<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-4328018118321824482</id><updated>2011-11-27T15:21:36.125-08:00</updated><category term='SNMP'/><category term='electronic medical record system'/><category term='backup monitoring'/><category term='safeguard'/><category term='vulnerability'/><category term='malware'/><category term='loss'/><category term='how to'/><category term='cubersecurity'/><category term='what is cyber security'/><category term='ranking'/><category term='how'/><category term='understanding cyber security'/><category term='audit logs'/><category term='remediation'/><category term='cyber security'/><category term='incident'/><category term='remedy security breach'/><category term='NIST'/><category term='Trojan horse'/><category term='externally facing assets'/><category term='trusted users'/><category term='safeguard data confidentiality'/><category term='rank assets'/><category term='acquire'/><category term='application monitoring'/><category term='prioritize assets'/><category term='assets'/><category term='NERC'/><category term='what is HIPAA'/><category term='reporting suspicious'/><category term='network monitoring'/><category term='protection'/><category term='laptop'/><category term='understanding PCI'/><category term='backup'/><category term='door'/><category term='real time'/><category term='periodic reporting'/><category term='false positives'/><category term='EMR'/><category term='account management'/><category term='credit card number'/><category term='lock'/><category term='protect'/><category term='security'/><category term='critical'/><category term='policy'/><category term='what is PCI'/><category term='security rule'/><category term='what are my critical assets'/><category term='computers'/><category term='user'/><category term='understanding cybersecurity'/><category term='basics of'/><category term='reaction'/><category term='how to identify sensitive assets'/><category term='access control'/><category term='e-commerce system'/><category term='theft'/><category term='HIPAA'/><category term='alert'/><category term='continuing'/><category term='prioritize'/><category term='worm'/><category term='design'/><category term='network'/><category term='rank'/><category term='external'/><category term='uniformity'/><category term='framework'/><category term='integrity'/><category term='IT security'/><category term='payment card industry'/><category term='initial'/><category term='space'/><category term='define HIPAA'/><category term='setup'/><category term='cybersecurity'/><category term='data integrity'/><category term='media'/><category term='SOX'/><category term='security breach'/><category term='CIP'/><category term='types of security measures'/><category term='organization'/><category term='section 404'/><category term='sensitive data'/><category term='ISO'/><category term='availability'/><category term='worms'/><category term='trusted'/><category term='what are sensitive assets'/><category term='ongoing'/><category term='easy way'/><category term='human resources'/><category term='one time'/><category term='vulnerability patching'/><category term='what is NERC'/><category term='confidential data'/><category term='physical'/><category term='understanding NERC'/><category term='understanding HIPAA'/><category term='monitor'/><category term='computer'/><category term='spyware'/><category term='what is'/><category term='how to identify'/><category term='confidentiality'/><category term='untrusted'/><category term='how to identify critical assets'/><category term='common'/><category term='anomaly detection'/><category term='what is SOX'/><category term='COBIT'/><category term='PCI'/><category term='sensitive'/><category term='IT Governance'/><category term='data security standard'/><category term='security measures'/><category term='process'/><category term='vulnerability management'/><category term='storage device'/><category term='understanding SOX'/><category term='DLP'/><category term='reaction plan'/><category term='syslog'/><category term='high availability'/><category term='implementation'/><category term='data loss protection'/><category term='configuration monitoring'/><category term='internal'/><category term='made easy'/><category term='what is cybersecurity'/><category term='configuration management'/><category term='untrusted users'/><category term='identify'/><category term='practical guide'/><category term='define PCI'/><category term='healthcare'/><category term='minimization'/><category term='virus'/><category term='compliance'/><category term='pattern'/><category term='prioritization'/><category term='maintain'/><title type='text'>CyberSecurity Help: CIO/CSO Cybersecurity Handbook</title><subtitle type='html'>CIO Security Handbook - Many standards contain best practice truths but don't show you how to start an IT security program.  This blog provides concrete examples and explains the rationale behind security measures.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>31</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-6935633237176170798</id><published>2009-07-23T15:11:00.000-07:00</published><updated>2010-01-16T00:30:37.757-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='what is cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='understanding cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='SOX'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='understanding cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='what is cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI'/><category scheme='http://www.blogger.com/atom/ns#' term='IT security'/><title type='text'>CyberSecurity: Why You Should Read This Book</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_hJKVQaajsug/S1FrDiMo8FI/AAAAAAAAAGc/6vNLOJoZfYE/s1600-h/CyberSecurity+Framework+Top+Level+View.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_hJKVQaajsug/S1FrDiMo8FI/AAAAAAAAAGc/6vNLOJoZfYE/s1600-h/CyberSecurity+Framework+Top+Level+View.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_hJKVQaajsug/S1FrDiMo8FI/AAAAAAAAAGc/6vNLOJoZfYE/s400/CyberSecurity+Framework+Top+Level+View.bmp" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_hJKVQaajsug/S1F30pnMlKI/AAAAAAAAAG8/5mS9d2lONnA/s1600-h/Types+of+Security+Measures.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_hJKVQaajsug/S1F30pnMlKI/AAAAAAAAAG8/5mS9d2lONnA/s400/Types+of+Security+Measures.bmp" /&gt;&lt;/a&gt; &lt;a href="http://1.bp.blogspot.com/_hJKVQaajsug/S1F4ItoTSeI/AAAAAAAAAHE/2MJfA1_4OsE/s1600-h/Routes+to+Compromise+Pre.bmp" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_hJKVQaajsug/S1F4ItoTSeI/AAAAAAAAAHE/2MJfA1_4OsE/s400/Routes+to+Compromise+Pre.bmp" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size: 130%;"&gt;&lt;span style="font-size: 100%;"&gt;&lt;span style="font-size: small;"&gt;Security standards promote managerial truths but don't help you get things done.  Create processes.  Manage risk. Get organized.  Those ideas sound good, but what does the process look like? How do I do  risk analysis?  How do I organize my assets?&lt;br /&gt;&lt;br /&gt;Vendors paint a confusing picture of what I need to buy - one tells me the opposite of another vendor.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;   &lt;/span&gt;&lt;span style="font-size: small; font-style: italic;"&gt;"What do I do?" "What should I buy?" - &lt;/span&gt;&lt;span style="font-size: small;"&gt;Are you asking these questions?&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: 100%;"&gt;&lt;span style="font-size: small;"&gt;This book provides you with a practical approach to IT security by providing a methodical way to view your IT infrastructure, identify/prioritize assets you should protect and ways to protect them.&lt;br /&gt;&lt;br /&gt;If you want to gain a strong grasp of the basics of IT security and a "vendor-neutral" perspective on approaches to enhancing your security, this blog will help you.  Don't buy  products that vendors want you to buy - buy things that help your organization.&lt;/span&gt; &lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red; font-family: Arial,Helvetica,sans-serif; font-size: small; font-style: italic; font-weight: bold;"&gt;START HERE:&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/part-1-understanding-cybersecurity.html"&gt;Part 1: Understanding the CyberSecurity Framework&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size: 130%;"&gt;&lt;br style="font-family: Arial,Helvetica,sans-serif;" /&gt; &lt;span style="font-family: Arial,Helvetica,sans-serif; font-size: small; font-weight: bold;"&gt;Full Table of Contents&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/terms-of-use.html"&gt;Terms of Use&lt;/a&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/purpose-of-this-book.html"&gt;The Purpose of This Book&lt;/a&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/part-1-understanding-cybersecurity.html"&gt;Part 1: Understanding the CyberSecurity Framework&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;        &lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/article-1-defining-landscape-of-it.html"&gt;Article 1: Defining the Landscape of IT Security Issues - The CyberSecurity Framework&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/2-where-of-cybersecurity-framework.html"&gt;Article 2: “Where” of the CyberSecurity Framework – Critical Assets&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/3-where-of-cybersecurity-framework.html"&gt;Article 3: “Where” of the CyberSecurity Framework – Sensitive Assets&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/4-using-cybersecurity-framework-to.html"&gt;Article 4:  Using the CyberSecurity Framework to Understand PCI, HIPAA, SOX&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/5-gradations-of-criticality.html"&gt;Article 5: Gradations of Criticality&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/6-gradations-of-sensitivity.html"&gt;Article 6: Gradations of Sensitivity&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/7-who-of-cybersecurity-framework.html"&gt;Article 7: “Who” of the CyberSecurity Framework&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size: small;"&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/part-2-security-measures.html"&gt;Part 2: Security Measures&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/8-types-of-security-measures.html"&gt;Article 8:  Types of Security Measures&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/9-themes-of-design-security-measures.html"&gt;Article 9: Themes of “Design” Security Measures&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/10-themes-of-maintainmonitor-security.html"&gt;Article 10: Themes of “Maintain/Monitor” Security Measures&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/focus-of-this-article-introduction-this.html"&gt;Article 11: Themes of “Reaction Plan” Security Measures &lt;/a&gt;&lt;/span&gt;   &lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/12-security-measures-for-what-of.html"&gt;Article 12: Security Measures for “What” of the CyberSecurity Framework&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/13-security-measures-for-physical-space.html"&gt;Article 13: Security Measures for Physical Space of CyberSecurity Framework&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/14-routes-in-logical-space-to.html"&gt;Article 14:  Routes in Logical Space to Compromise of Availability, Integrity, Confidentiality&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/15-routes-to-acquiring-accounts.html"&gt;Article 15:  Routes to Acquiring Accounts – External Users and Security Measures&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/16-routes-to-acquiring-accounts.html"&gt;Article 16:  Routes to Acquiring Accounts – Internal Users and Security Measures&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/17-security-measures-for-accounts.html"&gt;Article 17: Security Measures for Accounts Management&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/18-security-measures-for-availability.html"&gt;Article 18: Security Measures for Availability&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/19-security-measures-for-integrity.html"&gt;Article 19: Security Measures for Integrity&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/20-security-measures-for.html"&gt;Article 20: Security Measures for Confidentiality&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size: small;"&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/part-3-compliance.html"&gt;Part 3: Compliance&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/21-pci-data-security-standard.html"&gt;Article 21: PCI DSS - Payment Card Industry Data Security Standard&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/22-hipaa-health-insurance-portability.html"&gt;Article 22: HIPAA - Health Insurance Portability and Accountability Act&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/23-other-compliance-standards-sox-and.html"&gt;Article 23: Other Compliance Standards: SOX and NERC&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size: small;"&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/final-words-on-cybersecurity.html"&gt;Final Words on CyberSecurity&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=4328018118321824482&amp;amp;postID=6935633237176170798" id="data:post.url" name="data:post.title" onclick="return addthis_sendto()" onmouseout="addthis_close()" onmouseover="'return"&gt;&lt;img alt="Bookmark and Share" height="16" src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" style="border: 0pt none;" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883" type="text/javascript"&gt;&lt;/script&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-6935633237176170798?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/6935633237176170798/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/why-you-should-read-this-book.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/6935633237176170798'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/6935633237176170798'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/why-you-should-read-this-book.html' title='CyberSecurity: Why You Should Read This Book'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_hJKVQaajsug/S1FrDiMo8FI/AAAAAAAAAGc/6vNLOJoZfYE/s72-c/CyberSecurity+Framework+Top+Level+View.bmp' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-3347068423172898204</id><published>2009-07-23T15:08:00.000-07:00</published><updated>2009-07-23T15:52:07.575-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='what is cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='understanding cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='understanding cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='what is cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='IT security'/><title type='text'>Final Words on CyberSecurity</title><content type='html'>I believe that the general principles of cybersecurity covered in this book will remain the same in the foreseeable future.  The three security goals of safeguarding availability, integrity, and confidentiality probably won’t change.  You will always have to worry about external users and internal users.&lt;br /&gt;&lt;br /&gt;This book describes a way to identify security issues that apply to your organization and provides examples of potential security measures.  I hope that this book helps IT professionals relate security measures to security issues.  This book should help you avoid getting stuck on the details of security technologies, see the big picture, and assess how vendor technologies fit your needs.&lt;br /&gt;&lt;br /&gt;It’s important to note that cybersecurity involves not just having technologies, but using technologies the right way.  You can buy the most expensive firewall in the market, but if it is not configured correctly, then it is not enhancing security.  You can buy the most expensive cybersecurity monitoring system, but it may be looking for the wrong things.&lt;br /&gt;&lt;br /&gt;Doing cybersecurity “right” is challenging.  Cybersecurity is not just a concern of IT professionals of your organization, but requires the participation of all members of your organization and partners who share your IT resources.  It’s not just about technologies; it’s also about expertise.&lt;br /&gt;&lt;br /&gt;No matter what compliance standard concerns your organization, I hope that this book gives you a starting point to begin a cybersecurity or compliance programs.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-3347068423172898204?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/3347068423172898204/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/final-words-on-cybersecurity.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/3347068423172898204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/3347068423172898204'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/final-words-on-cybersecurity.html' title='Final Words on CyberSecurity'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-7204705725848476604</id><published>2009-07-23T14:09:00.000-07:00</published><updated>2009-07-23T15:49:15.487-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='understanding NERC'/><category scheme='http://www.blogger.com/atom/ns#' term='CIP'/><category scheme='http://www.blogger.com/atom/ns#' term='SOX'/><category scheme='http://www.blogger.com/atom/ns#' term='what is NERC'/><category scheme='http://www.blogger.com/atom/ns#' term='cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='understanding SOX'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='what is SOX'/><category scheme='http://www.blogger.com/atom/ns#' term='easy way'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='NERC'/><category scheme='http://www.blogger.com/atom/ns#' term='section 404'/><category scheme='http://www.blogger.com/atom/ns#' term='IT security'/><title type='text'>23: Other Compliance Standards: SOX and NERC</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;The CyberSecurity Framework can be leveraged to better understand how to start the cybersecurity component of compliance.  This article will focus on two more compliance standards, SOX and NERC, and relate them to parts 1 and 2 of this book.  The point of this article is that the underlying security issues for different kinds of data and IT resources are largely the same although the data and assets of concern are different.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Sarbanes Oxley Section 404 - SOX&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;You can get a copy of the law here:&lt;br /&gt;&lt;a href="http://www.sec.gov/about/laws/soa2002.pdf"&gt;http://www.sec.gov/about/laws/soa2002.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;You can get more guidance from the SEC about SOX Section 404 for small businesses here: &lt;a href="http://www.sec.gov/info/smallbus/404guide/sources.shtml"&gt;http://www.sec.gov/info/smallbus/404guide/sources.shtml&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;SOX Section 404 requires adequacy of internal controls over financial reporting.&lt;br /&gt;&lt;br /&gt;Auditors may check whether the data entered into the accounting system is true by performing an audit.  If the company is depreciating assets, the auditor should check that the assets actually exist.  If records show that 5,000 widgets were sold and delivered to Widgets R Us, then the auditor can check that 5,000 widgets were actually delivered to Widgets R Us.  Auditors can check that the numbers being entered are real.&lt;br /&gt;&lt;br /&gt;While auditors can ensure the entry of truthful data, the cybersecurity team can ensure the integrity of financial data by ensuring that the right people are entering the data and no data is being altered without the knowledge of the organization’s rightful authorities.  So the cybersecurity measures boil down to safeguarding the integrity of financial data.  You must also be able to present evidence that the security measures are working.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;North American Electric Reliability Corporation - Critical Infrastructure Protection&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;You can get a copy of the Critical Infrastructure Protection [CIP] standard here:&lt;br /&gt;&lt;a href="http://www.nerc.com/page.php?cid=2%7C20"&gt;http://www.nerc.com/page.php?cid=2%7C20&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This standard concerns itself with safeguarding the availability of the assets that support the “Bulk Electric System.”  The assets to consider are listed in Standard CIP-002-10 Cyber Security – Critical Cyber Asset Identification R1, &lt;a href="http://www.nerc.com/files/CIP-002-1.pdf"&gt;http://www.nerc.com/files/CIP-002-1.pdf &lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;CIP includes the following sections:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Sabotage Reporting&lt;/li&gt;&lt;li&gt;Critical Cyber Asset Identification&lt;/li&gt;&lt;li&gt;Security Management Controls&lt;/li&gt;&lt;li&gt;Personnel and Training&lt;/li&gt;&lt;li&gt;Electronic Security Perimeter(s)&lt;/li&gt;&lt;li&gt;Physical Security of Critical Cyber Assets&lt;/li&gt;&lt;li&gt;Systems Security Management&lt;/li&gt;&lt;li&gt;Incident Reporting and Response Planning&lt;/li&gt;&lt;li&gt;Recovery Plans for Critical Cyber Assets&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;The approach presented in part 2 of this book to safeguard the availability of assets can help you get a more concrete vision of the security measures you will implement.&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;You are probably now discovering that the underlying security issues for compliance standards, even ones not mentioned in this book, are similar.  They boil down to safeguarding the availability, integrity, or confidentiality of your data or IT assets.  Security measures that address the underlying issues can be similar although the specific data and IT assets of concern are different.&lt;br /&gt;&lt;br /&gt;You must take measures to address security issues surrounding external and internal users.  You must address security issues in the physical and logical spaces.  You should have methods of continuously monitoring for potential security breaches and have some kind of reaction plan in store.  Giving right people the right level of access control to critical/sensitive data and assets is always an issue.&lt;br /&gt;&lt;br /&gt;Parts 1 and 2 of this book cover these common security issues and provide examples of security measures that address these issues.  When the specifics of a compliance requirement are unclear, understanding the requirements in the context of the CyberSecurity Framework will help you better judge what security measures are appropriate, build an effective security program, and avoid taking each compliance requirement as boxes to check off a laundry list.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/final-words-on-cybersecurity.html"&gt;&lt;span style="text-decoration: underline;"&gt;Final Words on CyberSecurity&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-7204705725848476604?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/7204705725848476604/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/23-other-compliance-standards-sox-and.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/7204705725848476604'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/7204705725848476604'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/23-other-compliance-standards-sox-and.html' title='23: Other Compliance Standards: SOX and NERC'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-6565949550273400981</id><published>2009-07-23T14:01:00.000-07:00</published><updated>2009-07-31T21:09:15.706-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='easy way'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='what is HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='understanding HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='security rule'/><category scheme='http://www.blogger.com/atom/ns#' term='IT security'/><category scheme='http://www.blogger.com/atom/ns#' term='define HIPAA'/><title type='text'>22: HIPAA - Health Insurance Portability and Accountability Act</title><content type='html'>&lt;span style="font-weight: bold;font-size:130%;" &gt;Introduction&lt;/span&gt;&lt;br /&gt;HIPAA was enacted in 1996.  The “Security Rule” of Title II of the act describes security safeguards.  The safeguards are categorized as:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Administrative safeguards&lt;/li&gt;&lt;li&gt;Physical safeguards&lt;/li&gt;&lt;li&gt;Technical safeguards&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Within the cybersecurity space, organizations are required to protect the availability, integrity and confidentiality of electronic forms of protected health information [PHI].  PHI on paper is also protected by HIPAA but in our cybersecurity space, we should concern ourselves with PHI in electronic form.&lt;br /&gt;&lt;br /&gt;With an understanding of the CyberSecurity Framework and security measures, we are better fit to understand what to do about HIPAA for cybersecurity.&lt;br /&gt;&lt;br /&gt;It is important to note that compliance to HIPAA requires other information technology measures.  For instance, the “Transaction and Code Sets Rule” describes how data should be exchanged between different organizations.  Furthermore, the Privacy Rule of HIPAA describes how PHI should be handled and these requirements may impact your information technology operations.  These topics, however, will not be discussed in this article.&lt;br /&gt;&lt;br /&gt;The Security Rule will be the focus of this article.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Where To Get Security Rule of Title II of HIPAA&lt;/span&gt;&lt;br /&gt;The US Department of Health and Human Services website is here:&lt;br /&gt;&lt;a href="http://www.hhs.gov/ocr/privacy/index.html"&gt;http://www.hhs.gov/ocr/privacy/index.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The final Security Rule (Feb. 20, 2003) is available here:&lt;br /&gt;&lt;a href="http://www.cms.hhs.gov/securitystandard/downloads/securityfinalrule.pdf"&gt;http://www.cms.hhs.gov/securitystandard/downloads/securityfinalrule.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Please refer to “Subpart C – Security Standards for the Protection of Electronic Protected Health Information” of the document.&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;&lt;br /&gt;HIPAA’s Sensitive Information&lt;/span&gt;&lt;br /&gt;The Security Rule applies to “covered entities” including health care plans, clearinghouses, and some providers.&lt;br /&gt;&lt;br /&gt;HIPAA requires the following 18 types of sensitive patient data (From: Title 45 Code of Federal Regulations 164.514(b)(2)(i) &lt;a href="http://aspe.hhs.gov/admnsimp/final/pvctxt01.htm"&gt;http://aspe.hhs.gov/admnsimp/final/pvctxt01.htm&lt;/a&gt;):&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    (A) Names;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    (B) All geographic subdivisions smaller than a State, including street address, city, county, precinct, zip code, and their equivalent geocodes, except for the initial three digits of a zip code if, according to the current publicly available data from the Bureau of the Census:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;        (1) The geographic unit formed by combining all zip codes with the same three initial digits contains more than 20,000 people; and&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;        (2) The initial three digits of a zip code for all such geographic units containing 20,000 or fewer people is changed to 000. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    (C) All elements of dates (except year) for dates directly related to an individual, including birth date, admission date, discharge date, date of death; and all ages over 89 and all elements of dates (including year) indicative of such age, except that such ages and elements may be aggregated into a single category of age 90 or older;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    (D) Telephone numbers;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    (E) Fax numbers;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    (F) Electronic mail addresses;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    (G) Social security numbers;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    (H) Medical record numbers;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    (I) Health plan beneficiary numbers;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    (J) Account numbers;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    (K) Certificate/license numbers;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    (L) Vehicle identifiers and serial numbers, including license plate numbers;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    (M) Device identifiers and serial numbers;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    (N) Web Universal Resource Locators (URLs);&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    (O) Internet Protocol (IP) address numbers;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    (P) Biometric identifiers, including finger and voice prints;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    (Q) Full face photographic images and any comparable images; and&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;    (R) Any other unique identifying number, characteristic, or code; and&lt;/span&gt; ...&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;HIPAA’s Security Rule’s Standards Primer&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This section helps you understand the thrust of the standards of the Security Rule.  Examples of “standard” include “Security Management Process” and “Access Control”.  Standards fall into three categories of safeguards: administrative, physical, and technical.  Under each standard are implementation specifications – a high level “what to do” guide for each standard.&lt;br /&gt;&lt;br /&gt;There are two types of implementation specifications: required and addressable. “Required” implementation specifications are required.  “Addressable” implementation specifications allow organizations to use alternate implementations to achieve the security standard.  Some implementation specifications might not be applicable to some organizations.  In this case, the organization does not have to implement the measures, but it must document its decision to not implement them.  Please review the finalized rule for details.&lt;br /&gt;&lt;br /&gt;This section explains each standard using concepts in parts 1 and 2 of this book, so that they are more easily understood.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;1. Administrative Safeguards&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Security Management Process&lt;/span&gt;&lt;br /&gt;This overarching standard requires that your organization must identify how availability, integrity, and confidentiality of PHI can be compromised and take security measures to reduce the likelihood of compromise.  Discipline people if you have to.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Assigned Security Responsibility&lt;/span&gt;&lt;br /&gt;The organization must clearly designate the person who is responsible for its security program.  