CBK#7 Operations Security - Page 3

CBK#7 Operations Security - Page 1 2 3 4 5

Operations Controls:
Day-to-day procedures used to protect computer operations.
Resource Protection:
Is the concept of protecting an organization's computing resources and assets from loss or compromise. Covers hardware, software and data resources.

Hardware Controls:
- Hardware Maintenance
- Maintenance Accounts
- Diagnostics Port Control
- Hardware Physical Control

Software Controls:
- Anti-virus Management
- Software Testing
- Software Utilities
- Safe Software Storage
- Backup Controls

Privileged Entity Controls / Privileged operations functions:
- Special access to system commands
- Access to special parameters
- Access to the system control program

Media Resource Protection:
Are implemented to protect any security threat by intentional or unintentional exposure of sensitive data -
- Media Security Controls:
Should be designed to prevent the loss of sensitive information and can be:
     - Logging
     - Access control
     - Proper disposal
- Media Viability Controls
Should be used to protect the viability of the data storage media.
Is required in the event of system recovery process -
     - Marking
     - Handling
     - Storage

Physical Access Controls:
Covers
- Hardware
- Software
Special arrangements for supervision must be made when external support providers are entering a data center.

Piggybacking: Is when an unauthorized person goes through a door behind an authorized person. The concept of a "man trap" is designed to prevent it.

CBK#7 Operations Security - Page 1 2 3 4 5

CISSP Summary 2002Related links | References

CBK#1 Access Control Systems & Methodology | CBK#2 Telecommunications & Network Security | CBK#3 Security Management Practices | CBK#4 Applications & Systems Development Security | CBK#5 Cryptography | CBK#6 Security Architecture & Models | CBK#7 Operations Security | CBK#8 Business Continuity Planning & Disaster Recovery Planning | CBK#9 Law, Investigations & Ethics | CBK#10 Physical Security

Contact:

E-mail: john.wallhoff@mailbox.swipnet.se
Written by: J.Wallhoff January - April 2002
Updated by: J.Wallhoff April 2002