WorksheetsAccess Controls Quiz
Total questions: 71
Worksheet time: 39mins
Involves limiting what objects can be available to what subjects according to what rules
Access Control
Subjects
Rule
Object
Any entity that requests access to our assets
Example: A ___ is the initiator of a request for service; therefore, a ___ is referred to as "active".
Subjects
Object
Rule
A device, process, person, user, program, server; client or other entity that responds to a request for service.
Example: An ___ has an owner, and the owner has the right to determine who or what should be allowed access to their ___.
Object
Rule
Subject
An instruction developed to allow or deny access to an object by comparing the validated identity of the subject to an access control list.
Example: When a user (subject) attempts to access a file (object), a ___ validated the level of access, if any, the user should have to that file.
Rule
Object
Subject
Access is based on three elements:
Subject
Object
Rule
Badge Systems and Gate Entry
Environment Design
Biometrics
Natural Surveillance
Natural Access Control
Natural Territory Reinforcement
Describes an information security strategy that integrates people, technology and operations capabilities to establish variable barriers across multiple layers and missions of the organization.
Defense in Depth
The Principle of Least Privilege (NIST SP 800-179)
Privileged Access Management
Privileged Accounts
Is a standard of permitting only minimum access necessary for users or programs to fulfill their function
The Principle of Least Privilege (NIST SP 800-179)
Privileged Access Management
Privileged Accounts
Segregation of Duties
Includes role-based specific subsets of privileges that only become active in real time when the identity is requesting the use of a resource or service.
Privileged Access Management
Privileged Accounts
Segregation of Duties
Two-person rule
Are those of normal users, such as managers and administrators
Privileged Accounts
Privileged Access Management
Segregation of Duties
Two-person rule
Record of the events occurring within an organization's systems and networks
Logging
Audited
Segregation of Duties
Two-person rule
To ensure compliance with established policies and operational procedures
Audited
Logging
Segregation of Duties
Two-person rule
Based on the security practice that no one person should control an entire high-risk transaction from start to finish
Segregation of Duties
Two-person rule
Physical access controls
Separation of employment
A security strategy that requires a minimum of two people to be in an area together, making it impossible for a person to be in the area alone
Two-person rule
Segregation of Duties
Separation of employment
Physical access controls
When employees leave the company, depending on company policy and procedures, their accounts must be disable after the termination data and time
Separation of employment
A new employee
Change of position
Are items you can physical touch.
Example: Prevent, monitor, or detect direct contact with systems or areas within a facility
Physical access controls
Verification
Logical access controls
Discretionary Access Control (DAC)
Types of Physical Access Controls:
Badge Systems and Gate Entry
Environment Design
Biometrics
Natural Surveillance
Natural Access Control
Natural Territory Reinforcement
Subject
Object
Rule
The user presents their biometric data to the system so that the biometric data can be compared with the stored biometric code
Verification
Logical access controls
Discretionary Access Control
Mandatory Access Control (MAC)
Monitoring Personnel:
Cameras
Logs
Security Guards
Alarm Systems
Passwords
Biometrics (implemented on a system, such as a smartphone or laptop)
Badge/token readers connected to a system
Pull permissions list
Review with managers
Make adjustments
Are electronic methods that limit some from getting access to systems, and sometimes even to tangible assets or areas.
Logical access controls
Discretionary Access Control (DAC)
Mandatory Access Control (MAC)
Role-Based Access Control (RBAC)
Enforced over all subjects and objects in an information system
Discretionary Access Control (DAC)
Mandatory Access Control (MAC)
Role-Based Access Control (RBAC)
Uniformly enforced across all subjects and objects within the boundary of an information system
Mandatory Access Control (MAC)
Role-Based Access Control (RBAC)
Discretionary Access Control (DAC)
Provides each worker privileges based on what role they have in the organization. Only Human Resources staff have access to personnel files.
Role-Based Access Control (RBAC)
Mandatory Access Control (MAC)
Discretionary Access Control (DAC)
Plays an important role in protecting information and systems
Physical security
Data centers
Server rooms
Media storage facilities
Contain massive quantities of valuable information and computing resources
Data centers
Server rooms
Media storage facilities
Evidence storage
Contain sensitive information in less secure locations
Server rooms
Media storage facilities
Evidence storage
Wiring closets
Require additional attention, particularly if in remote locations
Media storage facilities
Evidence storage
Wiring closets
Distribution cabling
Locations must preserve the chain of custody
Evidence storage
Wiring closets
Distribution cabling
Physical security
Offer access to eavesdroppers and network intruders
Wiring closets
Distribution cabling
Physical security
Data centers
Don't forget about (a) centers and other sensitive locations
Allow you to focus security controls
Gates
Bollards
Visit Management Procedures
Two Person Integrity
Provides direction to solve the challenges of crime with organizational (people), mechanical (technology and hardware) and natural designed (architectural and circulation flow) method.
Crime Prevention Through Environmental Design
Visitor Management Procedures
Two Person Integrity
Two Person Control
When a new employee is hired, the hiring manager sends a request to the security administrator to create new user ID.
A new employee
Change of position
Separation of employment
When an employee has been promoted, their permissions and access rights might change as defined by the new role, which will dictate any added privileges and update to access.
