Translate

петък, 5 юни 2015 г.

Сигурност на компютърните мрежи - основни стъпки за изпълнение



Guidance
10 Steps: Network Security

From: UK CESG, Department for Business, Innovation & Skills, Cabinet Office and Centre for the Protection of National Infrastructure
First published: 5 September 2012
Last updated: 16 January 2015 
Part of: Cyber security


1.Summary
Connecting to untrusted networks (such as the Internet) exposes corporate networks to attacks that seek to compromise the confidentiality, integrity and availability of Information and Communications Technologies (ICT) and the information they store and process. This can be prevented by developing policies and risk management approaches to protect corporate networks by applying security controls that are commensurate with the risks that have been identified and the organisation’s risk appetite.

2.What is the risk?
Corporate networks need to be protected against both internal and external threats. The level to which networks are protected should be considered in the context of the organisation’s risk appetite, risk assessment and corporate security policies.
Businesses that fail to protect their networks appropriately could be subject to a number of risks, including:
Leakage of sensitive corporate information
Poor network design could be exploited by both internal and external attackers to compromise information or conduct unauthorised releases of sensitive information resulting in compromises in confidentiality, integrity and availability
Import and export of malware
Failure to put in place appropriate boundary security controls could lead to the import of malware and the compromise of business systems. In addition, users could deliberately or accidentally release malware or other malicious content to business partners or the general public via network connections that are poorly designed and managed
Denial of service
Networks that are connected to untrusted networks (such as the Internet) are vulnerable to denial of services attacks, where access to services and information is denied to legitimate users, compromising the availability of the system or service
Exploitation of vulnerable systems
Attackers will exploit poorly protected networks to gain unauthorised access to compromise the confidentiality, integrity and availability of systems, services and information
Damage or defacement of corporate resources
Attackers that have successfully compromised the network can damage internal and externally facing systems and information (such as defacing corporate websites), harming the organisation’s reputation and customer confidence

3.How can the risk be managed?
Produce, implement and maintain network security policies that align with the organisation’s broader information risk management policies and objectives. Follow recognised network design principles (ie ISO/IEC 27033-1:2009) to help define the necessary security qualities for the perimeter and internal network segments and ensure that all network devices are configured to the secure baseline build.

3.1Police the network perimeter
Limit access to network ports, protocols and applications filtering and inspecting all traffic at the network perimeter to ensure that only traffic which is required to support the business is being exchanged. Control and manage all inbound and outbound network connections and deploy technical controls to scan for malware and other malicious content.
Install firewalls
Firewalls should be deployed to form a buffer zone between the untrusted external network and the internal network used by the business. The firewall rule set should deny traffic by default and a whitelist should be applied that only allows authorised protocols, ports and applications to communicate with authorised networks and network addresses. This will reduce the exposure of ICT systems to network based attacks.
Prevent malicious content
Deploy antivirus and malware checking solutions to examine both inbound and outbound data at the perimeter in addition to antivirus and malware protection deployed on internal networks and on host systems. The antivirus and malware solutions used at the perimeter should be different to those used to protect internal networks and systems in order to provide some additional defence in depth.

3.2Protect the internal network
Ensure that there is no direct network connectivity between internal systems and systems hosted on untrusted networks (such as the Internet), limit the exposure of sensitive information and monitor network traffic to detect and react to attempted and actual network intrusions.
Segregate network as sets
Identify, group and isolate critical business information assets and services and apply appropriate network security controls to them.
Secure wireless devices
Wireless devices should only be allowed to connect to trusted wireless networks. All wireless access points should be secured. Security scanning tools should have the ability to detect and locate unauthorised wireless access points.
Protect internal Internet Protocol (IP) addresses
Implement capabilities (such as Network Address Translation) to prevent internal IP addresses from being exposed to external networks and attackers and ensure that it is not possible to route network traffic directly from untrusted networks to internal networks.
Enable secure administration
Administrator access to any network component should only be carried out over dedicated network infrastructure and secure channels using communication protocols that support encryption.
Configure the exception handling processes
Ensure that error messages returned to internal or external systems or users do not include sensitive information that may be useful to attackers.
Monitor the network
Tools such as network intrusion detection and network intrusion prevention should be placed on the network and configured by qualified staff to monitor traffic for unusual or malicious incoming and outgoing activity that could be indicative of an attack or an attempt. Alerts generated by the system should be promptly managed by appropriately trained staff.
Assurance processes
Conduct regular penetration tests of the network infrastructure and undertake simulated cyber attack exercises to ensure that all security controls have been implemented correctly and are providing the necessary levels of security.

