Translate

петък, 26 юни 2015 г.

Кибер разузнаване - оперативно ниво за действие



INTELLIGENCE AND NATIONAL SECURITY ALLIANCE CYBER INTELLIGENCE (INSA) TASK FORCE - USA

OCTOBER 2014
 www.insaonline.org | 703.224.4672

OPERATIONAL CYBER INTELLIGENCE

THE THIRD WHITE PAPER IN THE “LEVELS OF CYBER INTELLIGENCE” SERIES 

While much attention has been paid to cyber attacks against organizations of all sizes and from across all sectors, there has been less discussion of how organizations can strengthen their risk management processes in such a diverse and evolving threat climate. Operational cyber intelligence encompasses an understanding of both tactical means – how cyber threats function to disrupt and/or degrade an organization’s networks and cyber capabilities – and the broader strategic motivations of potential adversaries. This intelligence can inform senior leadership and help executives and managers develop strategic plans and policies that allow an organization to operate while navigating countless cyber threats. 
Specifically, this white paper examines: 

• How operational cyber intelligence seeks to protect the enterprise by facilitating predictive analysis and a more comprehensive understanding of specific threats;
 • Business and mission considerations for operational cyber intelligence; and 
• Workforce and skill sets necessary to support the cyber intelligence role. 

While tactical cyber intelligence is directed at efforts to detect and respond to adversaries already operating within an organization’s network, operational cyber intelligence protects the enterprise by facilitating predictive analysis of specific threat actors before they gain access. The ultimate goal of a cyber intelligence program is to reduce risk to an organization’s critical information, intellectual property and ability to successfully conduct its mission. 

Operational cyber intelligence does this by: 
1. Defining the operating environment.
2. Describing the impact of the operating environment. 
3. Evaluating the adversary. 
4. Determining adversaries’ potential courses of action. 

Operational cyber intelligence provides a thread that links the probability and impact of a cyber attack with its strategic-level implications. The result is a coherent framework for analysis and prioritization of potential threats and vulnerabilities given an organization’s threat environment. 

Operational Cyber Intelligence is the third in the INSA white paper series on levels of cyber intelligence. The series began with the overview paper, Operational Levels of Cyber Intelligence, in September 2013, followed by Strategic Cyber Intelligence in March 2014. The next installment on tactical cyber intelligence will be published in early 2015.

Връзка за достъп до целия документ:
http://www.insaonline.org/i/d/a/Resources/OCI_wp.aspx

Кибер разузнаване - стратегическо ниво за действие



INTELLIGENCE AND NATIONAL SECURITY ALLIANCE CYBER INTELLIGENCE (INSA) TASK FORCE - USA

MARCH 2014
 www.insaonline.org | 703.224.4672

STRATEGIC CYBER INTELLIGENCE

CYBER INTELLIGENCE TASK FORCE WHITE PAPER SYNOPSIS 

The Intelligence and National Security Alliance (INSA) Cyber Intelligence Task Force defined the strategic, operational, and tactical levels of Cyber Intelligence in its white paper The Operational Levels of Cyber Intelligence. While much attention has been directed towards the tactical, on-the-network cyber domain, this paper contends that not enough resources have been devoted to strategic cyber intelligence. The fundamental purpose of this white paper is to promote thought and dialogue on the importance of cyber intelligence, and specifically strategic cyber intelligence, to senior leaders’ risk-informed decision making, ultimately leading to improved strategy, policy, architecture, and investment. 

The paper discusses the: 
• Nexus between strategic cyber intelligence and risk management in relation to strategic cyber intelligence consumer and producer roles and responsibilities. 
• Role of strategic cyber intelligence analysis based upon the National Institute of Standards and Technology (NIST) risk assessment methods: vulnerability-based, threat-based, and impact-based. 
• Inextricable linkage between intelligence production and information sharing. 

