· 9 years ago · May 27, 2017, 01:16 PM
1For Amy, the day began like any other at the Sequential Label and Supply Company
2(SLS) help desk. Taking calls and helping office workers with computer problems was not
3glamorous, but she enjoyed the work; it was challenging and paid well enough. Some of her
4friends in the industry worked at bigger companies, some at cutting-edge tech companies,
5but they all agreed that jobs in information technology were a good way to pay the bills.
6The phone rang, as it did about four times an hour. The first call of the day, from a worried
7user hoping Amy could help him out of a jam, seemed typical. The call display on her mon-
8itor showed some of the facts: the user’s name, his phone number and department, where
9his office was on the company campus, and a list of his past calls to the help desk.
10“Hi, Bob,†she said. “Did you get that document formatting problem squared away?â€
11“Sure did, Amy. Hope we can figure out what’s going on this time.â€
12“We’ll try, Bob. Tell me about it.â€
13“Well, my PC is acting weird,†Bob said. “When I go to the screen that has my e-mail
14program running, it doesn’t respond to the mouse or the keyboard.â€
15“Did you try a reboot yet?â€
161
17Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
18Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
19“Sure did. But the window wouldn’t close, and I had to turn my PC off. After it restarted, I
20opened the e-mail program, and it’s just like it was before—no response at all. The other
21stuff is working OK, but really, really slowly. Even my Internet browser is sluggish.â€
22“OK, Bob. We’ve tried the usual stuff we can do over the phone. Let me open a case, and
23I’ll dispatch a tech over as soon as possible.â€
24Amy looked up at the LED tally board on the wall at the end of the room. She saw that
25only two technicians were dispatched to user support at the moment, and since it was the
26day shift, four technicians were available. “Shouldn’t be long at all, Bob.â€
27She hung up and typed her notes into ISIS, the company’s Information Status and Issues
28System. She assigned the newly generated case to the user dispatch queue, which would page
29the roving user support technician with the details in a few minutes.
30A moment later, Amy looked up to see Charlie Moody, the senior manager of the server
31administration team, walking briskly down the hall. He was being trailed by three of his
32senior technicians as he made a beeline from his office to the room where the company
33servers were kept in a carefully controlled environment. They all looked worried.
34Just then, Amy’s screen beeped to alert her of a new e-mail. She glanced down. The screen
35beeped again—and again. It started beeping constantly. She clicked the envelope icon and,
36after a short delay, the mail window opened. She had 47 new e-mails in her inbox. She
37opened one from Davey Martinez in the Accounting Department. The subject line said,
38“Wait till you see this.†The message body read, “Funniest joke you’ll see today.†Davey
39often sent her interesting and funny e-mails, and she clicked the file attachment icon to open
40the latest joke.
41After that click, her PC showed the hourglass pointer icon for a second and then the normal
42pointer reappeared. Nothing happened. She clicked the next e-mail message in the queue.
43Nothing happened. Her phone rang again. She clicked the ISIS icon on her computer desk-
44top to activate the call management software and activated her headset. “Hello, Help Desk,
45how can I help you?†She couldn’t greet the caller by name because ISIS had not responded.
46“Hello, this is Erin Williams in Receiving.â€
47Amy glanced down at her screen. Still no ISIS. She glanced up to the tally board and was
48surprised to see the inbound-call counter tallying up waiting calls like digits on a stopwatch.
49Amy had never seen so many calls come in at one time.
50“Hi, Erin,†Amy said. “What’s up?â€
51“Nothing,†Erin answered. “That’s the problem.†The rest of the call was a replay of Bob’s,
52except that Amy had to jot notes down on a legal pad. She couldn’t dispatch the user
53support team either. She looked at the tally board. It had gone dark. No numbers at all.
54Then she saw Charlie running down the hall from the server room. His expression had
55changed from worried to frantic.
56Amy picked up the phone again. She wanted to check with her supervisor about what to do
57now. There was no dial tone.
582 Chapter 1
59Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
60Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
611
62LEARNING OBJECTIVES:
63Upon completion of this material, you should be able to:
64• Define information security
65• Recount the history of computer security, and explain how it evolved into information security
66• Define key terms and critical concepts of information security
67• List the phases of the security systems development life cycle
68• Describe the information security roles of professionals within an organization
69Introduction
70JamesAnderson, executiveconsultantatEmagined Security, Inc., believesinformationsecurityin
71an enterprise is a “well-informed sense of assurance that the information risks and controls are in
72balance.†He is not alone in his perspective. Many information security practitioners recognize
73that aligning information security needs with business objectives must be the top priority.
74For more information on Emagined Security Consulting, visit www.emagined.com.
75This chapter’s opening scenario illustrates that information risks and controls may not be in
76balance at SLS. Though Amy works in a technical support role to help users with their prob-
77lems, she did not recall her training about malicious e-mail attachments, such as worms or
78viruses, and fell victim to this form of attack herself. Understanding how malware might be
79the cause of a company’s problems is an important skill for information technology (IT) sup-
80port staff as well as users. SLS’s management also shows signs of confusion and seems to have
81no idea how to contain this kind of incident. If you were in Amy’s place and were faced with
82a similar situation, what would you do? How would you react? Would it occur to you that
83something far more insidious than a technical malfunction was happening at your company?
