Integrating Physical And Logical Security

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

2 comments

Comments 1 - 2 of 2 previous next Post a comment

  • + guestdc0b359 guestdc0b359 7 months ago
    can i have a pdf orppt. santoshkhadsare@gmail.com
  • + havilson havilson 2 years ago
    Very nice presentation. Right now I’m working on this subject and will be gratefull if you could send a copy (ppt or pdf) of the presentation.

    Best regards.
Post a comment
Embed Video
Edit your comment Cancel

18 Favorites & 1 Group

Integrating Physical And Logical Security - Presentation Transcript

  1. Integrating Physical & Logical Security Jorge Sebastião, CISSP, ISP, BSLA Founder and CEO “ Security is:… a continuous skilled process which safeguards your business value…” Jorge S., 1999
  2. Security
    • Protection systems
      • Safeguard assets
      • Safeguard of personnel
      • Integrate People, Process, Technology
      • Two major types:
        • Physical Security
        • Information Security (infosec)
  3. Physical Security-Focus
    • Protection of physical assets
    • Personnel
    • Buildings
    • Computing Facilities
    • Physical Access Control
    • Power
  4. Information Security-Focus
    • Protection of information assets
    • Computer Systems
    • Data Networks
    • Databases, Applications
    • Logical Access Control
    • Disaster Recovery
  5. Signal also applies to cars of other colors
  6. Signal also applies to cars of other colors
  7. Scenario
    • CFO Traveling abroad for 2 weeks
      • Normally in Riyadh HQ Office
      • Now in Dubai visiting
    • Non-Integrated, non-compatible physical access control
    • Trusted employee uses CFO password to access confidential data in Riyadh
      • Normal working hours
      • Sensitive files shared with competitors
    • No Alarm raised by system???
    • No violation in either physical sec or infosec systems
  8. Data Center
  9. Threats and risks Human faults Operational disruptions Software Faults In-compatability Fraud Forgery Access Control Espionage Illegal copying Virus Natural phenomena Fire, Smoke, Explosion Destruction, Sabotage Power Failure Water Damage Leakage Theft Vandalism Delivery Problem Service Disruption Loss of Key personnel Notice to quit, Sickness
  10. Security as: TPP Technology Process People
  11. Attack-NCR, IBM ATMs
    • UAE Bank Attack May-June 2003
    • Exploits ATM Vulnerabilities
    • Special Device capture cards
    • Physical Security
    • 1.5-?.? Million Dhs
    Technology
  12. Microsoft
    • SQL Slammer Worm 25/01/2003
    • Exploits SQL Server 2000 Vulnerabilities
    • Document since July 2002
    • Traveled Globe in 15 min
    Process
  13. Verisign
    • Verisign 22/03/2001 Someone tricked digital security specialist VeriSign ( VRSN ) , which authenticates parties in e-commerce transactions, into issuing two digital certificates with Microsoft's name on them. The certificates could be used by a malicious poseur to spread viruses or other harmful programs by camouflaging them as Microsoft software.
    People
  14. PDR
    • Defence in Depth (layered security)
    • No Single Point of Vulnerability
    • Centralized Security Management
    • Heterogeneous
    • Effective
    • Process
    • Implement Protection, Detection, Response
    PROTECTION DETECTION RESPONSE FORENSICS
  15. Security = Time Protection Detection Response SECURITY P>D+R Anti-virus VPN Access Control Firewall Intrusion Prevention Managed Services CIRT Patch Mgmt Vulnerability Testing Intrusion Detection CCTV Log Correlation
  16. Securing the System Effective security requires a balanced application of all methods Personnel System Security Computer Security Physical Security Process Encryption
  17. Security Continuous process ASSESS ARCHITECT APPLY ADMINISTER Business Risk Controls Maturity
  18. Integrated Security Management Business Security Management Physical Security Management ICT Security Management
  19. Security Management Processes
  20. Convergence APPLY
  21. Identity and Access Management Strategic Context Physical Security Network / System Application / Data Suppliers, Partners, Customers Employees
  22. New Boundaries
    • Platforms
      • Data Center
      • Laptops
      • PDA
      • Mobiles
    • Distributed Access
      • Dialup, ADSL, VPN
      • VSAT
      • Wifi, WiMax
      • GPRS/3G
    • Communication Centric Applications
      • Web
      • Email
      • IPM
      • VoIP
    • Multiple Networks
      • Intranet
      • Extranet
      • Internet
    • Users
      • Employees
      • Partners
      • Suppliers
      • Customers
      • Consumers/Prospects
    • Location
      • Office
      • Internet Café/Restaurants
      • Airport
      • Hotels
      • Home
  23. Identity and Access Management Interoperability Control Loosely-coupled, Dynamic exterior Tightly-coupled, Persistent interior Intranet Extranets Customers Partners/Suppliers Employees Consumers Internet
  24. Identity and Access Management Flexibility Intranet Extranets Internet Control Customers Partners/Suppliers Employees Consumers Federation, Cooperation Integration
  25. Physical Security Physical Security Sprinkler hallon Alarm System UPS CCTV System Intrusion Detection Intercom Evacuation Physical Access Control Elevator Fire HVAC Lighting Power Mgmt