четвъртък, 4 юни 2015 г.

Информационна сигурност - основни стъпки за управление на конфигурациите


Guidance
10 Steps: Secure Configuration

From: UK CESG, Department for Business, Innovation & Skills, Cabinet Office and Centre for the Protection of National Infrastructure
First published: 5 September 2012
Last updated: 16 January 2015 
Part of: Cyber security

1. Summary
By putting in place corporate policies and processes to develop secure baseline builds and manage the configuration and the ongoing functionality of all Information and Communications Technologies (ICT), organisations can greatly improve the security of their ICT systems. Good corporate practice is to develop a strategy to remove or disable unnecessary functionality from ICT systems and keep them patched against known vulnerabilities. Failure to do so is likely to result in increased exposure of the business and its ICT to threats and vulnerabilities and therefore increased risk to the confidentiality, integrity and availability of systems and information.

2. What is the risk?
Establishing and then actively maintaining the secure configuration of ICT systems should be seen as a key security control. ICT systems that are not locked down, hardened or patched will be particularly vulnerable to attacks that may be easily prevented.
Organisations that fail to produce and implement corporate security policies that manage the secure configuration and patching of their ICT systems are subject to the following risks:
Unauthorised changes to systems
An attacker could make unauthorised changes to ICT systems or information, compromising confidentiality, availability and integrity
Exploitation of unpatched vulnerabilities
New patches are released almost daily and the timely application of security patches is critical to preserving the confidentiality, integrity and availability of ICT systems. Attackers will attempt to exploit unpatched systems to provide them with unauthorised access to system resources and information. Many successful attacks are enabled by exploiting a vulnerability for which a patch had been issued prior to the attack taking place
Exploitation of insecure system configurations
An attacker could exploit a system that has not been locked down or hardened by:
Gaining unauthorised access to information assets or importing malware
Exploiting unnecessary functionality that has not been removed or disabled to conduct attacks and gain unauthorised access to systems, services, resources and information
Connecting unauthorised equipment to exfiltrate information or introduce malware
Creating a back door to use in the future for malicious purposes
Increases in the number of security incidents
Without an awareness of vulnerabilities that have been identified and the availability (or not) of patches and fixes, the business will be increasingly disrupted by security incidents

