technology
Technology could be a powerful enabler of business
“Security is a chain, and People are the weakest link in the chain ”
productivity as well as a catalyst for crime activity:
Access Control attacks:
Access control is the process that involves :
- One Identifying who they are - Identification
- Proving that they are, who they say they are - Authentication
- Getting granted access to those areas of the system, where they are
supposed to have access - Authorization
This process could be compromised by any of the following attacks:
1. A dictionary attack uses a brute-force technique of successively trying
all the words in an exhaustive list (from a pre-arranged list of values)
- Brute force is trying every possible combinations
www.bitworkconsult.com
“ICT advisory services”
The Threats - Technology
2. Spoofing at login: A technique used by an attacker to present a fake
“Security
is a screen,
chain, and
People
are the
in thelogin.
chainThe
” credentials
login
often
tricking
theweakest
user to link
try and
are stored somewhere for the attacker to use later.
www.bitworkconsult.com
“ICT advisory services”
The Threats - Technology
Email and Instant Messaging Redirectors:
“Security
a chain, and
are the
weakest
link and
in therelay
chainoutgoing
”
Email isredirectors
arePeople
programs
that
intercept
emails,
and send an additional copy to an unintended address to which an
attacker has access. Instant messaging redirectors monitor instant
messaging applications and transmit transcripts to an attacker.
Session hijacking attack: Session hijacking refers to an attack in which
a legitimate user session is commandeered.
System Reconfiguration Attacks/ Ransomware: System
reconfiguration attacks, such as hostname lookup attacks and proxy
attacks, modify settings on a user’s computer to cause information to be
compromised. Ransomware can encrypts data and extort money from the
target in order to restore it.
Rootkits: refers generally to any software that hides the presence and
activity of malicious software.
www.bitworkconsult.com
“ICT advisory services”
The Threats - Technology
Man-in-the-Middle Attacks: A man-in-the-middle attack refers generally
“Security
a chain,
and People
are the weakest
in the chain
”
to an is
attack
in which
the attacker
positionslink
himself
between
two
communicating parties and gleans information to which he should not
have access.
Zero Day Attacks: A zero day vulnerability occurs when a flaw in software
code has been discovered and exploits of the flaw appear before a fix or
patch is available. Once a working exploit of the vulnerability is released
into the wild, users of the affected software will be compromised until a
software patch is available or some form of mitigation is taken by the user.
Phishing attack is a process of attempting to acquire sensitive
information such as usernames, passwords and credit card details by
masquerading as a trustworthy entity in an electronic communication.
Keyloggers and Screenloggers: Program installed on a victim's
machine that records every keystroke that a user makes. Used to steal
login in details.
www.bitworkconsult.com
“ICT advisory services”
The Threats - Technology
Content Injection Attacks: Content injection refers to inserting
“Security
is a chain,
andinto
People
are the weakest
linkaddition
in the chain
”
malicious
content
a legitimate
site. In
to deceptive
actions
such as redirecting to other sites, malicious content can install
crimeware on a user’s computer through a web browser vulnerability
or by social engineering, such as asking a user to download and install
anti-virus software that actually contains crimeware. Examples include:
1. Cross-Site Scripting (XSS):
Cross site scripting, better known as XSS, is the most pernicious and easily found
web application security issue. XSS allows attackers to deface web sites, insert
hostile content, conduct phishing attacks, take over the user’s browser using
JavaScript malware, and force users to conduct commands not of their own
choosing - an attack known as Cross-site Cross request forgeries (CSRF).
2. SQL Injection:
Injections, particularly SQL injections, are common in web applications. Injections
are possible due to intermingling of user supplied data within dynamic queries or
within poorly constructed stored procedures
www.bitworkconsult.com
“ICT advisory services”
Cross-Site Scripting
www.bitworkconsult.com
“ICT advisory services”
The Threats - Technology
Denial of service (DoS): is a general term for many different types of
“Security
is aHowever,
chain, andeach
People
are the
link in
in common,
the chain ” which is the goal
attacks.
attack
hasweakest
one thing
to deny others the service that the victim system usually provides.
Spam E-mail: Spam is anonymous, unsolicited bulk email – it is
effectively the email equivalent of physical junk mail delivered through the
post office. Spam is a problem not only because of the enormous
resources it demands, but also because it now serves as a means for
other types of attack. There is also reduced system performance and the
costs of filtering e-mail, loss of employee productivity or required
increased usage of help desk support. Spam consumes network
bandwidth used to transmit messages or consumes disk storage used to
store messages.
