Managing IT Security

INFO420: Managing the IT Function


Information Security    

The Threats
Scope of Security Management
Security’s Five Pillars
Tools for Computer Security 

Business Continuity

Information Security  Information security is more than just protecting hardware and software from being crashed…  It's about protecting the information resources that keep the company operating  Goals are to ensure:   Data integrity, availability and confidentiality Business continuity

Threats from outside…

Common Attacks - Personal  Spoofing: Masquerade as a legitimate web site and redirect traffic to a fraudulent site  Con artists: calling to offer credit card account to obtain info about email, SSN, or credit card information  Denial of Service: Attacks from coordinated computers that floods a site with so many requests until the site crashes > Thousands of page requests/minute on an ecommerce site (virus as well)

Common Attacks - Corporate  Virus/Worm: A computer program that appears to perform a legitimate task, but is a hidden malware > E.g. copy passwords, wipe out a hard drive, send out an unauthorized email, etc. > Samy  Sniffing: Interception and reading of electronic messages as they travel over the Internet > E.g.  Phishing or Fishing: Fraudulent email attempt to obtain sensitive information > E.g. email notifying a bank account owner that s/he account had a security breach, and request the owner to log in a fraudulent website to "reset the password"

Threats from inside…  Employee illegally accesses email accounts  Angry / misguided technical personnel:    Deletes sensitive data Rewrites a program so data is corrupted/company can't operate Leaves a 'cyber bomb' that detonates in the event he/she is fired  Employee steals sensitive data (customer) and sells it to a competitor

Many dimensions of security      Data security Application and OS security Network security Facility security Egress security should be enforced

Catch me if you can…  Why are criminals able to carry out identity theft?  What can credit card companies due to prevent this?  Individuals?

Security's Five Pillars  Authentication: Verifying the authenticity of users – ensuring people are who they say they are. > ID/Password, biometric, questions  Identification: Identifying users to grant them appropriate access > Allowing system to know who someone is to give appropriate access rights  Privacy: Protecting information from being seen > E.g. against spyware installed without consent in a computer to collect information

Security Five Pillars  Integrity: Keeping information in its original form > Ensuring data is not altered in any way  Non-repudiation: Preventing parties from denying actions they have taken > Ensuring that the parties in a transaction are who they say they are and cannot deny that transaction took place

Technical Countermeasures  Firewalls:  hardware/software to control access between networks / blocking unwanted access > Windows Vista  Encryption/decryption:  Using an algorithm (cipher) to make a plain text unreadable to anyone that does not have a key > SSL

Technical Countermeasures  Virtual Private Networks (VPNs)   Allow strong protection for data communications Cheaper than private networks, but do not provide 100% end-to-end security

Encryption / SSL  An SSL Certificate enables encryption of sensitive information during online transactions.  Each SSL Certificate consists of a public key and a private key.  A Certificate Authority authenticates the server (Web site) and the client (Web browser).  Each SSL Certificate contains unique, authenticated information about the certificate owner when it is issued. Public key: scramble. Private Key: unscramble verifies the identity of the certificate owner  Secure Sockets Layer handshake  Unique session key established and secure transmission can begin.

Business Continuity        Earlier: technical 'disaster recovery' 9/11 and Katrina: 'business continuity' Alternate workspace for people with working computers and communications Backup IT sites (business programs and data) Backup mobile devices with corporate information Up-to-date evacuation plans and drills Disaster recovery support (emergency procedures, etc.)