3. How can the risk be managed?
3.1 Develop corporate policies to update and patch systems
Use the latest versions of operating systems, web browsers and applications. Develop and implement corporate policies to ensure that security patches are applied in a timeframe that is commensurate with the organisation’s overall risk management approach. Organisations should use automated patch management and software update tools.
3.2 Create and maintain hardware and software inventories
Create inventories of the authorised hardware and software that constitute ICT systems across the organisation. Ideally, suitably configured automated tools should be used to capture the physical location, the business owner and the purpose of the hardware together with the version and patching status of all software used on the system. The tools should also be used to identify any unauthorised hardware or software, which should be removed.
3.3 Lock down operating systems and software
Consider the balance between system usability and security and then document and implement a secure baseline build for all ICT systems, covering clients, mobile devices, servers, operating systems, applications and network devices such as firewalls and routers. Essentially, any services, functionality or applications that are not required to support the business should be removed or disabled. The secure build profile should be managed by the configuration control and management process and any deviation from the standard build should be documented and formally approved.
3.4 Conduct regular vulnerability scans
Organisations should run automated vulnerability scanning tools against all networked devices regularly and remedy any identified vulnerabilities within an agreed time frame. Organisations should also maintain their situational awareness of the threats and vulnerabilities they face.
3.5 Establish configuration control and management
Produce policies and procedures that define and support the configuration control and change management requirements for all ICT systems, including software.
3.6 Disable unnecessary input/output devices and removable media access
Assess business requirements for user access to input/output devices and removable media (this could include MP3 players and Smart phones). Disable ports and system functionality that is not needed by the business (which may include USB ports, CD/DVD/Card media drives)
3.7 Implement whitelisting and execution control
Create and maintain a whitelist of authorised applications and software that can be executed on ICT systems. In addition, ICT systems need to be capable of preventing the installation and execution of unauthorised software and applications by employing process execution controls, software application arbiters and only accepting code that is signed by trusted suppliers;
3.8 Limit user ability to change configuration
Provide users with the minimum system rights and permissions that they need to fulfil their business role. Users with ‘normal’ privileges should be prevented from installing or disabling any software or services running on the system.

Управление на рисковете към Информационната сигурност - основни стъпки


Guidance
10 Steps: Information Risk Management Regime

From: UK CESG, Department for Business, Innovation & Skills, Cabinet Office and Centre for the Protection of National Infrastructure
First published: 5 September 2012
Last updated: 16 January 2015 
Part of: Cyber security

1. Summary
It is best practice for an organisation to apply the same degree of rigour to assessing the risks to its information assets as it would to legal, regulatory, financial or operational risk. This can be achieved by embedding an information risk management regime across the organisation, which is actively supported by the Board, senior managers and an empowered Information Assurance (IA) governance structure. Defining and communicating the organisation’s attitude and approach to risk management is crucial. Boards may wish to consider communicating their risk appetite statement and information risk management policy across the organisation to ensure that employees, contractors and suppliers are aware of the organisation’s risk management boundaries.

2. What is the risk?
Risk is an inherent part of doing business. For any organisation to operate successfully it needs to address risk and respond proportionately and appropriately to a level which is consistent with the organisation’s risk appetite. If an organisation does not identify and manage risk it can lead to business failure.
A lack of effective information risk management and governance may lead to the following:

Increased exposure to risk

Information risk must be owned at Board level. Without effective risk governance processes it is impossible for the Board to understand the risk exposure of the organisation. The Board must be confident that information risks are being managed within tolerance throughout the lifecycle of deployed systems or services

Missed business opportunities

Where risk decisions are being taken at junior level without effective governance and ownership back to senior levels, it may promote an overly cautious approach to information risk which may lead to missed business opportunities. Alternatively, an overly open approach may expose the organisation to unacceptable risks

Ineffective policy implementation

An organisation’s Board has overall ownership of the corporate security policy. Without effective risk management and governance processes the Board will not have confidence that its stated policy is being consistently applied across the business as a whole

Poor reuse of security investment

A lack of effective governance means that information risk management activities may be undertaken locally when they could be more effectively deployed at an organisational level

3. How can the risk be managed?

3.1 Establish a governance framework
A governance framework needs to be established that enables and supports a consistent and empowered approach to information risk management across the organisation, with ultimate responsibility for risk ownership residing at Board level.

3.2 Determine the organisation’s risk appetite
Agree the level of information risk the organisation is prepared to tolerate in pursuit of its business objectives and produce a risk appetite statement to help guide information risk management decisions throughout the business.

3.3 Maintain the Board’s engagement with information risk
The risks to the organisation’s information assets from a cyber attack should be a regular agenda item for Board discussion. To ensure senior ownership and oversight, the risk of cyber attack should be documented in the corporate risk register and regularly reviewed; entering into knowledge sharing partnerships with other companies and law enforcement can help you in understanding new and emerging threats that might be a risk to your own business and also to share mitigations that might work.