Assigning clear responsibility assures that the job gets done.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Workforce Security&lt;/span&gt;&lt;br /&gt;Make sure the right internal people have access to PHI.  Remove access when people should no longer have access to PHI.  Access management should be ongoing.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Information Access Management&lt;/span&gt;&lt;br /&gt;Make sure that you continue to provide the right access to internal/external applications and external users. Access management should be ongoing.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Security Awareness and Training&lt;/span&gt;&lt;br /&gt;Encourage security awareness among your internal users with reminders and training.  Training should include measures to protecting against evil software, detecting irregularities in last login data, and using strong passwords.  Security can be enhanced through the participation of internal users.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Security Incident Procedures&lt;/span&gt;&lt;br /&gt;Have a process and organization in place so that the organization can respond to security incidents.  Keep records of the history.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Contingency Plan&lt;/span&gt;&lt;br /&gt;Have ongoing processes to backup data.   Have a reaction plan including recovery plans and interim operation plan in place for occasions when availability is compromised.  Make sure the plan actually works.  You want to avoid discovering that there’s a glitch in the recovery program when you actually have to recover data.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Evaluation&lt;/span&gt;&lt;br /&gt;Adjust security measures to protect PHI as circumstances change.  The security program should be ongoing.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Business Associate Contracts and Other Arrangement&lt;/span&gt;&lt;br /&gt;Get documented assurances from business associates that they will safeguard shared PHI.  Organizations should not ignore how shared PHI is being handled by business associates.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2. Physical Safeguards&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Facility Access Controls&lt;/span&gt;&lt;br /&gt;Only allow the right people with the right physical access during normal operations and during special operations.  During special operations such as disaster recovery, people who are not allowed physical access during normal operation may need to enter the facility.  Keep track of who goes in and out.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Workstation Use&lt;/span&gt;&lt;br /&gt;Understand and define what role each workstation or type of workstation should be allowed to take with respect to PHI.  If a workstation has a specific role, then you can monitor the workstation to verify that the workstation is not doing stuff it shouldn’t be doing.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Workstation Security&lt;/span&gt;&lt;br /&gt;Protect workstations in the physical space so only the right people access PHI.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Device and Media Controls&lt;/span&gt;&lt;br /&gt;Ensure that PHI on devices and media do not escape.  Protect against the physical theft of data.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3. Technical Safeguards&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Access Control&lt;/span&gt;&lt;br /&gt;Only allow the right people to have accounts that access PHI.  Do not share accounts.    Accounts that are left with a user logged on should be automatically closed and the user logged off.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Audit Controls&lt;/span&gt;&lt;br /&gt;Make sure that your system is operating in the manner expected.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Integrity&lt;/span&gt;&lt;br /&gt;Protect against unauthorized changes to data.  Make sure that the PHI data being access is the right data.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Person or Entity Authentication&lt;/span&gt;&lt;br /&gt;Make sure the right people and organizations are accessing PHI.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Transmission Security&lt;/span&gt;&lt;br /&gt;Ensure integrity of PHI is preserved when transmitted.  Encrypt transmissions of PHI when eavesdropping is enough of a risk.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Prioritization&lt;/span&gt;&lt;br /&gt;The Security Rule does not prioritize the safeguards.&lt;br /&gt;&lt;br /&gt;A possible approach to prioritizing the implementation of these safeguards is to identify where the highest risk of compromise is and implement security measures that effectively reduce the risk and are easy to implement.&lt;br /&gt;&lt;br /&gt;If you have no physical protection of your sensitive assets, implement barriers to your equipment room.  If it’s been a very long time since you’ve checked whether the right internal people have the right access rights to PHI, update your access control assignments.  Worry about making this an ongoing process later.  If there are no measures to ensure that only the right external users and applications are accessing PHI, then erect network-based and host-based barriers to block unauthorized outsiders.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Conclusion&lt;/span&gt;&lt;br /&gt;It’s important to look at the actual standard itself to understand its details and history.  This article serves as a primer.  Reviewing parts 1 and 2 of this book will help you understand the context of the Security Rule’s implementation specifications and get more concrete ideas of the security measures you should implement.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/23-other-compliance-standards-sox-and.html"&gt;&lt;span style="text-decoration: underline;"&gt;Article 23: Other Compliance Standards: SOX and NERC&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-6565949550273400981?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/6565949550273400981/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/22-hipaa-health-insurance-portability.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/6565949550273400981'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/6565949550273400981'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/22-hipaa-health-insurance-portability.html' title='22: HIPAA - Health Insurance Portability and Accountability Act'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-4847880836840265216</id><published>2009-07-02T17:53:00.001-07:00</published><updated>2009-07-23T15:28:52.963-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='easy way'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='understanding PCI'/><category scheme='http://www.blogger.com/atom/ns#' term='payment card industry'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='data security standard'/><category scheme='http://www.blogger.com/atom/ns#' term='cyber security'/><category scheme='http://www.blogger.com/atom/ns#' term='what is PCI'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='define PCI'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI'/><category scheme='http://www.blogger.com/atom/ns#' term='IT security'/><title type='text'>21: PCI DSS - Payment Card Industry Data Security Standard</title><content type='html'>&lt;span style="font-weight: bold;font-size:130%;" &gt;Introduction&lt;/span&gt;&lt;br /&gt;Payment Card Industry Data Security Standard [PCI DSS] was created to ultimately reduce the theft and fraudulent use of cardholder information by providing guidance to merchants on safeguarding the confidentiality of payment card information.  The PCI Security Standards Council, the body that created the standard, was established by major credit card companies.&lt;br /&gt;&lt;br /&gt;PCI DSS provides many specific technical measures as well as some abstract guidance.  With an understanding of parts 1 and 2 of this book, we can fit the measures into the larger context of cybersecurity and “fill in the details” of some of the abstract guidance given in the standard.&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Where To Get PCI DSS&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;The official PCI DSS website is here:&lt;br /&gt;&lt;a href="https://www.pcisecuritystandards.org/"&gt;https://www.pcisecuritystandards.org/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;As of July 2009, a copy of the latest standard is available here:&lt;br /&gt;&lt;a href="https://www.pcisecuritystandards.org/security_standards/pci_dss_download.html"&gt;https://www.pcisecuritystandards.org/security_standards/pci_dss_download.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;A prioritized list of requirements is available here:&lt;br /&gt;&lt;a href="https://www.pcisecuritystandards.org/education/prioritized.shtml"&gt;https://www.pcisecuritystandards.org/education/prioritized.shtml&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;&lt;br /&gt;PCI DSS’s Sensitive Information&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The scope of PCI DSS includes all systems and equipment that are potential paths to the compromise of the confidentiality of cardholder information.  This includes systems that are not necessarily owned by your organization such as third party systems that your organization relies on.&lt;br /&gt;&lt;br /&gt;PCI requires the following sensitive data to be protected:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Primary Account Number&lt;/li&gt;&lt;li&gt;Cardholder Name&lt;/li&gt;&lt;li&gt;Service Code&lt;/li&gt;&lt;li&gt;Expiration Date&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;No other card related data should be stored.&lt;br /&gt;&lt;br /&gt;The standard requires measures that are one-time design measures, ongoing maintain/monitor measures, and reaction plan measures that involve technology, people, and processes.  In addition, the standard describes methods to test that security measures are actually operating as envisioned.  The requirements address security issues of external and internal users.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;PCI DSS Requirements Primer&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This section helps you understand the thrust of each PCI requirement.  The title of each requirement has been rewritten to help you more easily understand the standard.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Requirement 1 – Design your network to be secure&lt;/span&gt;&lt;br /&gt;Design your network to be secure.  This includes designing the network topology and configuring your perimeter network equipment so that sensitive assets are not easily reached by external users.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Requirement 2 – Design your hosts to be secure&lt;/span&gt;&lt;br /&gt;Requirement 1 focused on the network.  Requirement 2 covers configuration of hosts.  Follow the minimization rules to reduce the vulnerabilities of host.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Requirement 3 – Encrypt cardholder data&lt;/span&gt;&lt;br /&gt;Store only the data you are allowed to store.  Encrypt the data that you do store.  Protect your decryption keys.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Requirement 4 – Encrypt cardholder data transmissions&lt;/span&gt;&lt;br /&gt;Encrypt cardholder data when transmitting them on public networks.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Requirement 5 – Maintain defense against evil software&lt;/span&gt;&lt;br /&gt;Protect against evil software.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Requirement 6 – Maintain defense by patching vulnerabilities&lt;/span&gt;&lt;br /&gt;Patch vulnerabilities in operating systems, servers, and applications including your own application – especially if they are exposed to external users.&lt;br /&gt;&lt;br /&gt;Use development best practices to develop custom applications so vulnerabilities are minimized and no rogue developer is embedding evil programs.&lt;br /&gt;&lt;br /&gt;Don’t mix real cardholder data in the product environment and mock data for development and testing of your application. If you do, you’ll be revealing real cardholder data to your developers.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Requirement 7 – Give accounts to the minimal number of people&lt;/span&gt;&lt;br /&gt;Don’t give data access to people who don’t need the data.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Requirement 8 – Manage and protect accounts&lt;/span&gt;&lt;br /&gt;Don’t share accounts.  Make account passwords hard to guess.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Requirement 9 – Protect your assets in the physical space&lt;/span&gt;&lt;br /&gt;Protect your assets in the physical space.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Requirement 10 – Monitor for bad things happening&lt;/span&gt;&lt;br /&gt;Use audit data to detect bad things happening.  Keep an audit trail of activities and protect the audit trail data.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Requirement 11 – Maintain defenses&lt;/span&gt;&lt;br /&gt;Test your defenses periodically.  Maintain tools, such as IDS, that you are using to detect bad things.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Requirement 12 – Make defense an ongoing activity throughout your organization&lt;/span&gt;&lt;br /&gt;Train your people.  Make processes that make protecting the confidentiality of cardholder data a regular part of your organization’s work.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Prioritization&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Tackling all 12 requirements at once is challenging.  Prioritizing these requirements can help your organization follow a logical trajectory to eventually satisfying the requirements.&lt;br /&gt;&lt;br /&gt;From a technical standpoint, it makes sense to design the groundwork of the system to be defensible before adding new monitoring systems on top.  Comprehensive documentation should come later; documents, however, should not be completely ignored if writing them helps you get design work done.  The design of the system drives how the system will be maintained and monitored.  Once the underlying design is stable, investing in monitoring/auditing systems and other systems that run on top of your fundamental design makes more sense.&lt;br /&gt;&lt;br /&gt;PCI DSS 1.2 suggests a series of milestones that the organization should achieve.  Achieving the milestones involves satisfying a variety of specific “sub-requirements” spread across the 12 requirements.&lt;br /&gt;&lt;br /&gt;PCI DSS suggests milestones in the following order:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Minimize the amount of sensitive data that you have.  Get rid of card data that you are not allowed to store in the first place.  Destroy media holding sensitive data when the storing data on media serves no useful purpose.&lt;/li&gt;&lt;li&gt;Design your network to be secure and encrypt transmissions of card data.&lt;/li&gt;&lt;li&gt;Design your hosts and the applications to be secure.&lt;/li&gt;&lt;li&gt;Maintain access control by giving accounts only to the right people and protect the accounts.&lt;/li&gt;&lt;li&gt;Design your physical space to be secure.&lt;/li&gt;&lt;li&gt;Design monitoring systems to watch over the system and make maintaining defense of card data an ongoing part of your organization.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;It’s important to look at the actual standard itself to understand its details and its prioritization.  This article serves as a primer to help you avoid getting bogged down in details of the standard.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/22-hipaa-health-insurance-portability.html"&gt;Article 22: HIPAA - Health Insurance Portability and Accountability Act&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-4847880836840265216?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/4847880836840265216/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/21-pci-data-security-standard.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/4847880836840265216'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/4847880836840265216'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/21-pci-data-security-standard.html' title='21: PCI DSS - Payment Card Industry Data Security Standard'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-1765533414772617972</id><published>2009-07-02T17:04:00.000-07:00</published><updated>2009-07-25T13:50:51.581-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SOX'/><category scheme='http://www.blogger.com/atom/ns#' term='understanding SOX'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='what is HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='understanding HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI'/><category scheme='http://www.blogger.com/atom/ns#' term='what is SOX'/><category scheme='http://www.blogger.com/atom/ns#' term='easy way'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='understanding PCI'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='what is PCI'/><category scheme='http://www.blogger.com/atom/ns#' term='IT security'/><title type='text'>PART 3: COMPLIANCE</title><content type='html'>&lt;div&gt;Now that we covered the CyberSecurity Framework and examples of security measures, we are better equipped to understand compliance requirements.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Reading compliance standards for HIPAA or SOX without background knowledge of IT security can be difficult because you are trying to understand abstract guidance.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Part 1 and 2 of this book teaches you an approach to cybersecurity.  Part 3 reviews a few selected compliance standards and explains them in a way that leverages cybersecurity concepts already presented.&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/21-pci-data-security-standard.html"&gt;Article 21: PCI DSS - Payment Card Industry Data Security Standard&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-1765533414772617972?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/1765533414772617972/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/part-3-compliance.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/1765533414772617972'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/1765533414772617972'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/part-3-compliance.html' title='PART 3: COMPLIANCE'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-8446156143426774701</id><published>2009-07-02T16:58:00.001-07:00</published><updated>2009-07-05T19:44:27.826-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security measures'/><category scheme='http://www.blogger.com/atom/ns#' term='DLP'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='credit card number'/><category scheme='http://www.blogger.com/atom/ns#' term='safeguard data confidentiality'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='data loss protection'/><category scheme='http://www.blogger.com/atom/ns#' term='confidential data'/><category scheme='http://www.blogger.com/atom/ns#' term='e-commerce system'/><title type='text'>20: Security Measures for Confidentiality</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Focus of This Article&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_hJKVQaajsug/Sk1J3E37MtI/AAAAAAAAAFM/WyS0JiNIhzY/s1600-h/Security+Measures+Confidentiality.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://3.bp.blogspot.com/_hJKVQaajsug/Sk1J3E37MtI/AAAAAAAAAFM/WyS0JiNIhzY/s400/Security+Measures+Confidentiality.bmp" alt="" id="BLOGGER_PHOTO_ID_5354016742563328722" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;In addition to the security measures preventing unauthorized account acquisitions, another layer of security measures can be applied downstream in the logical space to safeguard confidentiality.   Costs and benefits of these downstream security measures should be considered before their implementation.  The more effectively upstream measures are implemented, the less valuable downstream measures may be.&lt;br /&gt;&lt;br /&gt;These measures can also be considered when you are concerned about trusted users going “rogue” and inflicting harm against your organization.&lt;br /&gt;&lt;br /&gt;This article follows the pattern established by previous articles about safeguarding availability and integrity.  The additional layer of security measures involves monitoring the actual viewing activities of the user and monitoring/blocking the information from escape.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Data Access Points&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;There are multiple logical access points to data. Someone can access data through a client application.  For instance, someone can use a sales management system to view customers’ purchase histories and their credit card numbers.  The software client to the system’s application is an access point.  However, if this data resides inside a database, then someone can directly access the data in the database without the software client.&lt;br /&gt;&lt;br /&gt;It is important to use this idea when applying account management security measures discussed in an earlier article.  The accounts of both the application and the underlying database should be maintained.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Security Measures&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Security measures in addition to the account management measures described in an earlier article can be considered for preserving data confidentiality.&lt;br /&gt;&lt;br /&gt;One security measure is to track which trusted user is viewing what information.&lt;br /&gt;&lt;br /&gt;The thief must escape with sensitive data beyond the boundaries of your IT infrastructure to profit. Blocking the thief’s escape is another measure that can be taken to safeguard data confidentiality.  The escape routes are numerous and some are extremely difficult to block.&lt;br /&gt;&lt;br /&gt;Escape Routes of Sensitive Information:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Memorize it.&lt;/li&gt;&lt;li&gt;Write it down.&lt;/li&gt;&lt;li&gt;Print it out.&lt;/li&gt;&lt;li&gt;Send it via facsimile.&lt;/li&gt;&lt;li&gt;Copy and paste it into a web mail service – if not text, then take screen captures and upload as attachment to web mail service.&lt;/li&gt;&lt;li&gt;Send it out as attachment in email from company account.&lt;/li&gt;&lt;li&gt;Send it out as body of message in email from company account.&lt;/li&gt;&lt;li&gt;Transfer the file using FTP, scp, or similar file transfer client.  &lt;/li&gt;&lt;li&gt;Transfer using peer-to-peer file sharing clients or applications like Skype that support file transfer.&lt;/li&gt;&lt;li&gt;Transfer data to portable media like a USB memory key or other portable storage device, and leave with device.&lt;/li&gt;&lt;li&gt;Transfer data to writable DVD’s or CD’s and leave with media.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Security measures that safeguard confidentiality are:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Monitor who is viewing sensitive information.&lt;/li&gt;&lt;li&gt;Block escape routes.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Implementation Approach – Illustrative Examples&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Let’s assume that we are an e-commerce company that stores customer credit card information.  A web application calls the credit card numbers so it can place a charge on the customer’s credit card when he checks out his shopping cart.  We are safeguarding the confidentiality of credit card numbers.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Monitoring Who Is Viewing Sensitive Information&lt;/span&gt;&lt;br /&gt;Application logs or database logs are potential sources of information to monitor which users are viewing what.  However, logs may not generate the information that you need to implement the security measures.  If the logs do generate the information that you need, the logs will generate other information that you do not need.  You may collect so much data that no analysis tool can easily process the records that you need.&lt;br /&gt;&lt;br /&gt;If logs do not contain the necessary information, then you will have build or buy a product that allows you to monitor who is viewing which sensitive information.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Alert Example&lt;/span&gt;&lt;br /&gt;Sensitive information such as credit card numbers should only be called by a known set of function calls of the web application.  If an inappropriate function calls the database for sensitive data or someone is querying the database directly, something fishy is going on.  An alert should be sent.  The security team should investigate the root cause and take appropriate action depending on the results of the investigation.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Block Escape Routes&lt;/span&gt;&lt;br /&gt;Blocking escape routes only when confidential data is on the verge of escaping is difficult to do because a thief can obfuscate the data that is escaping.  For instance, a 16 digit number on an email can be detected as a credit card number and blocked from escaping the company; however, a smart thief can disguise the 16 digit number by adding letters in between the digits or simply transforming the 16 digit number into letters or words.  Building intelligence into software so it can detect when sensitive data is leaving is challenging.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Design Example&lt;/span&gt;&lt;br /&gt;Employees’ personal computers can be configured such that some escape routes are blocked.  For instance, the personal computer’s USB can be disabled for data transfer to a USB memory key and other storage devices.  Furthermore, it can be configured to disallow installation of applications such as FTP or other file transferring applications.&lt;br /&gt;&lt;br /&gt;An agent can be installed on the personal computer to scan email for sensitive information.  This agent can also monitor for sensitive information being pasted into web mail applications.  When violations are detected, the action can be blocked and an alert can be sent to the IT security team.&lt;br /&gt;&lt;br /&gt;It is important to note that these measures undermine the conveniences that employees are accustomed to having.  A simple example is the transfer of a large file between employees.  Transfer via email is not possible because the email system rejects big files.  All other routes are blocked.&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Going Beyond the Examples&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;There may be clever approaches to block escape routes for only people who have access to sensitive information.  Not every person may need to be monitored.&lt;br /&gt;&lt;br /&gt;Some development shops in India use the following procedure to ensure that their client’s software is protected from theft.  Each employee entering the office is searched to ensure that he is not bringing in anything but himself.  In the office, he works on a computer that is not connected to the Internet.  At the end of the day, he is searched to ensure that he is not leaving with anything from the office.&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Encrypt Confidential Information&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Confidential information should be encrypted when transmitted on the network, especially public networks where anyone can be eavesdropping.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;We covered additional measures that can be taken as lines of defense in addition to the initial safeguards of providing accounts and appropriate privileges to the right people to protect data confidentiality.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/part-3-compliance.html"&gt;Part 3: Compliance&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-8446156143426774701?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/8446156143426774701/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/20-security-measures-for.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/8446156143426774701'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/8446156143426774701'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/20-security-measures-for.html' title='20: Security Measures for Confidentiality'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_hJKVQaajsug/Sk1J3E37MtI/AAAAAAAAAFM/WyS0JiNIhzY/s72-c/Security+Measures+Confidentiality.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-6162360034680521139</id><published>2009-07-02T16:49:00.000-07:00</published><updated>2009-07-05T19:43:21.006-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='electronic medical record system'/><category scheme='http://www.blogger.com/atom/ns#' term='data integrity'/><category scheme='http://www.blogger.com/atom/ns#' term='monitor'/><category scheme='http://www.blogger.com/atom/ns#' term='security measures'/><category scheme='http://www.blogger.com/atom/ns#' term='safeguard'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='healthcare'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='maintain'/><category scheme='http://www.blogger.com/atom/ns#' term='EMR'/><title type='text'>19: Security Measures for Integrity</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Focus of This Article&lt;/span&gt;&lt;/span&gt; &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_hJKVQaajsug/Sk1INRwSZTI/AAAAAAAAAFE/OkGsQpl98_8/s1600-h/Security+Measures+Integrity.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://3.bp.blogspot.com/_hJKVQaajsug/Sk1INRwSZTI/AAAAAAAAAFE/OkGsQpl98_8/s400/Security+Measures+Integrity.bmp" alt="" id="BLOGGER_PHOTO_ID_5354014924954821938" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;In addition to the security measures preventing unauthorized account acquisitions, another layer of security measures can be applied downstream in the logical space to safeguard integrity.   Costs and benefits of these downstream security measures should be considered before their implementation.  The more effectively upstream measures are implemented, the less valuable downstream measures may be.&lt;br /&gt;&lt;br /&gt;These measures can also be considered when you are concerned about trusted users going “rogue” and inflicting harm against your organization.&lt;br /&gt;&lt;br /&gt;This article follows the pattern established by the previous article about safeguarding availability.  The additional layer of security measures involves tracking the changes to data and who made the changes.&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Data Access Points&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;There are multiple logical access points to data.  Someone can access data through a client application.  For instance, someone can use an account on an EMR system to retrieve patient records; the EMR client is an access point.  However, if this data resides inside a database, then someone can directly access the data in the database with the database client instead of the EMR client.