Botnets: A Botnet is collection of infected and compromised computing
devices harnessed together and remotely controlled for malicious
purposes. Thousands of systems with zombie codes can be used in
DDOS (Distributed denial of Service attacks) or spammers.
www.bitworkconsult.com
“ICT advisory services”
The Threats - Technology
Click Fraud: Online advertising networks offer the ability for a web site
operator to host third-party advertisements and collect payment for every
“Security is a chain, and People are the weakest link in the chain ”
time a user clicks on an advertisement. “Click fraud” refers to various
schemes in which the number of clicks is artificially inflated..
Other Malware: software designed to cause damage to a single
computer, server, or computer network. These include:
- Viruses - Virus is a small application, or a string of code, that infects
application, requires user action to compromise a machine. .
- Spy ware – Software that monitors user activity without user knowledge
or consent. Spyware can capture and release sensitive data, make
unauthorized changes, and decrease system performance.
- Trojan Horse - Trojan Horse is a program that is disguised as another
program, masquerades as useful application, but does harm.
- Worm - A Worm is Malware that reproduces on its own without a host
application. Worms can infect and take over computers without any help,
bar lax security, from a victim
www.bitworkconsult.com
“ICT advisory services”
The Threats - Technology
Wireless Networks threats: Wireless networks have now become
very common, for both organizations and individuals. Most laptops
“Security is a chain, and People are the weakest link in the chain ”
ship with wireless adaptors and organizations have also deployed
wireless LANs given the easy of deployment. Some of the security
issues with wireless networks include the following:
- Accidental association: When a user turns on a computer and it latches
on to a wireless access point from a neighboring company’s overlapping
network, this could cause security issues if the victim network is not
secure.
- War driving - War driving is the act of searching for Wi-Fi wireless
networks by a person in a moving vehicle, using a portable computer
(laptop) or PDA. Software for war driving is freely available on the Internet,
notably NetStumbler for Windows, Kismet or SWScanner for Linux. These
tools can sniff for any available wireless access points (APS)
www.bitworkconsult.com
“ICT advisory services”
The Threats - Technology
Blue tooth attacks: Various security holes have already appeared in
“Security
is a chain,
and
are the
weakest
linkin
in mobile
the chainphones
”
Bluetooth,
which
isPeople
becoming
widely
used
and highend smart phones. Some of these are listed below:
- Bluebugging - Refers to hacking into a Bluetooth device and using the
commands of that device without notifying or alerting the user. By blue
bugging, a hacker could eavesdrop on phone conversations, place phone
calls, send and receive text messages, and even connect to the Internet.
- Bluejacking - A kind of practical joke played out between Bluetoothenabled devices, bluejacking takes advantage of a loophole in the
technology's messaging options that allows a user to send unsolicited
messages to other nearby Bluetooth. (Similar to doorbell ditching)
www.bitworkconsult.com
“ICT advisory services”
The Threats - Technology
Physical ICT Infrastructure threats:
“Security is a chain, and People are the weakest link in the chain ”
The threats to the Physical ICT infrastructures include Natural
environment threats (earthquakes floods, tornadoes), Supply system
threats (power, Internet and Telecom outage, water, gas etc..),
Manmade threats (vandalism, fraud, theft), Politically motivated threats
(terrorist attacks, riots, bombings).
Other threats to look out for:
- 419 scam - “Advance Fee Fraud”
- Web vandalism: Attacks that deface web pages
- Fake products / Product imitations
www.bitworkconsult.com
“ICT advisory services”
So What is the solution?:
Strategies for protecting ICT Infrastructures
www.bitworkconsult.com
“ICT advisory services”
What is it that were are trying to protect?
- (Information) ASSET
DATA
www.bitworkconsult.com
“ICT advisory services”
Defense in-depth: a layered approach to security
National Legislations and Industry Compliance
Management practices
Laws, Int. Standards, Industry best practices..
Policies, Standards, Procedures, Awareness ...
Physical security
Guards, Biometrics, CCTV etc..
Perimeter
Network segments, Monitoring, IDS etc..
Internal Network
Host
Applications
DATA
www.bitworkconsult.com
“ICT advisory services”
Firewalls, VPN, IPS, Content Filters ..
OS hardening, updates, Authentication …
Patches, Anti-virus etc..