3.4 Produce supporting policies
An overarching corporate information risk policy needs to be created and owned by the Board to help communicate and support risk management objectives, setting out the information risk management strategy for the organisation as a whole.

3.5 Adopt a lifecycle approach to information risk management
The components of a risk can change over time so a continuous through-life process needs to be adopted to ensure security controls remain appropriate to the risk.

3.6 Apply recognised standards
Consider the application of recognised sources of security management good practice, such as the ISO/IEC 27000 series of standards, and implement physical, personnel, procedural and technical measures.

3.7 Make use of endorsed assurance schemes
Consider adopting the Cyber Essentials Scheme. It provides guidance on the basic controls that should be put in place and offers a certification process that demonstrates your commitment to cyber risk management.

3.8 Educate users and maintain their awareness
All users have a responsibility to manage the risks to the organisation’s Information and Communications Technologies (ICT) and information assets. Provide appropriate training and user education that is relevant to their role and refresh it regularly; encourage staff to participate in knowledge sharing exchanges with peers across business and Government.

3.9 Promote a risk management culture
Risk management needs to be organisation-wide, driven by corporate governance from the top down, with user participation demonstrated at every level of the business.



четвъртък, 12 март 2015 г.

INFOSEC SERVICES BG - ОСНОВНИ УСЛУГИ


ОСНОВНИ УСЛУГИ, ПРЕДОСТАВЯНИ ОТ INFOSECSERVICES BG  :

Обучение, консултации, изграждане, поддръжка и развитие на Системи за управление на качеството, информационната сигурност, ИТ услугите и непрекъснатостта на бизнеса, в съответствие с изискванията на международните стандарти:

-       ISO 9001:2008 (2015 Draft) – Системи за управление на качеството;
-       ISO 27001:2013 – Системи за управление на информационната сигурност;
-       ISO 20000-1:2011 – Системи за управление на ИТ услугите;
-       ISO 22301:2012Системи за управление на непрекъснатостта на бизнеса.

-    Услугите са приложими, както при изграждането на самостоятелни системи за управление, така и за интегрирани системи за управление, включващи каквато и да е комбинация от горепосочените стандарти.

Услугите  включват и подготовка за акредитирана сертификация на съответните системи за управление – самостоятелни или интегрирани.

За повече информация и въпроси:

0886 655 315 – Пламен Каменов


сряда, 28 януари 2015 г.


5 тенденции в информационната сигурност, които ще доминират през 2015

Експертите не очакват много нови заплахи, а по-скоро увеличаване на тяхната сложност