Change of position
A new employee
Separation of employment
CPTED Goals:
Natural Surveillance
Natural Access Control
Natural Territory Reinforcement
Describe allowable visit purposes
Explain visit approval authority
Describe requirements for unescorted access
Explain role of visitor escorts
Pull permissions list
Review with managers
Make adjustments
Watch for suspicious activity
Alert administrators to anomalies
Protect against intrusions
Visitor Management Procedures
Job rotation
Mandatory vacation policies
Two-Person Control
Visitor Procedures:
Describe allowable visit purposes
Explain visit approval authority
Describe requirements for unescorted access
Explain role of visitor escorts
Natural Surveillance
Natural Access Control
Natural Territory Reinforcement
Impossible travel time logins
Unusual network location logins
Unusual time-of-day logins
Deviations from normal behavior
Deviations in volume of data transferred
All visitor access to secure areas should be logged
True
False
(a) should be clearly identified with distinctive badges
(a) provide an added degree of monitoring in visitor areas
(a) play a crucial role in physical security
(a) may act as security guards
Although a menacing look is sometimes desirable
True
False
(a) sentries may replace human security patrols
Two people must enter sensitive areas together
Two Person Integrity
Two Person Control
Job rotation
Mandatory vacation policies
Two people must jointly approve sensitive actions
Two Person Control
Two Person Integrity
Job rotation
Mandatory vacation policies
Moves employees through different positions
Job rotation
Mandatory vacation policies
Inaccurate Permissions
Privilege Creep
Require time away from work
Mandatory vacation policies
Inaccurate Permissions
Privilege Creep
Account Audits
(a) Convention:
Kayla Mann -> Kmann or Kmann777
Block work and/or violate least privilege
Inaccurate Permissions
Privilege Creep
Account Audits
Prioritize reviews
A condition when users switch jobs and gain new permissions but never have their old permissions revoked
Privilege Creep
Account Audits
Prioritize reviews
Attestation reviews
Protect against inaccurate permissions
Account Audits
Prioritize reviews
Attestation reviews
Unauthorized use
User Account Audits:
Pull permissions list
Review with managers
Make adjustments
Badge Systems and Gate Entry
Environment Design
Biometrics
Natural Surveillance
Natural Access Control
Natural Territory Reinforcement
Users with changed jobs
Prioritize reviews
Attestation reviews
Unauthorized use
Formal approval documentation
Attestation reviews
Prioritize reviews
Unauthorized use
Permissions by legitimate users
Unauthorized use
Attestation reviews
Prioritize reviews
Continuous Account Monitoring:
Watch for suspicious activity
Alert administrators to anomalies
Prevents users from accessing resources without permission
Is especially critical when a user leaves under adverse circumstances
May inform a user in advance of pending termination
May allow a user access to resources after termination
Access Policy Violations:
Impossible travel time logins
Unusual network location logins
Unusual time-of-day logins
Deviations from normal behavior
Deviation in volume of data transferred
Describe allowable visit purposes
Explain visit approval authority
Describe requirements for unescorted access
Explain role of visitor escorts
Natural Surveillance
Natural Access Control
Natural Territory Reinforcement
Adds user location information to logs
Geotagging
Geofencing
Provisioning
Deprovisioning
Alerts when a device leaves defined boundaries
Geofencing
Geotagging
Provisioning
Deprovisioning
A crucial identity and access management task
Provisioning and Deprovisioning Accounts
Routine Workflow
Emergency Workflow
Authorization
After onboarding, administrators create authentication credentials and grant appropriate authorization
Provisioning
Deprovisioning
Inaccurate Permissions
Privilege Creep
During offboarding process, administrators disable accounts and revoke authorizations at the appropriate time
Deprovisioning
Provisioning
Least Privilege
Routine Workflow
Prompt Termination is Critical:
Prevents users from accessing resources without permission.
Is especially critical when a user leaves under adverse circumstances.
May inform a user in advance of pending termination
May allow a user access to resources after termination
Watch for suspicious activity
Alert administrators to anomalies
Disables accounts on a scheduled basis for planned departures
Routine Workflow
Emergency Workflow
Authorization
Least Privilege
Immediately suspends access when user is unexpectedly terminated
Emergency Workflow
Routine Workflow
Authorization
Least Privilege
Incorrectly Timed Account Revocations:
May inform a user in advance of pending termination
May allow a user access to resources after termination
Watch for suspicious activity
Alert administrators to anomalies
Prevents users from accessing resources without permission.
Is especially critical when a user leaves under adverse circumstances.
Determines what an authenticated user can do
Authorization
Least Privilege
Mandatory Access Control (MAC)
Discretionary Access Control (DAC)
Says that the user should have the minimum set of permissions necessary to perform their job
Least Privilege
Mandatory Access Control (MAC)
Discretionary Access Control (DAC)
Role-based Access Control (RBAC)
In a ___ system, permissions are determined by the system.
Mandatory Access Control (MAC)
Discretionary Access Control (DAC)
Role-based Access Control (RBAC)
In a ___ system, permissions are determined by file owners
Discretionary Access Control (DAC)
Mandatory Access Control (MAC)
Role-based Access Control (RBAC)
Grants permissions to groups of people
Role-based Access Control (RBAC)
Mandatory Access Control (MAC)
Discretionary Access Control (DAC)