Acl, encryption etc..
The Solutions
People
Process
Technology
www.bitworkconsult.com
“ICT advisory services”
The Solution
People
Administrative Security
Logical Security
Technology
Physical security
www.bitworkconsult.com
“ICT advisory services”
Process
The Role of People: Administrative Security
Top management is responsible for overall security
in the organization and security management.
Senior Management takes care of assets (including
Human Resources, Data, Trade Secrets, Copy
rights, Reputation, Competitive edge etc..).
Management has to ensure that necessary action is
taken against identified threats / Risks. (Transferred,
avoided, reduced or accepted)
www.bitworkconsult.com
“ICT advisory services”
The Role of People: Administrative Security
Develop a security program :Organizations need to develop
security programs that outline the Roles, policy, procedures, standards
and guidelines for the ICT infrastructure security.
- Roles: Outline who is responsible for what e.g. ISO is
responsible for ensuring a good security posture for the
organization.
- Policies: general organization wide statements that set out the
mandatory requirements to ensure that a minimum security level.
Examples include: Acceptable E-mail Use Policy, Internet use
policy, Mobile devices use policy etc…
- Standards: Derived from policies, lay out specific steps or
processes required to meet a certain requirement. For example a
requirement that all email communication be encrypted.
www.bitworkconsult.com
“ICT advisory services”
The Role of People: Administrative Security
- Procedures: A procedure is the most specific of security
documents. A procedure is a detailed, in-depth, step-by-step
document that details exactly what is to be done. Examples
could include: Incident Identification and Reporting
Procedures, Media Handling Procedures etc...
- Guidelines: A guideline points to a statement in a policy or
procedure by which to determine a course of action. It’s a
recommendation or suggestion of how things should be done.
It is meant to be flexible so it can be customized for individual
situations. Examples could include: Virus Detection
Guidelines, Disaster recovery guidelines etc..
www.bitworkconsult.com
“ICT advisory services”
The Role of People: Administrative Security
Carry out Security Risk Management:
- Risk management is the process of identifying risk, assessing
risk, and taking steps to reduce risk to an acceptable level.
- identifying the assets in the organization that could include
human resources, technology, trade secrets, patents,
copyrights etc..
- identifying all possible risks that could affect the availability,
confidentiality and integrity of these assets.
- Management can then decide if the identified risks are to be
mitigated or transferred to a third party like an insurance
company or accepted as unmanageable at given time.
www.bitworkconsult.com
“ICT advisory services”
The Role of People: Administrative Security
Use Employee best practices:
- Applicant screening: During the hiring process steps like
background checks, reference checks, verification of educational
records, should be undertaken.
- Employee controls: Including
Detailed job descriptions,
Rotation of duties, the addition of dual controls, and mandatory
vacations, employees signing non disclosure agreements (NDAs)
etc..
- Termination procedures — Administrative control that should
be in place to address the termination of employees. E.g Exit
interviews, review of NDAs, suspension of network access, and
checklists for returned items e.g. remote-access tokens, keys, ID
cards, cell phones, pagers, credit cards, laptops, and software.
www.bitworkconsult.com
“ICT advisory services”
The Role of People: Administrative Security
So what do we have so far?
Management practices
DATA
www.bitworkconsult.com
“ICT advisory services”
•Risk Management
•Policies
•Standards
•Procedures
•Awareness Training
• separation of duties
•Dual controls
•Job rotation
•mandatory vacations...etc..
The Solutions
People
Process
Technology
www.bitworkconsult.com
“ICT advisory services”
Refine Process:
Adopt Industry best Practices
Beyond the need to manage ICT technology is
the need to establish and employ best practices
and processes to optimize IT services.
Our Processes need to be refined to enable
better ICT Infrastructure management and
security, a number of internationally recognized
frameworks have been developed to describe
effective ICT infrastructure management
processes. – No need to re-invent the wheel
www.bitworkconsult.com
“ICT advisory services”
Refine Process:
Adopt Industry best Practices
Control Objectives for Information and related
Technology (COBIT)
- This is a model for IT Governance issued by ISACA
(Information System Control Standard) a non profit
organization for IT Governance.