Публикувано в CIO - 23 януари 2015
В областта на информационната сигурност 2014 г. беше година на сякаш безкрайни събития от киберзаплахи и пробиви на данни, засегнали търговски вериги на дребно, банки, гейминг мрежи, правителства и други.
И въпреки че годината отмина, очакванията на експертите са, че размерът, обхватността и сложността на киберзаплахите ще продължава да нараства.
5 тенденции в информационната сигурност, които ще доминират през 2015Според Стийв Дърбин, управляващ директор на Information Security Forum (ISF), неправителствена организация, която оценява проблеми, свързани с управлението на сигурността и риска, цитиран от CIO.com, съществуват 5 тенденции в областта на сигурността, които ще доминират през 2015-а. "Според мен няма да съществуват голямо количество заплахи, които са изцяло нови. Това, което ще бъде ново, е увеличаването на тяхната сложност и усъвършенстваност", коментира Дърбин.
1. Киберпрестъпност
Интернет става все по-привлекателно място за криминални елементи, активисти и терористи, мотивирани да правят пари, да бъдат забелязани, да причинят прекъсване или дори да сринат изцяло корпорации и правителства чрез онлайн атаки.
Днешните киберпрестъпници често използват инструменти от 21-и век, за да атакуват системи от 20-и век. "През 2014 г. киберпрестъпниците демонстрираха висока степен на колаборация и на техническа компетентност, които завариха много големи организации неподготвени, - коментира Дърбин. – През 2015-а организациите трябва да са подготвени за непредсказуемост, така че те трябва да имат гъвкавостта да противостоят на неочаквани атаки с голямо въздействие."
Киберпрестъпниците, заедно с увеличаване популярността на онлайн каузите (хактивизъм), увеличаване на разходите за постигане на съответствие с регулаторните изисквания, и в съчетание с неумолимия напредък в технологиите на фона на инвестициите в отделите по сигурността, могат да предизвикат истинска буря в областта на заплахите. Организациите, които идентифицират на какво разчита бизнесът най-много, ще бъдат добре подготвени в преценката си на инвестиции в гъвкавост с цел минимизиране влиянието на неочаквани атаки.
2. Поверителност и регулации
Повечето правителства вече са създали или са в процес на създаване на регулации, които налагат условия за защита и използване на лична идентификационна информация, с глоби за онези организации, които не успеят достатъчно добре да защитят тази информация. Като резултат организациите трябва да се отнасят към поверителността, както към съответствието с регулаторните изисквания и проблемите, свързани с бизнес рисковете.
В същото време объркаността в регулациите по света вероятно ще увеличи натоварването върху организациите през 2015-а. "Наблюдаваме нарастващ брой планове за регулации във връзка със събирането, съхранението и използването на информацията, заедно със сериозни глоби за загуба на данни и пробиви, особено в рамките на Европейския съюз, - споделя Дърбин. – Очаквам това да продължи и да се развие в посока налагане на регулаторен мениджмънт и отвъд секюрити функциите, като задължително да обхваща правни, HR аспекти и ниво борд на директорите."
Той добавя също, че организациите трябва да гледат на действията на ЕС относно регулациите в областта на пробивите като на датчик и план съответно. Организациите трябва да имат ресурси на място, за да реагират и трябва да внимават за това какво се случва.
3. Заплахи от доставчици трети страни
Веригата на доставки е жизненоважен компонент на всяка организация с глобални бизнес операции и е гръбнакът на съвременната глобална икономика. В същото време шефовете по сигурност стават все по-съсредоточени върху това доколко системите им са отворени за редица рискови фактори. Част от ценната и чувствителна информация често се споделя с доставчици, а след като тази информация бива споделена, контролът върху нея е изгубен. Това води до увеличен риск нейната конфиденциалност, цялостност или достъпност да бъдат компрометирани.
"През следващите няколко години, доставчици трети страни ще продължат да изпитват натиск от страна на таргетирани атаки и е много малко вероятно да бъдат в състояние да предоставят сигурност на конфиденциалността, целостта и/или достъпност, - смята Дърбин. – Организации от всякакъв размер трябва да помислят за последиците от предоставяне на инцидентен, но опасен достъп до тяхната интелектуална собственост, информация за клиенти или служители, търговски планове или договори. И този начин на мислене не трябва да бъде ограничен до партньори в производството или дистрибуцията. Той трябва да включва също така вашите доставчици на професионални услуги, вашите юристи и счетоводители, всички, на които често предоставяте споделен достъп до вашите най-ценни активи от данни."
Наложително е също организациите да имат надеждни планове за непрекъсваемост на бизнеса, за да се подпомогнат както гъвкавостта, така и увереността на ръководството във възможностите за действие. Един добре структуриран подход за оценка на информационния риск при веригата за доставки може да предостави подробен подход, стъпка по стъпка, за разделяне на един иначе стряскащ проект в управляеми компоненти. Този метод би трябвало да бъде задвижван от информацията, а не ориентиран към доставчика, така че да бъде скалируем и повторяем за цялото предприятие.
4. BYOx тенденциите на работното място
Тенденцията “носи свое собствено” (BYO) е тук и ще остане независимо дали организациите харесват това или не.
"Тъй като тенденцията служителите да носят свои мобилни устройства и да достъпват приложения и облачно базирано съхранение на работното си място продължава да расте, компаниите от всички размери наблюдават разрастване експлоатирането на рисковете от атаки в информационната сигурност до размери, много по-големи от преди, - коментира Дърбин. – Тези рискове произхождат както от вътрешни, така и от външни заплахи, включително лошо управление на самите устройства, външно управление на софтуерните уязвимости и внеряване на недостатъчно добре тествани, ненадеждни бизнес приложения.”
Експертите предупреждават, че при лоша имплементация една стратетегия за персонално устройство на работното място би могла да се сблъска с инцидентно разкриване на информация поради загуба на границата между използваните служебни и лични данни и достъп до информацията по един незащитен начин на потребителските устройства.
5. Работете с хората си
И така стигаме до най-големия актив на всяка една организация и в същото време – най-уязвимата цел: хората.
През последните няколко десетилетия организациите харчеха милиони, ако не и милиарди долари за дейности по повишаване на познанията в областта на информационната сигурност. Рационалното в един такъв подход е да се обърне внимание на техния най-голям актив — хората — и да се промени тяхното поведение, като по този начин се намали рискът чрез предоставяне на служителите на знания за техните отговорности и какво те трябва да правят.
“Но това е — и ще продължава да бъде — губеща кауза, - смята Дърбин. – Вместо това организациите трябва да направят правилното поведение относно сигурността част от бизнес процеса, трансформирайки ролята на служителите от рискова в първа линия на защита в сигурността на организацията."
Вместо просто да накара хората да осъзнаят своите отговорности относно информационната сигурност и как те трябва да реагират, отговорът за бизнеса от всякакъв мащаб трябва да бъде внедряване на положителни поведения относно информационната сигурност, което ще доведе до превръщане на поведението от типа “спри и помисли" в навик и част от организационната култура в областта на информационната сигурност. Въпреки че много организации имат дейности по съответствие, които попадат под общото название “осведоменост за сигурността”, реалният комерсиален двигател би трябвало да бъде рискът и как новият тип поведение може да намали този риск, заключава експертът.

