{"id":314,"date":"2018-07-12T11:14:40","date_gmt":"2018-07-12T11:14:40","guid":{"rendered":"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/?post_type=chapter&#038;p=314"},"modified":"2019-05-14T10:32:56","modified_gmt":"2019-05-14T10:32:56","slug":"administering-security","status":"publish","type":"chapter","link":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/chapter\/administering-security\/","title":{"rendered":"Administering security"},"content":{"raw":"<div><span style=\"float: right;\"><a href=\"https:\/\/youtu.be\/kwjH3g6JWSk\" target=\"_blank\" rel=\"noopener\"><img src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"epgp books\" width=\"75px\" height=\"75px;\" \/><\/a>\r\n<\/span><\/div>\r\n\r\n<strong>Administering security<\/strong>\r\n\r\n<img class=\"size-full wp-image-315 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-202.png\" alt=\"\" width=\"386\" height=\"812\" \/>\r\n\r\nSecurity Plan :\r\n\r\n&nbsp;\r\n<ul>\r\n \t<li>How organization addresses security requirements. Security planning needs periodic revisions according to the need of an organization.<\/li>\r\n \t<li>A good security plan includes current security practices and changes to be adopted to improve practices.<\/li>\r\n<\/ul>\r\n<img class=\"size-full wp-image-316 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-203.png\" alt=\"\" width=\"771\" height=\"264\" \/>\r\n\r\n<img class=\"size-full wp-image-317 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-204.png\" alt=\"\" width=\"825\" height=\"415\" \/>\r\n\r\nContents of a security plan:\r\n\r\n&nbsp;\r\n<ol>\r\n \t<li>Policy: Includes the goals set for security and readiness of the people for putting efforts towards achieving goals.<\/li>\r\n \t<li>Current State: Describes the status of security while planning is taking place.<\/li>\r\n \t<li>Requirements: Recommendations for how to fulfill the goals set for achieving security.<\/li>\r\n \t<li>Recommended controls: Maps controls to vulnerabilities identified in the policy and requirements.<\/li>\r\n \t<li>Accountability: Description of responsibility attached to every activity related to security.<\/li>\r\n \t<li>Timetable: Identify when to perform functions related to security.<\/li>\r\n \t<li>Continuing attention: Define the organization for updating the security plan according to time line.<\/li>\r\n<\/ol>\r\nRequirements lead to recommendations to fulfill goals pertaining to security. Recommended controls map to vulnerabilities. Responsibility for security activity is identified by mentioning Accountability. Timetable maps the time when each security. Continuing attention suggest when to periodically update security plan.\r\n\r\n&nbsp;\r\n\r\nApproaches to create and update security plan:\r\n\r\n&nbsp;\r\n\r\nPolicy:\r\n\r\nA security policy is a high level statement of function and objective. If policy is to be strengthened, it involves cost and inconvenience to users.\r\n\r\nPolicy statements answer 3 questions.\r\n<ol>\r\n \t<li>Who all should have access?<\/li>\r\n \t<li>Which resources in the organization are allowed accesses?<\/li>\r\n \t<li>What type of access should each user is allowed for each resource?<\/li>\r\n<\/ol>\r\nPolicy statement specifies:\r\n<ul>\r\n \t<li>Goals to be achieved by organization.<\/li>\r\n \t<li>Which group in an organization is responsible for security?<\/li>\r\n \t<li>Organization\u2019s commitment to security.<\/li>\r\n<\/ul>\r\nCurrent Security Status:\r\n\r\n&nbsp;\r\n\r\nRisk analysis:\u00a0 Determine the vulnerabilities by performing risk analysis.\r\n\r\n&nbsp;\r\n<ul>\r\n \t<li>he risk analysis describes the current status of security.<\/li>\r\n<\/ul>\r\nCurrent status is described by listing assets of an organization, security threats to assets, controls to protect the assets.\r\n\r\n&nbsp;\r\n\r\nRequirements:\r\n\r\n&nbsp;\r\n\r\n<img class=\"size-full wp-image-318 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-205.png\" alt=\"\" width=\"592\" height=\"761\" \/>\r\n\r\n&nbsp;\r\n<ol start=\"3\">\r\n \t<li>completeness<\/li>\r\n \t<li>realism<\/li>\r\n \t<li>need<\/li>\r\n \t<li>verifiability<\/li>\r\n \t<li>traceability<\/li>\r\n<\/ol>\r\n&nbsp;\r\n\r\nRecommended Controls:\r\n\r\n&nbsp;\r\n\r\n<img class=\"size-full wp-image-319 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-206.png\" alt=\"\" width=\"503\" height=\"180\" \/>\r\n\r\nResponsibility for Implementation (Accountability):\r\n\r\n&nbsp;\r\n\r\nIdentify which people are responsible for implementation. In case of zero day attack, security policy must specify what action must be taken.