Always assume Discretionary Access Control (DAC) Always assume a large company (100+) Don’t get wrapped up in US Law (in many countries, in some countries = ignore US law) Example: Reasonable expectation of privacy while using business systems. In US, there is usually no expectation of privacy. In EU, there is an expectation of privacy by law. If they don’t tell you budget is a concern, assume budget is not concern and go with the Cadillac answer Don’t forget about Physical Security (a lot of times a lock and key could be the best answer), Don't forget about availability Take breaks! If you don’t know what a question is asking, try taking a break. When the test asks about 'senior management': Unless told otherwise, assume they mean CEO, CFO, and board of directors. When we talk about accounting, we're talking about writing log entries and holding people accountable. When talking about auditing, we're talking about reading those log entries. When trying to decide between different answers, 1 answer will appeal to sys admin, 1 will appeal to manager. Pick the manager. i.e. if you have multiple answers and 1 says 'do what policy says' that’s going to be the answer. If you come across a question and you think it's an easy win, read it again. It's probably a trick. Be aware of "Answer Bias" If you read a multiple choice question, you have a bias towards A or B and bias against C or D. Overcome by reading answers first, and questions second. General Axioms: Number 1 goal is to protect life Building is on fire, they want you to run into building to get backup tapes. Always assume getting people out of the building is first priority even when stated otherwise. Everyone is responsible for security Janitor with no login is responsible too. After he sweeps server room, he must lock the door behind him. Senior Management is ultimately Responsbile for security CISO is accountable, but senior management is responsible. Senior management writes the security policy, CISO uses that to do their job. If there is a breach CISO is fired, senior management puts another CISO in place. Never spend more for a control than what you are protecting. (Single loss expectancy * Annual rate of occurance) $500 car that you pay $1500 a year on to protect. Not a good investment. We don’t accept risk, only senior management can accept risk. We advise on what risks to accept. Can't transfer ultimate responsibility, just some of the fallout i.e. financial responsibility If you're reading a network question and it covers layer 1-4, recheck the model. Training and awareness are mandatory. This includes cross-training. Cross-training Staffing for resilience Paper is a media. Consider paper the same way you would a hard drive. Patterns are bad (Cryptography) Senior Management can do whatever they want. Our job is to make sure when they make the decision, they have a basic understanding of the risks. As long as they do, they can make whatever decision they want. IT Security supports the business, not vice versa. If it wasn't this way, we'd just get rid of half the things they do. An attack on availability could be just slowing down the system, rather than knocking it out. Making a system run at degraded speed is a successful attack Digital signatures don't do shit for confidentiality. Only integrity and non-repudiation. No single control can be considered perfect. Does this mean you need multiple or that you should assume each one is inherently flawed? eCommerce = Encryption. If they mention eCommerce, they want you to be aware of you handling credit cards. PCI Requirement 4 = protect data in transit Best way to protect data in transit? Encryption. No way to inspect an encrypted payload Users = Subjects Subject Anything that wants to get to an object. Before a subject can get to an object, it should have a 'referee' i.e. something that grants or denies access. Security kernel Contains rules that allow the referee to make decisions. Audit file Keeps a protected log of all subjects, what objects they accessed and preferably reasoning from the kernel Is this a reference monitor? Can it block a subject from getting to an object? Yes: It is a reference monitor No: it is not a reference monitor. Complete Mediation Even if you've been through the reference monitor a million times and were granted access a million times. You should not circumvent the reference monitor as at a minimum, you want an audit file which the reference monitor will generate. Covert Channel Anything that circumvents a reference monitor. Confidentiality Keeping secrets secret. Enemy of Confidentiality is Disclosure How do you protect confidentiality? Encryption Logical Access control Physical Access Control Integrity Can you trust the data? Has the data been changed? Was it correct when it was collected? Enemy of Integrity is Alteration How do you provide Integrity Hashing Goals of integrity: Stop unauthorized changes from unauthorized subject Threat agents Stop unauthorized changes from authorized subject Mistakes and errors Maintain data consistency Availability Data is available to authorized users when they need it. Enemy of availability is Destruction or downtime D.A.D.D. Enemies of CIA Disclosure Alteration Destruction/Downtime Risk Appetite How much risk is senior management comfortable taking on in the organization? CISO Manage security infrastructure Metrics - If you can't measure it, you can't improve it. Advise Senior management on security risks Metrics Comes from 2 places Measurement Variation Don’t change the way you're measuring. Stay consistent to see trends over time. Process variation The actual variation that is happening in the process Policy Brief, high-level statement "Policy should never be longer than 2 pages" Don't leave policy up for interpretation. e.g. "We will be HIPAA compliant." Standards "Bulleted list" Procedures "Numbered list" Baselines Minimum security configuration for different systems. Senior management is responsible for establishing baselines. Baseline info may be collected from vendors, open standards, etc. Scoping Go through everything a baseline talks about, decide what works and what doesn’t. Armed guards are too much for us, but security cameras is a good fit. Tailoring Make the baseline specific to your business. 