C7 Information Security

Systems reliability ← (Confidentiality + Privacy + Processing integrity + Availability) ← Security

Fundamental Concepts

  1. Security is a management issue, rather than a technology one
  • Policy development
  • Effective communication of policies
  • Design and employment of appropriate control procedures
  • Monitoring & taking remedial action
  1. The time-based model of security
  • Focusing on the relationship of preventive, detective, and corrective controls
  • P>D+C → Effective
  1. Defense-in-depth
  • To employ multiple layers of controls to avoid single failures

Targeted Attacks

  1. Reconnaissance
  2. Attempt social engineering
  3. Scan & map the target
  4. Research
  5. Execute
  6. Cover tracks

Preventive Controls

  • Authentication controls: while accessing, verify the identify
  • Authorization controls: restricting specific portions and what actions permitted to perform
  • Access control matrix, compatibility test
  • Both for users and devices
  • Training
  • Importance of security, anti-social engineering, IS professionals, keep abreast, top-management support
  • Controlling physical access
  • Controlling remote access
  • Border router, firewall, DMZ (demilitarized zone), TCP / IP, routers
  • ACL (access control list), static / stateful packet filtering
  • Deep packet inspection, IPS (intrusion prevention systems)
  • Host & application hardening
  • Encryption: transforming plaintext to ciphertext (decryption)
  • Symmetric / asymmetric (private and public key)

Detective Controls

  • Log analysis
  • Intrusion detection systems
  • Managerial reports
  • Security testing

Corrective Controls

  • CERT (computer emergency response team)
  • CISO (chief information security officer)
  • Patch management
最后编辑于
©著作权归作者所有,转载或内容合作请联系作者
平台声明:文章内容(如有图片或视频亦包括在内)由作者上传并发布,文章内容仅代表作者本人观点,简书系信息发布平台,仅提供信息存储服务。

推荐阅读更多精彩内容

  • PLEASE READ THE FOLLOWING APPLE DEVELOPER PROGRAM LICENSE...
    念念不忘的阅读 13,526评论 5 6
  • 番石榴(番石榴,又名芭乐、拔子、鸡矢果、鸡屎拔、黄肚子。因其种壳极硬,且不怕禽胃而随粪便排至鸟迹所到之处萌发生长,...
    小虫_6c80阅读 284评论 0 0
  • 有大半年了,日子过得稀里糊涂,总没头绪,总忙不清楚,心里总是很焦虑。 暑假了,决定理理头绪。 我知道自己的焦虑源自...
    山鬼_碧芳阅读 299评论 0 0
  • 很喜欢日本的动画电影,也的确看过不少,有的堪称经典,有的看完就忘,而《萤火虫之墓》,是在诸多电影中,为数不多的一部...
    千千子衿阅读 1,559评论 0 1
  • 北角,North Point,是一个非常适合来港吃住行的地方。没有尖沙咀、铜锣湾那么拥挤,也尽享地铁、叮叮车、码头...
    339da1fbd744阅读 1,690评论 0 0