CBK#7 Operations Security - Page 4

CBK#7 Operations Security - Page 1 2 3 4 5

Monitoring and Auditing
Monitoring:
Contains the mechanisms, tools and techniques which permit the identification of security events that could impact the operations of a computer facility.
Monitoring techniques -
- Intrusion detection
- Penetration testing
   - Scanning and probing
   - Demon Dialling
   - Sniffing
   - Dumpster Diving
   - Social Engineering
- Violation processing using clipping levels

Auditing:
Is the foundation of operational security controls monitoring.
Audit Trails:
Enables a security practitioner to trace a transaction's history.
Problem Management Concepts:
- Reduce failures to a manageable level
- Prevent the occurrence or re-occurrence of a problem
- Mitigate the negative impact of problems on computing services and resources.

Threats and Vulnerabilities
Threats:
Accidential loss:
Is a loss that is incurred unintentionally, though either the lack of operator training or proficiency or by the malfunctioning of an application processing procedure.
- Operator input error and omissions
- Transaction processing errors
Inappropriate Activities:
Is computer behaviour that, while not rising to the level of criminal activity may be grounds for job action or dismissal.
- Inappropriate Content
- Waste of Corporate Resources
- Sexual or Racial Harassment
- Abuse of Privileges or Rights
Illegal Computer Operations and Intentional Attacks:
Computer activities that are considered as intentional and illegal computer activity for personal financial gain for destruction.
- Eavesdropping
- Fraud
- Theft
- Sabotage
- External Attack

Vulnerabilities:
- Traffic / Trend Analysis
- Maintenance Accounts
- Data Scavenging Attacks
- IPL Vulnerabilities
- Network Address Hijacking

CBK#7 Operations Security - Page 1 2 3 4 5

CISSP Summary 2002Related links | References

CBK#1 Access Control Systems & Methodology | CBK#2 Telecommunications & Network Security | CBK#3 Security Management Practices | CBK#4 Applications & Systems Development Security | CBK#5 Cryptography | CBK#6 Security Architecture & Models | CBK#7 Operations Security | CBK#8 Business Continuity Planning & Disaster Recovery Planning | CBK#9 Law, Investigations & Ethics | CBK#10 Physical Security

Contact:

E-mail: john.wallhoff@mailbox.swipnet.se
Written by: J.Wallhoff January - April 2002
Updated by: J.Wallhoff April 2002