84As you explore the chapters of this book and learn more about information security, you will
85become more capable of answering these questions. But, before you can begin studying details
86about the discipline of information security, you must first know its history and evolution.
87The History of Information Security
88Key Term
89computer security In the early days of computers, this term specified the need to secure the
90physical location of computer technology from outside threats. This term later came to represent
91all actions taken to preserve computer systems from losses. It has evolved into the current
92concept of information security as the scope of protecting information in an organization has
93expanded.
94The history of information security begins with the concept of computer security. The
95need for computer security arose during World War II when the first mainframe computers
96were developed and used to aid computations for communication code breaking, as shown in
97The History of Information Security 3
98Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
99Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
100Figure 1-1. Multiple levels of security were implemented to protect these devices and the mis-
101sions they served. This required new processes as well as tried-and-true methods needed to
102maintain data confidentiality. Access to sensitive military locations, for example, was con-
103trolled by means of badges, keys, and the facial recognition of authorized personnel by secu-
104rity guards. The growing need to maintain national security eventually led to more complex
105and technologically sophisticated computer security safeguards.
106During these early years, information security was a straightforward process composed pre-
107dominantly of physical security and simple document classification schemes. The primary
108threats to security were physical theft of equipment, espionage against products of the systems,
109and sabotage. One of the first documented security problems that fell outside these categories
110occurred in the early 1960s, when a systems administrator was working on a MOTD (mes-
111sage of the day) file and another administrator was editing the password file. A software glitch
112mixed the two files, and the entire password file was printed on every output file. 3
113‡ The 1960s
114During the Cold War, many more mainframe computers were brought online to accomplish
115more complex and sophisticated tasks. These mainframes required a less cumbersome process
116of communication than mailing magnetic tapes between computer centers. In response to this
117need, the Department of Defense’s Advanced Research Projects Agency (ARPA) began exam-
118ining the feasibility of a redundant, networked communications system to support the mili-
119tary’s exchange of information. In 1968, Dr. Larry Roberts developed the ARPANET
1204 Chapter 1
121Earlier versions of the German code machine Enigma
122were first broken by the Poles in the 1930s. The British
123and Americans managed to break later, more complex
124versions during World War II. The increasingly complex
125versions of the Enigma, especially the submarine or
126Unterseeboot version of the Enigma, caused considerable
127anguish to Allied forces before finally being cracked. The
128information gained from decrypted transmissions was
129used to anticipate the actions of German armed forces.
130â€Some ask why, if we were reading the Enigma, we did
131not win the war earlier. One might ask, instead, when, if
132ever, we would have won the war if we hadn’t read it.â€
133Figure 1-1 The Enigma 1
134Source: National Security Agency. Used with permission. 2
135Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
136Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1371
138project. Figure 1-2 is an excerpt from his Program Plan. ARPANET evolved into what we
139now know as the Internet, and Roberts became known as its founder.
140For more information on Dr. Roberts and the history of the Internet, visit his Web site at
141www.packet.cc.
142‡ The 1970s and 80s
143During the next decade, ARPANET became more popular and saw wider use, increasing the
144potential for its misuse. In 1973, Internet pioneer Robert M. Metcalfe (pictured in Figure 1-3)
145identified fundamental problems with ARPANET security. As one of the creators of Ethernet,
146a dominant local area networking protocol, he knew that individual remote sites did not
147have sufficient controls and safeguards to protect data from unauthorized remote users.
148Other problems abounded: vulnerability of password structure and formats; lack of safety
149procedures for dial-up connections; and nonexistent user identification and authorizations.
150Phone numbers were widely distributed and openly publicized on the walls of phone
151booths, giving hackers easy access to ARPANET. Because of the range and frequency of
152computer security violations and the explosion in the numbers of hosts and users on
153ARPANET, network security was commonly referred to as network insecurity. 5 In 1978,
154Richard Bisbey and Dennis Hollingworth, two researchers in the Information Sciences Insti-
155tute at the University of Southern California, published a study entitled “Protection Analysis:
156Final Report.†It focused on a project undertaken by ARPA to understand and detect
157The History of Information Security 5
158Figure 1-2 Development of the ARPANET
159Source: Courtesy of Dr. Lawrence Roberts. Used with permission. 4
160Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
161Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
162vulnerabilities in operating system security. For a timeline that includes this and other semi-
163nal studies of computer security, see Table 1-1.
164Security that went beyond protecting the physical location of computing devices began with a
165single paper sponsored by the Department of Defense. Rand Report R-609 attempted to
166define the multiple controls and mechanisms necessary for the protection of a computerized
167data processing system. The document was classified for almost ten years, and is now consid-
168ered to be the paper that started the study of computer security.