Strategic Cyber Intelligence offers senior leaders an accurate assessment of how to direct cyber-related expenses in line with an organization’s risk heuristic. Leveraging Strategic Cyber Intelligence to address strategic information requirements allows an organization to: 
• Effectively assess, explain, and quantify risk to senior management and other key stakeholders. 
• Collaborate in a more meaningful manner with members of law enforcement, defense organizations, the intelligence community, and the information security community on interests at large. 
• Demonstrate an appropriate standard of diligence to auditors, regulators, and stakeholders.
 • Reduce the exposure of the business to regulatory or legal sanctions. 
• Demonstrate responsible security resource expenditure by defending not just what is important to the firm but what is relevant to the threat. 

The ultimate goal of a such a program is to reduce risk to an organization’s critical mission and assets. It enables senior leadership to make informed decisions and proactively defend the enterprise. To succeed in the cyber domain in 2014 and beyond, strategic cyber intelligence will play a crucial role in defending private companies and government sectors by providing the necessary intelligence to prevent potential incidents that could cripple our security as well as our economy.

Връзка за достъп да целия документ:
http://www.insaonline.org/i/d/a/Resources/StrategicCyber.aspx

Кибер разузнаване - нива за действия



INTELLIGENCE AND NATIONAL SECURITY ALLIANCE CYBER INTELLIGENCE (INSA) TASK FORCE - USA

SEPTEMBER 2013
 www.insaonline.org | 703.224.4672

OPERATIONAL LEVELS OF CYBER INTELLIGENCE

CYBER INTELLIGENCE WHITE PAPER SYNOPSIS 

The purpose of the INSA white paper, Operational Levels of Cyber Intelligence, is to explore cyber intelligence as a disciplined methodology with understandable frames of reference that address both the human and technical aspects of the cyber domain. All operations in cyberspace begin with a human being; therefore, cyber intelligence should not be limited to an understanding of network operations and activities. Rather, it is an analytic discipline relying on information collected from traditional intelligence sources intended to inform decision makers on issues pertaining to operations at all levels in the cyber domain. Embracing these concepts helps one understand the steps required to develop malicious cyber actions and points toward a process that can assist network defenders in understanding the kill chain process used to deter, neutralize or defeat malicious network activity. 

The Three Levels of Cyber Activities:

Strategic: The guidance and determination of objectives by the highest organizational entity and its use of the organization’s resources toward the achievement of these objectives. Intelligence must be included in the calculus so that strategic-level decision makers can understand the threats that may inhibit or prevent obtaining their strategic objectives. 

Operational: This level affords opportunity to design defenses, based upon intelligence, against the threats actively, or most likely to, target an organization’s network and data. The more informed CISOs and CIOs are on the objectives and capabilities of malicious actors, the better they are able to posture their enterprise to defend against threats. 

Tactical: Activities at this level focus on the ordered arrangement and maneuver of elements in relation to each other and to the enemy to achieve objectives. Typical tactical actions are primarily conducted in the Network Operations Center or Security Operations Center and operate best when informed by intelligence. Pre-coordination and advanced warning alone may make the difference between critical web support services being available or not.

 Conclusions:

 • Defining the cyber “lay of the land” in manageable levels—strategic, operational, and tactical—and integrating sound intelligence methodology into the equation, makes it easier for organizations to address the challenge of cyber security. 

• Supporting the three-level spectrum of requirements also necessitates cyber intelligence analysts understand the human element: adversaries’ intentions, how they plan, coordinate and execute and what motivates them towards action or inaction. 

• While the movement of malicious files occurs in milliseconds, or at the “speed of cyber,” the human-enabled activities necessary to execute malicious cyber operations take careful planning and an investment of time. A kill chain is a sequence of activities and overall operations that a threat vector must traverse in order to cause an effect. Thus, defenders need to expand their understanding of the kill chain beyond merely the network activity. 

• Once an adversary is identified and understood, the challenge is to provide decision makers at every level with the information needed and the tactics necessary to collect, integrate and make accessible the intelligence required to act against malicious network activity.

Връзка за достъп до целия документ:
http://www.insaonline.org/i/d/a/Resources/CyberIntel_WP.aspx


понеделник, 22 юни 2015 г.