Препоръки за внедряване на добри практики за информационна сигурност


Security & Privacy Best Practices

Online Trust Alliance (OTA) publication
Released January 21, 2015 
OTA recommends that all organizations implement the following best practices:
1.    Enforce effective password management policies.  Attacks against user credentials, including brute force, sniffing, host-based access and theft of password databases, remain very strong attack vectors warranting the use of effective password management controls.  Best practices for password management include:
a.    Use multi-factor authentication (e.g. one-time PINs) for access to administratively privileged accounts. Administrative privileges should be unique accounts and monitored for anomalous activity and should be used only for administrative activities;
b.    Require users to have a unique password for external vendor systems and refrain from reusing the same password for internal system and personal website logins;
c.    Require strong passwords comprised of an 8-character minimum including a combination of alphanumeric characters, and force password changes every 90 days with limited reuse permitted;
d.    Deploy a log-in abuse detection system monitoring connections, login counts, cookies, machine IDs, and other related data;
e.    Avoid storing passwords unless absolutely necessary and only store passwords (and files) that are hashed with salt or are otherwise encrypted;
f.     Remove or disable all default accounts from all devices and conduct regular audits to ensure that inactive accounts can no longer access your infrastructure;
g.    Remove access immediately for any terminated employees or any third parties or vendors that no longer require access to your infrastructure.
 
2.    Least privilege user access (LUA) is a core security strategy component, and all accounts should run with as few privileges and access levels as possible. LUA is widely recognized as an important design consideration in enhancing data security. It also provides protections against malicious behavior and system faults. For example, a user might have privileges to edit a specific document or email campaign, but lack permissions to download payroll data or access customer lists.  Also, LUA controls help to minimize damages from exposed passwords or rogue employees.
 