&lt;br /&gt;&lt;br /&gt;It is important to use this idea when applying account management security measures discussed in an earlier article.  The accounts of both the EMR system and the underlying database should be maintained.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Security Measures&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;There are two types of data worth distinguishing because the approaches to safeguarding their data integrity differ:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Data that should never be changed by anyone&lt;/li&gt;&lt;li&gt;Data that should be changed by the right people&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Data That Should Never Change&lt;/span&gt;&lt;br /&gt;Historical data should never be changed.  Examples include financial accounting history, bill payments history, stock trading history, and patient history.  When corrections need to be made, records that correct the history are added as new data.  Nothing should be deleted or modified.  Information about new transactions are added as new data.&lt;br /&gt;&lt;br /&gt;The two security measures that can be taken to safeguard integrity of this data are:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Make sure that existing data is not being changed.&lt;/li&gt;&lt;li&gt;Make sure that new data is authorized.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Data That Should Change&lt;/span&gt;&lt;br /&gt;The billing address of a utilities customer must be changed at the customer’s request, so the monthly bill is delivered to the right address.  Someone who’s changing her name after marriage will report the change to her credit card companies.&lt;br /&gt;&lt;br /&gt;The security measure for this data is similar to the second measure above:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Make sure that changes are authorized.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Implementation Approach – Illustrative Examples&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;The difficulty of implementation will vary with the asset.  Some applications will already have mechanisms for reporting changes.  Others might generate an audit log that captures change history.  There are many approaches to implementing these measures; there is no single correct approach.&lt;br /&gt;&lt;br /&gt;This section describes a hypothetical approach to implementing the measures on an electronic medical record system [EMR].  The point of the example is to illustrate a possible approach at a high level; I make big assumptions about the capabilities of the EMR system and make simplifying assumptions about the patient history data structure.&lt;br /&gt;&lt;br /&gt;Data about a patient includes basic elements:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Content data – This includes data created by the doctor about the patient or test results.&lt;/li&gt;&lt;li&gt;Meta data – This includes data about the content: who entered the content, when and from where.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Data That Should Never Change&lt;/span&gt;&lt;br /&gt;A message digest algorithm can be applied to historical data and the generated hash can be kept as a baseline.  Periodic comparisons can verify that the hash of the historical data is the same as the baseline hash.  If the hash changes from the baseline hash, there’s something fishy going on and is worth generating a report that shows a “diff” comparison to identify the changes that were made.  Ideally, a report would show what changes were made and show “before” and “after” versions of the data.&lt;br /&gt;&lt;br /&gt;An alert should be sent whenever the data integrity check is completed.  A successful integrity check will ensure that the checks are actually being done.  Since changes to this data should never happen, an alert should be sent to the IT security team when they are detected.&lt;br /&gt;&lt;br /&gt;This baseline hash should be regenerated whenever new data is added.  Before the new data is added, the existing baseline hash should be compared with the hash generated with the old data to confirm that the old data has had no unauthorized changes.&lt;br /&gt;&lt;br /&gt;The reaction plan can involve locking down the patient record so that the patient record is not used by an unwary doctor or nurse.  Reverting the patient record to the original state and investigating the root cause of the data change will probably be additional steps.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;New Data&lt;/span&gt;&lt;br /&gt;New data should be added by only the right people.  Security measures for account management covered in an earlier article address this.&lt;br /&gt;&lt;br /&gt;Some additional measures can be considered as extra layers of defense.  For instance, when someone submits an update to the patient record, he can be prompted for his password again so that each submission is tightly bound to the submitter. If a doctor leaves the EMR application session open without logging off, the wrong people can masquerade as a doctor and enter bad submissions.  At the end of the day, the doctor can review a summary of documents that he added to his patients’ files and verify that the right files have been added.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Data That Should Change&lt;/span&gt;&lt;br /&gt;Data should be changed by only the right people. Security measures for account management covered in an earlier article address this.&lt;br /&gt;&lt;br /&gt;If the patient’s billing address has changed, then the person entering the change must verify that the person requesting the change is in fact the patient before changing the address.  The “right” people, in this case, are the patient and the person entering the new address.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Trusted Users Abusing Accounts and Privileges&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;So far we assumed that people who unrightfully gained access were altering data.  Additional security measures that monitor the activity of trusted users can be taken.  You may have a rogue doctor or nurse adding false data.  You should consider the cost of taking such measures – the cost of implementing the technology and the people time that must be used to support the measure.&lt;br /&gt;&lt;br /&gt;Having doctors and nurses not only sign off on the submissions they make themselves but the submissions of their teammates can be a measure to detect a single rogue user who is entering incorrect data.  That is, if a doctor and a nurse submitted new data for patient John Smith, then the doctor will check the nurse’s submission and the nurse will review the doctor’s.&lt;br /&gt;&lt;br /&gt;A security measure to guard against rogue trusted users collaborating to falsify data is to have someone apart from the people who entered the data independently review the data.  This person must have the expertise to detect that something is wrong.  Again, the cost and benefits of implementing this kind of measure must be considered.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Going Beyond the Examples&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;The core principles of checking data integrity do not change and can be applied to everything from file systems to databases.  The above measures help you understand the general principles.  Your implementation will vary depending on the capabilities of your system.&lt;br /&gt;&lt;br /&gt;For instance, an accounting system contains historical data that should not be modified; new data is entered by only the accounting team.   Again, the above approach can be used to verify that already entered data is not being changed.  Furthermore, making sure that the right person is entering the new account entries will better ensure that bad data is not being entered.  A periodic internal audit process that has the head of accounting inspect all newly entered data can ensure that the right data is being entered.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;We covered additional measures that can be taken as lines of defense in addition to the initial safeguards of providing accounts and privileges to the right people to protect data integrity.  These measures can also detect trusted users gone rogue.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/20-security-measures-for.html"&gt;Article 20: Security Measures for Confidentiality&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-6162360034680521139?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/6162360034680521139/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/19-security-measures-for-integrity.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/6162360034680521139'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/6162360034680521139'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/19-security-measures-for-integrity.html' title='19: Security Measures for Integrity'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_hJKVQaajsug/Sk1INRwSZTI/AAAAAAAAAFE/OkGsQpl98_8/s72-c/Security+Measures+Integrity.bmp' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-5880492070462187501</id><published>2009-07-02T16:39:00.000-07:00</published><updated>2009-07-05T19:42:43.934-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='monitor'/><category scheme='http://www.blogger.com/atom/ns#' term='security measures'/><category scheme='http://www.blogger.com/atom/ns#' term='high availability'/><category scheme='http://www.blogger.com/atom/ns#' term='safeguard'/><category scheme='http://www.blogger.com/atom/ns#' term='backup monitoring'/><category scheme='http://www.blogger.com/atom/ns#' term='configuration monitoring'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='maintain'/><category scheme='http://www.blogger.com/atom/ns#' term='configuration management'/><category scheme='http://www.blogger.com/atom/ns#' term='availability'/><title type='text'>18: Security Measures for Availability</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Focus of This Article&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_hJKVQaajsug/Sk1GPx4WZHI/AAAAAAAAAEk/b75s2eihi9o/s1600-h/Security+Measure+Availability.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://1.bp.blogspot.com/_hJKVQaajsug/Sk1GPx4WZHI/AAAAAAAAAEk/b75s2eihi9o/s400/Security+Measure+Availability.bmp" alt="" id="BLOGGER_PHOTO_ID_5354012768915055730" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;In addition to the security measures preventing unauthorized account acquisitions, another layer of security measures can be applied downstream in the logical space for critical assets.   Costs and benefits of these downstream security measures should be considered before their implementation.  The more effectively upstream measures are implemented, the less valuable downstream measures may be.&lt;br /&gt;&lt;br /&gt;These measures can also be considered when you are concerned about trusted administrative users going “rogue” and inflicting harm against your organization.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Security Measures&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Security measures that safeguard availability detect unauthorized changes to the configuration of critical assets.  Unauthorized changes can change the expected behavior of computers and network equipment, and undermine their availability.&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Prevent unauthorized changes to high availability configurations&lt;/li&gt;&lt;li&gt;Prevent unauthorized changes to network equipment such as firewalls&lt;/li&gt;&lt;li&gt;Prevent unauthorized changes to backup mechanisms&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Once critical assets are correctly configured for high availability, security measures can be taken to protect against unauthorized changes to their configurations.   Unauthorized changes can render the high availability mechanism inoperative.&lt;br /&gt;&lt;br /&gt;The configuration of network equipment is changed infrequently after it has been put into production.  Again, the correct configuration of the equipment must be protected against unauthorized change.&lt;br /&gt;&lt;br /&gt;Changes to the configuration of backup mechanisms of critical assets must be protected for the same reasons.  An operative backup mechanism must be protected from unauthorized changes that can undermine the availability of critical data.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Implementation of Measures – Illustrative Examples&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;The difficulty of implementation will vary with the asset.&lt;br /&gt;&lt;br /&gt;This section proposes an implementation approach can apply to any organization.&lt;br /&gt;&lt;br /&gt;Someone with an unrightfully acquired account must log on before he can make any configuration changes.  The frequency of logins should be very low and the configuration should only change as part of intended maintenance.   Therefore unusual logins and changes to configuration files can be an indicator of “bad things” happening.&lt;br /&gt;&lt;br /&gt;Please remember that these security measures that apply after someone has already acquired an account.&lt;br /&gt;&lt;br /&gt;Instead of periodic reports, real-time alerts may be more appropriate because harm that can be done can be catastrophic.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Alert Examples&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;1.    An alert should be sent to the IT security team when someone logs into any account on network equipment – equipment that should not be frequently changed.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_hJKVQaajsug/Sk1GQbSkWmI/AAAAAAAAAEs/pkJbCwWdXWg/s1600-h/Alert+Firewall+Successful+Login.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 165px;" src="http://1.bp.blogspot.com/_hJKVQaajsug/Sk1GQbSkWmI/AAAAAAAAAEs/pkJbCwWdXWg/s400/Alert+Firewall+Successful+Login.bmp" alt="" id="BLOGGER_PHOTO_ID_5354012780030876258" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;2.    An alert should be sent when the configuration of network equipment, high availability mechanism, or backups has been modified.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_hJKVQaajsug/Sk1GQZFaynI/AAAAAAAAAE0/V23qTjX4HUw/s1600-h/Alert+Firewall+Configuration+Change.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 163px;" src="http://3.bp.blogspot.com/_hJKVQaajsug/Sk1GQZFaynI/AAAAAAAAAE0/V23qTjX4HUw/s400/Alert+Firewall+Configuration+Change.bmp" alt="" id="BLOGGER_PHOTO_ID_5354012779438852722" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_hJKVQaajsug/Sk1GQowyr8I/AAAAAAAAAE8/3e5C2Bj2H9g/s1600-h/Alert+Backup+Configuration+Change.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 158px;" src="http://4.bp.blogspot.com/_hJKVQaajsug/Sk1GQowyr8I/AAAAAAAAAE8/3e5C2Bj2H9g/s400/Alert+Backup+Configuration+Change.bmp" alt="" id="BLOGGER_PHOTO_ID_5354012783647305666" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;In order to identify the changes made, you should make it a habit to save the configuration in a protected location apart from the equipment.  The current configuration file can be diff-ed with the latest copy of the configuration file that you saved to identify changes.  Saving your configuration files will also allow you to reverse changes.  There are products that can help you with management.&lt;br /&gt;&lt;br /&gt;We have been assuming rogue users making adverse changes.  However, sometimes legitimate users make mistakes that harm availability.  Saving configuration files of your critical assets can help you recover from legitimate mistakes.&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Going Beyond the Example Alerts&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Another approach to identify unwanted logons or configuration changes would be set time windows for which maintenance is typically done.  If logons or changes occur outside this time block, then an alert can be sent.&lt;br /&gt;&lt;br /&gt;You should not limit yourself to the presented alerts if you feel there are other alerts that better fits the needs of your organization.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Security Measure - Monitor Backups&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Backups can fail for reasons other than adverse changes to its configuration.  Therefore, it is important to monitor that backups are being successfully taken.  An alert should be generated for each successful and failed backup.  An alert for a successful backup verifies that the backups are indeed being taken.  The failure of the backup warrants immediate response.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Reaction Plan&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;If something fishy is detected with the above measures, then you should investigate the root cause.  You should decide your next steps depending on the results of the investigation.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;We covered additional measures that can be taken as lines of defense in addition to the initial safeguards of providing accounts and appropriate privileges to the right people.  These measures can also help you detect a rogue administrator who is undermining the availability of your critical assets.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/19-security-measures-for-integrity.html"&gt;Article 19: Security Measures for Integrity&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-5880492070462187501?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/5880492070462187501/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/18-security-measures-for-availability.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/5880492070462187501'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/5880492070462187501'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/18-security-measures-for-availability.html' title='18: Security Measures for Availability'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_hJKVQaajsug/Sk1GPx4WZHI/AAAAAAAAAEk/b75s2eihi9o/s72-c/Security+Measure+Availability.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-7237483751059824876</id><published>2009-07-02T16:29:00.000-07:00</published><updated>2009-07-05T19:42:10.420-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='reaction plan'/><category scheme='http://www.blogger.com/atom/ns#' term='security measures'/><category scheme='http://www.blogger.com/atom/ns#' term='design'/><category scheme='http://www.blogger.com/atom/ns#' term='account management'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='implementation'/><category scheme='http://www.blogger.com/atom/ns#' term='confidentiality'/><category scheme='http://www.blogger.com/atom/ns#' term='monitor'/><category scheme='http://www.blogger.com/atom/ns#' term='safeguard'/><category scheme='http://www.blogger.com/atom/ns#' term='maintain'/><category scheme='http://www.blogger.com/atom/ns#' term='integrity'/><category scheme='http://www.blogger.com/atom/ns#' term='availability'/><title type='text'>17: Security Measures for Accounts Management</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Focus of this Article&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_hJKVQaajsug/Sk1DZ6D52KI/AAAAAAAAAD8/iC4B31SeZoA/s1600-h/Security+Measure+Account+Management.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://4.bp.blogspot.com/_hJKVQaajsug/Sk1DZ6D52KI/AAAAAAAAAD8/iC4B31SeZoA/s400/Security+Measure+Account+Management.bmp" alt="" id="BLOGGER_PHOTO_ID_5354009644374808738" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;&lt;br /&gt;Introduction&lt;/span&gt;&lt;br /&gt;Even with disciplined implementation of the security measures that block unauthorized acquisition of accounts and privileges, your IT team should consider implementing maintain/monitor measures as a second line of defense.&lt;br /&gt;&lt;br /&gt;The following examples will help you get a feel for what to maintain and monitor.  They are largely measures that “keep your ducks in a row.”  The difficulty of implementing the security measures depends on the assets you are safeguarding.  Some applications may already generate reports that support these measures.&lt;br /&gt;&lt;span style="font-size:130%;"&gt; &lt;span style="font-weight: bold;"&gt;Security Measures&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;These measures require the collaborative effort of system administrators and the “authorities” of the assets.  For example, an administrator of an accounting application must work together with the accounting department’s authority to agree on which accounts to delete.   An administrator of an operating system may need to confirm with his manager about deleting accounts from an operating system.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Accounts Management&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Delete needless accounts.  If George Washington left the company, delete his accounts.  Someone can continue using George’s accounts without the knowledge of the proper authorities.  Delete unused service accounts.&lt;/li&gt;&lt;li&gt;Delete dormant accounts.  Abraham Lincoln is still with the company, but he hasn’t used his account on the ABC Accounting Application for a long time.  Why does he have it?  If he doesn’t need it anymore, delete it.&lt;/li&gt;&lt;li&gt;Make sure no new accounts are being made without knowledge of the proper authorities.  If a new account “benjamin.franklin” is added but it does not map to a real person or it doesn’t map to a service account, something fishy is going on.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Privilege Management&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Make sure no accounts are being placed in a group without the knowledge of the proper authorities.  Adding accounts to groups can give the account the privileges attached to the groups.&lt;/li&gt;&lt;li&gt;Make sure no single account is expanding its privileges (e.g. creating accounts) without knowledge of proper authorities.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Group Management&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Delete empty groups.  If nobody is in a group, why is it there?  Delete it.&lt;/li&gt;&lt;li&gt;Make sure no new groups are being created without knowledge of proper authorities.&lt;/li&gt;&lt;li&gt;Make sure no group is acquiring privileges without knowledge of proper authorities.&lt;/li&gt;&lt;/ol&gt; &lt;span style="font-weight: bold;"&gt;General Management&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Make sure that administrative actions are performed by the right users.  If a user behaves like an administrator but is not one, something fishy is going on.&lt;/li&gt;&lt;li&gt;Make sure that no new trust relationships are being created without knowledge of the proper authorities.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Implementation of Measures – Illustrative Examples&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The difficulty of implementation will vary with the asset.  The asset might already have built-in capabilities that generate the reports described below.  An enterprise wide roll out that implements the security measures for all assets is not necessary.  You can focus only on critical and sensitive assets.&lt;br /&gt;&lt;br /&gt;This section proposes an implementation approach for an accounting system fictitiously named “Accounting Pro” of a medium-size business of a few hundred to a few thousand people.&lt;br /&gt;&lt;br /&gt;For the purpose of explaining these examples, let’s assume that reports that support the above security measures are generated periodically once a quarter.  Each time the reports are generated, they cover a period of time between now and the previous time the reports were generated.&lt;br /&gt;&lt;br /&gt;Because you are generating reports for a particular asset and not the entirety of the enterprise, the reports will contain a manageable number of records.  It is hard to imagine an accounting team of a hundred people for even a company with a few thousand employees.&lt;br /&gt;&lt;br /&gt;The following set of reports can help the head of accounting, the person in charge over the use of the system, determine if the right people have accounts and support the security measures described above.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt; &lt;span style="font-weight: bold;"&gt;Reports Examples&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;1.    All User Accounts – A snapshot view of all accounts.  If there are 20 people total in the accounting department, it may be worth figuring out why there are 5 extra.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_hJKVQaajsug/Sk1EdK4qzUI/AAAAAAAAAEE/Iy2MzmEio80/s1600-h/Report+All+User+Accounts.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 162px;" src="http://2.bp.blogspot.com/_hJKVQaajsug/Sk1EdK4qzUI/AAAAAAAAAEE/Iy2MzmEio80/s400/Report+All+User+Accounts.bmp" alt="" id="BLOGGER_PHOTO_ID_5354010799942323522" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;2.    Added User Accounts - List of users that were added during period.  You can see if someone who wasn’t supposed to be added, was added.  You can detect this problem on the All Users report but it’s more easily detected on this report.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_hJKVQaajsug/Sk1EdTM7EwI/AAAAAAAAAEM/GVg8_RtvRnA/s1600-h/Report+Accounts+ADDED.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 164px;" src="http://4.bp.blogspot.com/_hJKVQaajsug/Sk1EdTM7EwI/AAAAAAAAAEM/GVg8_RtvRnA/s400/Report+Accounts+ADDED.bmp" alt="" id="BLOGGER_PHOTO_ID_5354010802174759682" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;3.    Deleted User Accounts - List of users that were deleted during period.  If someone left the company and he’s not on the deleted list, there’s a problem.  You can detect the same problem on the “All Accounts” report, but it’s easier to detect here.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Edk4Y8dI/AAAAAAAAAEU/hFgHZu2ftgI/s1600-h/Report+Accounts+DELETED.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 165px;" src="http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Edk4Y8dI/AAAAAAAAAEU/hFgHZu2ftgI/s400/Report+Accounts+DELETED.bmp" alt="" id="BLOGGER_PHOTO_ID_5354010806920475090" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;4.    Dormant Accounts - List of users that did not log into Accounting Pro during period.  This helps you identify accounts that should be deleted.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_hJKVQaajsug/Sk1Ed7wt_mI/AAAAAAAAAEc/pAIGiqT3sPc/s1600-h/Report+Accounts+DORMANT.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 153px;" src="http://4.bp.blogspot.com/_hJKVQaajsug/Sk1Ed7wt_mI/AAAAAAAAAEc/pAIGiqT3sPc/s400/Report+Accounts+DORMANT.bmp" alt="" id="BLOGGER_PHOTO_ID_5354010813062315618" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Similar reports can be made for the other security measures for privilege, group, and general management.&lt;br /&gt;&lt;br /&gt;We assumed that the above reports were generated quarterly; however, you may want to generate them more frequently in order to catch “fishy” things as quickly as possible.&lt;br /&gt;&lt;br /&gt;Here’s another approach.  The reports are generated daily; however, if there are no additions or deletions to accounts, then IT security team is notified that nothing has changed.  This helps the IT Security team avoid spending time with non-informative reports.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Approaches to Generating The Reports&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;If your application cannot generate these reports, then there may be other roundabout ways to generate them.&lt;br /&gt;&lt;br /&gt;Your application may generate a log that keeps track of account additions and deletions.   Not all applications can do this.  If it does, then you can parse the log file to create the “all,” “add,” and “delete” reports.  You can develop this, find a freely available program, or buy a product that can help you.&lt;br /&gt;&lt;br /&gt;If your application can only generate a list of usernames, then you can identify the differences, additions and deletions, and generate the report.  It is important to note, however, that this method of generation will miss accounts that were added and deleted in the same period.&lt;br /&gt;&lt;br /&gt;Your application may generate a log that records which accounts were logged into when.  Not all applications can do this.  If your application can do this, you can parse the log file and reference a list of all existing user accounts to roughly determine which accounts were dormant.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Going Beyond the Example Reports&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;There are plenty of other reports that may be possible.  For instance, if you noticed that user accounts were being mysteriously added, then you would want to know who added it.  Generating the “add” report with the username of the administrator might be helpful in this case.  You may choose to generate this report as part of the quarterly routine or request an investigation by the IT team if the need arises.&lt;br /&gt;&lt;br /&gt;Again, the feasibility of making this report relies on the capabilities of your application.  If no such data is kept in your application, then generating the report will be very difficult.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Security Measures for the User&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;So far, we’ve discussed what the system administrator and the head of accounting could do to safeguard against unauthorized account acquisition.  There are security measures that individual users of the system can follow to protect their account against hijacking.&lt;br /&gt;&lt;br /&gt;If the application displays the previous time the account was active when the user logs in, the user can check whether he was actually the guy who last logged in.  If he logged in two weeks ago but the last login record shows his last login as yesterday, something fishy is going on.&lt;br /&gt;&lt;br /&gt;Encouraging your users to check the last login dates every time he logs in and to report anything fishy to the proper authorities can enhance your security.&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;&lt;br /&gt;Reaction Plan&lt;/span&gt;&lt;br /&gt;If something fishy is detected with the above measures, then you should investigate the root cause.  Depending on the results of the investigation, you may want to take disciplinary action or implement more security measures if you discover a weakness in your measures.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;This article presented ideas on maintaining and monitoring accounts in an accounting system as a measure to make sure that wrong people do not have accounts.  Using an old account of someone who has left the company is a security hole that people can take advantage of.  Keeping “your ducks in a row” is an important practice that organization should adopt to reduce the probability of compromises to availability, integrity, and confidentiality.&lt;br /&gt;&lt;br /&gt;It is important to point out that, in general, one account should only be used by one person and never shared.  