Guide to Information Technology Security
Total Page:16
File Type:pdf, Size:1020Kb
Guide to Information Technology Security WMO-No. 1115 WMO-No. 1115 © World Meteorological Organization, 2016 The right of publication in print, electronic and any other form and in any language is reserved by WMO. Short extracts from WMO publications may be reproduced without authorization, provided that the complete source is clearly indicated. Editorial correspondence and requests to publish, reproduce or translate this publication in part or in whole should be addressed to: Chair, Publications Board World Meteorological Organization (WMO) 7 bis, avenue de la Paix Tel.: +41 (0) 22 730 84 03 P.O. Box 2300 Fax: +41 (0) 22 730 80 40 CH-1211 Geneva 2, Switzerland E-mail: [email protected] ISBN 978-92-63-11115-9 NOTE The designations employed in WMO publications and the presentation of material in this publication do not imply the expression of any opinion whatsoever on the part of the Secretariat of WMO concerning the legal status of any country, territory, city or area, or of its authorities, or concerning the delimitation of its frontiers or boundaries. Opinions expressed in WMO publications are those of the authors and do not necessarily reflect those of WMO. The mention of specific companies or products does not imply that they are endorsed or recommended by WMO in preference to others of a similar nature which are not mentioned or advertised. Revision History 2005-02-02 – ET-EUDCS, Draft version. 2006-07-19 – ET-CTS, First complete version. 2012-04-18 – ET-CTS, Second version with review of all text and addition of external references. 2016-04 – ET-CTS, Document review. CONTENTS 1 INTRODUCTION .................................................................................... Error! Bookmark not defined. 2 INFORMATION TECHNOLOGY SECURITY ...................................................................................... 8 2.1 Protecting systems against potential failures ............................................................................... 8 2.2 Malicious versus non-malicious activities ..................................................................................... 8 2.3 Establishing security criteria ........................................................................................................... 8 2.4 Security techniques and procedures to consider ........................................................................ 9 3 SECURITY THREATS ........................................................................................................................... 10 3.1 Reasons for threats ........................................................................................................................ 10 3.1.1 Obtain information or resources ............................................................................................... 10 3.1.2 Desire to cause harm ................................................................................................................. 10 3.1.3 Playful or exploration ............................................................................................................... 10 3.1.4 Accident .................................................................................................................................... 10 3.2 Common threats ............................................................................................................................. 10 3.2.1 Malicious codes: viruses, ransomware, worms and Trojans ..................................................... 10 3.2.2 Denial of service ....................................................................................................................... 11 3.2.3 Malicious hacking ..................................................................................................................... 11 3.2.4 Spying ....................................................................................................................................... 11 3.2.5 Compromising and abusing system resources .......................................................................... 11 3.3 Main attack methods ...................................................................................................................... 11 3.3.1 Hacking systems by finding security holes in systems ............................................................. 11 3.3.2 Denial-of-service attacks .......................................................................................................... 11 3.3.3 Malicious spam ......................................................................................................................... 12 3.3.4 Spying ....................................................................................................................................... 12 3.3.5 Root or domain controller access .............................................................................................. 12 3.3.6 Wireless Local Area Networks ................................................................................................. 12 4 IMPACTS OF THREATS AND SECURITY EVENTS ...................................................................... 14 4.1 System and service impacts ......................................................................................................... 14 4.2 Administrative, legal and reputation impacts ............................................................................. 15 5 INFORMATION TECHNOLOGY SECURITY PROCESS ............................................................... 16 5.1 Identify assets ................................................................................................................................. 16 5.2 Threats and risk assessment ....................................................................................................... 16 5.3 Business continuity planning ........................................................................................................ 16 5.4 Prevent ............................................................................................................................................. 16 5.5 Detect ............................................................................................................................................... 16 5.6 Respond and recover .................................................................................................................... 16 5.7 Investigate and correct .................................................................................................................. 17 6 BEST PRACTICES IN INFORMATION TECHNOLOGY SECURITY ........................................... 18 6.1 Information technology system security ..................................................................................... 18 6.2 Network architecture ...................................................................................................................... 19 6.2.1 Local Area Networks ................................................................................................................ 20 6.2.2 Wireless Local Area Networks ................................................................................................. 21 6.2.3 Firewall systems ........................................................................................................................ 21 6.3 Remote access ............................................................................................................................... 23 6.4 Server access and security ........................................................................................................... 23 6.4.1 File system authorization rules ................................................................................................. 25 6.5 Security policies .............................................................................................................................. 25 6.5.1 Requirement for a security policy ............................................................................................. 25 6.5.2 Developing a policy .................................................................................................................. 25 6.6 Threat and risk assessment ......................................................................................................... 26 6.7 Policy control ................................................................................................................................... 26 6.8 Procedures ...................................................................................................................................... 27 6.8.1 System management ................................................................................................................. 27 6.8.2 New system installation and change management .................................................................... 27 6.8.3 Installation of security patches .................................................................................................. 27 6.8.4 User account management ........................................................................................................ 27 6.8.5 Backup/restore procedures and regular testing ......................................................................... 28 6.8.6 Detection procedures ................................................................................................................ 28 6.8.7 Response/recovery procedures .................................................................................................