Managing Information Security
Book information
Description
Managing Information Security offers focused coverage of how to protect mission critical systems, and how to deploy security management systems, IT security, ID management, intrusion detection and prevention systems, computer forensics, network forensics, firewalls, penetration testing, vulnerability assessment, and more. It offers in-depth coverage of the current technology and practice as it relates to information security management solutions. Individual chapters are authored by leading experts in the field and address the immediate and long-term challenges in the authors’ respective areas of expertise. Front Cover Managing Information Security Copyright Page Contents Acknowledgements About the Editor Contributors Introduction Organization of this Book 1. Information Security Essentials for IT Managers 1. Information Security Essentials for it Managers, Overview Scope of Information Security Management CISSP Ten Domains of Information Security What is a Threat? Common Attacks Impact of Security Breaches 2. Protecting Mission-Critical Systems Information Assurance Information Risk Management Administrative, Technical, and Physical Controls Risk Analysis Defense in Depth Contingency Planning An Incident Response (IR) Plan Business Continuity Planning (BCP) 3. Information Security from the Ground Up Physical Security Facility Requirements Administrative, Technical, and Physical Controls Data Security Data Classification Access Control Models Systems and Network Security Host-Based Security Network-Based Security Intrusion Detection Intrusion Prevention Business Communications Security General Rules for Self-Protection Handling Protection Resources Rules for Mobile IT Systems Operation on Open Networks Additional Business Communications Guidelines Wireless Security Access Control Confidentiality Integrity Availability Enhancing Security Controls Web and Application Security Web Security Application Security Security Policies and Procedures Security Employee Training and Awareness The Ten Commandments of SETA 4. Security Monitoring and Effectiveness Security Monitoring Mechanisms Incidence Response and Forensic Investigations Validating Security Effectiveness Vulnerability Assessments and Penetration Tests 5. Summary Chapter Review Questions/Exercises True/False Multiple Choice Exercise Problem Hands-On Projects Project Case Projects Problem Optional Team Case Project Problem 2. Security Management Systems 1. Security Management System Standards 2. Training Requirements 3. Principles of Information Security 4. Roles and Responsibilities of Personnel 5. Security Policies 6. Security Controls 7. Network Access 8. Risk Assessment 9. Incident Response 10. Summary Chapter Review Questions/Exercises True/False Multiple Choice Exercise Problem Hands-On Projects Project Case Projects Problem Optional Team Case Project Problem 3. Information Technology Security Management 1. Information Security Management Standards Federal Information Security Management Act International Standards Organization 2. Other Organizations Involved in Standards 3. Information Technology Security Aspects Security Policies and Procedures Security Organization Structure End User Executive Management Security Officer Data/Information Owners Information System Auditor Information Technology Personnel Systems Administrator IT Security Processes Processes for a Business Continuity Strategy Processes for IT Security Governance Planning Rules and Regulations 4. Summary Chapter Review Questions/Exercises True/False Multiple Choice Exercise Problem Hands-On Projects Project Case Projects Problem Optional Team Case Project Problem 4. Online Identity and User Management Services 1. Introduction 2. Evolution of Identity Management Requirements Digital Identity Definition Identity Management Overview Privacy Requirement User Centricity Usability Requirement 3. The Requirements Fulfilled by Identity Management Technologies Evolution of Identity Management 4. Identity Management 1.0 Silo Model Solution by