169The security—or lack thereof—of systems sharing resources inside the Department of Defense
170was brought to the attention of researchers in the spring and summer of 1967. At that time,
171systems were being acquired at a rapid rate and securing them was a pressing concern both
172for the military and defense contractors.
173In June 1967, ARPA formed a task force to study the process of securing classified informa-
174tion systems. The task force was assembled in October 1967 and met regularly to formulate
175recommendations, which ultimately became the contents of Rand Report R-609. 6 The docu-
176ment was declassified in 1979 and released as Rand Report R-609-1. The content of the two
177documents is identical with the exception of two transmittal memorandums.
178For more information on the Rand Report, visit www.rand.org/pubs/reports/R609-1.html and
179click the Read Online Version button.
1806 Chapter 1
181Figure 1-3 Dr. Metcalfe receiving the National Medal of Technology
182Source: U.S. Department of Commerce. Used with permission.
183Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
184Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1851
186Rand Report R-609 was the first widely recognized published document to identify the role of
187management and policy issues in computer security. It noted that the wide use of networking
188components in military information systems introduced security risks that could not be miti-
189gated by the routine practices then used to secure these systems. Figure 1-4 shows an illustration
190of computer network vulnerabilities from the 1979 release of this document. This paper sig-
191naled a pivotal moment in computer security history—the scope of computer security expanded
192significantly from the safety of physical locations and hardware to include:
193â—
194Securing the data
195â—
196Limiting random and unauthorized access to that data
197â—
198Involving personnel from multiple levels of the organization in information security
199MULTICS Much of the early research on computer security centered on a system called
200Multiplexed Information and Computing Service (MULTICS). Although it is now obsolete,
201The History of Information Security 7
202Date Document
2031968 Maurice Wilkes discusses password security in Time-Sharing Computer Systems.
2041970 Willis H. Ware authors the report Security Controls for Computer Systems: Report of Defense Science
205Board Task Force on Computer Security - RAND Report R-609, which was not declassified until 1979. It
206became known as the seminal work identifying the need for computer security.
2071973 Schell, Downey, and Popek examine the need for additional security in military systems in Preliminary
208Notes on the Design of Secure Military Computer Systems.
2091975 The Federal Information Processing Standards (FIPS) examines DES (Digital Encryption Standard) in
210the Federal Register.
2111978 Bisbey and Hollingworth publish their study “Protection Analysis: Final Report,†which discussed the
212Protection Analysis project created by ARPA to better understand the vulnerabilities of operating
213system security and examine the possibility of automated vulnerability detection techniques in
214existing system software. 7
2151979 Morris and Thompson author “Password Security: A Case History,†published in the Communications
216of the Association for Computing Machinery (ACM). The paper examined the design history of a
217password security scheme on a remotely accessed, time-sharing system.
2181979 Dennis Ritchie publishes “On the Security of UNIX†and “Protection of Data File Contents,†which
219discussed secure user IDs, secure group IDs, and the problems inherent in the systems.
2201982 The U.S. Department of Defense Computer Security Evaluation Center publishes the first version of
221the Trusted Computer Security (TCSEC) documents, which came to be known as the Rainbow Series.
2221984 Grampp and Morris write “The UNIX System: UNIX Operating System Security.†In this report, the
223authors examined four “important handles to computer security:†physical control of premises and
224computer facilities, management commitment to security objectives, education of employees, and
225administrative procedures aimed at increased security. 8
2261984 Reeds and Weinberger publish “File Security and the UNIX System Crypt Command.†Their premise
227was: “No technique can be secure against wiretapping or its equivalent on the computer. Therefore
228no technique can be secure against the system administrator or other privileged users...the naive user
229has no chance.†9
2301992 Researchers for the Internet Engineering Task Force, working at the Naval Research Laboratory,
231develop the Simple Internet Protocol Plus (SIPP) Security protocols, creating what is now known as
232IPSEC security.
233Table 1-1 Key Dates in Information Security
234© Cengage Learning 2015
235Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
236Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
237MULTICS is noteworthy because it was the first operating system to integrate security into
238its core functions. It was a mainframe, time-sharing operating system developed in the mid-
2391960s by a consortium of General Electric (GE), Bell Labs, and the Massachusetts Institute
240of Technology (MIT).
241For more information on the MULTICS project, visit web.mit.edu/multics-history.
242In 1969, not long after the restructuring of the MULTICS project, several of its developers (Ken
243Thompson, Dennis Ritchie, Rudd Canaday, and Doug McIlroy) created a new operating sys-
244tem called UNIX. While the MULTICS system implemented multiple security levels and pass-
245words, the UNIX system did not. Its primary function, text processing, did not require the
246same level of security as that of its predecessor. Not until the early 1970s did even the simplest
247component of security, the password function, become a component of UNIX.
248In the late1970s, the microprocessor brought the personal computer (PC) and a new age of com-
249puting. The PC became the workhorse of modern computing, moving it out of the data center.
250This decentralization of data processing systems in the 1980s gave rise to networking—the inter-
251connecting of PCs and mainframe computers, which enabled the entire computing community to
252make all its resources work together.