Управление на сменяеми носители на данни / информация



Guidance
10 Steps: Removable Media Controls

From: UK CESG, Department for Business, Innovation & Skills, Cabinet Office and Centre for the Protection of National Infrastructure
First published: 5 September 2012
Last updated: 16 January 2015 


1.Summary
Failure to control or manage the use of removable media can lead to material financial loss, the theft of information, the introduction of malware and the erosion of business reputation. It is good practice to carry out a risk benefit analysis of the use of removable media and apply appropriate and proportionate security controls, in the context of their business and risk appetite.

2.What is the risk?
The use of removable media to store or transfer significant amounts of personal and commercially sensitive information is an everyday business process. However, if organisations fail to control and manage the import and export of information from their Information and Communications Technologies (ICT) using removable media they could be exposed to the following risks:

Loss of information
The physical design of removable media can result in it being misplaced or stolen, potentially compromising the confidentiality and availability of the information stored on it
Introduction of malware
The uncontrolled use of removable media will increase the risk from malware if the media can be used on multiple ICT systems
Information leakage
Some media types retain information after user deletion; this could lead to an unauthorised transfer of information between systems
Reputational damage
A loss of sensitive data often attracts media attention which could erode customer confidence in the business
Financial loss
If sensitive information is lost or compromised the organisation could be subjected to financial penalties

3.How can the risk be managed?
Removable media should only be used to store or transfer information as a last resort, under normal circumstances information should be stored on corporate systems and exchanged using appropriately protected and approved information exchange connections.

3.1Produce corporate policies
Develop and implement policies, processes and solutions to control the use of removable media for the import and export of information.

3.2Limit the use of removable media
Where the use of removable media is unavoidable the business should limit the media types that can be used together with the users, systems and types of information that can be stored or transferred on removable media.

3.3Scan all media for malware
Protect all host systems (clients and servers) with an anti-virus solution that will actively scan for malware when any type of removable media is introduced. The removable media policy should also ensure that any media brought into the organisation is scanned for malicious content by a standalone media scanner before any data transfer takes place.

3.4Audit media holdings regularly
All removable media should be formally issued by the organisation to individuals who will be accountable for its secure use and return for destruction or reuse. Records of holdings and use should be made available for audit purposes.

3.5Encrypt the information held on the media
Where removable media has to be used, the information should be encrypted. The type of encryption should be proportionate to the value of the information and the risks posed to it.

3.6Lock down access to media drives
The secure baseline build should deny access to media drives (including USB drives) by default and only allow access to approved authorised devices.

3.7Monitor systems
The monitoring strategy should include the capability to detect and react to the unauthorised use of removable media within an acceptable time frame.

3.8Actively manage the reuse and disposal of removable media
Where removable media is to be reused or destroyed then appropriate steps should be taken to ensure that previously stored information will not be accessible. The processes will be dependent on the value of the information and the risks posed to it and could range from an approved overwriting process to the physical destruction of the media by an approved third party.

3.9Educate users and maintain their awareness
Ensure that all users are aware of the risks posed to the organisation from the use of removable media and their personal security responsibility for following the corporate removable media security policy.

сряда, 17 юни 2015 г.

Препоръки за провеждане на наблюдение по сигурността на ИТ системите



Guidance
10 Steps: Monitoring

From: UK CESG, Department for Business, Innovation & Skills, Cabinet Office and Centre for the Protection of National Infrastructure
First published: 5 September 2012
Last updated: 16 January 2015 


1.Summary
Monitoring Information and Communications Technologies (ICT) activity allows businesses to better detect attacks and react to them appropriately whilst providing a basis upon which lessons can be learned to improve the overall security of the business. In addition, monitoring the use of ICT systems allows the business to ensure that systems are being used appropriately in accordance with organisational policies. Monitoring is often a key capability needed to comply with security, legal and regulatory requirements.