Aggregation Centralized vs. Federation Identity Management A Simple Centralized Model Meta-Directories Virtual Directories Single-Sign-On (SSO) Federated Identity Management Identity 2.0 Identity 2.0 Initiatives LID XRI/XDI SAML Shibboleth ID-WSF Roadmap to Interoperable Federated Identity Services OpenID 2.0 OpenID Stack Discovery Authentication Data Transport InfoCard SXIP 2.0 Higgins Summarizing Table 5. Social Login and User Management 6. Identity 2.0 for Mobile Users Introduction Mobile Web 2.0 Mobility Evolution of Mobile Identity PDA as Solution to Strong Authentication Different Kinds of Strong Authentication Through a Mobile PDA SMS Based One-Time Password (OTP) Soft Token Application Full Option Mobile Solution Future of Mobile User-Centric Identity Management in an Ambient Intelligence (AmI) World AmI Scenario Requirements for Mobile User-centric Identity Management in an AmI world 7. Summary Chapter Review Questions/Exercises True/False Multiple Choice Exercise Problem Hands-On Projects Project Case Projects Problem Optional Team Case Project Problem References 5. Intrusion Prevention and Detection Systems 1. What is an ‘Intrusion’ Anyway? 2. Physical Theft 3. Abuse of Privileges (The Insider Threat) 4. Unauthorized Access by Outsider 5. Malware Infection 6. The Role of the ‘0-Day’ 7. The Rogue’s Gallery: Attackers and Motives Script Kiddy Joy Rider Mercenary Nation-State Backed 8. A Brief Introduction to TCP/IP 9. The TCP/IP Data Architecture and Data Encapsulation 10. Survey of Intrusion Detection and Prevention Technologies 11. Anti-Malware Software 12. Network-Based Intrusion Detection Systems 13. Network-Based Intrusion Prevention Systems 14. Host-Based Intrusion Prevention Systems 15. Security Information Management Systems 16. Network Session Analysis 17. Digital Forensics 18. System Integrity Validation 19. Summary Chapter Review Questions/Exercises True/False Multiple Choice Exercise Problem Hands-On Projects Project Case Projects Problem Optional Team Case Project Problem References 6. Firewalls 1. Introduction 2. Network Firewalls 3. Firewall Security Policies Rule-Match Policies 4. A Simple Mathematical Model for Policies, Rules, and Packets 5. First-Match Firewall Policy Anomalies 6. Policy Optimization Policy Reordering Combining Rules Default Accept or Deny? 7. Firewall Types Packet Filter Stateful Packet Firewalls Application Layer Firewalls 8. Host and Network Firewalls 9. Software and Hardware Firewall Implementations 10. Choosing the Correct Firewall 11. Firewall Placement and Network Topology Demilitarized Zones Perimeter Networks Two-Router Configuration Dual-Homed Host Network Configuration Summary 12. Firewall Installation and Configuration 13. Supporting Outgoing Services Through Firewall Configuration Forms of State Payload Inspection 14. Secure External Services Provisioning 15. Network Firewalls for Voice and Video Applications Packet Filtering H.323 16. Firewalls and Important Administrative Service Protocols Routing Protocols Internet Control Message Protocol Network Time Protocol Central Log File Management Dynamic Host Configuration Protocol 17. Internal IP Services Protection 18. Firewall Remote Access Configuration 19. Load Balancing and Firewall Arrays Load Balancing in Real Life How to Balance the Load Advantages and Disadvantages of Load Balancing 20. Highly Available Firewalls Load Balancer Operation Interconnection of Load Balancers and Firewalls 21. Firewall Management 22. Summary Chapter Review Questions/Exercises True/False Multiple Choice Exercise Problem Hands-On Projects Project Case Projects Problem Optional Team Case Project Problem 7. Penetration Testing 1. Introduction 2. What is Penetration Testing? 