Showing posts with label Access Control. Show all posts
Showing posts with label Access Control. Show all posts

Tuesday, October 1, 2019

Access Control - Biometric and Federated Identity


There are different types of biometric systems in the industry today. Some make authentication decision based on behavior and some make authentication decisions based on physical attributes. However, a system that uses physical attributes provides more accuracy than one that uses behavior attributes. This is because
A biometric system can make authentication decisions based on an individual's behavior, as in signature dynamics and voice prints, but these can change over time and possibly be forged. Biometric systems that base authentication decisions on physical attributes (iris, retina, fingerprint) provide more accuracy, because they do not change as often and are harder to impersonate.

A federated identity is a portable identity, and its associated entitlements, that can be used across business boundaries. It allows a user to be authenticated across multiple IT systems and enterprises. Identity federation is based upon linking a user's otherwise distinct identities at two or more locations without the need to synchronize or consolidate directory information. Federated identity offers businesses and consumers a more convenient way of accessing distributed resources and is a key component of e-commerce. It is essentially when one organization agrees to trust another organization's authentication of a user, and provide them a degree of access based on that authentication.

Thursday, September 5, 2019

NIST 800-171 Compliance - Access Control

"Almost all physical and logical entry points to the organization and its information system need some type of access control"

Access Controls specifies following four:
  • which users can access a system or facility
  • what resources those users can access
  • what operations those users can perform
  • Enforce accountability for those users' actions
Access control is the process of allowing only authorized users, programs, or other computer systems (i.e. networks) to observe, modify, or otherwise take possession of the resources of a computer system. It is also a mechanism for limiting the use of some resources to authorized users.

In short, access controls are the collection of mechanisms, processes, or techniques that work together to protect the assets of an organization. They help protect against threats and mitigate vulnerabilities by reducing exposure to unauthorized activities and providing access to information and systems to only authorized people, processes, or systems.

Access controls incorporates all operational levels of an organizations:

  • Facilities: Protects entry to, and movement around, organization's physical location. This protects personnel, equipment, information and other assets inside that facility.
  • Support Systems: Systems like power, heating, ventilation, AC, fire suppression controls must be carefully controlled.
  • Information Systems: Multilayer of access controls needs to be applied in information systems and networks. This protect those systems from harm or misuse.
  • Personnel: Ensure right people have access right access and they do not interfere with people with whom they do not have any legitimate business.

NIST 800-171

A guideline from NIST provides following security requirements for access control (including basic and derived requirements) for protecting the confidentiality of CUI (Controlled Unclassified Information) in nonfederal information systems and organizations. The basic security requirements are obtained from FIPS Publication 200, which provides the high-level and fundamental security requirements for federal information and information systems. The derived security requirements, which supplement the basic security requirements, are taken from the security controls in NIST Special Publication 800-53.

Basic Security Requirements:

  • 3.1.1  Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).
  • 3.1.2  Limit information system access to the types of transactions and functions that authorized users are permitted to execute.

Derived Security Requirements:

  • 3.1.3  Control the flow of CUI in accordance with approved authorizations.
  • 3.1.4  Separate the duties of individuals to reduce the risk of malevolent activity without collusion.
  • 3.1.5  Employ the principle of least privilege, including for specific security functions and privileged accounts.
  • 3.1.6  Use non-privileged accounts or roles when accessing nonsecurity functions.
  • 3.1.7  Prevent non-privileged users from executing privileged functions and audit the execution of such functions.
  • 3.1.8  Limit unsuccessful logon attempts.
  • 3.1.9  Provide privacy and security notices consistent with applicable CUI rules.
  • 3.1.10  Use session lock with pattern-hiding displays to prevent access/viewing of data after period of inactivity.
  • 3.1.11  Terminate (automatically) a user session after a defined condition.
  • 3.1.12  Monitor and control remote access sessions.
  • 3.1.13  Employ cryptographic mechanisms to protect the confidentiality of remote access sessions.
  • 3.1.14  Route remote access via managed access control points.
  • 3.1.15  Authorize remote execution of privileged commands and remote access to security-relevant information.
  • 3.1.16  Authorize wireless access prior to allowing such connections.
  • 3.1.17  Protect wireless access using authentication and encryption.
  • 3.1.18  Control connection of mobile devices.
  • 3.1.19  Encrypt CUI on mobile devices.
  • 3.1.20  Verify and control/limit connections to and use of external information systems.
  • 3.1.21  Limit use of organizational portable storage devices on external information systems.
  • 3.1.22  Control information posted or processed on publicly accessible information systems.