\r\n\r\n&nbsp;\r\n\r\nRoles of people:\r\n\r\n&nbsp;\r\n\r\n<img class=\"size-full wp-image-320 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-207.png\" alt=\"\" width=\"611\" height=\"599\" \/>\r\n\r\nTimetable:\r\n\r\n&nbsp;\r\n<ul>\r\n \t<li>Shows at what time the activity of plan will be executed and what process it will follow.<\/li>\r\n \t<li>Time line chart helps management track how many steps of the plan have been implemented.<\/li>\r\n<\/ul>\r\nContinuing Attention:\r\n<ul>\r\n \t<li>Objects and applied controls need to be scrutinized periodically and updated according to need.<\/li>\r\n \t<li>The security plan defines the time when the periodic review must take place.<\/li>\r\n<\/ul>\r\nTeam members needed for security planning:\r\n\r\n<img class=\"size-full wp-image-321 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-208.png\" alt=\"\" width=\"561\" height=\"171\" \/>\r\n\r\nSecurity planning team has member from each of the following group:\r\n\r\n&nbsp;\r\n<ul>\r\n \t<li>Computer hardware group<\/li>\r\n \t<li>System administrators<\/li>\r\n \t<li>System programmers<\/li>\r\n \t<li>Application programmers<\/li>\r\n \t<li>Data entry personnel<\/li>\r\n \t<li>Physical security personnel<\/li>\r\n \t<li>Representative users<\/li>\r\n \t<li>Commitment to the plan is ---- Security functions will be implemented and security activities are carried out.<\/li>\r\n \t<li>The planning team<\/li>\r\n \t<li>Those affected by security recommendations<\/li>\r\n \t<li>Management<\/li>\r\n<\/ul>\r\nBusiness Continuity Plans\r\n\r\n&nbsp;\r\n<ul>\r\n \t<li>This is a documentation describing the situation of computer security incident and how a business will continue to function. The situations are catastrophic situations and long duration.<\/li>\r\n \t<li>To assess the impact of failure of business, ask questions:<\/li>\r\n<\/ul>\r\n<img class=\"size-full wp-image-322 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-209.png\" alt=\"\" width=\"664\" height=\"438\" \/>\r\n<ul>\r\n \t<li>Develop strategy: Strategy finds how the key assets can be safeguarded?<\/li>\r\n \t<li>Develop Plan:<\/li>\r\n<\/ul>\r\nWhose responsibility when an incident takes place?\r\n\r\nWhat actions to be performed?\r\n\r\nWho will perform the actions?\r\n<ul>\r\n \t<li>Incident Response Plans<\/li>\r\n<\/ul>\r\n<img class=\"size-full wp-image-323 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-210.png\" alt=\"\" width=\"729\" height=\"746\" \/>\r\n\r\n<img class=\"size-full wp-image-324 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-211.png\" alt=\"\" width=\"577\" height=\"783\" \/>\r\n\r\n&nbsp;\r\n\r\nRisk is distinguished by\r\n<ol>\r\n \t<li>Calculating loss occurred due to an event<\/li>\r\n \t<li>The probability of the event to occur.<\/li>\r\n \t<li>The variation in the outcome.<\/li>\r\n<\/ol>\r\nRisk exposure - Calculate the effects of a risk by multiplying the risk impact and the risk probability.\r\n\r\n&nbsp;\r\n<ol>\r\n \t<li>Avoid the risk<\/li>\r\n \t<li>Transfer the risk<\/li>\r\n \t<li>Accept the risk<\/li>\r\n<\/ol>\r\n<ul>\r\n \t<li>Risk analysis - Examine a system and the context in which it is operating to determine possible exposures and potential harm that can be caused.<\/li>\r\n<\/ul>\r\n&nbsp;\r\n\r\nSteps of a risk analysis\r\n\r\n&nbsp;\r\n<ol>\r\n \t<li>Identify assets<\/li>\r\n<\/ol>\r\n<ul>\r\n \t<li>hardware<\/li>\r\n \t<li>software<\/li>\r\n \t<li>data<\/li>\r\n \t<li>people<\/li>\r\n \t<li>documentation<\/li>\r\n \t<li>Computer supplies<\/li>\r\n \t<li>Civil infrastructure<\/li>\r\n \t<li>Power, water,air and other environmental conditions<\/li>\r\n \t<li>Human and social assets<\/li>\r\n<\/ul>\r\n<ol start=\"2\">\r\n \t<li>Evaluate the vulnerabilities<\/li>\r\n<\/ol>\r\n<ol start=\"3\">\r\n \t<li>Estimate probability of exploitation<\/li>\r\n<\/ol>\r\n<ol start=\"4\">\r\n \t<li>Calculate annual loss that may occur<\/li>\r\n \t<li>Assess the controls that may be applied and their cost.<\/li>\r\n \t<li>Project annual savings of control.