2538 Chapter 1
254Radiation
255Radiation
256Radiation
257Crosstalk Crosstalk
258Processor
259Switching
260center
261Communication
262lines
263Files
264Theft
265Copying
266Unauthorized access
267Failure of protection circuits
268contribute to software failures
269Radiation
270Computer Network Vulnerabilities
271Radiation
272Taps
273Taps
274Hardware
275Replace supervisor
276Reveal protective measures
277Operator
278Improper connections
279Cross coupling
280Hardware
281Attachment of recorders
282Bugs
283Access
284Remote
285Consoles
286Identification
287Authentication
288Subtle software
289modifications
290User
291Disable hardware devices
292Use stand-alone utility programs
293Maintenance Man
294Disable protective features
295Provide “insâ€
296Reveal protective measures
297Systems Programmer
298Failure of protection features
299Access control
300Bounds control
301etc.
302Software
303Figure 1-4 Illustration of computer network vulnerabilities from Rand Report R-609
304Source: Rand Report R-609. Used with permission. 10
305Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
306Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
3071
308In the mid-1980s, the U.S. Government passed several key pieces of legislation that formalized
309the recognition of computer security as a critical issue for federal information systems. The
310Computer Fraud and Abuse Act of 1986 and the Computer Security Act of 1987 defined com-
311puter security and specified responsibilities and associated penalties. These laws and others are
312covered in Chapter 3, “Legal, Ethical, and Professional Issues in Information Security.â€
313In 1988, the Defense Advanced Research Projects Agency (DARPA) within the Department of
314Defense created the Computer Emergency Response Team (CERT) to address network security.
315‡ The 1990s
316At the close of the 20th century, networks of computers became more common, as did the need
317to connect them to each other. This gave rise to the Internet, the first global network of net-
318works. The Internet was made available to the general public in the 1990s after decades of
319being the domain of government, academia, and dedicated industry professionals. The Internet
320brought connectivity to virtually all computers that could reach a phone line or an Internet-
321connected local area network (LAN). After the Internet was commercialized, the technology
322became pervasive, reaching almost every corner of the globe with an expanding array of uses.
323Since its inception as a tool for sharing Defense Department information, the Internet has
324become an interconnection of millions of networks. At first, these connections were based
325on de facto standards because industry standards for interconnected networks did not exist.
326These de facto standards did little to ensure the security of information, though some degree
327of security was introduced as precursor technologies were widely adopted and became indus-
328try standards. However, early Internet deployment treated security as a low priority. In fact,
329many problems that plague e-mail on the Internet today result from this early lack of secu-
330rity. At that time, when all Internet and e-mail users were presumably trustworthy computer
331scientists, mail server authentication and e-mail encryption did not seem necessary. Early
332computing approaches relied on security that was built into the physical environment of the
333data center that housed the computers. As networked computers became the dominant style
334of computing, the ability to physically secure a networked computer was lost, and the stored
335information became more exposed to security threats.
336In 1993, the first DEFCON conference was held in Las Vegas. Originally it was established
337as a gathering for people interested in information security, including authors, lawyers, gov-
338ernment employees, and law enforcement officials. A compelling topic was the involvement
339of hackers in creating an interesting venue for the exchange of information between two
340adversarial groups—the “white hats†of law enforcement and security professionals and the
341“black hats†of hackers and computer criminals.
342In the late 1990s and into the 2000s, many large corporations began publicly integrating
343security into their organizations. Antivirus products became extremely popular.
344‡ 2000 to Present
345Today, the Internet brings millions of unsecured computer networks into continuous commu-
346nication with each other. The security of each computer’s stored information is contingent on
347the security level of every other computer to which it is connected. Recent years have seen a
348growing awareness of the need to improve information security, as well as a realization that
349information security is important to national defense. The growing threat of cyberattacks has
350made governments and companies more aware of the need to defend the computerized
351The History of Information Security 9
352Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
353Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
354control systems of utilities and other critical infrastructure. Another growing concern is the
355threat of nation-states engaging in information warfare, and the possibility that business and
356personal information systems could become casualties if they are undefended. Since 2000,
357Sarbanes-Oxley and other laws related to privacy and corporate responsibility have affected
358computer security.
359The attack on the World Trade Centers on September 11, 2001 resulted in major legislation
360changes related to computer security, specifically to facilitate law enforcement’s ability to col-
361lect information about terrorism. The USA PATRIOT Act of 2001 and its follow-up laws,
362the USA PATRIOT Improvement and Reauthorization Act of 2005 and the PATRIOT
363Sunsets Act of 2011, are discussed in Chapter 3.
364For more information on the history of computer security, visit the NIST Computer Security site at
365http://csrc.nist.gov/publications/history/. NIST is the National Institute of Standards and
366Technology.
367What Is Security?
368Key Terms
369C.I.A. triangle The industry standard for computer security since the development of the
370mainframe. The standard is based on three characteristics that describe the utility of information:
371confidentiality, integrity, and availability.
372communications security The protection of all communications media, technology, and
373content.