This eases mapping of accounts to their rightful owners.  When accounts are shared, then tracking who did what becomes very difficult.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/18-security-measures-for-availability.html"&gt;Article 18: Security Measures for Availability&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-7237483751059824876?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/7237483751059824876/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/17-security-measures-for-accounts.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/7237483751059824876'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/7237483751059824876'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/17-security-measures-for-accounts.html' title='17: Security Measures for Accounts Management'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_hJKVQaajsug/Sk1DZ6D52KI/AAAAAAAAAD8/iC4B31SeZoA/s72-c/Security+Measure+Account+Management.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-1623806562456065373</id><published>2009-07-02T16:21:00.000-07:00</published><updated>2009-07-05T19:41:19.033-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='common'/><category scheme='http://www.blogger.com/atom/ns#' term='security measures'/><category scheme='http://www.blogger.com/atom/ns#' term='reaction plan'/><category scheme='http://www.blogger.com/atom/ns#' term='untrusted'/><category scheme='http://www.blogger.com/atom/ns#' term='access control'/><category scheme='http://www.blogger.com/atom/ns#' term='design'/><category scheme='http://www.blogger.com/atom/ns#' term='internal'/><category scheme='http://www.blogger.com/atom/ns#' term='acquire'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='trusted'/><category scheme='http://www.blogger.com/atom/ns#' term='monitor'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='safeguard'/><category scheme='http://www.blogger.com/atom/ns#' term='pattern'/><category scheme='http://www.blogger.com/atom/ns#' term='maintain'/><title type='text'>16:  Routes to Acquiring Accounts – Internal Users and Security Measures</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Focus of This Article&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_hJKVQaajsug/Sk1Bj0s0C4I/AAAAAAAAADk/1knVYO3VyBM/s1600-h/Routes+to+Compromise+Pre.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://3.bp.blogspot.com/_hJKVQaajsug/Sk1Bj0s0C4I/AAAAAAAAADk/1knVYO3VyBM/s400/Routes+to+Compromise+Pre.bmp" alt="" id="BLOGGER_PHOTO_ID_5354007615711218562" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt; &lt;span style="font-weight: bold;"&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;This article continues the discussion started in the previous article; the previous article discussed routes that external untrusted and external trusted users could take to acquire accounts.  This article discusses routes internal untrusted and trusted users can take.&lt;br /&gt;&lt;br /&gt;External users are largely confined to using routes in the logical space to acquire access to externally facing assets.  In contrast, internal users have access to a physical space that external users do not have; they reside in the office so they can physically access computers and influence people at the office.  Therefore, internal users have a set of routes in addition to the routes available to external users.  Internal users can attempt to acquire access through using external user’s tactics like exploiting a vulnerability of an asset, but they are more likely to use the easier routes suggested below.&lt;br /&gt;&lt;br /&gt;Many of the internal security measures require influencing the behavior of people.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Who: Internal Untrusted&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_hJKVQaajsug/Sk1Bw6d2HfI/AAAAAAAAADs/ec6xd-fTg4g/s1600-h/Who+Internal+Untrusted.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://1.bp.blogspot.com/_hJKVQaajsug/Sk1Bw6d2HfI/AAAAAAAAADs/ec6xd-fTg4g/s400/Who+Internal+Untrusted.bmp" alt="" id="BLOGGER_PHOTO_ID_5354007840597351922" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Internal untrusted users can use exploit tactics to gain control of internal assets just like external users use against externally facing assets.  For internal users, there are additional routes.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Context For Discussion&lt;/span&gt;&lt;br /&gt;Let’s imagine a public company.  It must report its quarterly financial performance to its investors.  Safeguarding the integrity of its accounting data is an IT requirement.  The IT team must ensure that the right people enter the data.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Acquisition Route&lt;/span&gt;: Ask for an account from IT.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security Measure&lt;/span&gt;: Design – Make a process that checks that only the right people get accounts and the right people get right privileges.&lt;br /&gt;&lt;br /&gt;Often, the person who is responsible for administrating a system does not know who should have accounts and what privileges they should have.  The administrator may end up providing an account without asking any questions.&lt;br /&gt;&lt;br /&gt;Making a process that makes the administrator verify that the requester should in fact be provisioned an account with the authority of the asset is a possible security measure.  This measure is more important the more critical or sensitive the asset is.  The process need not be elaborate.   In this case, the administrator would contact the authority in the accounting department to confirm that an account should be provided with what privileges.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Acquisition Route&lt;/span&gt;:  A coworker shares his username and password because you need temporary access or he needs your help.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security Measures&lt;/span&gt;:  Design – Discourage sharing of usernames and passwords no matter what the reason.&lt;br /&gt;&lt;br /&gt;Users often use the same usernames and passwords across multiple assets because they don’t want to memorize multiple passwords.  Someone can share his password for an asset that is NOT sensitive, but the same password may allow access to assets that are far more sensitive.  The person who receives the username and password pair can try to use them on other assets.&lt;br /&gt;&lt;br /&gt;For example, someone can share his password for an internal portal; however, the password for the wiki may be the same as his accounting system account.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 3&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Acquisition Route&lt;/span&gt;: Memorize a password that is written down on a piece of paper in open view in someone’s cubicle.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security Measure&lt;/span&gt;:  Design – Encourage behavior that conceals passwords.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 4&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Acquisition Route&lt;/span&gt;: Memorize a password that is being typed in open view.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security Measure&lt;/span&gt;:  Design – Encourage behavior that conceals passwords.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Who: Internal Trusted&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_hJKVQaajsug/Sk1CNTv9ZeI/AAAAAAAAAD0/ciUynn_57rQ/s1600-h/Who+Internal+Trusted.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://2.bp.blogspot.com/_hJKVQaajsug/Sk1CNTv9ZeI/AAAAAAAAAD0/ciUynn_57rQ/s400/Who+Internal+Trusted.bmp" alt="" id="BLOGGER_PHOTO_ID_5354008328420550114" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Internal trusted users have the option of taking the same tactics as an external user.  They can try to exploit vulnerabilities that are exposed to gain administrative control over an asset.&lt;br /&gt;&lt;br /&gt;Internal trusted users can explore the data that is already available to them.  Some assets contain files with usernames and passwords that may be discovered by a trusted user if the administrator does not take proper precautions.  For instance, Unix operating systems can have a /etc/passwd file that contains usernames and passwords.&lt;br /&gt;&lt;br /&gt;Trusted users who find this data can use other people’s accounts without the knowledge of the real account owners.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Acquisition Route&lt;/span&gt;: Steal usernames and passwords within asset.  For example, the /etc/passwd file of Unix operating systems can be left open to the view of trusted users.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security Measure&lt;/span&gt;:  Design – Obfuscate or encrypt password data in all assets.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Upon Acquiring an Account&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;People with accounts can move to the next step in harming availability, integrity, and confidentiality.  Some trusted users may pursue administrative access rights by exploiting vulnerabilities in the applications that they now have access to.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;By understanding the routes that are available for internal users, we can create security measures that can block each route.  The examples presented in this article were largely habits that the company should promote as company policy.  The participation of each member of your organization is important to an effective security program.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/17-security-measures-for-accounts.html"&gt;Article 17: Security Measures for Accounts Management&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-1623806562456065373?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/1623806562456065373/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/16-routes-to-acquiring-accounts.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/1623806562456065373'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/1623806562456065373'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/16-routes-to-acquiring-accounts.html' title='16:  Routes to Acquiring Accounts – Internal Users and Security Measures'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_hJKVQaajsug/Sk1Bj0s0C4I/AAAAAAAAADk/1knVYO3VyBM/s72-c/Routes+to+Compromise+Pre.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-6227804139584388052</id><published>2009-07-02T16:10:00.001-07:00</published><updated>2009-07-05T19:40:32.071-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='common'/><category scheme='http://www.blogger.com/atom/ns#' term='security measures'/><category scheme='http://www.blogger.com/atom/ns#' term='untrusted users'/><category scheme='http://www.blogger.com/atom/ns#' term='access control'/><category scheme='http://www.blogger.com/atom/ns#' term='acquire'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='confidentiality'/><category scheme='http://www.blogger.com/atom/ns#' term='trusted users'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='pattern'/><category scheme='http://www.blogger.com/atom/ns#' term='external'/><category scheme='http://www.blogger.com/atom/ns#' term='integrity'/><category scheme='http://www.blogger.com/atom/ns#' term='availability'/><title type='text'>15:  Routes to Acquiring Accounts – External Users and Security Measures</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Focus of This Article&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_hJKVQaajsug/Sk0-hCwCUiI/AAAAAAAAADM/o6-OQqHFrSI/s1600-h/Routes+to+Compromise+Pre.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://2.bp.blogspot.com/_hJKVQaajsug/Sk0-hCwCUiI/AAAAAAAAADM/o6-OQqHFrSI/s400/Routes+to+Compromise+Pre.bmp" alt="" id="BLOGGER_PHOTO_ID_5354004269408342562" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;A previous article defined phases to compromising availability, integrity, and confidentiality and identified “acquire accounts” as a common phase.  Understanding how someone can unrightfully acquire accounts can help us create security measures to prevent it.&lt;br /&gt;&lt;br /&gt;This article organizes the discussion by different groups in the “Who” of the CyberSecurity Framework.  This article will discuss external trusted and external untrusted users.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Who: External Untrusted &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_hJKVQaajsug/Sk0_DlN3t_I/AAAAAAAAADU/WsvT2A_roYY/s1600-h/Who+External+Untrusted.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://1.bp.blogspot.com/_hJKVQaajsug/Sk0_DlN3t_I/AAAAAAAAADU/WsvT2A_roYY/s400/Who+External+Untrusted.bmp" alt="" id="BLOGGER_PHOTO_ID_5354004862775834610" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Someone can gain control of an account by hijacking someone else’s account or getting one created.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Context For Discussion&lt;/span&gt;&lt;br /&gt;Let’s imagine an organization that runs an online web trading service.  The organization’s customers use web screens to trade stock in real time. An untrusted user is someone who does not have a trading account.  A trusted user is someone who does.&lt;br /&gt;&lt;br /&gt;The web server and related network equipment only allow connections to http and https. No other ports are open.  The application is designed to only allow the display of the login screen to anyone who has not authenticated.&lt;br /&gt;&lt;br /&gt;This article will list examples of ways that an external untrusted person can gain access to a trading account or an account of the operating system that the web application runs on.  Security measures are suggested.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Acquisition Route&lt;/span&gt;: Steal usernames and passwords by eavesdropping network packets.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security Measure&lt;/span&gt;: Design – Encrypt transmissions of usernames and passwords.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Acquisition Route&lt;/span&gt;:  Guess usernames and passwords – use brute force.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security Measures&lt;/span&gt;:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Design – Only allow use of strong passwords.&lt;/li&gt;&lt;li&gt;Monitor - Upon three consecutive failures to login, lock the account so no more attempts can be made.  Notify administrator that there have been three failed attempts.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Network equipment often have default usernames and passwords.  Delete these commonly known usernames and passwords from equipment.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 3&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Acquisition Route&lt;/span&gt;: Exploit vulnerabilities of an unwary trusted user’s web browser to acquire trusted user information.  Use that information to take over trusted user’s account.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security Measure&lt;/span&gt;:  Design – When someone logs in from an IP address that has never been used to log into an account, then ask user self-identifying information to verify identity following successful login with username and password.  Self-identifying information can be mother’s maiden name.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 4&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Acquisition Route&lt;/span&gt;: Exploit vulnerabilities in web application, web server, operating system to gain control of the host.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security Measure&lt;/span&gt;:  Maintain - Patch vulnerabilities as quickly as possible.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Who: External Trusted&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_hJKVQaajsug/Sk0_ngluH2I/AAAAAAAAADc/Esy_I0Ff894/s1600-h/Who+External+Trusted.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://4.bp.blogspot.com/_hJKVQaajsug/Sk0_ngluH2I/AAAAAAAAADc/Esy_I0Ff894/s400/Who+External+Trusted.bmp" alt="" id="BLOGGER_PHOTO_ID_5354005480008982370" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Let’s continue using the web trading context to go through examples of external trusted users.&lt;br /&gt;&lt;br /&gt;Trusted users already have a username and password and are given access to web application screens that are not accessible to untrusted users.  Trusted users can attempt to do harm to your asset by exploiting vulnerabilities in your web application.  Trusted users have the option of using routes that are available to external untrusted users.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Acquisition Route&lt;/span&gt;: Exploit vulnerabilities in web application.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security Measures&lt;/span&gt;:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Design – Make your web application validate all parameters passed to the web application so that values are what you expect.   Guard against insertion of code into text.&lt;/li&gt;&lt;li&gt;Monitor – Make web application notify your security team when user attempts to enter harmful text.&lt;/li&gt;&lt;li&gt;Monitor – Make web application notify your security team when user tries to access a page that he doesn’t have permission to access.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Upon Acquiring an Account&lt;/span&gt;&lt;br /&gt;An external untrusted user who hijacks accounts on the web application can place trades without the knowledge of the real account owner.  An external untrusted user who gains administrative control of the operating system of an asset can take a variety of actions to cause damage.  Furthermore, he may use the compromised asset as a launch point for penetrating deeper into your IT infrastructure.&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Reaction Plan&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Once the compromise of an asset is detected, you must decide how to react.  Do you want to lead him to believe that he’s undiscovered and monitor him to accumulate evidence against him to take to court?&lt;br /&gt;&lt;br /&gt;It can be very difficult to identify all the changes an intruder made to your computing resources and reverse them.  Once you understand how he penetrated your asset, do you want to take the computer offline and do a fresh reinstall with the vulnerability fixed?  It’s probably a good idea.&lt;br /&gt;&lt;br /&gt;Do you want to notify the owners of the accounts that were broken into?&lt;br /&gt;&lt;br /&gt;It’s up to your organization to determine the reaction plan to the results of the compromise.  Having a human organization ready to determine the next steps is important.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;By understanding the routes that are available for external trusted users and external untrusted users, we can formulate security measures that block each route.  A range of design, maintain/monitoring, and reaction plan measures were presented.  The next article will cover internal untrusted and internal trusted users.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/16-routes-to-acquiring-accounts.html"&gt;Article 16:  Routes to Acquiring Accounts – Internal Users and Security Measures&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-6227804139584388052?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/6227804139584388052/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/15-routes-to-acquiring-accounts.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/6227804139584388052'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/6227804139584388052'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/15-routes-to-acquiring-accounts.html' title='15:  Routes to Acquiring Accounts – External Users and Security Measures'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_hJKVQaajsug/Sk0-hCwCUiI/AAAAAAAAADM/o6-OQqHFrSI/s72-c/Routes+to+Compromise+Pre.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-8185652018393593789</id><published>2009-07-02T15:58:00.001-07:00</published><updated>2009-07-05T19:39:57.728-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security measures'/><category scheme='http://www.blogger.com/atom/ns#' term='reaction plan'/><category scheme='http://www.blogger.com/atom/ns#' term='access control'/><category scheme='http://www.blogger.com/atom/ns#' term='design'/><category scheme='http://www.blogger.com/atom/ns#' term='acquire'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='confidentiality'/><category scheme='http://www.blogger.com/atom/ns#' term='monitor'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='safeguard'/><category scheme='http://www.blogger.com/atom/ns#' term='maintain'/><category scheme='http://www.blogger.com/atom/ns#' term='integrity'/><category scheme='http://www.blogger.com/atom/ns#' term='availability'/><title type='text'>14:  Routes in Logical Space to Compromise of Availability, Integrity, Confidentiality</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Focus of this Article&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_hJKVQaajsug/Sk09RYkAdkI/AAAAAAAAAC8/A2KiAPsGKSE/s1600-h/Focus+Logical+Space.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://1.bp.blogspot.com/_hJKVQaajsug/Sk09RYkAdkI/AAAAAAAAAC8/A2KiAPsGKSE/s400/Focus+Logical+Space.bmp" alt="" id="BLOGGER_PHOTO_ID_5354002900873934402" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Introduction&lt;/span&gt;&lt;br /&gt;Previous articles covered the types of security measures, security measures against “What” and physical space components of the CyberSecurity Framework.  This article will focus on the logical space.&lt;br /&gt;&lt;br /&gt;The route for someone to compromise availability, integrity, or confidentiality, has recognizable phases.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Phases to Compromise of Availability, Integrity, and Confidentiality&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;An external hacker can exploit vulnerabilities in externally facing software to compromise availability, integrity, and confidentiality.  For instance, vulnerabilities in externally facing web applications can be exploited to alter or steal data, or even damage the operation of the computer.  These damages can be inflicted without acquiring an administrative account on any application or software.  However, acquiring an administrative account allows far greater access to data and IT operations; therefore, acquiring an account is of strong interest to “bad people.”&lt;br /&gt;&lt;br /&gt;The route to compromising availability, integrity, and confidentiality starts with acquiring accounts on assets.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_hJKVQaajsug/Sk09dt5RWdI/AAAAAAAAADE/PpDd3ShZfC4/s1600-h/Routes+to+Compromise.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://3.bp.blogspot.com/_hJKVQaajsug/Sk09dt5RWdI/AAAAAAAAADE/PpDd3ShZfC4/s400/Routes+to+Compromise.bmp" alt="" id="BLOGGER_PHOTO_ID_5354003112758696402" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Availability&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Someone gains control of an account on a critical asset.  &lt;/li&gt;&lt;li&gt;He can then take a variety of actions that can undermine the availability of your critical assets.  For instance, he can shutdown a host or reconfigure an asset to be inaccessible to everyone else.  He can delete critical data.&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-weight: bold;"&gt;Integrity&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Someone gains control of an account on a sensitive asset. &lt;/li&gt;&lt;li&gt;He can then alter sensitive data.  For instance, he can add false sales records so that the organization’s financials are overstated or give himself a raise in the payroll database.&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-weight: bold;"&gt;Confidentiality&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Someone gains control of an account on a sensitive asset.  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;He can view data.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;He can “escape” with the sensitive data.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Security measures that protect against unauthorized acquisition of accounts are very important in preventing bad things from starting.&lt;br /&gt;&lt;br /&gt;We assumed that one person was going through these phases.  There can be multiple people involved in the compromise of data confidentiality.  Someone may have access to sensitive data that he shares with someone.  The second person can then escape with the data.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Acquiring control over accounts is a step toward undermining availability, integrity, and confidentiality.  The following article will discuss routes users can take to acquire accounts.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/15-routes-to-acquiring-accounts.html"&gt;Article 15:  Routes to Acquiring Accounts – External Users and Security Measures&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-8185652018393593789?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/8185652018393593789/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/14-routes-in-logical-space-to.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/8185652018393593789'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/8185652018393593789'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/14-routes-in-logical-space-to.html' title='14:  Routes in Logical Space to Compromise of Availability, Integrity, Confidentiality'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_hJKVQaajsug/Sk09RYkAdkI/AAAAAAAAAC8/A2KiAPsGKSE/s72-c/Focus+Logical+Space.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-6454191914248523549</id><published>2009-07-02T15:48:00.000-07:00</published><updated>2009-07-05T19:39:27.217-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security measures'/><category scheme='http://www.blogger.com/atom/ns#' term='loss'/><category scheme='http://www.blogger.com/atom/ns#' term='physical'/><category scheme='http://www.blogger.com/atom/ns#' term='space'/><category scheme='http://www.blogger.com/atom/ns#' term='lock'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='door'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='media'/><category scheme='http://www.blogger.com/atom/ns#' term='computer'/><category scheme='http://www.blogger.com/atom/ns#' term='confidentiality'/><category scheme='http://www.blogger.com/atom/ns#' term='laptop'/><category scheme='http://www.blogger.com/atom/ns#' term='safeguard'/><category scheme='http://www.blogger.com/atom/ns#' term='backup'/><category scheme='http://www.blogger.com/atom/ns#' term='theft'/><category scheme='http://www.blogger.com/atom/ns#' term='storage device'/><category scheme='http://www.blogger.com/atom/ns#' term='integrity'/><category scheme='http://www.blogger.com/atom/ns#' term='availability'/><title type='text'>13: Security Measures for Physical Space of CyberSecurity Framework</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Focus of This Article&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_hJKVQaajsug/Sk05ikr6BDI/AAAAAAAAAC0/-C9VkQk2RAI/s1600-h/CyberSecurity+Framework+Physical+Space.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://4.bp.blogspot.com/_hJKVQaajsug/Sk05ikr6BDI/AAAAAAAAAC0/-C9VkQk2RAI/s400/CyberSecurity+Framework+Physical+Space.bmp" alt="" id="BLOGGER_PHOTO_ID_5353998798139556914" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;A variety of “bad things” can happen in the physical space to harm availability, integrity, and confidentiality.  For example, someone can steal a traveling CFO’s laptop.  A USB key containing confidential information can be stolen from someone’s cubicle.  Someone can spill coffee on your core router in the equipment room and break it.  Someone can plug cables into the wrong NIC unintentionally.  People can do many things intentionally and unintentionally to undermine your security goals.&lt;br /&gt;&lt;br /&gt;This article will focus on people caused events that undermine availability, integrity, and confidentiality in the physical space.  It structures the discussion by looking at physical types of assets including portable media/storage devices, portable computers, desktop computers, and IT equipment.&lt;br /&gt;&lt;br /&gt;This article will NOT cover physical hardware failures or failures caused by shortage of resources such as shortage of network bandwidth, memory/disk space or CPU time.  Sizing assets appropriately, designing redundancy into your assets and having a tested process for recovery prevent these failures.&lt;br /&gt;&lt;br /&gt;Essentially, physical security measures boil down to:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Encouraging people to physically protect assets from theft&lt;/li&gt;&lt;li&gt;Implementing physical barriers with doors and locks&lt;/li&gt;&lt;li&gt;Using processes to only allow the right people into the right places&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Portable Media/Storage Devices - Anywhere&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Mishandling of portable media and storage devices can lead to compromises in confidentiality. If a thief steals media or a device that happens to contain usernames and passwords, the thief can gain logical access to your resources and later undermine availability and integrity.&lt;br /&gt;&lt;br /&gt;Portable media and storage devices containing sensitive information are sensitive assets that must be safeguarded.  Security measures require encouraging people to keep/use them in a manner that reduces likelihood of “bad things” happening.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Habits To Encourage For Portable Media/Storage Devices In Any Physical Space&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Do not keep sensitive information - especially unobfuscated usernames and passwords - on them unless you absolutely must.&lt;/li&gt;&lt;li&gt;If you must keep sensitive information on them, protect them against theft or loss.  Treat them like you would with your wallet or purse. &lt;/li&gt;&lt;li&gt;Report theft or loss to your organization’s authorities immediately.&lt;/li&gt;&lt;li&gt;If you use media like USB keys or other portable media to transfer data, then make it a habit to delete files on the media after each transfer.  People copying data from your USB key to their computer can copy other files that were not meant for them.  Be especially careful when you are transferring files to someone outside your organization like a client or a partner.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;There are additional measures that can be taken.  For instance, there are products that encrypt data on media to protect sensitive information.  Encryption of data is helpful if the media contains sensitive data and is stolen.  An organization that effectively exercises the above habits may be able to sufficiently reduce the probability of data theft without additional measures.&lt;br /&gt;&lt;br /&gt;If the large majority of your organization does not handle sensitive data and effectively adopts the above habits, then an organization wide roll out of additional measures is probably not worth the cost.  