- The Cobit main function is to help the company, mapping
their IT process to ISACA best practices standard. Cobit is
usually chosen by the company who performing information
system audit, whether related to financial audit or General IT
audit.
www.isaca.org/cobit/
www.bitworkconsult.com
“ICT advisory services”
Refine Process:
Adopt Industry best Practices
www.bitworkconsult.com
“ICT advisory services”
Refine Process:
Adopt Industry best Practices
The Information Technology Infrastructure
Library (ITIL)
- This is a set of concepts and policies for managing the
Information Technology (IT) services. ITIL was built around a
process-model based view of controlling and managing
operations by The UK’s Office of Government Commerce
(OGC).
- ITIL is a cohesive best practice framework, drawn from the
public and private sectors internationally. It describes the
organization of IT resources to deliver business value, and
documents processes, functions and roles in IT Service
Management (ITSM).
www.bitworkconsult.com
“ICT advisory services”
Refine Process:
Adopt Industry best Practices
www.bitworkconsult.com
“ICT advisory services”
Refine Process:
Adopt Industry best Practices
ISO 27001
- ISO 27001 is an Information Security Management System
(ISMS) standard published in October 2005 by the
International Organization for Standardization (ISO) and the
International Electrotechnical Commission (IEC). Its full name
is ISO/IEC 27001:2005 - Information technology -- Security
techniques -- Information security management systems –
Requirements, but it is commonly known as "ISO 27001".
- Sets out the requirements for an Information Security
Management System (ISMS). An ISMS is a systematic
approach to managing the security of sensitive information encompassing people, processes, IT systems and policy.
www.bitworkconsult.com
“ICT advisory services”
Refine Process:
Adopt Industry best Practices
www.bitworkconsult.com
“ICT advisory services”
Refine Process:
Adopt Industry best Practices
COBIT
Function/ Use:
Issued by:
Suited For:
ITIL
ISO27001
Mapping IT Process
Mapping IT Service Level
Management
Information
Security
Framework
ISACA (Information System
Control Standard)
The UK’s Office of
Government
Commerce (OGC)
International
Standards
(ISO) Board
Manage Service Level
Compliance to
security
standard
Information System Audit
www.bitworkconsult.com
“ICT advisory services”
The Solutions
People
Process
Technology
www.bitworkconsult.com
“ICT advisory services”
Technology:
Technical Controls
Streamline physical / environmental security:
Physical security is vital in protection of information assets
and ICT Infrastructure. Physical security should look at issue
like:
- Monitoring and detection e.g. security guards, alarms, CCTV
- Access control and deterrent solutions e.g locks, fencing,
lighting, mantraps, Biometrics etc..
- Environmental control and design – server room
temperature, humidity, air conditioning, static electricity, fire
suppression and detection
- Power generation and backup should all be well streamlined.
www.bitworkconsult.com
“ICT advisory services”
Technology:
Technical Controls
Management practices
Physical security
DATA
www.bitworkconsult.com
“ICT advisory services”
• Alarms
• security guards
• CCTV
• Locks
• Fencing
• Lighting
• Mantraps
• Biometrics
• Temperature control
• Humidity control
• Air conditioning
• Static Electricity issues
• Fire suppression and
detection
• Power backup etc…
Technology:
Technical Controls
Deploy content filtering / inspection solutions:
-
Web filters to enforce organizational Internet usage
policies through content filtering, application blocking, and
best-of-breed spyware protection.
Spam filters / Firewalls to protect your email server from
spam, virus, spoofing, phishing and spyware attacks.
Unified Threat management solutions(UTM): Several
organization choose to deploy UTM solutions that offer
industry leading functionalities within one package
including Intrusion Prevention System; Antivirus with
Antispam; Web Filtering; Antispam; Firewall; SSL - VPN;
Traffic Shaping etc..
-
www.bitworkconsult.com
“ICT advisory services”
Technology:
Technical Controls
Network vulnerability and patch management
-Tools to audit networks for the presence of vulnerabilities
and missing security patches are readily available.
- Identifying missing patches in the operating system and
third party applications. Patch management involves being
pro-active and making sure that your systems have the
latest security updates.
Network segmentation, VPN and VLANS
-On top of aiding security, Could help free network
resources and therefore improve on network performance
and availability.
www.bitworkconsult.com
“ICT advisory services”
Technology:
Technical Controls
what have we done so far?
Management practices
Physical security
Perimeter
DATA
www.bitworkconsult.com
“ICT advisory services”
• Web filters
• Spam filters
• Firewalls
• VPN
• IPS / IDS
• Content Filters
• Proxy servers etc..