2.What is the risk?
Monitoring the organisation’s ICT systems provides the business with the means to assess how they are being used by authorised users and if they have been or are being attacked. Without the ability to monitor, an organisation will not be able to:
Detect attacks
Either originating from outside the organisation or attacks as a result of deliberate or accidental insider activity
React to attacks
So that an appropriate and proportionate response can be taken to prevent or minimise the resultant impact of an attack on the business
Account for activity
The business will not have a complete understanding of how their ICT systems or information assets are being used or enforce user accountability
Failure to monitor ICT systems and their use for specific business processes could lead to non-compliance with the corporate security policy and legal or regulatory requirements or result in attacks going unnoticed.

3.How can the risk be managed?
Businesses need to put strategies, policies, systems and processes in place to ensure that they are capable of monitoring their ICT systems and respond appropriately to attacks. A consistent approach to monitoring needs to be adopted across the business that is based on a clear understanding of the risks.

3.1Establish a monitoring strategy and supporting policies
Develop and implement an organisational monitoring strategy and policy based on an assessment of the risks. The strategy should take into account any previous security incidents and attacks and align with the organisation’s incident management policies.

3.2Monitor all ICT systems
Ensure that the solution monitors all networks and host systems (such as clients and servers) potentially through the use of Network and Host Intrusion Detection Systems (NIDS/HIDS) and Prevention Solutions (NIPS/HIPS), supplemented as required by Wireless Intrusion Detection Systems (WIDS). These solutions should provide both signature based capabilities to detect known attacks and heuristic capabilities to detect potentially unknown attacks through new or unusual system behaviour.

3.3Monitor network traffic
The inbound and outbound network traffic traversing network boundaries should be continuously monitored to identify unusual activity or trends that could indicate attacks and the compromise of data. The transfer of sensitive information, particularly large data transfers or unauthorised encrypted traffic should automatically generate a security alert and prompt a follow up investigation. The analysis of network traffic can be a key tool in preventing the loss of data.

3.4Monitor all user activity
The monitoring capability should have the ability to generate audit logs that are capable of identifying unauthorised or accidental input, misuse of technology or data. Critically, it should be able to identify the user, the activity that prompted the alert and the information they were attempting to access.

3.5Test legal compliance
Ensure that the monitoring processes comply with legal or regulatory constraints on the monitoring of user activity.

3.6Fine-tune monitoring systems
Ensure that monitoring systems are fine-tuned appropriately only to collect logs, events and alerts that are relevant in the context of delivering the requirements of the monitoring policy. Inappropriate collection of monitoring information could breach data protection and privacy legislation. It could also be costly in terms storing the audit information and could hinder the efficient detection of real attacks.

3.7Establish a centralised collection and analysis capability
Develop and deploy a centralised capability that can collect and analyse accounting logs and security alerts from ICT systems across the organisation, including user systems, servers, network devices, and including security appliances, systems and applications. Much of this should be automated due to the volume of data involved enabling analysts to quickly identify and investigate anomalies. Ensure that the design and implementation of the centralised solution does not provide an opportunity for attackers to bypass normal network security and access controls.

3.8Ensure there is sufficient storage
Security managers should determine the types of information needed to satisfy the organisation’s monitoring policy. Vast quantities of data can be generated and appropriate storage will need to be made available. The organisation will also need to consider the sensitivity of the processed audit logs and any requirement for archiving to satisfy any regulatory or legal requirements.

3.9Provide resilient and synchronised timing
Ensure that the monitoring and analysis of audit logs is supported by a centralised and synchronised timing source that is used across the entire organisation to time-stamp audit logs, alerts and events to support incident response, security investigations and disciplinary or legal action.

3.10Train the security personnel
Ensure that security personnel receive appropriate training on the deployment of monitoring capability and the analysis of security alerts, events and accounting logs.

3.11Align the incident management policies
Ensure that policies and processes are in place to appropriately manage and respond to incidents detected by monitoring solutions.

3.12Conduct a lessons learned review
Ensure that processes are in place to test monitoring capabilities and learn from security incidents and improve the efficiency of the monitoring capability.

събота, 13 юни 2015 г.