On the opposite extreme, if the large majority of your organization does handle very sensitive information, needs to store sensitive data in portable media, and doesn’t adopt the above habits, then additional measures may be worth considering.&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Backup Storage Media&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Backup storage media require special attention because mismanagement of backup media can impact availability, integrity, and confidentiality.  The theft of backup media undermines availability by undermining data recovery and also undermines confidentiality if the backup data is sensitive.  Backup data can be altered to undermine integrity especially if the data is used for auditing or to restore production data.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security Measures for Backup Storage Media&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Store backup data in a separate location from your equipment room.  If you keep backups in your equipment room and the room suffers physical damage from fire, flood, or a person, then your backups can be damaged together with the production equipment that rely on the backup data.&lt;/li&gt;&lt;li&gt;Protect your backup storage like you would your valuables.   Keep them locked up.  Allow only the right people to have access to them. &lt;/li&gt;&lt;li&gt;Report theft to your organization’s proper authorities immediately.&lt;/li&gt;&lt;li&gt;If you do lose username and password data, ask everyone potentially affected to change their passwords.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;There are additional measures that can be taken such as encryption.  Again, if your organization follows the suggested rules of thumb, your security measures may be sufficient to secure backup storage media.  Weighing benefits and cost of your security measures is a good idea.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Computers Outside and Inside Organization&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Computers outside and inside your organization are subject to theft just like portable media and storage devices.  Stolen computers differ from stolen media because a determined thief can potentially acquire logical access to resources that the computer has depending on how the computer has been configured.&lt;br /&gt;&lt;br /&gt;For example, people often have their browser memorize usernames and passwords to web applications they frequently access.  A determined thief can use those usernames and password.  The thief who has logical access to resources can undermine availability, integrity, and confidentiality of your critical and sensitive assets.&lt;br /&gt;&lt;br /&gt;Fortunately, stolen/missing computers do not go unnoticed for very long by their owners.  Efforts to address theft/loss can be taken quickly.&lt;br /&gt;&lt;br /&gt;The best way to reduce theft outside and resulting impact is to encourage your organization to adopt the following habits.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;Outside: Habits To Encourage For Portable Computers&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Prevent the theft of computers outside by treating your portable computers like your other valuables.&lt;/li&gt;&lt;li&gt;Report theft to your organization’s authorities immediately.  Quick reporting gives IT more time to react to the theft and less time to the thief to use the stolen computer to gain access to other resources.&lt;/li&gt;&lt;li&gt;If you do lose username and password data, change all potentially affected passwords immediately.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Computers inside the organization are best protected with a physical security measure and careful habits.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Inside: Physical Security Measure&lt;/span&gt;&lt;br /&gt;Have a door lock / key system to guard against non-employees entering your office.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Inside: Habits To Encourage For Portable Computers&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Keep your portable computer with you as much as possible.  Take it home over weekends and overnight.  Portable computers are easy to take out the door and susceptible to opportunistic theft.&lt;/li&gt;&lt;li&gt;Report theft to your organization’s proper authorities immediately.  Quick reporting gives IT more time to react to the theft and less time to the thief to use the stolen computer to gain access to other resources.&lt;/li&gt;&lt;li&gt;If you do lose username and password data, change all potentially affected passwords immediately.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;It’s hard to imagine people walking out the door with desktop computers, but it can happen.  If you think you are particularly vulnerable, you may want to consider additional physical measures that discourage theft of large items.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Additional Security Measures to Consider for Large Computers Inside Organization&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Lock it down if a particular desktop can be used to gain logical access to sensitive/critical resources.&lt;/li&gt;&lt;li&gt;Monitor exit points of your office with cameras/people.&lt;/li&gt;&lt;li&gt;Require someone to sign out any large packages leaving the office.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;The benefit and cost of security measures should be weighed before implementation.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Equipment in Equipment Room&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Security measures for computers and network equipment in the equipment room follow a similar pattern as the others.  Allowing the wrong guy to enter the equipment room can undermine availability because he can break things.  Furthermore, as with personal computers, getting physical access opens more opportunity to gain logical access.  Someone can plug into a box’s serial port to gain logical access or add snooping equipment that can help that person gather sensitive information.  When someone gets unauthorized logical access to critical assets, he can damage availability, integrity, and confidentiality.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security Measures for Equipment Room&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Have a door lock / key system to allow only authorized personnel inside the equipment room.&lt;/li&gt;&lt;li&gt;Don’t enter the room with drinks or anything that can cause damage to equipment.  It is not difficult to be careful and accidents do happen.&lt;/li&gt;&lt;li&gt;When making physical changes to the equipment, plan the change so you know what you are doing.  An orderly equipment room and documentation that explains the stuff inside the equipment room can help you avoid cabling mix ups that can hurt the availability of your assets.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;If your organization is doing a good job practicing the above security measures, you may deem those security measures sufficient.  Implementing the above security measures may be easy for a small company but if you have a large company, then it may be harder for you to track who has the keys to enter the equipment room and who’s actually going in and what’s actually being performed.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Alternative Security Measures to Consider for Equipment Room&lt;/span&gt;&lt;br /&gt;You might want to consider the following measures as an alternative.&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt; Allow only a few key personnel to have a copy of the key to the equipment room.  The key should not be easily copied.  For the sake of this example let’s say Joe and Tom have the only two keys.&lt;/li&gt;&lt;li&gt;When someone – say Jennifer - must go into the equipment room, then Jennifer must request the key to the equipment room from either Joe or Tom.  She goes to Tom.&lt;/li&gt;&lt;li&gt;Jennifer must explain to Tom what she needs to get done in the equipment room.  Tom approves.  Jennifer and Tom sign a document that verifies Tom has given the key to Jennifer.&lt;/li&gt;&lt;li&gt;Jennifer must return the key to Tom before the end of the day or when she completes the task.  This is both Tom and Jennifer’s responsibility.  Jennifer and Tom sign a document that verifies that Tom now has the key.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;The above security measure was presented to show that implementing a process can increase security; you don’t need buy high tech solutions to enhance security.  It’s also important to note that each security measure can have its “challenges.”   In this case, either Joe or Tom must always be accessible to Jennifer just in case there’s an emergency and Jennifer must enter the equipment room immediately.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Although this article is a presentation of common sense measures, there are a few points worth noting.&lt;br /&gt;&lt;br /&gt;Security measures can be lots of things other than technology:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Influencing people’s behavior&lt;/li&gt;&lt;li&gt;Making physical barriers&lt;/li&gt;&lt;li&gt;Using processes&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;There isn’t one way to implement physical security measures.  The general goal of physical security measures is to allow physical access only to the right people.  There are lots of ways to implement measures to satisfy the goal and each method has varying strengths and weaknesses.&lt;br /&gt;&lt;br /&gt;The better job you do of implementing “upstream” security measures, the less important “downstream” security measures are.  For example, if you do a great job with only allowing the minimum number of “right” people to have access to the equipment room, you don’t have to worry about monitoring the actual activities in the equipment room with a camera.  If you aren’t sure who all have the keys to the equipment room, then you might want to consider additional measures such as camera monitoring to discourage unauthorized personnel from entering.&lt;br /&gt;&lt;br /&gt;Cost of security measure not only includes the money spent on locks and cameras, but time and energy spent exercising the process or the negative impact on user experience.  For instance, encrypting PC hard drives can slow things down and hurt user experience.&lt;br /&gt;&lt;br /&gt;Lastly, the benefit and cost of security measures must be assessed by each organization and each may choose different or more stringent measures that fit its unique needs.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/14-routes-in-logical-space-to.html"&gt;Article 14:  Routes in Logical Space to Compromise of Availability, Integrity, Confidentiality&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-6454191914248523549?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/6454191914248523549/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/13-security-measures-for-physical-space.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/6454191914248523549'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/6454191914248523549'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/13-security-measures-for-physical-space.html' title='13: Security Measures for Physical Space of CyberSecurity Framework'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_hJKVQaajsug/Sk05ikr6BDI/AAAAAAAAAC0/-C9VkQk2RAI/s72-c/CyberSecurity+Framework+Physical+Space.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-232278618098100381</id><published>2009-07-02T15:42:00.000-07:00</published><updated>2009-07-05T19:38:47.136-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='externally facing assets'/><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='safeguard'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='vulnerability management'/><category scheme='http://www.blogger.com/atom/ns#' term='vulnerability patching'/><category scheme='http://www.blogger.com/atom/ns#' term='protection'/><category scheme='http://www.blogger.com/atom/ns#' term='worms'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojan horse'/><title type='text'>12: Security Measures for “What” of the CyberSecurity Framework</title><content type='html'>&lt;span style="font-weight: bold;font-size:130%;" &gt;Focus of This Article&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_hJKVQaajsug/Sk04MQReAwI/AAAAAAAAACs/cFy9OHir52g/s1600-h/CyberSecurity+Framework+What.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://3.bp.blogspot.com/_hJKVQaajsug/Sk04MQReAwI/AAAAAAAAACs/cFy9OHir52g/s400/CyberSecurity+Framework+What.bmp" alt="" id="BLOGGER_PHOTO_ID_5353997315191210754" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;This article discusses the “What” component of the CyberSecurity Framework and the security measures that should be used to address them.&lt;br /&gt;&lt;br /&gt;Evil software, such as viruses and worms, can undermine availability, integrity, and confidentiality.  Evil software can be programmed to do arbitrary things that can harm your systems.&lt;br /&gt;&lt;br /&gt;Furthermore, software vulnerabilities in your computing resources can be exploited by people or by programs to ultimately impact availability, integrity, and confidentiality.  New vulnerabilities are always being discovered and being patched by software makers.  Because new evil software continues to be born and new vulnerabilities are discovered, your security measures will involve continuously patching vulnerabilities.&lt;br /&gt;&lt;br /&gt;Detailed documents about running vulnerability management programs are available on the Internet.  This article won’t reproduce those documents but provide a nutshell summary of approaches.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Security Measures Against Evil Software&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Use of antivirus and other anti-malware software is a measure that reduces the likelihood of IT trouble.  There are many products that address systems that are often targeted by evil software.  Implementation using these products may not be as challenging as the implementation of other measures.&lt;br /&gt;&lt;br /&gt;Ideally, your security measures should do the following:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Protect your critical and sensitive assets especially if they are on systems that are often targeted by evil software.&lt;/li&gt;&lt;li&gt;Ensure antivirus is actually working:  it’s scanning for evil software and getting the latest updates.&lt;/li&gt;&lt;li&gt;Periodically check that it’s working or, if possible, get notified when the antivirus software fails.  Remedy failures quickly – especially if the failures affect critical or sensitive assets.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;If you have a very large number of assets and need to focus your efforts, pay more attention to the critical and sensitive assets that you identified in the order that you ranked them.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Security Measures Against Vulnerabilities&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;The cost of neglecting vulnerability patching can result in IT troubles that are far more costly. Anyone from the outside can exploit vulnerabilities on externally facing assets to gain control of the asset.  Compromised assets are used as a launch point to attack assets deeper in your IT infrastructure.&lt;br /&gt;&lt;br /&gt;Patching software vulnerabilities soon after your software maker releases patches will better protect your systems. Apply patches as quickly as possible to minimize the duration the vulnerability is exposed.&lt;br /&gt;&lt;br /&gt;Ideally, your security measures should do the following:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Keep up with vulnerabilities and patch releases for your software – especially on assets that are exposed to external people.  Get your software maker to push that information to you.&lt;/li&gt;&lt;li&gt;Read the documentation so that you know the patch works on your particular asset configuration.  Installing the patch on an identical non-production system and verifying that it doesn’t cause problems reduces the probability of the patch breaking your assets.&lt;/li&gt;&lt;li&gt;Install the patch.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Assets with vulnerabilities exposed to external people should be your highest priority for vulnerability patching.  The prioritization of patching other assets is driven by a few factors: the level of criticality and sensitivity of the assets, the severity of the vulnerabilities, and the size of the internal population who can potentially exploit the vulnerabilities from inside.  The greater the number of internal people can exploit the vulnerability, the more urgent the patching is.&lt;br /&gt;&lt;br /&gt;Products are available that can support the installation of patches to a large number of assets.  Ideally the products should help you:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Provide visibility that patches are being successfully applied in appropriate priority.&lt;/li&gt;&lt;li&gt;Provide notification when the patching fails.  Your IT should remedy failures quickly – especially if the failures affect external assets.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Use of antivirus and vulnerability management are two security measures that safeguard availability, integrity, and confidentiality.  These measures should be considered a regular component of your IT security program.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/13-security-measures-for-physical-space.html"&gt;Article 13: Security Measures for Physical Space of CyberSecurity Framework&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-232278618098100381?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/232278618098100381/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/12-security-measures-for-what-of.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/232278618098100381'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/232278618098100381'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/12-security-measures-for-what-of.html' title='12: Security Measures for “What” of the CyberSecurity Framework'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_hJKVQaajsug/Sk04MQReAwI/AAAAAAAAACs/cFy9OHir52g/s72-c/CyberSecurity+Framework+What.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-2140726246560520143</id><published>2009-07-02T15:38:00.000-07:00</published><updated>2009-07-05T19:37:27.645-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='process'/><category scheme='http://www.blogger.com/atom/ns#' term='remedy security breach'/><category scheme='http://www.blogger.com/atom/ns#' term='reporting suspicious'/><category scheme='http://www.blogger.com/atom/ns#' term='human resources'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='security breach'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='policy'/><category scheme='http://www.blogger.com/atom/ns#' term='reaction'/><category scheme='http://www.blogger.com/atom/ns#' term='remediation'/><category scheme='http://www.blogger.com/atom/ns#' term='how to'/><category scheme='http://www.blogger.com/atom/ns#' term='organization'/><title type='text'>11: Themes of “Reaction Plan” Security Measures</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Focus of This Article&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_hJKVQaajsug/Sk02_AerDGI/AAAAAAAAACk/xBfi50xWTPU/s1600-h/Types+of+Security+Measures+React.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://3.bp.blogspot.com/_hJKVQaajsug/Sk02_AerDGI/AAAAAAAAACk/xBfi50xWTPU/s400/Types+of+Security+Measures+React.bmp" alt="" id="BLOGGER_PHOTO_ID_5353995988101696610" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;This article discusses the most important elements of “Reaction Plan” security measures. Planning for all possibilities is impractical.  However, having a few measures in place can improve the efficacy of your IT security program.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Have A Critical Data Recovery Plan&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Critical data can be lost from hardware breakdown, intentional/unintentional human action, or catastrophes.  Using technologies such as RAID and high availability can safeguard data against loss from hardware breakdown, but they do not protect against human actions or catastrophes.  Therefore, it is important to have a data recovery plan to address these dangers.&lt;br /&gt;&lt;br /&gt;The loss of critical data such as customer data at an e-commerce company or source code at an enterprise software company can do irreversible harm.  Having a recovery plan in place can safeguard your organization against disaster.&lt;br /&gt;&lt;br /&gt;The recovery plan should be tested end to end, from taking the backup to restoring critical data using the backups.  You do not want to discover that there’s a glitch in the backup process that prevents full data recovery AFTER you have lost critical data.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Train Your IT Security Team to React&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;When your IT security team discovers something fishy is going on, then the team should know what to do next.  Having an agreed upon process and the human organization to support the process will better ensure that potential security breaches do not go unaddressed.&lt;br /&gt;&lt;br /&gt;The following is a generic process that can help you get started:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Notify proper authorities of potential security breach&lt;/li&gt;&lt;li&gt;Investigate whether there has been a security breach&lt;/li&gt;&lt;li&gt;Report findings to proper authorities&lt;/li&gt;&lt;li&gt;Agree on and execute next steps&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Next steps can be immediately blocking harmful actions of a user, disciplinary action of an internal employee, monitoring the wrongdoer to do more to collect more evidence of wrong doing against him, correcting the damage, and redesigning security measures.  Next steps depend on the particulars of the situation.&lt;br /&gt;&lt;br /&gt;Designating someone as a collection point for all potential security breaches can ease reporting. This person can also be responsible for leading the creation and execution of a plan if investigation reveals that there has been a real security breach.  This person will not work alone but collaborate with the owners of the breached asset and the IT team.  For example, the security breach of an accounting system will require the notification of the head of accounting so that relevant people are involved in addressing the security issue.  The IT team supports investigation and remediation.&lt;br /&gt;&lt;br /&gt;Having a perfect process and organization completely planned is probably not worth your investment in time.  Relying on your IT team to use their own judgment and following the rough process above may be enough to get the job done.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Encourage Your Organization to React&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Fishy things can be detected not only by the IT security team but any member of your organization or even partners and customers.  Anyone using your computing assets should be encouraged to notify the proper authorities when something fishy is detected.&lt;br /&gt;&lt;br /&gt;Having a designated contact point to report all fishy things can facilitate the process of reporting potential security breaches.  Informing everyone about availability of the contact point and encouraging people to use it can reduce the chances that security breaches go unaddressed.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Having a tried and true data recovery process protects organizations against loss of critical data.  Furthermore, encouraging people to react to fishy things is important so that potential security issues do not go unaddressed.  Having clear channels to communicate concerns and initiate an investigation process improves probability of discovering and addressing security breaches.&lt;br /&gt;&lt;br /&gt;These topics will be revisited in the context of the CyberSecurity Framework.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/12-security-measures-for-what-of.html"&gt;Article 12: Security Measures for “What” of the CyberSecurity Framework&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-2140726246560520143?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/2140726246560520143/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/focus-of-this-article-introduction-this.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/2140726246560520143'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/2140726246560520143'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/focus-of-this-article-introduction-this.html' title='11: Themes of “Reaction Plan” Security Measures'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_hJKVQaajsug/Sk02_AerDGI/AAAAAAAAACk/xBfi50xWTPU/s72-c/Types+of+Security+Measures+React.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-5105566128313092592</id><published>2009-07-02T15:28:00.000-07:00</published><updated>2009-07-05T19:36:53.189-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='audit logs'/><category scheme='http://www.blogger.com/atom/ns#' term='syslog'/><category scheme='http://www.blogger.com/atom/ns#' term='SNMP'/><category scheme='http://www.blogger.com/atom/ns#' term='real time'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='network monitoring'/><category scheme='http://www.blogger.com/atom/ns#' term='application monitoring'/><category scheme='http://www.blogger.com/atom/ns#' term='false positives'/><category scheme='http://www.blogger.com/atom/ns#' term='alert'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='anomaly detection'/><category scheme='http://www.blogger.com/atom/ns#' term='periodic reporting'/><title type='text'>10: Themes of “Maintain/Monitor” Security Measures</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Focus of This Article&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_hJKVQaajsug/Sk00xrNl8PI/AAAAAAAAACc/BeJRSxCDujQ/s1600-h/Types+of+Security+Measures+Maintain.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://3.bp.blogspot.com/_hJKVQaajsug/Sk00xrNl8PI/AAAAAAAAACc/BeJRSxCDujQ/s400/Types+of+Security+Measures+Maintain.bmp" alt="" id="BLOGGER_PHOTO_ID_5353993560031359218" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;This article discusses a variety of topics surrounding “Maintain/Monitor” security measures.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;What You Can Monitor Depends On Your Data Source&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;There are two general approaches to monitoring application activity:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Use native logs (e.g. syslog, audit log) as sources of information.&lt;/li&gt;&lt;li&gt;Use an additional program that provides information that is not recorded in “native” logs.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;The level of detail of logs can be set by setting the log’s audit level.  Even if a log is generated at the highest level of detail, the log still may not provide all the information that you desire.  For example, a failed logon to a fileserver may be recorded but the reason for the failure might not be available in the log.  A log file may tell you that the permissions of a file changed but it might not tell you what it changed from or who changed it.  A database audit log might not tell you which user on a web application queried out sensitive information from the database.&lt;br /&gt;&lt;br /&gt;When information in native logs is insufficient, you must develop a program, find a freely available program, or purchase a product that can creates the necessary information.&lt;br /&gt;&lt;br /&gt;You should also be aware that a log that generates the information you need will generate lots of other information that you do not need.  You may generate an overwhelming amount of information that no tool can effectively process to extract the events that you need.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Use Snapshot to Snapshot Comparisons If A Continuous History Is Unavailable&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Identifying differences in data between two points in time can be one tool to monitor data integrity if a continuous change history is not available.  One weakness to this approach is that data can be changed temporarily to fulfill a harmful purpose and then reversed between the two points in time that snapshots are taken.&lt;br /&gt;&lt;br /&gt;This approach can be taken to monitor anything from user accounts that were added or deleted, to journal records in general ledger accounting systems.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Let Urgency Determine Periodic vs. Real-Time Monitoring&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Monitoring can be done in real-time or periodically.  Depending on what you are monitoring, you may want to be notified immediately with an alert when something fishy is detected.  In other cases, periodic reports may be sufficient.&lt;br /&gt;&lt;br /&gt;For instance, you may want to be immediately notified about a failure to backup critical data.  However, you may not need to know immediately when a dormant account, an account that nobody has used in 90 days, is discovered.  A weekly or monthly clean up of dormant accounts may be sufficient.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Strategies For Detecting Anomalies&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Anomaly means irregularity from the norm.  You can detect anomalies across a variety of dimensions such as logical location, physical location, and time band.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Logical Location&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The Norm&lt;/span&gt;:  John always logs in from his computer.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Anomaly&lt;/span&gt;:  John logs in from Debbie’s computer.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Physical Location&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The Norm&lt;/span&gt;:  John should be accessing computing resources from one geographic location at one point in time.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Anomaly&lt;/span&gt;: John is accessing his company’s customer database from the office in Palo Alto and a company file server from his home in San Francisco.  There’s probably a second person who is not John accessing the company’s resources.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Time Band&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The Norm&lt;/span&gt;:  Network maintenance is only done between 7am-8am on weekdays.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Anomaly&lt;/span&gt;:  John logs into a router and changes its configuration outside the time band set by company policy.  It might not be John making changes to the router.