<\/li>\r\n<\/ol>\r\n\r\n<table>\r\n<tbody>\r\n<tr>\r\n<td><strong>you can view video on Administering security<\/strong><\/td>\r\n<td><a href=\"https:\/\/youtu.be\/kwjH3g6JWSk\" target=\"_blank\" rel=\"noopener\"><img class=\"alignnone wp-image-120\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"\" width=\"36\" height=\"36\" \/><\/a><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n\r\n<strong>Suggested Reading:<\/strong>\r\n<ol>\r\n \t<li>Cryptography and Network Security Principles and Practice by William Stallings, sixth Edition, PEARSON.<\/li>\r\n \t<li>Security in Computing by Charles Pfleeger &amp; Shari Lawrence Pfleeger, fourth Edition, PEARSON.<\/li>\r\n \t<li>Network Security by Charlie Kaufman, Radia Perlman, Mike Speciner, second Edition, PHI.<\/li>\r\n \t<li>The Complete Reference \u2013 Network Security by Roberta Bragg, Mark Rhodes-Ousley &amp; Keith Strassberg, Tata McGraw Hill<\/li>\r\n \t<li>Network Security Bible by Eric Cole, Ronald Krutz, James Conley, Wiley<\/li>\r\n \t<li>Hacking 6 Exposed by Stuart McClure, Joel Scambray &amp; George Kurtz , Tata McGraw Hill .<\/li>\r\n \t<li><a href=\"http:\/\/www.snort.org\/\">www.snort.org<\/a><\/li>\r\n \t<li><a href=\"https:\/\/nmap.org\/\">https:\/\/nmap.org<\/a><\/li>\r\n<\/ol>","rendered":"<div><span style=\"float: right;\"><a href=\"https:\/\/youtu.be\/kwjH3g6JWSk\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"epgp books\" width=\"75px\" height=\"75px;\" \/><\/a><br \/>\n<\/span><\/div>\n<p><strong>Administering security<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-315 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-202.png\" alt=\"\" width=\"386\" height=\"812\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-202.png 386w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-202-143x300.png 143w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-202-65x137.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-202-225x473.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-202-350x736.png 350w\" sizes=\"auto, (max-width: 386px) 100vw, 386px\" \/><\/p>\n<p>Security Plan :<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>How organization addresses security requirements. Security planning needs periodic revisions according to the need of an organization.<\/li>\n<li>A good security plan includes current security practices and changes to be adopted to improve practices.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-316 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-203.png\" alt=\"\" width=\"771\" height=\"264\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-203.png 771w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-203-300x103.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-203-768x263.png 768w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-203-65x22.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-203-225x77.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-203-350x120.png 350w\" sizes=\"auto, (max-width: 771px) 100vw, 771px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-317 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-204.png\" alt=\"\" width=\"825\" height=\"415\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-204.png 825w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-204-300x151.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-204-768x386.png 768w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-204-65x33.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-204-225x113.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-204-350x176.png 350w\" sizes=\"auto, (max-width: 825px) 100vw, 825px\" \/><\/p>\n<p>Contents of a security plan:<\/p>\n<p>&nbsp;<\/p>\n<ol>\n<li>Policy: Includes the goals set for security and readiness of the people for putting efforts towards achieving goals.<\/li>\n<li>Current State: Describes the status of security while planning is taking place.<\/li>\n<li>Requirements: Recommendations for how to fulfill the goals set for achieving security.<\/li>\n<li>Recommended controls: Maps controls to vulnerabilities identified in the policy and requirements.<\/li>\n<li>Accountability: Description of responsibility attached to every activity related to security.<\/li>\n<li>Timetable: Identify when to perform functions related to security.<\/li>\n<li>Continuing attention: Define the organization for updating the security plan according to time line.<\/li>\n<\/ol>\n<p>Requirements lead to recommendations to fulfill goals pertaining to security. Recommended controls map to vulnerabilities. Responsibility for security activity is identified by mentioning Accountability. Timetable maps the time when each security. Continuing attention suggest when to periodically update security plan.