Превантивни мерки срещу зловреден код




Guidance
10 Steps: Malware Prevention


From: UK CESG, Department for Business, Innovation & Skills, Cabinet Office and Centre for the Protection of National Infrastructure
First published: 5 September 2012
Last updated: 16 January 2015 

1.Summary
Any information exchange carries a degree of risk as it could expose the organisation to malicious code and content (malware) which could seriously damage the confidentiality, integrity and availability of the organisation’s information and Information and Communications Technologies (ICT) on which it is hosted. The risk may be reduced by implementing security controls to manage the risks to all business activities.

2.What is the risk?
Malware infections can result in the disruption of business services, the unauthorised export of sensitive information, material financial loss and legal or regulatory sanctions. The range, volume and originators of information exchanged with the business and the technologies that support them provide a range of opportunities for malware to be imported. Examples include:
Email
Still provides the primary path for internal and external information exchange. It can be used for targeted or random attacks (phishing) through malicious file attachments that will release their payload when the file is opened or contain embedded links that redirect the recipient to a website that then downloads malicious content
Web browsing and access to social media
Uncontrolled browsing, including access to social media websites and applications, could provide an opportunity for an attacker to direct malicious content to a individual user or lead to the download of malicious content from a compromised or malicious website
Removable media and personally owned devices
Malware can be transferred to a corporate ICT system through the use of removable media or the connection of a personally owned device

3.How can the risk be managed?
3.1Develop and publish corporate policies
Develop and implement policies, standards and processes that deliver the overall risk management objectives but directly address the business processes that are vulnerable to malware.

3.2Establish anti-malware defences across the organisation
Agree a top level corporate approach to managing the risk from malware that is applicable and relevant to all business areas.

3.3Scan for malware across the organisation
Protect all host and client machines with antivirus solutions that will actively scan for malware.

3.4Manage all data import and export
All information supplied to or from the organisation electronically should be scanned for malicious content.

3.5Blacklist malicious websites
Ensure that the perimeter gateway uses blacklisting to block access to known malicious websites.

3.6Provide dedicated media scanning machines
Standalone workstations (with no network connectivity) should be provided and equipped with two antivirus products. The workstation should be capable of scanning the content contained on any type of media and, ideally, every scan should be traceable to an individual.

4.Establish malware defences
Malware can attack any system process or function so the adoption of security architecture principles that provide multiple defensive layers (defence-in-depth) should be considered. The following controls are considered essential to manage the risks from malware:

Deploy antivirus and malicious code checking solutions with capabilities to continuously scan inbound and outbound objects at the perimeter, on internal networks and on host systems, preferably using different products at each layer. This will increase detection capabilities whilst reducing risks posed by any deficiencies in individual products. Any suspicious or infected objects should be quarantined for further analysis

Deploy a content filtering capability on all external gateways to try to prevent attackers delivering malicious code to the common desktop applications used by the user, the web browser being a prime example. Content filtering can also help to counter the risks from a compromised information release mechanism or authorisation process that may allow sensitive data to be sent to external networks

Install firewalls on the host and gateway devices and configure them to deny traffic by default, allowing only connectivity associated with known white listed applications

If the business processes can support it, disable scripting languages such as Windows Scripting, Active X, VBScript and JavaScript

Where possible, disable the auto run function to prevent the automatic import of malicious code from any type of removable media. Equally, if removable media is introduced, the system should automatically scan it for malicious content

Regularly scan every network component and apply security patches in compliance with the corporate security patching and vulnerability management policy

Apply the secure baseline build to every network device and mobile platform

5.User education and awareness
Users should understand the risks from malware and the day to day secure processes they need to follow to prevent a malware infection from occurring. The security operating procedures for the corporate desktop should contain the following:
Comply with the removable media policy at all times
Do not open attachments from unsolicited emails
Do not click on hyperlinks in unsolicited emails
Do not connect any unapproved removable media or any unapproved personally owned device to the corporate network. For more information consult the BYOD Guidance at https://gov.uk/cesg/byod-guidance
Report any strange or unexpected system behaviours to the appropriate security team
Maintain an awareness of how to report a security incident

четвъртък, 11 юни 2015 г.

Препоръки за основни стъпки при управлението на инциденти, свързани с информационната сигурност.