3.    Harden client devices by deploying multilayered firewall protections (both client and WAN-based hardware firewalls), using up-to-date anti-virus software, disabling by default locally shared folders and removing default accounts.  Enable automatic patch management for operating systems, applications (including mobile and web apps) and add-ons. All ports should be blocked to incoming traffic by default. Disable auto-running of removable media (e.g. USB drives, external drives, etc.). Whole disk encryption should be deployed on all laptops, mobile devices and systems hosting sensitive data.
 
4.    Conduct regular penetration tests and vulnerability scans of your infrastructure in order to identify and mitigate vulnerabilities and thwart potential attack vectors.  Regularly scan your cloud providers and look for potential vulnerability points and risks of data loss or theft.  Deploy solutions to detect anomalous flows of data which will to help detect attackers staging data for exfiltration.
 
5.    Require email authentication on all inbound and outbound mail streams to help detect malicious and deceptive emails including spear phishing and spoofed email.  All organizations should:
a.    Authenticate outbound mail with SPF and DKIM, including parked and delegated sub-domains;
b.    Adopt a DMARC reject or quarantine policy once you have validated that you are authenticating all outbound mail streams;
c.    Implement inbound email authentication check for SPF, DKIM, and DMARC;
d.    Encourage business partners to authenticate all email sent to your organization to help minimize the risk of receiving spear-phishing and spoofed emails;
e.    Require end-to-end email authentication using SPF and DKIM with a DMARC reject or quarantine policy for all mail streams managed or hosted by third parties.
 
6.    Implement a mobile device management program, requiring authentication to unlock a device, locking out a device after five failed attempts, using encrypted data communications/storage, and enabling the remote wiping of devices if a mobile device is lost or stolen.
 
7.    Continuously monitor in real-time the security of your organization’s infrastructure including collecting and analyzing all network traffic in real time, and analyzing centralized logs (including firewall, IDS/IPS, VPN and AV) using log management tools, as well as reviewing network statistics.  Identify anomalous activity, investigate, and revise your view of anomalous activity accordingly.
 
8.    Deploy web application firewalls to detect/prevent common web attacks, such as cross-site scripting, SQL injection and directory traversal attacks.  Review and mitigate the top 10 list of web application security risks identified by the Open Web Application Security Project (OWASP).  If relying on third-party hosting services, require deployment of firewalls.
 
9.    Permit only authorized wireless devices to connect to your network, including point of sale terminals and credit card devices, and encrypt communications with wireless devices such as routers and printers. Keep all "guest" network access on separate servers and access devices with strong encryption such as WPA2 with AES encryption or use of an IPSec VPN.
 
10.  Implement Always On Secure Socket Layer (AOSSL) for all servers requiring log in authentication and data collection.  AOSSL helps prevent sniffing data from being transmitted between client devices, wireless access points and intermediaries.
 
11. Review server certificates for vulnerabilities and risks of your domains being hijacked.  Attackers often use “Domain Validated” (DV) SSL certificates to impersonate e-commerce websites and defraud consumers.  Sites are recommended to upgrade from DV certificates to “Organizationally Validated” (OV) or “Extended Validation” (EVSSL) SSL certificates.  OV and EV SSL certificates are validated by the Certificate Authority to ensure the identity of the applicant.  EV SSL certificates offer the highest level of authentication and verification of a website.  EVSSL provides users a higher level of assurance that the site owner is who they purport to be, presenting the user a green trust indicator in a browser’s address bar.
 

12. Develop, test and continually refine a data breach response plan. Regularly review and improve the plan based upon changes in your organization’s information technology, data collection and security posture. Take the time after an incident to conduct a post-mortem and make improvements to your plan. Conduct regular tabletop exercises testing your plan and personnel.

Данни за кибер атаки в България за 2014 год.


