88
1 Information Weapon: Concepts, Means, Methods …
There is one more problem implying use of not only tools but first of all new
regulatory documentation (standards). This is about rather routine standard procedure such as audit of computer systems security at nuclear power plants (rules and
procedures).
Audit of computer systems security as per standards of nuclear power plants is
divided into a few phases. At the first phase, it is appropriate to evaluate information
security management system—managerial audit. At the second phase—technological audit. The third phase is information security risk analysis.
Generally speaking such approach suggests no novelties and the majority of
experts accept it. The customers (cybersecurity service) discover problems with
details—what exactly will be done in the progress of the works under such scheme,
particularly at the phases of technological audit and risk analysis.
The matter is that even the notion of “audit” involves as a rule evaluation for
conformity to some clear criterion (or standard).
As for the first phase then for appraisal of information security management
system as such criterion standard ISO27001/ISO17799 is used and in spite of
complexity and lack of practical methods to check how profoundly its requirements
are complied with in practice more or less successfully the audit is performed for
conformity to the requirements of the said standard. The main problems meanwhile
emerge at the second phase of the audit—when technological evaluation of immunity
is being performed. It is explained by the fact that so far there is no clear precise
criterion enabling to understand at the technological level whether the systems are
secured or not, whether it has some vulnerabilities facilitating penetration inside
or not. Hence there is no precise checklist the auditor should follow. And what is
dangerous, by the information at our disposal for the time being there are no plans to
elaborate such criterion and unified check list. In future one can expect just development of general procedure for performing such inspections which is obviously not
sufficient.
At the time when this book is published, all the international standards we are
aware of advise to perform the so-called active audit (by NSAINFOSEC’ terminology: tests for penetration by “red group”). In case of active audit of the internal
network, there is used violator model when the auditors are provided with the
following minimum privileges: physical access to the guarded perimeter and permission to enter corporate network at physical level. At this phase, auditor has no logical
rights to access data pool of Display and Control Systems.
At this phase, it is appropriate to review the capabilities of real intruder (person)
found inside the informational system of NPP where the violator really can penetrate.
One of the most important tasks for active audit is to simulate the actions of potential
intruder implementing in full possible vulnerabilities discovered at scanning and
confirming in such a way their existence for 100% and showing in practice the
actual level of immunity of information systems. Besides, only performing similar
internal test for intrusion (phase of vulnerabilities implementation) makes it possible
to discover and implement sophisticated comprehensive attack strategies (expansion
phase) which are always put into practice by computer hacker.
1 Information Weapon: Concepts, Means, Methods …
There is one more problem implying use of not only tools but first of all new
regulatory documentation (standards). This is about rather routine standard procedure such as audit of computer systems security at nuclear power plants (rules and
procedures).
Audit of computer systems security as per standards of nuclear power plants is
divided into a few phases. At the first phase, it is appropriate to evaluate information
security management system—managerial audit. At the second phase—technological audit. The third phase is information security risk analysis.
Generally speaking such approach suggests no novelties and the majority of
experts accept it. The customers (cybersecurity service) discover problems with
details—what exactly will be done in the progress of the works under such scheme,
particularly at the phases of technological audit and risk analysis.
The matter is that even the notion of “audit” involves as a rule evaluation for
conformity to some clear criterion (or standard).
As for the first phase then for appraisal of information security management
system as such criterion standard ISO27001/ISO17799 is used and in spite of
complexity and lack of practical methods to check how profoundly its requirements
are complied with in practice more or less successfully the audit is performed for
conformity to the requirements of the said standard. The main problems meanwhile
emerge at the second phase of the audit—when technological evaluation of immunity
is being performed. It is explained by the fact that so far there is no clear precise
criterion enabling to understand at the technological level whether the systems are
secured or not, whether it has some vulnerabilities facilitating penetration inside
or not. Hence there is no precise checklist the auditor should follow. And what is
dangerous, by the information at our disposal for the time being there are no plans to
elaborate such criterion and unified check list. In future one can expect just development of general procedure for performing such inspections which is obviously not
sufficient.
At the time when this book is published, all the international standards we are
aware of advise to perform the so-called active audit (by NSAINFOSEC’ terminology: tests for penetration by “red group”). In case of active audit of the internal
network, there is used violator model when the auditors are provided with the
following minimum privileges: physical access to the guarded perimeter and permission to enter corporate network at physical level. At this phase, auditor has no logical
rights to access data pool of Display and Control Systems.
At this phase, it is appropriate to review the capabilities of real intruder (person)
found inside the informational system of NPP where the violator really can penetrate.
One of the most important tasks for active audit is to simulate the actions of potential
intruder implementing in full possible vulnerabilities discovered at scanning and
confirming in such a way their existence for 100% and showing in practice the
actual level of immunity of information systems. Besides, only performing similar
internal test for intrusion (phase of vulnerabilities implementation) makes it possible
to discover and implement sophisticated comprehensive attack strategies (expansion
phase) which are always put into practice by computer hacker.