374information security Protection of the confidentiality, integrity, and availability of information
375assets, whether in storage, processing, or transmission, via the application of policy, education,
376training and awareness, and technology.
377network security A subset of communications security; the protection of voice and data
378networking components, connections, and content.
379physical security The protection of physical items, objects, or areas from unauthorized access
380and misuse.
381security A state of being secure and free from danger or harm. Also, the actions taken to make
382someone or something secure.
383Security is protection. Protection from adversaries—those who would do harm, intentionally
384or otherwise—is the ultimate objective of security. National security, for example, is a multi-
385layered system that protects the sovereignty of a state, its assets, its resources, and its people.
386Achieving the appropriate level of security for an organization also requires a multifaceted sys-
387tem. A successful organization should have multiple layers of security in place to protect its
388operations, physical infrastructure, people, functions, communications, and information.
389The Committee on National Security Systems (CNSS) defines information security as the pro-
390tection of information and its critical elements, including the systems and hardware that use,
391store, and transmit the information. 11 Figure 1-5 shows that information security includes the
392broad areas of information security management, data security, and network security. The
393CNSS model of information security evolved from a concept developed by the computer secu-
394rity industry called the C.I.A. triangle. The C.I.A. triangle (see Figure 1-6) has been the
39510 Chapter 1
396Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
397Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
3981
399standard for computer security in both industry and government since the development of the
400mainframe. This standard is based on the three characteristics of information that give it value
401to organizations: confidentiality, integrity, and availability. The security of these three charac-
402teristics is as important today as it has always been, but the C.I.A. triangle model is generally
403viewed as no longer adequate in addressing the constantly changing environment. The threats
404to the confidentiality, integrity, and availability of information have evolved into a vast collec-
405tion of events, including accidental or intentional damage, destruction, theft, unintended or
406unauthorized modification, or other misuse from human or nonhuman threats. This vast
407array of constantly evolving threats has prompted the development of a more robust model
408that addresses the complexities of the current information security environment. The
409expanded model consists of a list of critical characteristics of information, which are described
410in the next section. C.I.A. triangle terminology is used in this chapter because of the breadth
411of material that is based on it.
412For more information on CNSS, visit www.cnss.gov and click the history link.
413‡ Key Information Security Concepts
414This book uses many terms and concepts that are essential to any discussion of information
415security. Some of these terms are illustrated in Figure 1-7; all are covered in greater detail in
416subsequent chapters.
417â—
418Access A subject or object’s ability to use, manipulate, modify, or affect another sub-
419ject or object. Authorized users have legal access to a system, whereas hackers must
420gain illegal access to a system. Access controls regulate this ability.
421â—
422Asset The organizational resource that is being protected. An asset can be logical, such
423as a Web site, software information, or data; or an asset can be physical, such as a
424person, computer system, hardware, or other tangible object. Assets, particularly
425information assets, are the focus of what security efforts are attempting to protect.
426What Is Security? 11
427Confidentiality
428Computer Security
429Data Security
430Network Security
431Integrity
432POLICY
433Management of
434Information Security
435Information Security
436Governance
437Availability
438Figure 1-5 Components of information security
439Data
440&
441Services
442Availability
443Confidentiality
444Integrity
445Figure 1-6 The C.I.A. triangle
446© Cengage Learning 2015
447© Cengage Learning 2015
448Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
449Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
450â—
451Attack An intentional or unintentional act that can damage or otherwise compromise
452information and the systems that support it. Attacks can be active or passive, intentional
453or unintentional, and direct or indirect. Someone who casually reads sensitive informa-
454tion not intended for his or her use is committing a passive attack. A hacker attempting
455to break into an information system is an intentional attack. A lightning strike that
456causes a building fire is an unintentional attack. A direct attack is perpetrated by a
457hacker using a PC to break into a system. An indirect attack is a hacker compromising a
458system and using it to attack other systems—for example, as part of a botnet (slang for
459robot network). This group of compromised computers, running software of the attack-
460er’s choosing, can operate autonomously or under the attacker’s direct control to attack
461systems and steal user information or conduct distributed denial-of-service attacks.
462Direct attacks originate from the threat itself. Indirect attacks originate from a compro-
463mised system or resource that is malfunctioning or working under the control of a threat.
464â—
465Control, safeguard, or countermeasure Security mechanisms, policies, or procedures
466that can successfully counter attacks, reduce risk, resolve vulnerabilities, and otherwise
467improve security within an organization. The various levels and types of controls are
468discussed more fully in the following chapters.
46912 Chapter 1
470Attack: Ima Hacker downloads an exploit from MadHackz
471web site and then accesses buybay’s Web site. Ima then applies
472the script, which runs and compromises buybay's security controls
473and steals customer data. These actions cause buybay to
474experience a loss.
475Threat: Theft
476Threat agent: Ima Hacker
477Exploit: Script from MadHackz
478Web site
479Asset: buybay’s
480customer database
481Vulnerability: Buffer
482overflow in online
483database Web interface
484Figure 1-7 Key concepts in information security
485Sources (top left to bottom right): © iStockphoto/tadija, Internet Explorer, © iStockphoto/darrenwise, Internet Explorer, Microsoft Excel.
486Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
487Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
4881
489â—
490Exploit A technique used to compromise a system. This term can be a verb or a noun.
491Threat agents may attempt to exploit a system or other information asset by using it
492illegally for their personal gain. Or, an exploit can be a documented process to take
493advantage of a vulnerability or exposure, usually in software, that is either inherent in
494the software or created by the attacker. Exploits make use of existing software tools or
495custom-made software components.
496â—
497Exposure A condition or state of being exposed; in information security, exposure
498exists when a vulnerability is known to an attacker.
499â—
500Loss A single instance of an information asset suffering damage or destruction, unin-
501tended or unauthorized modification or disclosure, or denial of use. When an organi-
502zation’s information is stolen, it has suffered a loss.
503â—
504Protection profile or security posture The entire set of controls and safeguards, including
505policy, education, training and awareness, and technology, that the organization imple-
506ments to protect the asset. The terms are sometimes used interchangeably with the term
507security program, although a security program often comprises
508managerial aspects of security, including planning, personnel, and subordinate programs.
509â—
510Risk The probability of an unwanted occurrence, such as an adverse event or loss.
511Organizations must minimize risk to match their risk appetite—the quantity and
512nature of risk they are willing to accept.
513â—
514Subjects and objects A computer can be either the subject of an attack—an agent entity
515used to conduct the attack—or the object of an attack: the target entity, as shown in
516Figure1-8.A computer can also be both the subject and object of an attack. For example, it
517can be compromised by an attack (object) and then used to attack other systems (subject).
518â—
519Threat A category of objects, people, or other entities that represents a danger to an
520asset. Threats are always present and can be purposeful or undirected. For example,
521hackers purposefully threaten unprotected information systems, while severe storms
522incidentally threaten buildings and their contents.
523â—
524Threat agent The specific instance or a component of a threat. For example, the threat of
525“trespass or espionage†is a category of potential danger to information assets, while
526“external professional hacker†(like Kevin Mitnick, who was convicted of
527hacking into phone systems) is a specific threat agent. A lightning strike, hailstorm,
528ortornado isa threatagent that is part ofthe threat known as “acts of God/acts ofnature.â€
529â—
530Vulnerability A weakness or fault in a system or protection mechanism that opens it to
531attack or damage. Some examples of vulnerabilities are a flaw in a software
532What Is Security? 13
533Hacker using a
534computer as the
535subject of an attack
536Hacker request
537Stolen information
538Remote system that is
539the object of an attack
540Internet
541Figure 1-8 Computer as the subject and object of an attack
542© Cengage Learning 2015
543Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
544Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
545package, an unprotected system port, and an unlocked door. Some well-known
546vulnerabilities have been examined, documented, and published; others remain
547latent (or undiscovered).
548‡ Critical Characteristics of Information
549Key Terms
550accuracy An attribute of information that describes how data is free of errors and has the value
551that the user expects.
552authenticity An attribute of information that describes how data is genuine or original rather
553than reproduced or fabricated.
554availability An attribute of information that describes how data is accessible and correctly
555formatted for use without interference or obstruction.
556confidentiality An attribute of information that describes how data is protected from disclosure
557or exposure to unauthorized individuals or systems.
558integrity An attribute of information that describes how data is whole, complete, and uncorrupted.
559possession An attribute of information that describes how the data’s ownership or control is
560legitimate or authorized.
561utility An attribute of information that describes how data has value or usefulness for an end
562purpose.
563The value of information comes from the characteristics it possesses. When a characteristic of
564information changes, the value of that information either increases or, more commonly,
565decreases. Some characteristics affect information’s value to users more than others, depend-
566ing on circumstances. For example, timeliness of information can be a critical factor because
567information loses much or all of its value when delivered too late. Though information secu-
568rity professionals and end users share an understanding of the characteristics of information,
569tensions can arise when the need to secure information from threats conflicts with the end
570users’ need for unhindered access to it. For instance, end users may perceive a .1-second
571delay in the computation of data to be an unnecessary annoyance. Information security pro-
572fessionals, however, may perceive .1 seconds as a minor delay that enables an important task,
573like data encryption. Each critical characteristic of information—that is, the expanded C.I.A.
574triangle—is defined in the following sections.
575Availability Availability enables authorized users—people or computer systems—to
576access information without interference or obstruction and to receive it in the required for-
577mat. Consider, for example, research libraries that require identification before entrance.
578Librarians protect the contents of the library so that they are available only to authorized
579patrons. The librarian must accept a patron’s identification before the patron has free access
580to the book stacks. Once authorized patrons have access to the stacks, they expect to find
581the information they need in a usable format and familiar language. In this case, the infor-
582mation is bound in a book that is written in English.