<\/p>\n<p>&nbsp;<\/p>\n<p>Approaches to create and update security plan:<\/p>\n<p>&nbsp;<\/p>\n<p>Policy:<\/p>\n<p>A security policy is a high level statement of function and objective. If policy is to be strengthened, it involves cost and inconvenience to users.<\/p>\n<p>Policy statements answer 3 questions.<\/p>\n<ol>\n<li>Who all should have access?<\/li>\n<li>Which resources in the organization are allowed accesses?<\/li>\n<li>What type of access should each user is allowed for each resource?<\/li>\n<\/ol>\n<p>Policy statement specifies:<\/p>\n<ul>\n<li>Goals to be achieved by organization.<\/li>\n<li>Which group in an organization is responsible for security?<\/li>\n<li>Organization\u2019s commitment to security.<\/li>\n<\/ul>\n<p>Current Security Status:<\/p>\n<p>&nbsp;<\/p>\n<p>Risk analysis:\u00a0 Determine the vulnerabilities by performing risk analysis.<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>he risk analysis describes the current status of security.<\/li>\n<\/ul>\n<p>Current status is described by listing assets of an organization, security threats to assets, controls to protect the assets.<\/p>\n<p>&nbsp;<\/p>\n<p>Requirements:<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-318 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-205.png\" alt=\"\" width=\"592\" height=\"761\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-205.png 592w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-205-233x300.png 233w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-205-65x84.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-205-225x289.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-205-350x450.png 350w\" sizes=\"auto, (max-width: 592px) 100vw, 592px\" \/><\/p>\n<p>&nbsp;<\/p>\n<ol start=\"3\">\n<li>completeness<\/li>\n<li>realism<\/li>\n<li>need<\/li>\n<li>verifiability<\/li>\n<li>traceability<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p>Recommended Controls:<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-319 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-206.png\" alt=\"\" width=\"503\" height=\"180\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-206.png 503w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-206-300x107.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-206-65x23.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-206-225x81.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-206-350x125.png 350w\" sizes=\"auto, (max-width: 503px) 100vw, 503px\" \/><\/p>\n<p>Responsibility for Implementation (Accountability):<\/p>\n<p>&nbsp;<\/p>\n<p>Identify which people are responsible for implementation. In case of zero day attack, security policy must specify what action must be taken.<\/p>\n<p>&nbsp;<\/p>\n<p>Roles of people:<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-320 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-207.png\" alt=\"\" width=\"611\" height=\"599\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-207.png 611w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-207-300x294.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-207-65x64.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-207-225x221.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-207-350x343.png 350w\" sizes=\"auto, (max-width: 611px) 100vw, 611px\" \/><\/p>\n<p>Timetable:<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>Shows at what time the activity of plan will be executed and what process it will follow.<\/li>\n<li>Time line chart helps management track how many steps of the plan have been implemented.<\/li>\n<\/ul>\n<p>Continuing Attention:<\/p>\n<ul>\n<li>Objects and applied controls need to be scrutinized periodically and updated according to need.<\/li>\n<li>The security plan defines the time when the periodic review must take place.<\/li>\n<\/ul>\n<p>Team members needed for security planning:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-321 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-208.png\" alt=\"\" width=\"561\" height=\"171\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-208.png 561w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-208-300x91.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-208-65x20.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-208-225x69.