3. How Does Penetration Testing Differ from an Actual “Hack?” 4. Types of Penetration Testing 5. Phases of Penetration Testing The Pre-Attack Phase The Attack Phase The Post-Attack Phase 6. Defining What’s Expected 7. The Need for a Methodology 8. Penetration Testing Methodologies 9. Methodology in Action EC-Council LPT Methodology Information Gathering Vulnerability Analysis External Penetration Testing Internal Network Penetration Testing Router Penetration Testing Firewall Penetration Testing IDS Penetration Testing Wireless Network Penetration Testing Denial-of-Service Penetration Testing Password-Cracking Penetration Testing Social Engineering Penetration Testing Stolen Laptop, PDA, and Cell Phone Penetration Testing Application Penetration Testing Physical Security Penetration Testing Database Penetration Testing Voice-Over-IP Penetration Testing VPN Penetration Testing 10. Penetration Testing Risks 11. Liability Issues 12. Legal Consequences 13. “Get Out of Jail Free” Card 14. Penetration Testing Consultants 15. Required Skill Sets 16. Accomplishments 17. Hiring a Penetration Tester 18. Why Should a Company Hire You? Qualifications Work Experience Cutting-Edge Technical Skills Communication Skills Attitude Team Skills Company Concerns 19. Summary Chapter Review Questions/Exercises True/False Multiple Choice Exercise Problem Hands-On Projects Project Case Projects Problem Optional Team Case Project Problem 8. What is Vulnerability Assessment? 1. Introduction 2. Reporting 3. The “it Won’t Happen to US” Factor 4. Why Vulnerability Assessment? DSS PCI Compliance 5. Penetration Testing Versus Vulnerability Assessment 6. Vulnerability Assessment Goal 7. Mapping the Network 8. Selecting the Right Scanners 9. Central Scans Versus Local Scans 10. Defense in Depth Strategy 11. Vulnerability Assessment Tools Nessus GFI LANguard Retina Core Impact ISS Internet Scanner X-Scan 12. SARA QualysGuard 13. SAINT 14. MBSA 15. Scanner Performance 16. Scan Verification 17. Scanning Cornerstones 18. Network Scanning Countermeasures 19. Vulnerability Disclosure Date Find Security Holes before they Become Problems 20. Proactive Security Versus Reactive Security 21. Vulnerability Causes Password Management Flaws Fundamental Operating System Design Flaws Software Bugs Unchecked User Input 22. Diy Vulnerability Assessment 23. Summary Chapter Review Questions/Exercises True/False Multiple Choice Exercise Problem Hands-On Projects Project Case Projects Problem Optional Team Case Project Problem 9. Cyber Forensics 1. What is Cyber Forensics? 2. Analysis of Data Cyber Forensics and Ethics, Green Home Plate Gallery View Database Reconstruction 3. Cyber Forensics in the Court System 4. Understanding Internet History 5. Temporary Restraining Orders and Labor Disputes Divorce Patent Infringement When to Acquire, When to Capture Acquisition Creating Forensic Images Using Software and Hardware Write Blockers Live Capture of Relevant Files Redundant Array of Independent (or Inexpensive) Disks (RAID) File System Analyses NTFS The Role of the Forensic Examiner in Investigations and File Recovery Password Recovery File Carving Things to Know: How Time Stamps Work Experimental Evidence XP Vista Email Headers and Time Stamps, Email Receipts, and Bounced Messages Steganography “Covered Writing” 6. First Principles 7. Hacking a Windows XP Password Net User Password Hack Lanman Hashes and Rainbow Tables Password Reset Disk Memory Analysis and the Trojan Defense User Artifact Analysis Recovering Lost and Deleted Files Software Installation Recent Files Start Menu Email Internet History 8. Network Analysis Protocols Analysis 9. Cyber Forensics Applied 10. Tracking, Inventory, Location of Files, Paperwork, Backups, and so on Testimonial Experience Needed Job Description, Technologist Job Description Management Commercial Uses Solid Background Education/Certification Programming and Experience Communications Publications 11. Testifying as an Expert Degrees of Certainty Generally True Reasonable Degree of Certainty Certainty without Doubt 12. Beginning to End in Court Defendants, Plaintiffs, and Prosecutors Pretrial Motions Trial: Direct and Cross-Examination Rebuttal Surrebuttal Testifying: Rule 702. Testimony by Experts Correcting Mistakes: Putting Your Head in the Sand Direct Testimony Cross-Examination 13. Summary Chapter Review Questions/Exercises True/False Multiple Choice Exercise Problem Hands-On Projects Project