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The Norm&lt;/span&gt;:  An automated batch job is done every first Monday of the month starting 1am with a designated service account.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Anomaly&lt;/span&gt;:  Someone logs into the service account out of the usual time band.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Frequency&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The Norm&lt;/span&gt;:  Usually, John accesses four different applications per week.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Anomaly&lt;/span&gt;: This week, John has tried to access 16 different applications, half of which he does not have an account on.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The Norm&lt;/span&gt;:  An average user downloads company’s proprietary intellectual property files at a rate of two files per week.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Anomaly&lt;/span&gt;: John downloaded 20 files in the last week.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;White List/Black List&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The Norm&lt;/span&gt;:  John uses the intranet search engine to find relevant information.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Anomaly&lt;/span&gt;: John, someone who has nothing to do with “Project XQ” the company’s super secret strategic plan, searches for the black listed term “Project XQ.”  John should not be seeking this kind of information.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Avoid False Positives&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;The purpose of monitoring is to detect something “fishy.”  Once something is detected, you must investigate it to determine whether what you detected is an indicator of something harmful going on.  You must be choosy about what you monitor to avoid putting too much time into investigating false positives.&lt;br /&gt;&lt;br /&gt;If your gut feeling is that certain security measures will lead to too many false positives, do not invest time in creating it.  If a security measure that you thought would be effective is triggering too many false positives, then consider revising the measure.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;These topics will be revisited later in the context of the CyberSecurity Framework.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/focus-of-this-article-introduction-this.html"&gt;Article 11: Themes of “Reaction Plan” Security Measures  &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-5105566128313092592?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/5105566128313092592/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/10-themes-of-maintainmonitor-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/5105566128313092592'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/5105566128313092592'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/10-themes-of-maintainmonitor-security.html' title='10: Themes of “Maintain/Monitor” Security Measures'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_hJKVQaajsug/Sk00xrNl8PI/AAAAAAAAACc/BeJRSxCDujQ/s72-c/Types+of+Security+Measures+Maintain.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-1940974788342438524</id><published>2009-07-02T15:23:00.000-07:00</published><updated>2009-07-05T19:36:22.573-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security measures'/><category scheme='http://www.blogger.com/atom/ns#' term='minimization'/><category scheme='http://www.blogger.com/atom/ns#' term='sensitive data'/><category scheme='http://www.blogger.com/atom/ns#' term='safeguard'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='user'/><category scheme='http://www.blogger.com/atom/ns#' term='framework'/><category scheme='http://www.blogger.com/atom/ns#' term='vulnerability patching'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='data loss protection'/><category scheme='http://www.blogger.com/atom/ns#' term='uniformity'/><title type='text'>9: Themes of “Design” Security Measures</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Focus of This Article&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_hJKVQaajsug/Sk0z336czSI/AAAAAAAAACU/wZjcDBcLvzY/s1600-h/Types+of+Security+Measures+Design.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://3.bp.blogspot.com/_hJKVQaajsug/Sk0z336czSI/AAAAAAAAACU/wZjcDBcLvzY/s400/Types+of+Security+Measures+Design.bmp" alt="" id="BLOGGER_PHOTO_ID_5353992567008316706" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Minimization and uniformity are often themes that are considered good practices.  This article provides examples to illustrate the concepts.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Minimization&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Enhancing security through minimization is best explained through examples.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Account Management Example&lt;/span&gt;&lt;br /&gt;Only provide accounts to people who need them and remove unnecessary accounts.  Providing accounts to people who request it without verifying their need can result in accounts being given to the wrong people.  Remove accounts of people who no longer need them.  Accounts of people who left the company can be hijacked without the knowledge of the organization.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Account Privilege Example&lt;/span&gt;&lt;br /&gt;Only provide privileges that are necessary.  For instance, grant privileges that allow deletion of your organization’s data from a critical application’s database to very few people if at all.  This protects against trusted administrators going “rogue.”&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Confidential Data Example&lt;/span&gt;&lt;br /&gt;Do not store sensitive data that you do not need.  Keeping around sensitive data only increases the probability of breaching confidentiality.  Do you need everyone’s physical mailing addresses in Active Directory for everyone to see?  Mailing addresses can be used for identity theft.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Services on Externally Facing Computers Example&lt;/span&gt;&lt;br /&gt;In externally facing assets, have the minimum number of active ports.  A computer that hosts a web server might only need http and https ports open on the external network connections.  If these are the only two ports that are open, do you need a firewall between the Internet and the computer?  Perhaps not.  If you choose not to have a firewall, then there’s one less equipment to manage.  You save money by not buying equipment and not spending time configuring it.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Uniformity&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Vulnerability Patching Example&lt;/span&gt;&lt;br /&gt;Having many one-of-a-kind computers can undermine your ability to automate patch roll out.  Patches may install correctly in some but not in others because of differences in their configuration.  Manual patching is a time consuming process and can leave your computers vulnerable for too long.  Uniformly configuring computers can make patch roll out easier; if the patch installs successfully, then the identical process can be used to patch sister computers.  This process can be automated with the use of patch management software.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Data Loss Protection Example&lt;/span&gt;&lt;br /&gt;DLP products may require an agent to be installed on everyone’s personal computers.  The successful roll out of the agent may rely on the uniform configuration of everyone’s personal computers.  Installation of the agent may fail if the user has changed the personal computer’s configuration drastically from the norm.  If the configuration on personal computers is kept the same, the roll out may be easier.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Minimization and uniformity are two themes to consider when designing your IT infrastructure.  These concepts will be revisited later in the context of the CyberSecurity Framework.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/10-themes-of-maintainmonitor-security.html"&gt;Article 10: Themes of “Maintain/Monitor” Security Measures&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-1940974788342438524?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/1940974788342438524/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/9-themes-of-design-security-measures.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/1940974788342438524'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/1940974788342438524'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/9-themes-of-design-security-measures.html' title='9: Themes of “Design” Security Measures'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_hJKVQaajsug/Sk0z336czSI/AAAAAAAAACU/wZjcDBcLvzY/s72-c/Types+of+Security+Measures+Design.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-5597586484614334701</id><published>2009-07-02T15:09:00.000-07:00</published><updated>2009-07-05T19:33:42.568-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='design'/><category scheme='http://www.blogger.com/atom/ns#' term='initial'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='setup'/><category scheme='http://www.blogger.com/atom/ns#' term='network monitoring'/><category scheme='http://www.blogger.com/atom/ns#' term='application monitoring'/><category scheme='http://www.blogger.com/atom/ns#' term='monitor'/><category scheme='http://www.blogger.com/atom/ns#' term='ongoing'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='types of security measures'/><category scheme='http://www.blogger.com/atom/ns#' term='incident'/><category scheme='http://www.blogger.com/atom/ns#' term='maintain'/><category scheme='http://www.blogger.com/atom/ns#' term='continuing'/><category scheme='http://www.blogger.com/atom/ns#' term='one time'/><title type='text'>8:  Types of Security Measures</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;This article defines types of security measures.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_hJKVQaajsug/Sk0wbA0i4oI/AAAAAAAAACM/mBb2znJil5k/s1600-h/Types+of+Security+Measures.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://2.bp.blogspot.com/_hJKVQaajsug/Sk0wbA0i4oI/AAAAAAAAACM/mBb2znJil5k/s400/Types+of+Security+Measures.bmp" alt="" id="BLOGGER_PHOTO_ID_5353988772648379010" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Secure A Fortress&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Drawing an analogy between guarding a fortress and guarding your IT infrastructure can help you more easily understand the types of security measures that can be taken.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;1. Measure - Design&lt;/span&gt;&lt;br /&gt;A fortress must be designed and built to keep bad guys out.  Fortresses have only a few entrances that can be easily monitored and high walls.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2. Measure – Maintenance/Monitoring&lt;/span&gt;&lt;br /&gt;The job of keeping the bad guys out does not end once the last brick is cemented into the fortress. The fortress receives regular inspection so any newly discovered weaknesses, like a crack in the wall or a broken lock, are repaired.&lt;br /&gt;&lt;br /&gt;Furthermore, guards monitor the walls at night because a determined invader can climb the fortress walls.&lt;br /&gt;&lt;br /&gt;Educating the entire population who reside in the fortress to report anything suspicious to the proper authorities can enhance security.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3. Measure - Reaction Plan&lt;/span&gt;&lt;br /&gt;If guards, during their patrol, discover evidence that someone unwanted has entered the fortress then the guards must try to catch the intruder.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Secure Your IT Infrastructure&lt;/span&gt;&lt;br /&gt;Now let’s discuss what design, maintain/monitor, and reaction plan measures you can take to defend your IT infrastructure.  Design measures are usually one-time setups, and maintain/monitor measures require continued action.  Reaction plans must be prepared when something bad actually happens.&lt;br /&gt;&lt;br /&gt;When addressing a security problem involving criticality, integrity, or confidentiality, you should consider measures across these broad categories.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;1. Measure – Design   &lt;/span&gt;&lt;br /&gt;Just as you must design the fortress to be difficult to penetrate, you can design your physical space to be difficult to penetrate by installing door locks to entrances to your office and your equipment room.  Provide keys to only the right people.&lt;br /&gt;&lt;br /&gt;Within the logical space, you can design the topology of your IT network so that only the right people gain access to the right parts of the network.  Furthermore, you can restrict logical access to applications by providing user accounts to only the people who should be accessing particular applications.&lt;br /&gt;&lt;br /&gt;You can use technology to encrypt your sensitive data so that only people with the right permission can view the data.&lt;br /&gt;&lt;br /&gt;There are measures that fall into both the physical space and logical space.  Building redundant hardware and software assets to protect against hardware failure is one example.  Having a system that backs up critical data can be another measure.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2. Measure - Maintain/Monitor&lt;/span&gt;&lt;br /&gt;Many design measures require continued maintenance because circumstances change.&lt;br /&gt;&lt;br /&gt;New evil software are born so you need to continue to update your antivirus software.  Furthermore, new vulnerabilities are being discovered so you need continue to patch software with the latest vulnerability patches.&lt;br /&gt;&lt;br /&gt;Because new people can enter your organization and old people can leave, you need to continue to make sure that the right people have access to the equipment room and the right people have accounts to the right applications.&lt;br /&gt;&lt;br /&gt;You may also choose to monitor who is entering the office or the equipment room with a security guard during office hours and a camera that monitors the doorways or snaps a photo whenever someone unlocks the door during closed hours.&lt;br /&gt;&lt;br /&gt;You can monitor the creation of accounts in your computers and applications so that you know that bad accounts are not being created.&lt;br /&gt;&lt;br /&gt;You can monitor that your backups are being properly performed.&lt;br /&gt;&lt;br /&gt;You can also inculcate safe IT security practices into members of your organization by periodically promoting habits that enhance security.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3. Measure - Reaction Plan&lt;/span&gt;&lt;br /&gt;When something fishy is detected, you should have a human organization ready to create a reaction plan.  Having a clear go-to person for reporting potential compromises can ensure that suspicious activities are addressed.&lt;br /&gt;&lt;br /&gt;When availability of your critical assets is compromised, you should have a plan to return the assets to production.  A “tried and true” plan to restore data from backups should be in place.&lt;br /&gt;&lt;br /&gt;Because of the wide variety of damage that can result from compromises of integrity and confidentiality, it’s not practical to have a “tried and true” reaction plan in store for every possibility.  You can, however, appoint someone as the go-to person for reporting compromises, so that your organization can react quickly.&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Implementation of Security Measures&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;The technology for implementing security measures can be developed by your team, bought from a vendor, or downloaded freely.  If you are going to use freely available tools, please use proper precautions to ensure that the tool is what you expect it to be and not malware.&lt;br /&gt;&lt;br /&gt;If you are buying from a vendor, make sure you know what your requirements are first.  Try to understand how vendor products fit into your requirements.  Buying an expensive but cool security technology and counting on figuring out how to use it later will result in failure more often than not.&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Now we know that there are three types of security measures:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Design – Set up your IT infrastructure the right way.&lt;/li&gt;&lt;li&gt;Maintain/Monitor – Maintain your design measures.  Monitor to ensure that infrastructure is working as expected and there are no anomalies.&lt;/li&gt;&lt;li&gt;Reaction Plan – Formulate a recovery plan for critical failures.  Create a team that server as the go-to contact for reporting incidents so your organization is ready to react quickly.&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/9-themes-of-design-security-measures.html"&gt;Article 9: Themes of “Design” Security Measures&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-5597586484614334701?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/5597586484614334701/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/8-types-of-security-measures.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/5597586484614334701'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/5597586484614334701'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/8-types-of-security-measures.html' title='8:  Types of Security Measures'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_hJKVQaajsug/Sk0wbA0i4oI/AAAAAAAAACM/mBb2znJil5k/s72-c/Types+of+Security+Measures.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-2831318343721696633</id><published>2009-07-02T15:08:00.000-07:00</published><updated>2009-07-05T19:33:01.231-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='confidentiality'/><category scheme='http://www.blogger.com/atom/ns#' term='security measures'/><category scheme='http://www.blogger.com/atom/ns#' term='safeguard'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='user'/><category scheme='http://www.blogger.com/atom/ns#' term='framework'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='integrity'/><category scheme='http://www.blogger.com/atom/ns#' term='availability'/><title type='text'>PART 2: SECURITY MEASURES</title><content type='html'>We can use the CyberSecurity Framework as a structure to cover the variety of security issues that must be addressed.&lt;br /&gt;&lt;br /&gt;First, I will discuss different types of security measures and their common themes.&lt;br /&gt;&lt;br /&gt;Second, I will discuss security measures that address components of the CyberSecurity Framework:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;What&lt;/li&gt;&lt;li&gt;Where – Physical Space&lt;/li&gt;&lt;li&gt;Where – Logical Space&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;This part of the book helps you develop your vision of security measures.  When evaluating security products, you will be able to think critically about how they fit into your vision and requirements.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/8-types-of-security-measures.html"&gt;Article 8:  Types of Security Measures&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-2831318343721696633?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/2831318343721696633/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/part-2-security-measures.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/2831318343721696633'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/2831318343721696633'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/part-2-security-measures.html' title='PART 2: SECURITY MEASURES'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-2602645549945921523</id><published>2009-07-02T15:04:00.001-07:00</published><updated>2009-07-05T19:32:26.750-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='network'/><category scheme='http://www.blogger.com/atom/ns#' term='untrusted'/><category scheme='http://www.blogger.com/atom/ns#' term='user'/><category scheme='http://www.blogger.com/atom/ns#' term='internal'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='trusted'/><category scheme='http://www.blogger.com/atom/ns#' term='sensitive'/><category scheme='http://www.blogger.com/atom/ns#' term='confidentiality'/><category scheme='http://www.blogger.com/atom/ns#' term='assets'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='safeguard'/><category scheme='http://www.blogger.com/atom/ns#' term='critical'/><category scheme='http://www.blogger.com/atom/ns#' term='framework'/><category scheme='http://www.blogger.com/atom/ns#' term='external'/><category scheme='http://www.blogger.com/atom/ns#' term='integrity'/><category scheme='http://www.blogger.com/atom/ns#' term='availability'/><title type='text'>7: “Who” of the CyberSecurity Framework</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;In an earlier article, I introduced the concept of “Who” in the CyberSecurity Framework.  “Who” refers to people.  This article provides more details about the importance of the following set of characteristics for people.&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;External vs. Internal&lt;/li&gt;&lt;li&gt;Trusted vs. Untrusted&lt;/li&gt;&lt;li&gt;Administrator vs. Non-Administrator&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_hJKVQaajsug/Sk0vEEH6tvI/AAAAAAAAACE/uGeZNNLcW7A/s1600-h/CyberSecurity+Framework+Who.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://2.bp.blogspot.com/_hJKVQaajsug/Sk0vEEH6tvI/AAAAAAAAACE/uGeZNNLcW7A/s400/CyberSecurity+Framework+Who.bmp" alt="" id="BLOGGER_PHOTO_ID_5353987278886319858" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;External vs. Internal&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;“External” and “internal” characteristics refer to the physical space.  People who are outside the physical boundaries of your office are classified as “external.”  People who are inside the bounds of your office are classified as “internal.”&lt;br /&gt;&lt;br /&gt;This distinction is important because someone who is “external” has access to different resources than someone who is “internal.”  People can be “external” at one point in time and “internal” in another.  A sales person is external when he travels and internal when he’s visiting the office.  But most people are one or the other.&lt;br /&gt;&lt;br /&gt;The following are things that “internal” people might have that “external” people often don’t.&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Access to internal wireless or Ethernet network&lt;/li&gt;&lt;li&gt;Access to personal computers that have direct access to internal critical and sensitive assets&lt;/li&gt;&lt;li&gt;Access to people whom you can influence to acquire information or access&lt;/li&gt;&lt;li&gt;Access to people’s workspace with documents with sensitive information (e.g. a slip of paper with a password)&lt;/li&gt;&lt;li&gt;Visual access to people typing in their password&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;There are potential security holes in the physical space of the “internal” environment that “external” people cannot leverage.  External people are largely constrained to attack assets that are exposed to them in the logical space.  The easiest path to compromising security is different for “internal” and “external” people.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Trusted vs. Untrusted&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;“Trusted” and “untrusted” users refer to users who have or do not have accounts in the logical space. Again, the vulnerabilities exposed to “trusted” and “untrusted” people are different.&lt;br /&gt;&lt;br /&gt;For example, Kim has a web trading account with StocksRUs.  David does not.  Kim has access to StocksRUs web screens, so she can find vulnerabilities within the web application.  David won’t have access to the web trading screens’ vulnerabilities.&lt;br /&gt;&lt;br /&gt;Here’s another example. Joe, an employee of ABC Co. has access to his company’s accounting system, but not Mary, who is also an employee.  Joe will have an easier time viewing confidential accounting information or inputting false records into the accounting system than Mary will have.  Security measures for Mary with respect to the accounting system will be different from Joe’s.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Administrator vs. Non-Administrator&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Administrators are a subset of “trusted” people.  It is important to distinguish administrators from non-administrators because administrators have many privileges that can be abused.  For instance, a database administrator can use his privileges to query out credit card information although he should not be doing it.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Conclusion&lt;/span&gt;&lt;br /&gt;Understanding the “Who” of the CyberSecurity Framework puts security issues in sharper focus.  Security measures can differ not only because you are addressing different security problems of availability, integrity, and confidentiality, but also because you are taking security measures against different people.  With a clearer sense of who you are guarding against, you can apply more specific and effective security measures.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/part-2-security-measures.html"&gt;Part 2: Security Measures&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-2602645549945921523?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/2602645549945921523/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/7-who-of-cybersecurity-framework.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/2602645549945921523'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/2602645549945921523'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/7-who-of-cybersecurity-framework.html' title='7: “Who” of the CyberSecurity Framework'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_hJKVQaajsug/Sk0vEEH6tvI/AAAAAAAAACE/uGeZNNLcW7A/s72-c/CyberSecurity+Framework+Who.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-3744556343950533537</id><published>2009-07-02T14:54:00.000-07:00</published><updated>2009-07-05T19:30:06.245-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='prioritize'/><category scheme='http://www.blogger.com/atom/ns#' term='network'/><category scheme='http://www.blogger.com/atom/ns#' term='user'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='ranking'/><category scheme='http://www.blogger.com/atom/ns#' term='protect'/><category scheme='http://www.blogger.com/atom/ns#' term='sensitive'/><category scheme='http://www.blogger.com/atom/ns#' term='confidentiality'/><category scheme='http://www.blogger.com/atom/ns#' term='safeguard'/><category scheme='http://www.blogger.com/atom/ns#' term='assets'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='prioritization'/><category scheme='http://www.blogger.com/atom/ns#' term='rank'/><category scheme='http://www.blogger.com/atom/ns#' term='integrity'/><category scheme='http://www.blogger.com/atom/ns#' term='how to identify'/><title type='text'>6: Gradations of Sensitivity</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Focus of This Article&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_hJKVQaajsug/Sk0s--7J3HI/AAAAAAAAAB0/VG0z1cYnSGQ/s1600-h/Focus+Sensitive+Assets.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 292px;" src="http://4.bp.blogspot.com/_hJKVQaajsug/Sk0s--7J3HI/AAAAAAAAAB0/VG0z1cYnSGQ/s400/Focus+Sensitive+Assets.bmp" alt="" id="BLOGGER_PHOTO_ID_5353984992568007794" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;A rank order list of assets by criticality or sensitivity can help your team prioritize their work.  This rank order list is only one decision-making factor out of many others when allocating resources.  Other factors include the ease of implementing the security measures and the efficacy of existing security measures.&lt;br /&gt;&lt;br /&gt;A previous article helped you identify your critical assets.  This article focuses on distinguishing levels of sensitivity.&lt;br /&gt;&lt;br /&gt;Assessing sensitivity is more of an art than a science.  This article suggests an approach to assessing sensitivity with a few questions that can help you to create a ranking pyramid that groups assets into bands of sensitivity and rank order assets within their bands.&lt;br /&gt;&lt;br /&gt;Sensitive assets hold sensitive data.  Sensitive assets often are databases on shared computing resources.  The more sensitive the data is, the more sensitive the asset is.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_hJKVQaajsug/Sk0tD3D2efI/AAAAAAAAAB8/gBDZsHkGDDY/s1600-h/Rank+Sensitive+Assets.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 288px;" src="http://1.bp.blogspot.com/_hJKVQaajsug/Sk0tD3D2efI/AAAAAAAAAB8/gBDZsHkGDDY/s400/Rank+Sensitive+Assets.bmp" alt="" id="BLOGGER_PHOTO_ID_5353985076356348402" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Questions to Assess Sensitivity&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;To assess the sensitivity of an asset, try to imagine it in isolation without the benefit of any protection such as Data Loss Protection.  This will help you separate the sensitivity of an asset from the security measures that protect the asset.  Furthermore, separate out the efficacy of the post-incident response plan.  The more sensitive the asset, the more interested you should be in implementing measures to quickly detect and respond to security incidents around the asset.&lt;br /&gt;&lt;br /&gt;The greater the negative impact of the tampering or theft of sensitive information is on your organization, the higher the sensitivity of the asset containing it.  Below are questions that help you size up the negative impact.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Questions to Assess Sensitivity&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Breadth&lt;/span&gt;: If data within the asset is altered or stolen, what is the breadth of the negative impact?  How many people are negatively impacted? The larger the number, the greater its sensitivity.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Depth&lt;/span&gt;: If data within the asset is altered or stolen, what is the depth of the negative impact?  Will your organization be fined?  Will people be sent to jail?  Will people die? Will your organization be less secure? Will your organization’s reputation be damaged? Will the competitiveness of your organization be compromised? &lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;The depth of the negative impact varies widely depending on what the sensitive information is and what is done with that information.  Therefore, it is difficult to summarize the sensitivity of an asset with a single rating.&lt;br /&gt;&lt;br /&gt;It is easy to say that larger fines are worse than smaller fines.  The loss of two lives is worse than the loss of one.  But how do you compare something less tangible and quantifiable like the competitiveness of your organization to a fine?  Another factor that influences these comparisons between money and lives is your organization’s values.  What is human life worth in terms of dollars?