CCIE SEC Security General
1. Policies - Security Policy Best Practices
2. Information Security Standards (ISO 17799, ISO 27001, BS7799)
Common Criteria
Provides a security framework whereby...
Users can specify what they want
Vendors can implement it
Labs can test vendors claims
derrived from BS7799
3. Standards Bodies
4. Common RFCs (e.g. RFC1918, RFC2827, RFC2401)
5. BCP 38
6. Attacks, Vulnerabilities and Common Exploits - recon, scan, priv escalation, penetration, cleanup, backdoor
Buffer Overflow
When Data written to a memory buffer, due to insufficient bounds checking, Corrupts data vales in memory address adjacent to the buffer
Bounds Checking: Checks if data is "appropriate for storage"
7. Security Audit & Validation
Risk Assessment
Quantitative
A Risk calculation based on figures
The probablility of an event, and the estimated cost if it does
The Outputs of this....
ALE Annual Loss Expectancy
EAC Estimated Annual Cost
+ A number is generated and risks can easily be ranked by importance
- Probability is rarely accurate / precice, an incorrect calculations can promote complacency
Qualitative
Only Potential Loss is Calculated
Compenents....
Threats
Things that "can go wrong" or "attacks"
e.g. Fire, Fraud
Vulnerabilities
Weaknesses or things that make a threat more likely
e.g. paper in the building = FIRE
Controls
Countermeasus for Threats & Vuln's
Deterrent
Reduce probability
Preventative
Prevent sucess if happens
Corrective
Reduces effectiviness
Detective
Discovers if happens
May trigger Corrective
9. Change Management Process
10. Incident Response Framework
11. Computer Security Forensics
CCIE SEC Security General
Added: 2008-12-15 09:45:19
From: (Joined 2008-12-15 05:32:23)
240 views |0 downloads
CCIE SEC Security General