Case Projects Problem Optional Team Case Project Problem 10. Cyber Forensics and Incident Response 1. Introduction to Cyber Forensics Responding to Incidents Applying Forensic Analysis Skills Distinguishing between Unpermitted Corporate and Criminal Activity 2. Handling Preliminary Investigations Planning for Incident Response Communicating with Site Personnel Knowing Your Organization’s Policies Minimizing the Impact on Your Organization Identifying the Incident Life Cycle Preparation Detection, Collection, and Analysis Containment, Eradication, and Recovery Post-Incident Activity Capturing Volatile Information 3. Controlling an Investigation Collecting Digital Evidence Chain of Custody and Process Integrity Advantages of Having a Forensic Analysis Team Legal Aspects of Acquiring Evidence: Securing and Documenting the Scene Processing and Logging Evidence 4. Conducting Disk-Based Analysis Forensics Lab Operations Acquiring a Bit-Stream Image Specialized Hardware Software: Linux Windows Enabling a Write Blocker Establishing a Baseline Physically Protecting the Media Disk Structure and Recovery Techniques Disk Geometry Components Inspecting Windows File System Architectures FAT (File Allocation Table) New Technology File System (NTFS) Master File Table (MFT) Alternate Data Streams (ADS) Locating and Restoring Deleted Content 5. Investigating Information-Hiding Techniques Uncovering Hidden Information Scanning and Evaluating Alternate Data Streams Executing Code from a Stream Steganography Tools and Concepts Detecting Steganography Scavenging Slack Space Inspecting Header Signatures and File Mangling Combining Files Binding Multiple Executable Files File Time Analysis 6. Scrutinizing Email Investigating the Mail Client Interpreting Email Headers Recovering Deleted Emails 7. Validating Email Header Information Detecting Spoofed Email Verifying Email Routing 8. Tracing Internet Access Inspecting Browser Cache and History Files Exploring Temporary Internet Files Visited URLs, Search Queries, Recently Opened Files Researching Cookie Storage Reconstructing Cleared Browser History Auditing Internet Surfing Tracking User Activity Uncovering Unauthorized Usage 9. Searching Memory in Real Time Comparing the Architecture of Processes Identifying User and Kernel Memory Inspecting Threads Discovering Rogue DLLs and Drivers Employing Advanced Process Analysis Methods Evaluating Processes with Windows Management Instrumentation (WMI) Walking Dependency Trees Auditing Processes and Services Investigating the Process Table Discovering Evidence in the Registry Deploying and Detecting a Rootkit 10. Summary Chapter Review Questions/Exercises True/False Multiple Choice Exercise Problem Hands-On Projects Project Case Projects Problem Optional Team Case Project Problem References 11. Network Forensics 1. Scientific Overview 2. The Principles of Network Forensics 3. Attack Traceback and Attribution IP Traceback Active Probing ICMP Traceback (iTrace) Packet Marking Log-Based Traceback Stepping-Stone Attack Attribution 4. Critical Needs Analysis 5. Research Directions VoIP Attribution Tracking Botnets Traceback in Anonymous Systems Online Fraudster Detection and Attribution Tracing Phishers Tracing Illegal Content Distributor in P2P Systems 6. Summary IDS Software Security Event Management Software NFAT Software DHCP Servers Packet Sniffers Network Monitoring ISP Records Send Network Traffic to the IP Address Chapter Review Questions/Exercises True/False Multiple Choice Exercise Problem Hands-On Projects Project Case Projects Problem Optional Team Case Project Problem Index
Similar books
Computer and Information Security Handbook
2024 · RAR
Computer and Information Security Handbook
2024 · EPUB
Cloud Computing Security: Foundations and Challenges
2020 · EPUB
Online Terrorist Propaganda, Recruitment, and Radicalization
2019 · PDF
Computer and Information Security Handbook
2013 · PDF
Nanoscale Networking and Communications Handbook
2019 · PDF
Computer and Information Security Handbook
2017 · PDF
Computer and information security handbook
2013 · PDF