Technology:
Technical Controls
Management practices
Physical security
Perimeter
Internal Network
DATA
www.bitworkconsult.com
“ICT advisory services”
•Network segmentation
• Monitoring
• IDS
• Firewalls
• Routers
• Access Control Lists
Technology:
Technical Controls
Use Strong Authentication:
-
Access control attacks are usually due to weak
Authentication. Need to use strong passwords that can not
easily be guessed e.g mix small/capital/numbers/ character
etc..
Passwords not enough as people will use weak ones any way
so what to do?
Multi -factor authentication: where more than one different
factors are used together to authenticate to a single system.
For example use of password or PIN code (“something you
know”), with a smart /swipe card (“something you have”) and
a biometric factor like finger scan (“something you are”)
-
-
www.bitworkconsult.com
“ICT advisory services”
Technology:
-
Technical Controls
CAPTCHA, Cognitive passwords & One time passwords:
- CAPTCHAS are the graphics that are usually used as an
additional layer to authentication to ensure that the response
is not automatically generated by a computer.
www.bitworkconsult.com
“ICT advisory services”
Technology:
Technical Controls
- Cognitive passwords are facts or opinion based
information that are used to verify someone’s identity.
For example, What is your mother’s maiden name?
Etc… Cognitive passwords are usually used to recover
forgotten passwords, but can also be used for
authentication to and add another layer of security.
- One time passwords are also known as Dynamic
passwords and are generated and used for
authentication only once, if an attacker managed to get
hold of one of these passwords, it will be of no use,
example is the Internet access codes used in some
Internet cafes.
www.bitworkconsult.com
“ICT advisory services”
Technology:
Technical Controls
Have an Identity and Rights Management
System:
-
Identity management is very vital and important to
avoid user rights violation and excessive rights
issue.
- Poor Identity management could lead to escalation
of rights.
- Put in place procedures, guideline and a system for
Identity management: creation of users, change of
user rights, removal of rights etc..
www.bitworkconsult.com
“ICT advisory services”
Retire User
Delete/Freeze Accounts
Delete/Freeze Entitlements
New User
User ID Creation
Password Mgmt
Credential Issuance
Strong Passwords
Access Rights
“Lost” Password
Account Changes
Promotions
Transfers
New Privileges
Attribute Changes
www.bitworkconsult.com
“ICT advisory services”
Password Reset
www.bitworkconsult.com
“ICT advisory services”
Technology:
Technical Controls
And Now?
Management practices
Physical security
Perimeter
Internal Network
Host
DATA
www.bitworkconsult.com
“ICT advisory services”
• Strong Authentication
• Patches and hot fixes
• Anti- Virus
• HIDS
•Identity management
Technology: Technical Controls
Data Leakage Prevention (DLP):
-
-
Data leakage prevention (DLP) encompasses the tools that
prevent accidental data leakage, including device and port
control, encryption (both hard-drive and removable media
encryption)
Encryption of data - What happens if an attacker gets
access to the physical media where sensitive data is stored
like USB stick, Hard disk, etc..? What if despite your efforts
to protect the perimeter of your ICT infrastructure, you one
day loose your laptop with sensitive company information?
Encryption is about protecting the contents of the
information from being known to people who aren’t
supposed to know.
www.bitworkconsult.com
“ICT advisory services”
Encrypt Data with readily available tools
TRUECrypt – open source
ID Data Encrypt - commercial
www.bitworkconsult.com
“ICT advisory services”
Technology:
Technical Controls
- Device and port Controls- Ensuring Endpoint security
- Most companies have anti-virus software, firewalls, email and
web content security to protect against external threats, few
realize how easy it is for an employee to simply walk in and
copy large amounts of sensitive data onto an iPod or USB
stick.
- There is also an increased risk of malicious and other illegal
software introduction to your network through these devices
- Endpoint security and control involves ensuring that the
insider threat introduced by users already on the inside in
reduced
www.bitworkconsult.com
“ICT advisory services”
Technology:
Technical Controls
- Data Media Control and disposal
- Its very vital that Data no longer required are
permanently removed from media before disposal or
reuse, a process called "media sanitization.
- The reuse, recycling, or disposal of computers and
other technologies that can store data, pose a
significant risk since data can easily be recovered
with readily available tools - even data from files that
were deleted long ago or a hard drive that were
formatted.
www.bitworkconsult.com
“ICT advisory services”
Technology:
Technical Controls
Technique for data disposal include:
- Degaussing – this involves demagnetizing magnetic storage media
like tape or a hard disk drive to render it permanently unusable.