Guidance
10 Steps: Incident Management

From: UK CESG, Department for Business, Innovation & Skills, Cabinet Office and Centre for the Protection of National Infrastructure
First published: 5 September 2012
Last updated: 16 January 2015 

1.Summary
All organisations will experience an information security incident at some point. Investment in establishing effective incident management policies and processes will help to improve resilience, support business continuity, improve customer and stakeholder confidence and reduce any financial impact.

2.What is the risk?
Security incidents are inevitable and they will vary in their business impact. All incidents need to be effectively managed, particularly those that invoke the organisation’s disaster recovery and business continuity plans. Some incidents can, on further analysis, be indicative of more severe underlying problems.
If businesses fail to implement an incident management capability that can detect, manage and analyse security incidents the following risks could be realised:
A major disruption of business operations
Failure to realise that an incident has occurred and manage it effectively may compound the impact of the incident, leading to a long term outage, serious financial loss and erosion of customer confidence
Continual business disruption
An organisation that fails to address the root cause of incidents by addressing weaknesses in the corporate security architecture could be exposed to consistent and damaging business disruption
Failure to comply with legal and regulatory reporting requirements
An incident resulting in the compromise of sensitive information covered by mandatory reporting controls that are not adhered to could lead to legal or regulatory penalties
The organisation’s business profile will determine the type and nature of incidents that may occur, and the impact they will have, and so a risk-based approach that considers all business processes should be used to shape the incident management plans. In addition, the quality and effectiveness of the security policies and the standards applied by the organisation will also be contributing factors to preventing incidents.

3.How can the risk be managed?
3.1Obtain senior management approval and backing
The organisation’s Board needs to understand the risks and benefits of incident management and provide appropriate funding to resource it and lead the delivery.

3.2Establish an incident response capability
The organisation should identify the funding and resources to develop, deliver and maintain an organisation-wide incident management capability that can address the full range of incidents that could occur. This capability could be outsourced to a reputable supplier, such as those on the Cyber Incident Response (CIR) scheme. The supporting policy processes and plans should be risk based and cover any legal and regulatory reporting or data accountability requirements.

3.3Provide specialist training
The incident response team may need specialist knowledge and expertise across a number of technical (including forensic investigation) and non-technical areas. The organisation should identify recognised sources of specialist incident management training and maintain the organisation’s skill base.

3.4Define the required roles and responsibilities
The organisation needs to appoint and empower specific individuals (or suppliers) to handle ICT incidents and provide them with clear terms of reference to manage any type of incident that may occur.

3.5Establish a data recovery capability
Data losses occur and so a systematic approach to the backup of the corporate information asset base should be implemented. Backup media should be held in a physically secure location on-site and off-site where at all possible and the ability to recover archived data for operational use should be regularly tested.

3.6Test the incident management plans
All plans supporting security incident management (including Disaster Recover and Business Continuity) should be regularly tested. The outcome of the tests should be used to inform the development and gauge the effectiveness of the incident management plans.

3.7Decide what information will be shared and with whom
For information bound by specific legal and regulatory requirements the organisation may have to report any incidents that affect the status of that information within a specific timeframe. All internal and external reporting requirements should be clearly identified in the Incident Management Plans.

3.8Collect and analyse post-incident evidence
The preservation and analysis of the user or network activity that led up to the event is critical to identify and remedy the root cause of an incident. The collected evidence could potentially support any follow on disciplinary or legal action and the incident management policy needs to set out clear guidelines to follow that comply with a recognised code of practice.

3.9Conduct a lessons learned review
Log the actions taken during an incident and review the performance of the incident management process post incident (or following a test) to see what aspects worked well and what could be improved. Review the organisational response and update any related security policy, process or user training that could have prevented the incident from occurring.

3.10Educate users and maintain their awareness
All users should be made aware of their responsibilities and the procedures they should follow to report and respond to an incident. Equally, all users should be encouraged to report any security weaknesses or incident as soon as possible and without fear of recrimination.

3.11Report criminal incidents to Law Enforcement
It is important that online crimes are reported to Action Fraud or the relevant law enforcement agency to build a clearer view of the national threat picture and deliver an appropriate response