&lt;br /&gt;&lt;br /&gt;There’s usually some way to quantify these fuzzy damages, but the method must be hand crafted for each situation, so I will not cover this topic in this book.&lt;br /&gt;&lt;br /&gt;Sometimes even after a thorough quantification using probabilities and consequences with the help of consultants, you’ll only be marginally more confident that the resulting rank order is right.  So spending an enormous amount of resources to create a perfect sensitivity ranking is dubious.  However, going through the exercise described in this article should help you better understand the sensitive assets that you should worry about.&lt;br /&gt;&lt;br /&gt;You can take a similar approach presented for criticality in the section “Bands of Criticality and Rank Ordering Assets” in the previous article.  Quantify when you can or use your “common sense” to place sensitive assets into bands.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Examples of Assessing Sensitivity&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Below are examples that demonstrate the above approach.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 1:  Theft of Passwords for Company Email System of Any Company&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Breadth&lt;/span&gt;: All can be affected.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Depth&lt;/span&gt;: Emails of executives can contain confidential information.  Furthermore, a person’s passwords for other resources are probably the same as the person’s email password.  Other resources can be compromised.  Furthermore, the password of an administrator can be used to cause greater damage.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Stolen passwords can provide unauthorized access to not only email but also other applications.  In general, sensitivity of passwords is high because the consequences can be extremely negative.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 2:  Theft of Credit Card Information from E-Commerce Company&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Breadth&lt;/span&gt;: All customers can be affected.  E-commerce company is affected.  Credit card company is affected.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Depth&lt;/span&gt;: Customers may be inconvenienced.  E-commerce company can be fined by credit card company.  Customers can stop shopping at E-commerce site.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;The consequences of stolen credit card numbers can be large; however, in general, password information can be considered more sensitive because it can ease the theft of credit card numbers and other sensitive information.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 3:  Alteration of Financial Data for Public Company&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Breadth: Investing public, inside investors, the company as a whole, the company’s executives can be affected.&lt;/li&gt;&lt;li&gt;Depth: Company executives can go to jail.  Misled investors can lose large amounts of money.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;If your organization is a public e-commerce company, then it’s hard to determine which is more sensitive: financial data or credit card information.&lt;br /&gt;&lt;br /&gt;If you must allocate resources to implement security measures between the two, you may have to rely on other factors and not just the sensitivity ranking to make your decision.  For instance, you may consider ease of implementation of security measures.  Furthermore, you may consider the security measures already in place.  Is one asset far more vulnerable than the other?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 4: Theft of Medical Records at Healthcare Provider&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Breadth&lt;/span&gt;: The healthcare provider as a whole can be affected.  Patient privacy can be violated.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Depth&lt;/span&gt;: Healthcare provider can be fined.  Patient loses privacy.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Again, you can be fined for not taking proper measures.  If medical records of celebrities are stolen and made public, then the consequences to your organization’s reputation may be large.  If you are a public healthcare provider, then the sensitivity ranking between financials and medical can be challenging.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 5:  Theft of Chip Company’s Blueprints of Proprietary Technology&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Breadth&lt;/span&gt;: The company as a whole can be affected.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Depth&lt;/span&gt;: Competitiveness can be undermined.  Revenue can be undermined.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Depending on what the blueprints are, the consequences can be large.  If the information reaches competitors who can reproduce copies or follow similar designs, then your company’s technological advantage is undermined.&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;&lt;br /&gt;Conclusion&lt;/span&gt;&lt;br /&gt;We now have an approach to rank ordering assets by sensitivity.&lt;br /&gt;&lt;br /&gt;Creating a rough rank ordered list is a good exercise for you and your team for the same reasons for going through the parallel exercise with criticality.  Once you have reviewed your sensitive assets with the above approach, your team will have an opinion about what is more important than others and use this list as one factor in prioritizing the implementation of security measures.&lt;br /&gt;&lt;br /&gt;Completing this exercise for both critical and sensitive assets will help you get a good feel of the assets that you should worry about.  Instead of a view of vast ocean of IT resources that appear equally important, you should now see your IT infrastructure with important areas and feel the weight of their importance.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/7-who-of-cybersecurity-framework.html"&gt;Article 7: “Who” of the CyberSecurity Framework&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-3744556343950533537?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/3744556343950533537/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/6-gradations-of-sensitivity.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/3744556343950533537'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/3744556343950533537'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/6-gradations-of-sensitivity.html' title='6: Gradations of Sensitivity'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_hJKVQaajsug/Sk0s--7J3HI/AAAAAAAAAB0/VG0z1cYnSGQ/s72-c/Focus+Sensitive+Assets.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-1045536946717162422</id><published>2009-07-02T14:13:00.000-07:00</published><updated>2009-07-05T19:28:45.526-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='network'/><category scheme='http://www.blogger.com/atom/ns#' term='user'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='prioritize assets'/><category scheme='http://www.blogger.com/atom/ns#' term='protect'/><category scheme='http://www.blogger.com/atom/ns#' term='assets'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='safeguard'/><category scheme='http://www.blogger.com/atom/ns#' term='critical'/><category scheme='http://www.blogger.com/atom/ns#' term='framework'/><category scheme='http://www.blogger.com/atom/ns#' term='availability'/><category scheme='http://www.blogger.com/atom/ns#' term='how to identify'/><category scheme='http://www.blogger.com/atom/ns#' term='rank assets'/><title type='text'>5: Gradations of Criticality</title><content type='html'>&lt;span style="font-weight: bold;font-size:130%;" &gt;Focus of This Article&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_hJKVQaajsug/Sk0jWNUF4II/AAAAAAAAABU/jHV3D0L13UU/s1600-h/Focus+Sensitive+Assets.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 292px;" src="http://1.bp.blogspot.com/_hJKVQaajsug/Sk0jWNUF4II/AAAAAAAAABU/jHV3D0L13UU/s400/Focus+Sensitive+Assets.bmp" alt="" id="BLOGGER_PHOTO_ID_5353974396451414146" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;A rank order list of assets by criticality or sensitivity can help your team prioritize their work.  This article focuses on distinguishing levels of criticality. This rank order list is only one decision-making factor out of many others when allocating resources.  Other factors include the ease of implementing the security measures and the efficacy of existing security measures.&lt;br /&gt;&lt;br /&gt;Assessing criticality is more of an art than a science.  This article suggests an approach to assessing criticality with a series of questions that can help you to create a ranking pyramid that groups assets into bands of criticality and rank order assets within their bands.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_hJKVQaajsug/Sk0jeAROJOI/AAAAAAAAABc/jDb_ULWo2wg/s1600-h/Rank+Critical+Assets.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 288px;" src="http://2.bp.blogspot.com/_hJKVQaajsug/Sk0jeAROJOI/AAAAAAAAABc/jDb_ULWo2wg/s400/Rank+Critical+Assets.bmp" alt="" id="BLOGGER_PHOTO_ID_5353974530388665570" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Questions to Assess Criticality&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;To assess the criticality of an asset, try to imagine it without redundancy or backup/recovery measures first. The higher the criticality of a system, the more you should be interested in implementing redundancy and backup/recovery measures.&lt;br /&gt;&lt;br /&gt;The greater the negative impact of the unavailability of an asset is on your organization, the higher its level of criticality.  Below are questions that help you size up the negative impact.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Questions to Assess Criticality&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Breadth&lt;/span&gt;: If an asset becomes unavailable, how many people are negatively impacted?  The larger the number, the greater the asset’s criticality.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Alternatives&lt;/span&gt;: If an asset becomes unavailable, are there alternative ways to get the same work done?  The more difficult it is to get the same work done, the greater the asset’s criticality.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Urgency&lt;/span&gt;: If an asset becomes unavailable, how urgent are the activities that cannot be completed?  The more urgent, the greater the asset’s criticality.  Is it always urgent?  The greater the frequency of urgency, the more critical.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Money Related&lt;/span&gt;: If an asset becomes unavailable, how does it impact the organization’s money making operations?  The less able an organization can earn money, the greater its criticality.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;The combined answers to the above questions will give you a sense of the criticality of an asset.  Some assets will be clearly more critical than others.  Some will be difficult to rank higher or lower than others.&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Bands of Criticality and Rank Ordering Assets&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Going through the process of asking the above questions and grouping assets into bands of criticality is the first step.  The highest band will contain the fewest assets that are of the highest criticality.  Each lower band may have increasingly more assets.  This basic grouping may be sufficient to get your security program started.&lt;br /&gt;&lt;br /&gt;If necessary, you can proceed to rank order the assets within each band with the following procedure.&lt;br /&gt;&lt;br /&gt;You can create a rank ordered list by comparing two assets at a time across the four questions and force yourself to decide which is more critical than the other.&lt;br /&gt;&lt;br /&gt;Let’s assume we have five assets in a band.  Choose two assets and decide which is more critical than the other.  Then take a third asset and make the same kind of comparison with the asset on ranked 1 in your list and the third asset.  If you decide that the third asset is less critical then compare the third asset with the asset ranked 2.  If the third is more critical than rank 2, then make the third asset rank 2, and what was originally ranked 2, rank 3.  You can follow the similar steps with the remaining assets to complete a prioritized list.  As you gain experience, this process will become quicker.&lt;br /&gt;&lt;br /&gt;I can provide you with a scoring system that rates criticality, but this system would be arbitrary and your organization may be worse off relying on my arbitrary formula for ranking your assets than using the approach described above.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Examples of Assessing Criticality&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Below are examples that demonstrate the above approach at fictitious organizations.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 1: Assets that Support the Internal Network At An Enterprise Software Company&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Breadth&lt;/span&gt;: Everyone is affected by a downed internal network.  Both internal and external people cannot access internal resources.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Alternatives&lt;/span&gt;: The phone is an alternative to email for the sales team and a few other people; the majority rely heavily on email and the phone is not a workable alternative.  The customer support team has no alternative to their electronic knowledge database.  Engineering has no alternative of getting latest source code.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Urgency&lt;/span&gt;: The customer support team cannot serve customers effectively without immediate access to electronic knowledge database.  Engineering cannot check in or check out new code, but they have enough to do on their personal computer to not need access to newest code immediately.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Money Related&lt;/span&gt;: The relationship with revenue is distant.  Customer satisfaction is undermined so revenue may be hurt in the long run, but it does not immediately impact the bottom line.  Engineering’s idle time may increase costs.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;The criticality of the internal network is higher than most other assets at the company.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 2: VPN Assets At The Same Enterprise Software Company&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Breadth&lt;/span&gt;: People working externally from home office or sales people who are on the road are affected. 15% of the work force is external.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Alternatives&lt;/span&gt;: External people can decide to go to the office, but going to the office is not a viable alternative for most.  Sales people can use the phone.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Urgency&lt;/span&gt;: People working from home have some work to do already on their home computers.  Sales people already have most of their sales materials on their personal computer.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Money Related&lt;/span&gt;: People are idle and productivity is decreasing, so cost is increasing. Revenue loss is unlikely.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;The criticality of the VPN system is high, but not as high as assets for the internal network at this company because breadth of impact is lower.  In terms of the other dimensions, alternatives, urgency, and money related-ness, the two assets might be about the same.  Using this kind of comparison between assets can help you rank order your assets.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 3: Online Shopping Website For An E-Commerce Company&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Breadth&lt;/span&gt;: Your organization as a whole is affected.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Alternatives&lt;/span&gt;: Your organization does not offer other ways customers can place orders.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Urgency&lt;/span&gt;:  Although some loyal customers will wait for your service to recover, most will buy elsewhere.  Every minute of downtime means that you lose revenue.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Money Related&lt;/span&gt;: This asset is directly related to your organization’s ability to generate revenue.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;The criticality of assets that support the online shopping site is very high for this organization.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;You now have an approach to rank order assets by criticality.&lt;br /&gt;&lt;br /&gt;Creating a rough rank ordered list is a good exercise for you and your team.  Once you have reviewed your critical assets with the above approach, your team will have an opinion about which assets are more important than others, and use this as one factor in prioritizing the implementation of security measures.&lt;br /&gt;&lt;br /&gt;You will inevitably change your mind about the ranking as you rethink the answers to the four questions and something new occurs to you.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/6-gradations-of-sensitivity.html"&gt;Article 6: Gradations of Sensitivity&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-1045536946717162422?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/1045536946717162422/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/5-gradations-of-criticality.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/1045536946717162422'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/1045536946717162422'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/5-gradations-of-criticality.html' title='5: Gradations of Criticality'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_hJKVQaajsug/Sk0jWNUF4II/AAAAAAAAABU/jHV3D0L13UU/s72-c/Focus+Sensitive+Assets.bmp' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-3154998785609478451</id><published>2009-07-02T14:09:00.000-07:00</published><updated>2009-07-21T18:39:53.521-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SOX'/><category scheme='http://www.blogger.com/atom/ns#' term='network'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='computer'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI'/><category scheme='http://www.blogger.com/atom/ns#' term='sensitive'/><category scheme='http://www.blogger.com/atom/ns#' term='confidentiality'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='assets'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='critical'/><category scheme='http://www.blogger.com/atom/ns#' term='framework'/><category scheme='http://www.blogger.com/atom/ns#' term='vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='integrity'/><category scheme='http://www.blogger.com/atom/ns#' term='availability'/><title type='text'>4:  Using the CyberSecurity Framework to Understand PCI, HIPAA, SOX</title><content type='html'>&lt;span style="font-weight: bold;font-size:130%;" &gt;Introduction&lt;/span&gt;&lt;br /&gt;The CyberSecurity Framework can help us more easily understand the thrust of PCI, HIPAA, or SOX in the IT universe.&lt;br /&gt;&lt;br /&gt;Let’s review the “Goals” and “Where” of the CyberSecurity Framework.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;Goals – Three Security Goals&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;There are three security goals:&lt;br /&gt;&lt;br /&gt;1.    Availability of IT Resources&lt;br /&gt;2.    Data Integrity&lt;br /&gt;3.    Data Confidentiality&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;Where – Sensitive and Critical Assets&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;There are two important asset characteristics: criticality and sensitivity.  Unavailability of critical assets disrupts your business. Sensitive assets contain sensitive information.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;PCI, HIPAA, SOX&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;The CyberSecurity Framework can help us more easily understand the thrust of PCI, HIPAA, and SOX.  The following explanation is NOT meant to be a complete explanation, but an explanation of the IT security component of compliance.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;PCI&lt;/span&gt;&lt;br /&gt;PCI requires security measures to protect the confidentiality of payment card information.  Assets that contain payment card information are sensitive assets that must be protected against theft.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HIPAA&lt;/span&gt;&lt;br /&gt;HIPAA requires security measures to protect the availability, integrity, and confidentiality of “protected health information” or PHI.  Assets that contain PHI are sensitive assets that require security measures.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;SOX&lt;/span&gt;&lt;br /&gt;SOX requires accurate financial performance reporting.  It holds executives responsible for the accuracy of their financial reports; they can go to jail for approving bad reports.  Protecting the integrity of financial data is therefore important.  Assets that contain financial data are sensitive assets that must be protected against tampering.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Now you can see that understanding IT security helps you better understand compliance requirements.  If you understand security measures that address IT security goals, then you will have an easier time understanding the measures necessary to achieve compliance.  PCI will pivot around payment card information, HIPAA will pivot around PHI, and SOX will pivot around financial data; however, each will use similar security principles to safeguard data.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/5-gradations-of-criticality.html"&gt;Article 5: Gradations of Criticality&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-3154998785609478451?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/3154998785609478451/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/4-using-cybersecurity-framework-to.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/3154998785609478451'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/3154998785609478451'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/4-using-cybersecurity-framework-to.html' title='4:  Using the CyberSecurity Framework to Understand PCI, HIPAA, SOX'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-5699015961916919427</id><published>2009-07-02T14:02:00.000-07:00</published><updated>2009-07-05T19:25:39.616-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='network'/><category scheme='http://www.blogger.com/atom/ns#' term='identify'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='protect'/><category scheme='http://www.blogger.com/atom/ns#' term='confidentiality'/><category scheme='http://www.blogger.com/atom/ns#' term='assets'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='safeguard'/><category scheme='http://www.blogger.com/atom/ns#' term='framework'/><category scheme='http://www.blogger.com/atom/ns#' term='how to identify sensitive assets'/><category scheme='http://www.blogger.com/atom/ns#' term='integrity'/><category scheme='http://www.blogger.com/atom/ns#' term='what are sensitive assets'/><title type='text'>3: “Where” of the CyberSecurity Framework – Sensitive Assets</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Focus of This Article&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_hJKVQaajsug/Sk0g18gzgJI/AAAAAAAAABE/xLNvcwIbJzQ/s1600-h/Focus+Sensitive+Assets.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 292px;" src="http://2.bp.blogspot.com/_hJKVQaajsug/Sk0g18gzgJI/AAAAAAAAABE/xLNvcwIbJzQ/s400/Focus+Sensitive+Assets.bmp" alt="" id="BLOGGER_PHOTO_ID_5353971643162263698" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Introduction&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;This article focuses on sensitive assets of the CyberSecurity Framework.  Reading this article should help you identify your organization’s critical assets, assets you must safeguard.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_hJKVQaajsug/Sk0hORatsuI/AAAAAAAAABM/oVI1ud3wr3M/s1600-h/Identify+Sensitive+Assets.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://2.bp.blogspot.com/_hJKVQaajsug/Sk0hORatsuI/AAAAAAAAABM/oVI1ud3wr3M/s400/Identify+Sensitive+Assets.bmp" alt="" id="BLOGGER_PHOTO_ID_5353972061090722530" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Identifying Sensitive Assets of Your Organization&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Sensitive assets such as databases, applications, and file servers contain sensitive information.  Security measures to safeguard data integrity and data confidentiality apply to sensitive assets.&lt;br /&gt;&lt;br /&gt;Each organization will regard different data as sensitive.  Examples of sensitive information are usernames/password pairs, credit card numbers and personal identity information.  Username and password pairs provide thieves with unauthorized access to accounts. Credit card numbers can be abused to make purchases on someone else’s dime.  People can commit identity theft with people’s identity information.&lt;br /&gt;&lt;br /&gt;There are three types of sensitive information:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Information that is inherent to the operation of your IT infrastructure.  Information such as username and password pairs can open unauthorized access to resources.  Configuration information can be altered to harm operations.  An internal network map can help hackers navigate your network.&lt;/li&gt;&lt;li&gt;Information tied to individuals such as credit card numbers and identity information that can be used for identity theft.&lt;/li&gt;&lt;li&gt;Information tied to the organization such as financial data, source code, strategy documents, and military intelligence.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Sensitive information differs across organizations.  For instance, a software company should regard its source code as sensitive.  The military should regard its top-secret information as sensitive.&lt;br /&gt;&lt;br /&gt;To identify your organization’s sensitive assets, you should ask yourself the question, “What information, if stolen or altered, can bring harm to people including employees, customers, and investors, and to the wellbeing of my business?”&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Examples of Sensitive Assets&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Walking through more examples can help you identify sensitive information of your organization.  Sensitive assets contain sensitive information.  The list is not meant to be complete.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 1:  Any Company&lt;/span&gt;&lt;br /&gt;Human resources data can include social security numbers, bank account numbers, and other employee information. This data is sensitive and its confidentiality must be protected because it can be used identity theft.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 2: Tax Paying/Public Company&lt;/span&gt;&lt;br /&gt;Accounting data is sensitive because organizations have to report their earnings to file corporate taxes.  Public companies must report its financial performance to its investors.  You must protect the integrity of accounting data so that your organization files taxes correctly and accurately reports earnings to investors.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 3: E-Commerce/Online Payment Company&lt;/span&gt;&lt;br /&gt;Many e-commerce/payment businesses store customer information such as name, web email address, password, physical address, credit card numbers, and bank account numbers.  The confidentiality of customer data must be safeguarded.  Since users often use a single password for all their accounts, the password for an e-commerce account may provide a thief with access to the customer’s email account too.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 4: Computer Chip Company&lt;/span&gt;&lt;br /&gt;Some information must be safeguarded for the well-being of your organization.  For instance, the confidentiality of a new chip design must be safeguarded so no competitor can copy your work.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 5:  B2B Company&lt;/span&gt;&lt;br /&gt;A B2B company’s clientele information is sensitive because competitors can use this information to steal customers away from you.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Identifying sensitive information helps identify sensitive assets that require safeguards.  These assets are focal points of your security program.&lt;br /&gt;&lt;br /&gt;The above examples show different types of sensitive data; some examples probably don’t apply to you.  However, you can think of parallels to the above example that are unique to your organization.  You should be able to compile a list of sensitive information and assets of your organization.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/4-using-cybersecurity-framework-to.html"&gt;Article 4:  Using the CyberSecurity Framework to Understand PCI, HIPAA, SOX&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-5699015961916919427?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/5699015961916919427/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/3-where-of-cybersecurity-framework.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/5699015961916919427'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/5699015961916919427'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/3-where-of-cybersecurity-framework.html' title='3: “Where” of the CyberSecurity Framework – Sensitive Assets'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_hJKVQaajsug/Sk0g18gzgJI/AAAAAAAAABE/xLNvcwIbJzQ/s72-c/Focus+Sensitive+Assets.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-8584577944695143561</id><published>2009-07-02T13:56:00.000-07:00</published><updated>2009-07-05T19:24:49.027-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='network'/><category scheme='http://www.blogger.com/atom/ns#' term='identify'/><category scheme='http://www.blogger.com/atom/ns#' term='user'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='protect'/><category scheme='http://www.blogger.com/atom/ns#' term='assets'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='safeguard'/><category scheme='http://www.blogger.com/atom/ns#' term='critical'/><category scheme='http://www.blogger.com/atom/ns#' term='framework'/><category scheme='http://www.blogger.com/atom/ns#' term='what are my critical assets'/><category scheme='http://www.blogger.com/atom/ns#' term='how to identify critical assets'/><category scheme='http://www.blogger.com/atom/ns#' term='availability'/><title type='text'>2: “Where” of the CyberSecurity Framework – Critical Assets</title><content type='html'>&lt;span style="font-weight: bold;font-size:130%;" &gt;Focus of This Article&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_hJKVQaajsug/Sk0fc3sB7PI/AAAAAAAAAA0/vpeXQPhfRYs/s1600-h/Focus+Critical+Assets.