16 cameras, 8 inside, 8 outside. Guidelines Generalized ideas on how management would expect something to be completed that may not have a set of standards/procedures/baselines in existence Governance leads into Compliance leads into Assurance Due Dilligence Making the rules What would any reasonably prudent person do? "Prudent person rule" An individual should make every effort to complete his or her responsibilities in an accurate and timely manner Due Care Everyone following the rules Superficial Security Frameworks: ITIL - Information Technology Infrastructure Library Continual Service Improvement COSO - Committee of sponsoring organizations All about financial Fraud COBIT - Control objectives for Information and related Technologies Developed by ISACA Auditors use this to define what controls you should have Real Security Frameworks ISO 27000 ISO/IEC 27000 General Overview Information security management systems Overview and vocabulary ISO/IEC 27001 Actual standard, includes ISMS and Requirements Information technology - Security Techniques - Information security management systems Requirements. The 2013 release of the standard specifies an information security management system in the same formalized, structured and succinct manner as other ISO standards specify other kinds of management systems. ISO/IEC 27002 Listing of example controls that could be used to meet 27001 requirements Code of practice for information security controls essentially a detailed catalog of information security controls that might be managed through the ISMS ISO/IEC 27003 Information security management system implementation guidance ISO/IEC 27004 Guidelines for metrics Information security management Monitoring, measurement, analysis and evaluation ISO/IEC 27005 Information security risk management (NIST SP800-39) ISO/IEC 27006 Requirements for bodies providing audit and certification of information security management systems ISO 22301 Information technology -- Security techniques -- Guidelines for information and communication technology readiness for business continuity NIST SP-800 US Specific Not as heavily placed into the CISSP test any more as the test is meant to be 'international' Compliance Frameworks PCI-DSS Actual Standard: https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf Review requirements 1-12 and Appendix A Only applies to organizations that do business directly with members of the PCI council. (i.e. VISA, MasterCard, Discover, etc.) PCI is not a law, it is a contract. PAN - Primary Account Number Credit Card Number, Expiration Date, CVV Tokenization Replace confidential information with placeholders for identification ("tokens") e.g. replace the credit card number of "0000-0000-0000-000" with "Token-CreditCard-1" QSA - Qualified Security Assessor PCI Auditors Business Impact Analysis: BIA ======================== Gather Info What all things do you do? Identify what's critical Map relationships between critical items and dependencies "Doing the math" Calculate "MTD" Maximum Tolerable Downtime Calculate "RTO" - recovery time objective Amount of time required to recover Can be split into 2 parts. Part 1 - RTO "amount of time to order a part" Part 2 - 'WRT' Work Recovery Time "amount of time to install the ordered parts Calculate "RPO" - Recovery Point objective If a problem is encountered, how much date/time are you able to lose? i.e. If you backups are every 24 hours, your RPO should say you're willing to lose up to 24 hours of data if you were to restore to the last backup. Perform Cost/Benefit analysis Develop continuity plans Perform cost/benefit analysis usiness Continuity - Disaster Recovery - Incident Response Means different things in practice, for this week and this week, consider these as completely separate islands. Business continuity. Critical Business functions, plans to get them back online fast enough. Disaster recovery When an incident is SO BAD that you had to 'move' Incident Response What's considered critical? Whatever senior management says is critical Whatever keeps the cash register ringing What's considered not critical Anything that doesn’t stop the cash register from ringing. Business Continuity Plan Perform "BIA" - business impact assessment No discussion of probability. Only impact BIA Plans -> pick an output Put plans into place Risk Assessments 3 main steps Identification Risk analysis Risk assessment Qualitative Assessment Measurement of impact and likelihood. Low -> Medium -> High Quantitative Risk Assessment Annualized Loss Expectency (ALE) = Annual Rate of Occurance (ARO) * Single Loss Expectancy (SLE) Single Loss Expectancy (SLE) = Asset Value (AV) * Exposure Factor (EF) ALE = ARO * (AV*EF) Terms: Annualized Rate of Occurance (ARO) How many times per year a risk is expected to be realized. Single Loss Expectancy Amount of money expected to be lost when a risk is realized. Asset Value In real life to determine value of an asset, hire a consultant "Test will likely give you the asset value" Exposure Factor Percentage of the asset's value that would be compromised if a risk is realized Example: Building burns to the ground. ARO = .01 (likely to happen once every 100 years) AV = 200,000 (building, all items inside, land the building sits on) EF = 75% (only 75% because 25% of the asset's value is land, which would not be affected by the building burning down) SLE = 200,000 * 0.75 = 150,000 ALE = .01 * 150,000 = $1,500 If insurance guy comes back saying fire insurance is $1000/year In scenario you are paying $1000 to save $1500. ROI = (Amount your saving - cost of control)/cost of control ROI = (1500-1000)/1000 ROI = 50% Risk Treatments Acceptance Accept the risk as a cost of doing business without necessarily doing anything Avoidance Don't do the ting that causes risk look for alternatives to achieve same goal Transference Pay someone else to be liable for the financial impact Ultimate responsibility stays with senior management Mitigation Invest in solutions to address the risk and hopefully prevent it. Address probability or impact Safeguards Reduces probability Countermeasures Reduces impact Risk Rejection Stick your head in the sand If you don’t know that you've been breached, due care is not required. Control Types "3 slice pie" : Administrative Policy/Rules Technical/Logical Software Physical If you can touch it Control Categories"7 slice pie" ----- pre-incident ------ Directive Policies on work computer, supervisor instruction Safeguard Deterrent Discourages you from trying Safeguard Preventative Stops you even if you try Safeguard ------ post incident ------- Detective Can alert you if an incident occurs Countermeasure Corrective First containment and/or eradication Stops the bleeding Countermeasure Recovery Resumes normal operation Countermeasure Compensating Put in place in the absence of another control