Monday, January 4, 2016

Organizational Security (Part III)

More on Organizational Security (Part 3)
Jerry Grugin


This is the last blog on organizational security.  In this blog, I discuss environmental controls, social engineering, survey of security + acronyms.  I hope that this blog is informative and helps you with the examination.


Environmental Controls


Environmental controls are important to organizational security.  One element of environmental controls is HVAC.  Many computer systems require that the humidity and temperature be controlled for reliable service.  Any time you go into a data room or server room, typically you have environmental controls there.  The more equipment you have, the more heat that is generated.  Therefore, there is a great need for environmental controls.  Typically, we have what is called zone-based air conditioning environments which allow the system to be turned off when the building is not occupied.  The environmental controls need to be monitored to ensure that humidity levels do not get too low.  If humidity gets too low, there is the risk of electrostatic damage due to electrostatic discharge.


Along with environmental controls are issues of water or flood damage.  We need environmental systems to detect and control these issues.  We also need to protect against fire.  Therefore, there is a need for a fire suppression system.  All computer rooms, server rooms, and data centers should have fire suppression systems and moisture detectors.  Just the smoke particles from a small fire can cause computer damage by smoke particles getting into the rewrite heads of hard disks.  This has the potential to cause massive data loss.  The three components of a fire are heat, fuel, and oxygen.  So, if any component is removed, a fire is not possible.  Most fire suppression systems work on the concept which revolves around removing one of the components of fire, without which the fire is not possible.  Another concept to be aware of is shielding.  Shielding is the process of preventing electronic emissions from your computer system from being used to gather intelligence or reconnaissance.  Designed to prevent outside electronic emissions from disrupting your activities.  Many times, in a fixed facility, the room will be surrounded with a Faraday cage.  A Faraday cage provides electronic shielding.  Devices generating EMI should be as physically separated from cables as possible.  A motor that is generating EMI's can actually disrupt data signals.

Social Engineering

Social engineering is a form of a possible attack on a computer system.  We need to be aware of this in order to mitigate social engineering tactics.  Training, awareness, and new-hire orientation should make a new employee aware of the dangers and prevalence of social engineering.  Social engineering involves concepts such as phishing, Hoaxes, shoulder surfing. 


Helpful Acronyms


3DES              Triple Digital Encryption Standard


ACL               Access Control List


AES                Advanced Encryption Standard


AES256          Advanced Encryption Standard 256 bit


AH                  Authentication Header


ALE                Annualized Loss Expectancy


ARO               Annualized Rate of Occurrence


ARP                Address Resolution Protocol


AUP                Acceptable Use Policy


BIOS               Basic Input / Output System


BOTS             Network Robots


CA                  Certificate Authority


CAN               Controller Area Network


CCTV            Closed Circuit Television


CHAP             Challenge Handshake Authentication Protocol


CRL               Certification Revocation List


DAC               Discretionary Access Control


DDOS             Distributed Denial of Service


DES                Digital Encryption Standard


DHCP             Dynamic Host Configuration Protocol


DLL                Dynamic Link Library


DMZ               Demilitarized Zone


DNS                Domain Name Server


DOS                Denial of Service


These are just a few acronyms.  There are more which will be listed in a separate blog.

No comments:

Post a Comment