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 291px;" src="http://4.bp.blogspot.com/_hJKVQaajsug/Sk0fc3sB7PI/AAAAAAAAAA0/vpeXQPhfRYs/s400/Focus+Critical+Assets.bmp" alt="" id="BLOGGER_PHOTO_ID_5353970112858811634" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Introduction&lt;/span&gt;&lt;br /&gt;This article focuses on critical assets of the CyberSecurity Framework.  Reading this article should help you identify your organization’s critical assets, assets you must safeguard.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_hJKVQaajsug/Sk0fiSkYXfI/AAAAAAAAAA8/Tt8BB76NUUI/s1600-h/Identify+Critical+Assets.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://1.bp.blogspot.com/_hJKVQaajsug/Sk0fiSkYXfI/AAAAAAAAAA8/Tt8BB76NUUI/s400/Identify+Critical+Assets.bmp" alt="" id="BLOGGER_PHOTO_ID_5353970205973831154" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Identifying Critical Assets of Your Organization&lt;/span&gt;&lt;br /&gt;The unavailability of critical assets disrupts your organization’s operations.  Security measures to safeguard availability apply to critical assets.&lt;br /&gt;&lt;br /&gt;Each organization has different critical assets because each organization is different.  A healthcare provider that uses only electronic medical records [EMR] and no paper records should regard its EMR system as critical because the unavailability of this system can obstruct the treatment of patients.&lt;br /&gt;&lt;br /&gt;If the web servers of an e-commerce site are unavailable, customers cannot buy products on the site.  Since customers can buy from another vendor, unavailability can mean lost revenue.  Any subsystem that supports the proper operation of the e-commerce site is a critical asset.&lt;br /&gt;&lt;br /&gt;To identify your critical assets, you should ask yourself, “The unavailability of which assets would cause my organization to feel immediate pain? … would hurt my organization in terms of decreased revenue or increased cost?  … would hurt my money making capability?  … would hurt my employees’ productivity?  … would block the way my organization gets its work done?”&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Examples of Critical Assets&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Walking through more examples can help you identify critical assets of your organization.  The list is not meant to be complete.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 1: Any Company&lt;/span&gt;&lt;br /&gt;It’s hard to imagine a productive work environment without network connectivity.  Network connectivity includes: connectivity of internal people to internal computing resources or to the Internet. It can also include connectivity of your mobile sales people to your internal computing resources.  The network assets that support these connections are critical.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 2: Any Company&lt;/span&gt;&lt;br /&gt;Your email server is probably a critical asset.  Many people in your organization rely on email to communicate and get things done.  Most emails might not need immediate attention but some may be urgent.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 3:  Stock Trading Firm&lt;/span&gt;&lt;br /&gt;The unavailability of a stock trading system for a few minutes may have large negative consequences to your business because you cannot perform trades that support your bottom line.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Example 4: Cell Phone Company&lt;/span&gt;&lt;br /&gt;The unavailability of a CRM system may render your organization incapable of serving customers who call in for help.  The data in the CRM system is critical because losing historical records of your customers will undermine the well-being of your business.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Critical assets are focal points of your security program.&lt;br /&gt;&lt;br /&gt;The examples above should help you identify your organization’s unique set of critical assets and compile a list.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/3-where-of-cybersecurity-framework.html"&gt;Article 3: “Where” of the CyberSecurity Framework – Sensitive Assets&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-8584577944695143561?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/8584577944695143561/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/2-where-of-cybersecurity-framework.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/8584577944695143561'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/8584577944695143561'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/2-where-of-cybersecurity-framework.html' title='2: “Where” of the CyberSecurity Framework – Critical Assets'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_hJKVQaajsug/Sk0fc3sB7PI/AAAAAAAAAA0/vpeXQPhfRYs/s72-c/Focus+Critical+Assets.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-2785578990004939280</id><published>2009-07-02T13:34:00.000-07:00</published><updated>2009-07-05T19:10:27.188-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='network'/><category scheme='http://www.blogger.com/atom/ns#' term='user'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojan horse'/><category scheme='http://www.blogger.com/atom/ns#' term='confidentiality'/><category scheme='http://www.blogger.com/atom/ns#' term='sensitive'/><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='assets'/><category scheme='http://www.blogger.com/atom/ns#' term='safeguard'/><category scheme='http://www.blogger.com/atom/ns#' term='critical'/><category scheme='http://www.blogger.com/atom/ns#' term='cubersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='integrity'/><category scheme='http://www.blogger.com/atom/ns#' term='availability'/><title type='text'>1: Defining the Landscape of IT Security Issues - The CyberSecurity Framework</title><content type='html'>&lt;span style="font-weight: bold;font-size:130%;" &gt;Introduction&lt;/span&gt;&lt;br /&gt;This article describes a framework that IT professionals can use to navigate the landscape of IT security issues.&lt;br /&gt;&lt;br /&gt;This framework defines:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Goals – Bad things that should be prevented&lt;/li&gt;&lt;li&gt;Where - Where bad things can happen &lt;/li&gt;&lt;li&gt;Who - Who can do bad things&lt;/li&gt;&lt;li&gt;What - “Non-people” things can do bad things&lt;/li&gt;&lt;/ol&gt; &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_hJKVQaajsug/Sk0aqa5wVGI/AAAAAAAAAAU/Hhokntqr0Mw/s1600-h/CyberSecurity+Framework+Top+Level+View.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://1.bp.blogspot.com/_hJKVQaajsug/Sk0aqa5wVGI/AAAAAAAAAAU/Hhokntqr0Mw/s400/CyberSecurity+Framework+Top+Level+View.bmp" alt="" id="BLOGGER_PHOTO_ID_5353964848091780194" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Goals – Three Security Goals&lt;/span&gt;&lt;br /&gt;Many organizations share the following common goals:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Availability of IT Resources&lt;/li&gt;&lt;li&gt;Data Integrity&lt;/li&gt;&lt;li&gt;Data Confidentiality&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Below are examples of failures in each.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Examples of Availability Failures:&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Crashed email system hurts employee productivity.&lt;/li&gt;&lt;li&gt;Inoperative internal network prevents completion of backups undermining disaster recovery.&lt;/li&gt;&lt;li&gt;Downed web servers of e-commerce site prevent customers from making purchases and your company from earning revenue.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Examples of Data Integrity Failures:&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Falsified financial data misrepresents your company’s financial performance.&lt;/li&gt;&lt;li&gt;Modified patient records under/overcharge insurance companies.&lt;/li&gt;&lt;li&gt;Modified source code library leaves a security hole in enterprise software product.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Examples of Data Confidentiality Failures:&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Credit card numbers are stolen from e-commerce website.&lt;/li&gt;&lt;li&gt;Design for new IC chip is stolen. &lt;/li&gt;&lt;li&gt;Stolen patient records betray patient privacy.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Where – Spaces and Assets&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Physical and Logical Space&lt;/span&gt;&lt;br /&gt;“Bad things” can happen in two different spaces: the physical space and the logical space.&lt;br /&gt;Physical space refers to the physical world.  Logical space refers to the world inside networks and computers, the world of user accounts, passwords, and databases.&lt;br /&gt;&lt;br /&gt;An example of a security incident in the physical space is someone physically stealing a computer.  An example of a security incident in the logical space is someone breaking into a database account over the network and stealing confidential information.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Types of Physical Spaces&lt;/span&gt;&lt;br /&gt;There are three types of physical spaces:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Outside.  Everyone can be outside. &lt;/li&gt;&lt;li&gt;Your organization’s office area.  It holds people’s personal computers and media.  Within the general office area, your organization’s internal network can be accessed.&lt;/li&gt;&lt;li&gt;Your organization’s equipment room.  It houses network equipment and shared computing resources.&lt;/li&gt;&lt;/ol&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_hJKVQaajsug/Sk0azFEDT1I/AAAAAAAAAAc/zHBrXTVohgg/s1600-h/CyberSecurity+Framework+Physical+Space.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://3.bp.blogspot.com/_hJKVQaajsug/Sk0azFEDT1I/AAAAAAAAAAc/zHBrXTVohgg/s400/CyberSecurity+Framework+Physical+Space.bmp" alt="" id="BLOGGER_PHOTO_ID_5353964996848209746" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Only select people can enter the office and even fewer are permitted to enter the equipment room.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Types of Assets in the Logical Space&lt;/span&gt;&lt;br /&gt;There are three classes of assets in the logical space.&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Network Equipment &lt;/li&gt;&lt;li&gt;Shared Computing Resources including OS and software that reside on hardware&lt;/li&gt;&lt;li&gt;Personal Computing Resources such as desktops and laptops&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;It is helpful to distinguish each class because their usage characteristics differ and their surrounding security issues differ.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Two Asset Characteristics&lt;/span&gt;&lt;br /&gt;There are two important asset characteristics: criticality and sensitivity.  Unavailability of critical assets disrupts your organization’s operation.  Sensitive assets contain sensitive information.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_hJKVQaajsug/Sk0a7oHLCvI/AAAAAAAAAAk/6eFrk58tAdY/s1600-h/CyberSecurity+Framework+Logical+Space.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://1.bp.blogspot.com/_hJKVQaajsug/Sk0a7oHLCvI/AAAAAAAAAAk/6eFrk58tAdY/s400/CyberSecurity+Framework+Logical+Space.bmp" alt="" id="BLOGGER_PHOTO_ID_5353965143695493874" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Examples of Critical Assets&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;You run an online stock trading business.  If your web servers crash, your customers cannot trade.  Your web servers are critical.&lt;/li&gt;&lt;li&gt;Your email servers go down.  Your employees cannot send/receive email.  Productivity is hurt.  Email servers are critical.&lt;/li&gt;&lt;li&gt;Your domain controllers go down and your employees cannot log into the network.  Productivity is hurt.  DC’s are critical.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Examples of Sensitive Assets&lt;/span&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;You have a public company.  The database containing your financial data is sensitive because if someone falsifies financial data, you are misrepresenting your financial performance.&lt;/li&gt;&lt;li&gt;You run a healthcare provider.  The database containing your patient identity information is sensitive because patient privacy must be protected.&lt;/li&gt;&lt;li&gt;You run a chip design company.  The database holding the blueprints for the latest chip designs is sensitive. &lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Assets can be both critical and sensitive.  For example, the unavailability of an electronic medical record system [EMR] can hurt a doctor’s ability to treat patients and the system contains sensitive patient information.  In this case, the EMR system is both critical and sensitive.&lt;br /&gt;&lt;br /&gt;Critical and sensitive assets should be the focal points of your security measures.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Who – People&lt;/span&gt;&lt;br /&gt;People are one cause of “bad things.”&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_hJKVQaajsug/Sk0bDlY4CAI/AAAAAAAAAAs/PVU_2JOB3xw/s1600-h/CyberSecurity+Framework+Who.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://2.bp.blogspot.com/_hJKVQaajsug/Sk0bDlY4CAI/AAAAAAAAAAs/PVU_2JOB3xw/s400/CyberSecurity+Framework+Who.bmp" alt="" id="BLOGGER_PHOTO_ID_5353965280403392514" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Distinguishing different groups of people in your organization is important because their surrounding security issues differ.&lt;br /&gt;&lt;br /&gt;The first set of characteristics distinguishes people by their physical location and their logical “status.”&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;External vs. Internal:&lt;/span&gt;  People who work physically outside your premises vs. people who work inside.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Trusted vs. Untrusted: &lt;/span&gt; People who have accounts on computing resources vs. people who don’t.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Administrator vs. Non-Administrator:&lt;/span&gt;  People who are empowered with special privileges vs. people who are not.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;A major security issue with untrusted users is allowing only the right people to become trusted users.  For example, someone in the sales department can be mistakenly provided an account on a finance system although only people in the finance department should have access.&lt;br /&gt;&lt;br /&gt;A major security issue with trusted users, especially administrators, is detecting the misuse of their privileges.  An administrator responsible for maintaining a database can abuse his privileges and query out social security numbers from the database although he is not supposed to.&lt;br /&gt;&lt;br /&gt;The following second set of characteristics defines people’s “business roles.”  Depending on their business role, they will have access to different assets, and therefore, different security measures will apply.&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Full Time Employee:  People who are full time employees.&lt;/li&gt;&lt;li&gt;Customers:  People who use your computing resources as customers.&lt;/li&gt;&lt;li&gt;Partners:  People who access your computing resources as partners.&lt;/li&gt;&lt;li&gt;Consultants/Contractors: People who are not full time employees, but work for you.&lt;/li&gt;&lt;li&gt;Accounting, Sales, Engineering, Human Resource, etc.: People from different departments have access to different assets.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;Combinations of characteristics can apply to a single person.  Someone can be a trusted/internal full time employee with administrative powers who works for the finance department.&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;&lt;br /&gt;What –  Non-People Related Dangers&lt;/span&gt;&lt;br /&gt;Non-people things can cause “bad things” to happen.  There are programmatic threats such as viruses, worms, and other malware that can undermine availability, data integrity and data confidentiality. Denial of service attacks also fall into this non-people category.&lt;br /&gt;&lt;br /&gt;Vulnerabilities within your software are another danger.  Vulnerabilities open opportunities for people and non-people to exploit and compromise availability, integrity, and confidentiality.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Conclusion&lt;/span&gt;&lt;br /&gt;We now have a framework for discussing security issues.  You know your goals, where you should focus, and who/what to protect against.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/2-where-of-cybersecurity-framework.html"&gt;Article 2: “Where” of the CyberSecurity Framework – Critical Assets&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-2785578990004939280?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/2785578990004939280/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/article-1-defining-landscape-of-it.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/2785578990004939280'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/2785578990004939280'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/article-1-defining-landscape-of-it.html' title='1: Defining the Landscape of IT Security Issues - The CyberSecurity Framework'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_hJKVQaajsug/Sk0aqa5wVGI/AAAAAAAAAAU/Hhokntqr0Mw/s72-c/CyberSecurity+Framework+Top+Level+View.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-2913057446089426940</id><published>2009-07-02T13:33:00.000-07:00</published><updated>2009-07-05T19:11:20.803-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='computers'/><category scheme='http://www.blogger.com/atom/ns#' term='network'/><category scheme='http://www.blogger.com/atom/ns#' term='user'/><category scheme='http://www.blogger.com/atom/ns#' term='worm'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojan horse'/><category scheme='http://www.blogger.com/atom/ns#' term='confidentiality'/><category scheme='http://www.blogger.com/atom/ns#' term='sensitive'/><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='assets'/><category scheme='http://www.blogger.com/atom/ns#' term='safeguard'/><category scheme='http://www.blogger.com/atom/ns#' term='critical'/><category scheme='http://www.blogger.com/atom/ns#' term='framework'/><category scheme='http://www.blogger.com/atom/ns#' term='vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='integrity'/><category scheme='http://www.blogger.com/atom/ns#' term='availability'/><title type='text'>PART 1: UNDERSTANDING THE CYBERSECURITY FRAMEWORK</title><content type='html'>This part covers the CyberSecurity Framework, a framework that helps you view your IT landscape in terms of security issues.  In the same way an army general must understand his terrain, the places he must protect, and his enemies when defending his territory, the IT professional must understand what he must protect and threats to his IT infrastructure.  This part helps you identify your most important IT assets and threats that endanger their well-being.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/article-1-defining-landscape-of-it.html"&gt;Article 1: Defining the Landscape of IT Security Issues - The CyberSecurity Framework&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-2913057446089426940?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/2913057446089426940/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/part-1-understanding-cybersecurity.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/2913057446089426940'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/2913057446089426940'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/part-1-understanding-cybersecurity.html' title='PART 1: UNDERSTANDING THE CYBERSECURITY FRAMEWORK'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-5124892713755031024</id><published>2009-07-02T13:29:00.000-07:00</published><updated>2009-07-23T15:50:15.926-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='how'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='SOX'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='ISO'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='NIST'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI'/><category scheme='http://www.blogger.com/atom/ns#' term='COBIT'/><title type='text'>Table of Contents</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/terms-of-use.html"&gt;Terms of Use&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/purpose-of-this-book.html"&gt;The Purpose of This Book&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/part-1-understanding-cybersecurity.html"&gt;Part 1: Understanding the CyberSecurity Framework&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/article-1-defining-landscape-of-it.html"&gt;Article 1: Defining the Landscape of IT Security Issues - The CyberSecurity Framework&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/2-where-of-cybersecurity-framework.html"&gt;Article 2: “Where” of the CyberSecurity Framework – Critical Assets&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/3-where-of-cybersecurity-framework.html"&gt;Article 3: “Where” of the CyberSecurity Framework – Sensitive Assets&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/4-using-cybersecurity-framework-to.html"&gt;Article 4:  Using the CyberSecurity Framework to Understand PCI, HIPAA, SOX&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/5-gradations-of-criticality.html"&gt;Article 5: Gradations of Criticality&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/6-gradations-of-sensitivity.html"&gt;Article 6: Gradations of Sensitivity&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/7-who-of-cybersecurity-framework.html"&gt;Article 7: “Who” of the CyberSecurity Framework&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/part-2-security-measures.html"&gt;Part 2: Security Measures&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/8-types-of-security-measures.html"&gt;Article 8:  Types of Security Measures&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/9-themes-of-design-security-measures.html"&gt;Article 9: Themes of “Design” Security Measures&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/10-themes-of-maintainmonitor-security.html"&gt;Article 10: Themes of “Maintain/Monitor” Security Measures&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/focus-of-this-article-introduction-this.html"&gt;Article 11: Themes of “Reaction Plan” Security Measures &lt;/a&gt;&lt;/span&gt;   &lt;/li&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/12-security-measures-for-what-of.html"&gt;Article 12: Security Measures for “What” of the CyberSecurity Framework&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/13-security-measures-for-physical-space.html"&gt;Article 13: Security Measures for Physical Space of CyberSecurity Framework&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/14-routes-in-logical-space-to.html"&gt;Article 14:  Routes in Logical Space to Compromise of Availability, Integrity, Confidentiality&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/15-routes-to-acquiring-accounts.html"&gt;Article 15:  Routes to Acquiring Accounts – External Users and Security Measures&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/16-routes-to-acquiring-accounts.html"&gt;Article 16:  Routes to Acquiring Accounts – Internal Users and Security Measures&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/17-security-measures-for-accounts.html"&gt;Article 17: Security Measures for Accounts Management&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/18-security-measures-for-availability.html"&gt;Article 18: Security Measures for Availability&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/19-security-measures-for-integrity.html"&gt;Article 19: Security Measures for Integrity&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/20-security-measures-for.html"&gt;Article 20: Security Measures for Confidentiality&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/part-3-compliance.html"&gt;Part 3: Compliance&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/21-pci-data-security-standard.html"&gt;&lt;span style="font-size:130%;"&gt;Article 21: PCI DSS - Payment Card Industry Data Security Standard&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/22-hipaa-health-insurance-portability.html"&gt;&lt;span style="font-size:130%;"&gt;Article 22: HIPAA - Health Insurance Portability and Accountability Act&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/23-other-compliance-standards-sox-and.html"&gt;&lt;span style="font-size:130%;"&gt;Article 23: Other Compliance Standards: SOX and NERC&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/final-words-on-cybersecurity.html"&gt;Final Words on CyberSecurity&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-5124892713755031024?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/5124892713755031024/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/5124892713755031024'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/5124892713755031024'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html' title='Table of Contents'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-5537452259550301025</id><published>2009-07-02T13:22:00.000-07:00</published><updated>2009-07-05T19:50:54.982-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SOX'/><category scheme='http://www.blogger.com/atom/ns#' term='basics of'/><category scheme='http://www.blogger.com/atom/ns#' term='ISO'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='practical guide'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Governance'/><category scheme='http://www.blogger.com/atom/ns#' term='network monitoring'/><category scheme='http://www.blogger.com/atom/ns#' term='application monitoring'/><category scheme='http://www.blogger.com/atom/ns#' term='COBIT'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='HIPAA'/><category scheme='http://www.blogger.com/atom/ns#' term='what is'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersecurity'/><category scheme='http://www.blogger.com/atom/ns#' term='made easy'/><category scheme='http://www.blogger.com/atom/ns#' term='how to'/><category scheme='http://www.blogger.com/atom/ns#' term='NIST'/><title type='text'>The Purpose of This Book</title><content type='html'>This book is for IT security professionals who have tried to use ISO 27002, COBIT 4, NIST SP 800-53, or compliance standards to start an IT security program but found them too generic and abstract to get started.  This book fills the gap between those standards and specialized materials that detail security measures specific to malware, hackers, Unix boxes, Windows boxes, firewalls, web applications, and others.&lt;br /&gt;&lt;br /&gt;I wrote this book with examples to help you understand security issues that may apply to your organization.  This book presents security measures in context so you can apply security measures in the right place for the right purpose.&lt;br /&gt;&lt;br /&gt;An understanding of IT security will ease your understanding of compliance standards in the IT context because they – in a nutshell –  require the implementation of IT security measures to safeguard particular kinds of data.  Therefore, IT security is covered first and compliance second.&lt;br /&gt;&lt;br /&gt;Many books and Internet resources detail specific IT security measures.  My goal is not to replicate those materials.  My goal is to help you build enough of an understanding of IT security so you can identify the security needs of your organization and know what specialized information you should pursue further.&lt;br /&gt;&lt;br /&gt;Each article builds on ideas presented in earlier articles, so reading them in order and treating each article as a lesson will help you get the most out of this book.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_hJKVQaajsug/Sk0Xa9Vba1I/AAAAAAAAAAM/VBjj-QnxSO8/s1600-h/Purpose+of+Book.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 297px;" src="http://2.bp.blogspot.com/_hJKVQaajsug/Sk0Xa9Vba1I/AAAAAAAAAAM/VBjj-QnxSO8/s400/Purpose+of+Book.bmp" alt="" id="BLOGGER_PHOTO_ID_5353961283921865554" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Next Article:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/part-1-understanding-cybersecurity.html"&gt;Part 1: Understanding the CyberSecurity Framework&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;!-- AddThis Button BEGIN --&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a name="data:post.title" id="data:post.url" onmouseover="'return" onmouseout="addthis_close()" onclick="return addthis_sendto()"&gt;&lt;img src="http://s7.addthis.com/static/btn/lg-bookmark-en.gif" alt="Bookmark and Share" style="border: 0pt none ;" height="16" width="125" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;script type="text/javascript" src="http://s7.addthis.com/js/250/addthis_widget.js?pub=xa-4a4e84d17003e883"&gt;&lt;/script&gt;&lt;/div&gt;&lt;br /&gt;&lt;!-- AddThis Button END --&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-5537452259550301025?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/5537452259550301025/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/purpose-of-this-book.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/5537452259550301025'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/5537452259550301025'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/purpose-of-this-book.html' title='The Purpose of This Book'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_hJKVQaajsug/Sk0Xa9Vba1I/AAAAAAAAAAM/VBjj-QnxSO8/s72-c/Purpose+of+Book.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-4328018118321824482.post-8437155706570913998</id><published>2009-07-02T13:21:00.001-07:00</published><updated>2009-07-05T19:49:18.847-07:00</updated><title type='text'>Terms of Use</title><content type='html'>The frameworks and ideas presented in this book are intended for use by organizations that seek guidance for starting their own IT security programs.&lt;br /&gt;&lt;br /&gt;They are not intended to serve commercial interests of any software and hardware vendor whatsoever without the written consent of the author.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Go to:&lt;/span&gt; &lt;a href="http://cybersecurityhelp.blogspot.com/2009/07/table-of-contents.html"&gt;Table of Contents&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4328018118321824482-8437155706570913998?l=cybersecurityhelp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cybersecurityhelp.blogspot.com/feeds/8437155706570913998/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/terms-of-use.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/8437155706570913998'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4328018118321824482/posts/default/8437155706570913998'/><link rel='alternate' type='text/html' href='http://cybersecurityhelp.blogspot.com/2009/07/terms-of-use.html' title='Terms of Use'/><author><name>Peter Y. Kim</name><uri>http://www.blogger.com/profile/02882146823040287194</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='21' src='http://2.bp.blogspot.com/_hJKVQaajsug/Sk1Xnnp8c3I/AAAAAAAAAFY/OvC6F-7jMR8/S220/Bismarck+Memorial+02.jpg'/></author><thr:total>0</thr:total></entry></feed>