583Accuracy Information has accuracy when it is free from mistakes or errors and has the
584value that the end user expects. If information has been intentionally or unintentionally
585modified, it is no longer accurate. Consider a checking account, for example. You assume
586that the information in your account is an accurate representation of your finances. Incor-
587rect information in the account can result from external or internal errors. If a bank teller,
588for instance, mistakenly adds or subtracts too much money from your account, the value of
58914 Chapter 1
590Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
591Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
5921
593the information is changed. Or, you may accidentally enter an incorrect amount into your
594account register. Either way, an inaccurate bank balance could cause you to make other
595mistakes, such as bouncing a check.
596Authenticity Authenticity of information is the quality or state of being genuine or origi-
597nal, rather than a reproduction or fabrication. Information is authentic when it is in the same
598state in which it was created, placed, stored, or transferred. Consider for a moment some com-
599mon assumptions about e-mail. When you receive e-mail, you assume that a specific individual
600or group created and transmitted the e-mail—you assume you know its origin. This is not
601always the case. E-mail spoofing, the act of sending an e-mail message with a modified field, is
602a problem for many people today because the modified field often is the address of the origina-
603tor. Spoofing the sender’s address can fool e-mail recipients into thinking that the messages are
604legitimate traffic, thus inducing them to open e-mail they otherwise might not have.
605Confidentiality Information has confidentiality when it is protected from disclosure or
606exposure to unauthorized individuals or systems. Confidentiality ensures that only users
607with the rights and privileges to access information are able to do so. When unauthorized
608individuals or systems can view information, confidentiality is breached. To protect the con-
609fidentiality of information, you can use several measures, including the following:
610â—
611Information classification
612â—
613Secure document storage
614â—
615Application of general security policies
616â—
617Education of information custodians and end users
618Confidentiality, like most characteristics of information, is interdependent with other charac-
619teristics and is most closely related to the characteristic known as privacy. The relationship
620between these two characteristics is covered in more detail in Chapter 3, “Legal, Ethical,
621and Professional Issues in Information Security.â€
622The value of information confidentiality is especially high for personal information about
623employees, customers, or patients. People who transact with an organization expect that their
624personal information will remain confidential, whether the organization is a federal agency,
625such as the Internal Revenue Service, or a business. Problems arise when companies disclose
626confidential information. Sometimes this disclosure is intentional, but disclosure of confiden-
627tial information also happens by mistake—for example, when confidential information is mis-
628takenly e-mailed to someone outside the organization rather than to someone inside it.
629Other examples of confidentiality breaches are an employee throwing away a document of
630critical information without shredding it, or a hacker who successfully breaks into an inter-
631nal database of a Web-based organization and steals sensitive information about the clients,
632such as names, addresses, and credit card numbers.
633As a consumer, you give up pieces of personal information in exchange for convenience or
634value almost daily. By using a “members†card at a grocery store, you disclose some of your
635spending habits. When you fill out an online survey, you exchange pieces of your personal his-
636tory for access to online privileges. When you sign up for a free magazine, Web resource, or free
637software application, you provide personally identifiable information (PII). The bits and pieces
638of personal information you disclose are copied, sold, replicated, distributed, and eventually
639coalesced into profiles and even complete dossiers of yourself and your life.
640What Is Security? 15
641Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
642Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
643Integrity Information has integrity when it is whole, complete, and uncorrupted. The integ-
644rity of information is threatened when it is exposed to corruption, damage, destruction, or other
645disruption of its authentic state. Corruption can occur while information is being stored or trans-
646mitted. Many computer viruses and worms are designed with the explicit purpose of corrupting
647data. For this reason, a key method for detecting a virus or worm is to look for changes in file
648integrity, as shown by the file size. Another key method of assuring information integrity is file
649hashing,inwhicha fileisread bya specialalgorithmthatusesthe bit valuesinthefiletocompute
650a single large number called a hash value. The hash value for any combination of bits is unique.
65116 Chapter 1
652Unintentional Disclosures
653The number of unintentional information releases due to malicious attacks is sub-
654stantial. Millions of people lose information to hackers and malware-focused attacks
655annually. However, organizations occasionally lose, misplace, or inadvertently
656release information in an event not caused by hackers or other electronic attacks.
657In January 2008, GE Money, a division of General Electric, revealed that a data
658backup tape with credit card data from approximately 650,000 customers and over
659150,000 Social Security numbers went missing from a records management com-
660pany’s storage facility. Approximately 230 retailers were affected when Iron Moun-
661tain, Inc., announced it couldn’t find a magnetic tape. 12
662In February 2005, the data aggregation and brokerage firm ChoicePoint revealed that
663it had been duped into releasing personal information about 145,000 people to identity
664thieves during 2004. The perpetrators used stolen identities to create ostensibly legiti-
665mate business entities, which then subscribed to ChoicePoint to acquire the data fraudu-
666lently.Thecompanyreportedthatthecriminalsopenedmanyaccountsandrecordedper-
667sonal information, including names, addresses, and identification numbers. They did so
668without using any network or computer-based attacks; it was simple fraud. The fraud
669was feared to have allowed the perpetrators to arrange hundreds of identity thefts.