SIEM and Compliance
Keeping up with compliance and reporting is a daunting tasks. SIEM solutions can help us here by providing holistic visibility into the network and improving detection and response capabilities. However, not everything mentioned by NIST is realizable through SIEM. Here's what you can implement with your SIEM to create a compliance reporting.

Basic Security Requirements:

3.1.1  Limit information system access to authorized users and process.
  • Check user authentication and their actions. Source and destination of authentication
Derived Security Requirements:

3.1.5  Principle of least privilege
  • Track activities by privileged accounts
3.1.6  Use non-privileged accounts or roles
  • Privilege authentication by user, source, destination, application etc.
3.1.7  Prevent non-privileged users from executing privileged functions and audit the execution of such functions.
  • Check for privilege escalation and associated events
3.1.8  Limit unsuccessful logon attempts.
  • Account lockout, failed logins, failed privileged logins, 3+ failed login within 1 minute, failed login from multiple location etc.
3.1.12  Monitor remote access sessions.
  • Remote login, vpn sessions by users. Summary and Time-trend analysis
3.1.18  Control connection of mobile devices.
  • track mobile device usage and users
Log Source Requirements
  • Hosts Logs (Windows, Unix etc.)

Sunday, January 6, 2019

Access Control - A Management of Subject and Object


Security mechanism is implemented to offer data confidentiality and integrity. This means, a high level of assurance is offered that data, objects or resources are restricted from unauthorized subjects. If a threat exists against confidentiality, unauthorized disclosure could take place. If a threat exists against integrity, unauthorized modification could take place.

There are two entities that are significant in security mechanism: Subject and Object.

An object is the passive element in a security relationship, such as files, computers, network connections, and applications. A subject is the active element in a security relationship, such as users, programs and process. A subject acts upon or against an object. Whenever one entity acts on another there should also be a mechanism in place to control the action. The relations between this subject and object is managed by a way called access control.

Thus, the management of the relationship between subjects and objects is known as access control.

Monday, December 10, 2018

Subject, Object and Access Control

Object
An object is the passive element in a security relationship

  • files, 
  • computers, 
  • network connections, and 
  • applications. 


Subject
A subject is the active element in a security relationship

  • users, 
  • programs, and 
  • computers. 
A subject acts upon or against an object.

Access Control
The management of the relationship between subjects and objects is known as access control.

Monday, March 13, 2017

Cryptography: Authentication and Access Control

An organization makes each lead system administrator responsible for the security of the system he or she runs. However, the management determines what programs are to be on the system and how they are to be configured.

  • Describe the security problem(s) that this division of power would create. 
Security mechanism in a company depends on who is responsible for the company’s security. The power to implement appropriate controls must reside with those who are responsible. If management determines what programs are to be on the system, then the system administrators who are responsible for the security, who see the need for security measures will be unable to implement the appropriate security measures. Since management is not aware of the technical aspects of security as much as system administrators it’s possible for management to make some poor choices with regard to cost, resources, security measures. Also coordination among the system coordinators is also pivotal in an organization and this coordination might be compromised if management makes the key security decisions.
Coursera DS Design 10Coursera AH Purple Design 2Coursera General Design 2 Green
  • How would you fix them? 
The problem can be fixed by providing system administrators (knowledgeable people) with more control and sufficient resources for administering computer systems. Management should consult the system administrators before making any decision on security issues. If the company has several divisions each should have separate system administrator then the company can have one security head who is knowledged about security issues and who heads all the systems administrators. Management should leave all the key security decisions to him. Security head should take care of delegating the appropriate security tasks to the concerned system administrators. Part of the management role requires them to know about the cost, resources, security polices etc, and management can get up to date about these by consulting the security head.


Career skills to jumpstart your future.  Start your future with a Business Analytics Certificate.