Since the media typically can no longer be used after degaussing,
it should only be used to purge data from media that will be
discarded.
- Incineration - A physically destructive method of sanitizing media;
the act of burning completely to ashes.
- To avoid data leaks and issues like dumpster diving, its important
that paper documents and removable media (CDS, Floppy disk
etc..) containing classified sensitive and restricted information are
disposed of in the manner required for the disposal of restricted
data, for example through shredding (cross-cut shredding is best)
and Pulverization - the act of grinding to a powder or dust.
www.bitworkconsult.com
“ICT advisory services”
Technology: Technical Controls
Other steps:
other steps that could be taken to ensure security and availability of the
ICT infrastructure include: Having a business continuity and disaster recovery plan
Carrying out backup and managing media storage and labeling them
properly.
Deploying fault tolerance solutions like RAID and Clustering (redundant
servers) to avoid single points of failure.
Having service Level agreements (SLAs) with Vendors
Having an IT audit and Penetration Tests a.k.a “Ethical hacking” carried
out on your own infrastructure.
Considering security in all stages of application development
Etc..
www.bitworkconsult.com
“ICT advisory services”
Technology:
Technical Controls
Management practices
Physical security
Perimeter
Internal Network
Host
Applications
DATA
www.bitworkconsult.com
“ICT advisory services”
•Updates
•Anti-virus
•Application security
Technology:
Technical Controls
Are we there yet?
Management practices
Physical security
Perimeter
Internal Network
Host
Applications
DATA
www.bitworkconsult.com
“ICT advisory services”
•Encryption
•Media Control, Re-use
& disposal
•Data Backup and
recovery
•Device and ports
Control
Technology:
Technical Controls
Finally?
Management practices
Policies, Standards, Procedures, Awareness ...
Physical security
Guards, Biometrics, CCTV etc..
Perimeter
Network segments, Monitoring, IDS etc..
Internal Network
Host
Applications
DATA
www.bitworkconsult.com
“ICT advisory services”
Firewalls, VPN, IPS, Content Filters ..
OS hardening, updates, Authentication …
Patches, Anti-virus etc..
Media control, encryption etc..
Current efforts to Mitigate Information
Systems Security Threats?:
www.bitworkconsult.com
“ICT advisory services”
Current Efforts: Industries
PCI DSS compliance:
To aid in preventing the theft of payment card information, key
industry players including Visa, MasterCard and Discover
created PCI DSS (Payment Card Industry Data Security
Standard). The standard was created to help organizations
that process card payments prevent credit card fraud through
increased controls around data and its exposure to
compromise. The standard applies to all organizations which
hold, process, or pass cardholder information from any card
branded with the logo of one of the card brands.
www.bitworkconsult.com
“ICT advisory services”
Current Efforts: Nations
FISMA Compliance:
The Federal Information Security Management
(FISMA) is a United States federal law to bolster
computer and network security within the Federal
Government and affiliated parties (such as
government contractors) by mandating yearly audits.
It is part of the E-Government Act of 2002. FISMA
does not require secure IT systems but a process for
assessing, testing and managing IT security. FISMA
is a powerful tool for improving federal IT security.
www.bitworkconsult.com
“ICT advisory services”
Current Efforts: Nations
HIPAA:
The Health Insurance Portability and Accountability
Act of 1996 (HIPAA), is a United States government
requirements which mandates that all healthcare
organizations need to effectively meet a set of
administrative, technical and physical safeguards. It
is a legal requirement to protect the privacy of
patient information, and to maintain data integrity for
employees, customers and shareholders.
www.bitworkconsult.com
“ICT advisory services”
Current Efforts: Nations
Gramm-Leach-Bliley Act:
This is a US Government Act that requires financial
institutions to take steps to ensure the privacy and
confidentiality of their customers' non-public
information, including social security numbers,
passwords, access codes, credit cards, ATM cards,
individual assets, credit reports, and account
numbers or other similar financial information.
www.bitworkconsult.com
“ICT advisory services”
Current Efforts:
Nations
U.K’s Data Protection Act 1998 (DPA) and the
Computer Misuse Act 1990:
The Data Protection Act generally deals with the actual
procurement and use of personal data detailing how data
may be processed fairly and lawfully, that data should only be
held in a specified and lawful manner for a specific purpose
and that data will not used or disclosed for anything other
than its intended purpose, and once that purpose is finished,
the data has to be destroyed in lawful manner.