CERT България отчете 2949 сигнала за 
кибер атаки през 2014

CERT България регистрира през декември 319 атаки, 37 от които са определени като заплахи с много висок риск, съобщи Красимир Симонски, изпълнителен директор на ИА „Електронни съобщителни мрежи и информационни системи” (ИА ЕСМИС) при откриването на конференция по ИТ сигурност.  

Най-често срещаните кибер-атаки са зловредният код – 67%. Разпределените атаки за отказ от услуги (DDoS) са  18%, 8% са опитите за проникване, а 4% са определени като  спам.
Кибер престъпленията навлизат във все повече аспекти от нашия живот. Във фокуса им е не само икономиката, на дневен ред е и политиката. Навлизат все повече и нови играчи и вече говорим за организирана престъпност,  допълни още Симонски.  Той сподели, че в ИА ЕСМИС е внедрен специализиран софтуер, като част от защита на мрежата на агенцията, който визуализира трафика. „Картината е поразителна – мрежата гъмжи от паразити и вируси и това, че не ги виждаме с просто око, не е успокоително, защото те си вършат своята работа“, каза още изпълнителният директор на ЕСМИС. Той посочи, че механизмите на информационната сигурност трябва да навлязат в държавното управление и това не е само въпрос на технологии, но и на управленски механизми и политики.

В Националния центъра за реакции при инциденти в областта на информационната сигурност (CERT България) към ЕСМИС са постъпили и обработени 2949 сигнала за нарушения в и от българското Интернет пространство през 2014 г., обяви Васил Грънчаров, директор на CERT България.
Автоматизираните системи са подали 1832 сигнала, а 1117 са дошли от външни CERT и други организации, включително банки. Общият брой на засегнатите IP адреси е над  46 хиляди, но броят на компютрите е много по-голям тъй като зад редица IP адреси стоят компютърни мрежи с много компютри, допълни той. Важно е да се знае, че не всеки получен сигнал означава непременно инцидент, подчерта Васил Грънчаров по време на конференцията. От видовете инциденти, най-голям е делът на DDoS атаките (41%), следват зловредните кодове (35,6%), опити за проникване (4,7%) и бот мрежи (3,32%).

„Най-слабото звено в информационната сигурност е човекът, именно към хората, а не към системите са насочени повечето атаки, коментира Васил Грънчаров. ИТ системите в някои държавни структури са сертифицирани за информационна сигурност, както се изисква от приетата наредба. Сертификацията обаче не е достатъчна, тъй като в законодателството не е предвидена отговорност за нарушаване на информационната сигурност“, добави Грънчаров. Според него ситуацията с информационната сигурност е такава, че не може и не трябва да се разчита само на помощта на държавата.

$445 млрд. е приблизителната оценка на световните загуби от пробиви в ИТ сигурността, което се равнява на 0,5% до 0,8% от брутния продукт на света, заяви Вим ван Кампен, вицепрезидент на Intel Security/McAfee за Северна и Източна Европа. Според доклада на CSIS, загубите от кибер престъпления се определят много трудно, тъй като засегнатите често не съобщават за атаките, за да не пострада репутацията им и това да увеличи косвените им загуби.

„ИТ са много важни за икономиката, и в България този бранш създава много работни места. ИТ има смисъл за икономиката обаче, само ако са защитени и се ползват по правилния начин“, смята ван Кампен. Според него социалният инженеринг цели провокиране на потребителя, без значение дали атаката е насочена към отделен човек или към цяла организация, или  инфраструктура.  Идеята е, че се разчита на възможността един потребител да бъде провокиран да влезе в някакво взаимодействие с мрежата, например кликване върху един линк и пътят на атаката е отворен, коментира той.
Конференцията по ИТ сигурност бе организирана от Computer 2000 България, МТИТС и ИА ЕСМИС.
Забележка: Тази информация е публикувана на 23.01.2015 год. в списания CIO / автор - Надя Кръстева