Security
  Home arrow Security arrow Page 5 - Security Management Architecture
Dev Shed Forums 
Administration  
Apache  
BrainDump  
DHTML  
Flash  
Java  
JavaScript  
Multimedia  
MySQL  
Oracle  
Perl  
PHP  
Practices  
Python  
Reviews  
Security  
Style-Sheets  
Web Services  
XML  
Zend  
Zope  
Forums Sitemap 
IBM® developerWorks 
Dedicated Servers 
E-Commerce Hosting 
Linux Web Hosting 
Managed Hosting 
Small Business Hosting 
Download TestComplete 
VPS Hosting 
Weekly Newsletter

 
Developer Updates  
Free Website Content 
 RSS  Articles
 RSS  Forums
 RSS  All Feeds
Write For Us Get Paid 
Request Media Kit
Contact Us 
Site Map 
Privacy Policy 
Support 
 USERNAME
 
 PASSWORD
 
 
  >>> SIGN UP!  
  Lost Password? 
SECURITY

Security Management Architecture
By: McGraw-Hill/Osborne
  • Search For More Articles!
  • Disclaimer
  • Author Terms
  • Rating: 3 stars3 stars3 stars3 stars3 stars / 5
    2004-05-11

    Table of Contents:
  • Security Management Architecture
  • Examples of AUP Enforcement Wording
  • Developing AUP Enforcement Policy Text
  • Enforcement Processing
  • Administrative Security
  • Management Practices
  • Activity Monitoring and Audit
  • A System and Device Log File Example (Windows)
  • System and Network Activity Monitoring

  • Rate this Article: Poor Best 
      ADD THIS ARTICLE TO:
      Del.ici.ous Digg
      Blink Simpy
      Google Spurl
      Y! MyWeb Furl
    Email Me Similar Content When Posted
    Add Developer Shed Article Feed To Your Site
    Email Article To Friend
    Print Version Of Article
    PDF Version Of Article
     
     
     
    ADVERTISEMENT

    Stay one step ahead of the competition. Evaluate and give feedback on some of the hottest web development tools on the market today. Make your opinion heard! Click Here

    Security Management Architecture - Administrative Security
    (Page 5 of 9 )

    When considering controls that determine the availability and integrity of computing systems, data, and networks, consider the potential opportunities an authorized administrator has as compared to the ordinary user. Systems administrators, operators who perform backup, database administrators, maintenance technicians, and even help desk support personnel, all have elevated privileges within your network. To ensure the security of your systems, you must also consider the controls that can prevent administrative abuse of privilege. Remember, strong controls over the day-to-day transactions and data uses of your organization cannot in themselves ensure integrity and availability. If the controls over the use of administrative authority are not strong as well, the other controls are weakened as well.

    In addition to directly controlling administrative privilege, several management practices will help secure networks from abuse and insecure practices.

    Preventing Administrative Abuse of Power

    Two principles of security will help you avoid abuse of power: limiting authority and separation of duties.

    Limiting Authority

    You can limit authority by assigning each IT employee only the authority needed to do their job. Within the structure of your IT infrastructure are different systems, and each can be naturally segmented into different authority categories. Examples of such segmentation are network infrastructure, appliances, servers, desktops, and laptops.

    Another way to distribute authority is between service administration and data administration. Service administration is that which controls the logical infrastructure of the network, such as domain controllers and other central administration servers. These administrators manage the specialized servers on which these controls run, segment users into groups, assign privileges, and so on. Data administrators, on the other hand, manage the file, database, web content, and other servers. Even within these structures, authority can be further broken down? -- that is, roles can be devised and privileges limited. Backup operators of file servers should not be the same individuals that have privileges to back up the database server. Database administrators may be restricted to certain servers, as may file and print server administrators.

    In the large enterprises, these roles can be subdivided ad infinitum: some help desk operators may have the authority to reset accounts and passwords, while others are restricted to helping run applications. The idea, of course, is to recognize that all administrators with elevated privileges must be trusted, but some should be trusted more than others. The fewer the number of individuals that have all-inclusive or wide-ranging privileges, the fewer that can abuse those privileges.

    Separation of Duties

    Another control is separation of duties. In short, if a critical function can be broken into two or more parts, divide the duties among IT roles. If this is done, abuses of trust would require collaboration and, therefore, will be less likely to occur. The classic example of this separation is the following rule: developers develop software, and administrators install and manage it on systems. This means that developers do not have administrative privileges on production systems. If a developer were to develop malicious code, she would not have the ability to launch it, on her own, in the production network. She would have to coerce, trick, or be in collusion with an administrator. She might also attempt to hide the code in customized, in-house software; however other controls, including software review and the fact that others work on the software, mean that there is a good chance of discovery, or at least, perhaps, enough of a chance to deter many attempts.

    Even on the administration side, many roles can be so split. Take, for example, the privilege of software backup. Should these individuals also have the right to restore software? In many organizations these roles are split. A backup operator cannot accidentally or maliciously restore old versions of data, thus damaging the integrity of databases and causing havoc. 

    Remember: this chapter is from Network Security: The Complete Reference, by Mark Rhodes-Ousley, Roberta Bragg and Keith Strassberg (McGraw-Hill/Osborne, ISBN 0-072-22697-8, 2003).

    Buy this book now

    More Security Articles
    More By McGraw-Hill/Osborne


     

       

    SECURITY ARTICLES

    - An Epilogue to Cryptography
    - A Sequel to Cryptography
    - An Introduction to Cryptography
    - Security Overview
    - Network Security Assessment
    - Firewalls
    - What’s behind the curtain? Part II
    - What’s behind the curtain? Part I
    - Vectors
    - PKI: Looking at the Risks
    - A Quick Look at Cross Site Scripting
    - PKI Architectures: How to Choose One
    - Trust, Access Control, and Rights for Web Se...
    - Basic Concepts of Web Services Security
    - Safeguarding the Identity and Integrity of X...

     
    Accelerating Trading Partner Performance
     
    Competing on Analytics
     
    Cost Effective Scaling with Virtualization and Coyote Point Systems
     
    Five Checkpoints to Implementing IP Telephony
     
    Hosted Email Security: Staying Ahead of New Threats
     




    © 2003-2008 by Developer Shed. All rights reserved. DS Cluster 6 hosted by Hostway