The Computer Misuse Act defines the laws, procedures,
and penalties surrounding unauthorized entry into computers.
www.bitworkconsult.com
“ICT advisory services”
Current Efforts:
Nations
The Singapore Computer Misuse Act:
This act from 1993 lacks clarity and tends to disregard the
human rights of suspects. Its objective to protect its victims
of computer misuse by criminalizing associate activities
such as eavesdropping, and the setting of higher penalties.
Compared to the Computer Misuse Acts (CMAs) of both the
UK and Germany (and other European Countries), the
punishments are very severe in Singapore..
www.bitworkconsult.com
“ICT advisory services”
Current Efforts:
Nations
Malaysia COMPUTER CRIMES ACT 1997:
This contains similar offences as the ones set out in the UK
legislation, but adds to the list unauthorized disclosure of
access codes, attempts, aiding and abetting and
obstruction of a lawful search or failure to comply with a
lawful search.
Penalties are considerably higher than in the United
Kingdom and the power of investigation tend not to respect
personal privacy.
www.bitworkconsult.com
“ICT advisory services”
Current Efforts:
Nations
Mauritius: Computer Misuse & Cyber
Crime Act 2003 and Spam Act 2003:
This Computer Misuse & Cyber Crime Act 2003 lists the following
offences: Unauthorized access to computer data, Access with
intent to commit offences, unauthorized access to and interception
of computer service, unauthorized modification of computer
material, damaging or denying access to computer system,
unauthorized disclosure of password, unlawful possession of
devices and data and electronic fraud.
The Spam Act 2003 sets up a scheme for regulating commercial email and other types of commercial electronic messages.
www.bitworkconsult.com
“ICT advisory services”
Current Efforts:
Others
Other legislations to consider:
South Africa: Electronic Communications and
Transactions Act 25 Of 2002
United Arab Emirates: Federal Law No. (2) 2006 on the
Prevention of Information Technology Crimes.
Ghana :Computer Crime Act 06 & Computer Misuse Act
International Telecommunications Union (ITU) - Global
Cybersecurity Agenda (GCA) : 1.Child Online Protection (COP).
2. Curbing Cyber threats 3. Cyber security Gateway
www.bitworkconsult.com
“ICT advisory services”
Can we add One final layer of
defense?
www.bitworkconsult.com
“ICT advisory services”
Defense in-depth: a layered approach to security
National Legislations and Industry Compliance
Management practices
Laws, Int. Standards, Industry best practices..
Policies, Standards, Procedures, Awareness ...
Physical security
Guards, Biometrics, CCTV etc..
Perimeter
Network segments, Monitoring, IDS etc..
Internal Network
Host
Applications
DATA
www.bitworkconsult.com
“ICT advisory services”
Firewalls, VPN, IPS, Content Filters ..
OS hardening, updates, Authentication …
Patches, Anti-virus etc..
Acl, encryption etc..
Conclusion
www.bitworkconsult.com
“ICT advisory services”
Ensure that security is built into products and processes:
Security is often treated as an afterthought or as optional —
downloadable antivirus software for example—rather than
being integral to a system’s hardware and software. As such,
security add-ons are often poorly integrated with the rest of the
system and are seen as an impediment rather than an enabler.
Take a holistic approach to security: This implies involving
the people, processes and technology at different layers of the
enterprise, we need to combine the logical, physical, and
administrative countermeasures.
Need for National Legal frame works and policies: All
countries need to develop an effective legal and policy
framework for security and the human dimension of security
must be addressed. .
www.bitworkconsult.com
“ICT advisory services”
Thank you!!
www.bitworkconsult.com
“ICT advisory services”
About BitWork Consult Ltd
Our services
- Information Security Awareness Training
- ISO 27001 - Information Security program development
- ICT Projects Management
- Penetration Testing
- Threat & Vulnerability Management
- Information Security Incident management
- Business Continuity and Recovery Services
- IT Audits, Compliance Management, & IT Governance
Contacts:
Plot 135, UMA Show Ground – Lugogo – Kampala - Uganda
E-mail: [email protected]
Tel: Tel: (+256) 414 579099 / 0782480878 / 0704556089
Web: www.bitworkconsult.com
www.bitworkconsult.com
“ICT advisory services”