670The giant pharmaceutical organization Eli Lilly and Co. released the e-mail
671addresses of 600 patients to one another in 2001. The American Civil Liberties Union
672(ACLU) denounced this breach of privacy, and information technology industry ana-
673lysts noted that it was likely to influence the public debate on privacy legislation.
674The company claimed the mishap was caused by a programming error that
675occurred when patients who used a specific drug produced by Lilly signed up for an
676e-mail service to access company support materials.
677In another incident in 2005, the intellectual property of Jerome Stevens Pharma-
678ceuticals, a small prescription drug manufacturer from New York, was compromised
679when the U.S. Food and Drug Administration (FDA) released documents the com-
680pany had filed with the agency. It remains unclear whether the release was pur-
681poseful or a simple error, but the company secrets were posted to a public Web
682site for several months before being removed.
683OFFLINE
684Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
685Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
6861
687If a computer system performs the same hashing algorithm on a file and obtains a different num-
688ber than the file’s recorded hash value, the file has been compromised and the integrity of the
689information is lost. Information integrity is the cornerstone of information systems because
690information is of no value or use if users cannot verify its integrity. File hashing and hash values
691are examined in detail in Chapter 8, “Cryptography.â€
692For more details on information losses caused by attacks, visit Wikipedia.org and search on the
693terms “Data breach†and “Timeline of Computer Security Hacker History.â€
694File corruption is not necessarily the result of external forces, such as hackers. Noise in the
695transmission media, for instance, can also cause data to lose its integrity. Transmitting data on
696a circuit with a low voltage level can alter and corrupt the data. Redundancy bits and check bits
697can compensate for internal and external threats to the integrity of information. During each
698transmission, algorithms, hash values, and error-correcting codes ensure the integrity of the
699information. Data whose integrity has been compromised is retransmitted.
700Utility The utility of information is the quality or state of having value for some purpose
701or end. In other words, information has value when it can serve a purpose. If information
702is available but is not in a meaningful format to the end user, it is not useful. For example,
703U.S. Census data can quickly become overwhelming and difficult for a private citizen to
704interpret; however, for a politician, the same data reveals information about residents in a
705district, such as their race, gender, and age. This information can help form a politician’s
706next campaign strategy.
707Possession The possession of information is the quality or state of ownership or con-
708trol. Information is said to be in one’s possession if one obtains it, independent of format
709or other characteristics. While a breach of confidentiality always results in a breach of pos-
710session, a breach of possession does not always lead to a breach of confidentiality. For
711example, assume a company stores its critical customer data using an encrypted file system.
712An employee who has quit decides to take a copy of the tape backups and sell the customer
713records to the competition. The removal of the tapes from their secure environment is a
714breach of possession. But, because the data is encrypted, neither the former employee nor
715anyone else can read it without the proper decryption methods; therefore, there is no breach
716of confidentiality. Today, people who are caught selling company secrets face increasingly
717stiff fines and a strong likelihood of jail time. Also, companies are growing more reluctant
718to hire people who have demonstrated dishonesty in their past.
719CNSS Security Model
720The definition of information security in this text is based in part on the CNSS document
721called the National Training Standard for Information Systems Security Professionals,
722NSTISSI No. 4011. The hosting organization is the Committee on National Security Systems,
723which is responsible for coordinating the evaluation and publication of standards related to
724the protection of National Security Systems (NSS). CNSS was originally called the National
725Security Telecommunications and Information Systems Security Committee (NSTISSC) when
726established in 1990 by National Security Directive (NSD) 42, National Policy for the Security
727of National Security Telecommunications and Information Systems. NSTISSI 4011 presents a
728CNSS Security Model 17
729Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
730Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
731comprehensive information security model and has become a widely accepted evaluation stan-
732dard for the security of information systems. The CNSS standards are expected to be replaced
733by the new NIST SP 800-16, “Information Technology Security Training Requirements:
734A Role-Based Model for Federal Information Technology/Cyber Security Training,†in the
735near future.
736For more information on CNSS and its standards, see www.cnss.gov/CNSS/issuances/Instructions
737.cfm.
738The model, which was created by John McCumber in 1991, provides a graphical representa-
739tion of the architectural approach widely used in computer and information security; it is now
740known as the McCumber Cube. 14 As shown in Figure 1-9, the McCumber Cube shows three
741dimensions. If extrapolated, the three dimensions of each axis become a 3×3×3 cube with 27
742cells representing areas that must be addressed to secure today’s information systems. To
743ensure system security, each of the 27 areas must be properly addressed during the security
744process. For example, the intersection of technology, integrity, and storage requires a control
745or safeguard that addresses the need to use technology to protect the integrity of information
746while in storage. One such control might be a system for detecting host intrusion that protects
747the integrity of information by alerting security administrators to the potential modification of
748a critical file. A common omission from such a model is the need for guidelines and policies
749that provide direction for the practices and implementations of technologies. The need for pol-
750icy is discussed in subsequent chapters of this book.
751Key Term
752McCumber Cube A graphical representation of the architectural approach widely used in
753computer and information security; commonly shown as a cube composed of 3×3×3 cells, similar