  26. Physical Security Architecture
  27. Biometrics Example
  28. Storage SMART CCTV + biometrics Corporate LAN / WAN / VLAN Internet
  29. Records Physical Protection
  30. Physical Security
  31.  
  32. Info warfare C4
      • Command, Control, Communications, Computers
  33. Logical Security Physical Security Data Encryption Host Intrusion Detection Antivirus Perimeter Security Network Intrusion Detection Remote Client VPN Access Control Remote Clientless HTTPS Disaster Recovery Content Filtering Anti-spam Intrusion Prevention Wireless Security Network / System Application/Data
  34. Architecture Layers Extended Perimeter Perimeter Layer Control Layer Resource Layer Identity & Access Mgmt Physical Security Integrated Directory Security Management Policy Management Remote Employees Consumers Partners Customers Suppliers
  35. Identity and Access Management Context Business policy: legal, liability, assurance for transactions Relationships to organization Applications/Services: access control and authorization Identity and information Presentation/Personalization: Identification Relationships Authentication: Identity (Person)
  36. Architecture and Infrastructure Directory Access Mgmt Portal/Device Identity Mgmt Policy Propagation Administration Control Access Resources Authentication Authorization User Device? Applications Platforms Databases Physical Services
  37. SSO~~Security
    • SSO and security
        • Reducing sign-on a goal
        • S ingle sign on is a risk in security compromise
        • Standard authentication infrastructure is good
        • SSO is not always realistic
        • Different applications
          • Different security
          • Different application states
        • Policy drives
        • No single credential should give access to everything
  38. Where to spend? High Low Excessive Exposure Low High R I S K SECURITY INVESTMENT Excessive Cost Appropriate Security
  39. Return On Investment (ROI)? ROI Curve Security Investment ROI design= 21% ROI implementation= 21% ROI testing= 12% ROI
  40. Security Architecture Incidence Response Operational Monitoring Administration Change Procedures Guidelines Roles and Responsibilities Incident Reporting Physical Dynamic Controls Selection Policy Configurations Baselines Standards Awareness Education Training Logical BIA Mapping Perimeter Architecture InfoSec Policy Security Organization Conceptual P > D + R Strategy Scope Executive InfoSec Policy Steering Committee Contextual Time (Risk Management) Technology Process People
  41. Beyond Technology
  42. Knowledge Base Incidence Response Applying the Knowledge Incidence Response Multiple Sources of Information Partners, Vendors, CERT ,… Internal Security Research Internet, Mailing lists and other sources ADMINISTER
  43. Integrated P+D+R Enterprise Security Management Routers Switches Firewall N-IDS H-IDS IPS Hosts Antivirus Access Ctrl Biometrics Smart Cards Power UPS Fire CCTV P-IDS Alarms Others…. 1.Logs 5. Response 2. Encrypted Logs 3. Analysis 6. (Ongoing) Patching Incidence Response Knowledge 4. Alerting
  44. Incidence Response Incident Response Analyse Contain Eliminate Restore Lessons Policy Refine Policy Continuous Monitoring T-1 T 0 T 1 T 1 T 3 T 4 T N Communicate
  45. Integrated Infosec Framework Vulnerability & Risk Assessment Assess, Audits VA, Pen-Testing, Risk Technology Strategy & Usage Technology, Tools Policy Insfosec Policy, Standards Security Architecture and Technical Standards Technical Architecture Technical Standards, Baselines Security Model Information Classification and Controls Administrative and End-User Guidelines and Procedures Implementation and Configurations Administration Guidelines and Procedures Recovery Processes Incidence Response Processes Enforcement Processes Compliance Mgmt Processes CEO, Senior Management ISMS, Information Assets, IT Infrastructure Awareness, Training, Education Monitoring Processes Monitoring Processes Security Strategy Business Initiatives & Processes Business Initiatives & Processes Vulnerabilities Threats
  46. Benefits of integration
    • Better Security
    • Less Vulnerabilities
    • Better Auditing
    • Cost Savings
    • Mitigate legal liability (negligence)
  47. Challenges
    • Lack of Standards
    • Focus on technology rather then management
    • Reluctance of physical security to embrace ICT / IT
    • No roadmap for organization readiness
    • www.opensecurityexchange.com
  48. Initiatives example
    • www.opensecurityexchange.com
    • X-industry collaboration
    • Initial participants
      • CA
      • Gemplus
      • HID
      • Software House
    • PHYSBITS-Physical Security bridge to IT
  49. ?

+ Jorge SebastiaoJorge Sebastiao, 2 years ago

custom

5998 views, 18 favs, 0 embeds more stats

Integration of Physical and IT Logical Security at more

More info about this document

© All Rights Reserved

Go to text version

  • Total Views 5998
    • 5998 on SlideShare
    • 0 from embeds
  • Comments 2
  • Favorites 18
  • Downloads 0
Most viewed embeds

more

All embeds

less

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel
File a copyright complaint
Having problems? Go to our helpdesk?

Categories

Groups / Events