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-208-350x107.png 350w\" sizes=\"auto, (max-width: 561px) 100vw, 561px\" \/><\/p>\n<p>Security planning team has member from each of the following group:<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>Computer hardware group<\/li>\n<li>System administrators<\/li>\n<li>System programmers<\/li>\n<li>Application programmers<\/li>\n<li>Data entry personnel<\/li>\n<li>Physical security personnel<\/li>\n<li>Representative users<\/li>\n<li>Commitment to the plan is &#8212;- Security functions will be implemented and security activities are carried out.<\/li>\n<li>The planning team<\/li>\n<li>Those affected by security recommendations<\/li>\n<li>Management<\/li>\n<\/ul>\n<p>Business Continuity Plans<\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>This is a documentation describing the situation of computer security incident and how a business will continue to function. The situations are catastrophic situations and long duration.<\/li>\n<li>To assess the impact of failure of business, ask questions:<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-322 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-209.png\" alt=\"\" width=\"664\" height=\"438\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-209.png 664w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-209-300x198.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-209-65x43.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-209-225x148.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-209-350x231.png 350w\" sizes=\"auto, (max-width: 664px) 100vw, 664px\" \/><\/p>\n<ul>\n<li>Develop strategy: Strategy finds how the key assets can be safeguarded?<\/li>\n<li>Develop Plan:<\/li>\n<\/ul>\n<p>Whose responsibility when an incident takes place?<\/p>\n<p>What actions to be performed?<\/p>\n<p>Who will perform the actions?<\/p>\n<ul>\n<li>Incident Response Plans<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-323 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-210.png\" alt=\"\" width=\"729\" height=\"746\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-210.png 729w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-210-293x300.png 293w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-210-65x67.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-210-225x230.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-210-350x358.png 350w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-324 aligncenter\" src=\"http:\/\/itp4.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-211.png\" alt=\"\" width=\"577\" height=\"783\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-211.png 577w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-211-221x300.png 221w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-211-65x88.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-211-225x305.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-content\/uploads\/sites\/25\/2018\/07\/Untitled-211-350x475.png 350w\" sizes=\"auto, (max-width: 577px) 100vw, 577px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Risk is distinguished by<\/p>\n<ol>\n<li>Calculating loss occurred due to an event<\/li>\n<li>The probability of the event to occur.<\/li>\n<li>The variation in the outcome.<\/li>\n<\/ol>\n<p>Risk exposure &#8211; Calculate the effects of a risk by multiplying the risk impact and the risk probability.<\/p>\n<p>&nbsp;<\/p>\n<ol>\n<li>Avoid the risk<\/li>\n<li>Transfer the risk<\/li>\n<li>Accept the risk<\/li>\n<\/ol>\n<ul>\n<li>Risk analysis &#8211; Examine a system and the context in which it is operating to determine possible exposures and potential harm that can be caused.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>Steps of a risk analysis<\/p>\n<p>&nbsp;<\/p>\n<ol>\n<li>Identify assets<\/li>\n<\/ol>\n<ul>\n<li>hardware<\/li>\n<li>software<\/li>\n<li>data<\/li>\n<li>people<\/li>\n<li>documentation<\/li>\n<li>Computer supplies<\/li>\n<li>Civil infrastructure<\/li>\n<li>Power, water,air and other environmental conditions<\/li>\n<li>Human and social assets<\/li>\n<\/ul>\n<ol start=\"2\">\n<li>Evaluate the vulnerabilities<\/li>\n<\/ol>\n<ol start=\"3\">\n<li>Estimate probability of exploitation<\/li>\n<\/ol>\n<ol start=\"4\">\n<li>Calculate annual loss that may occur<\/li>\n<li>Assess the controls that may be applied and their cost.<\/li>\n<li>Project annual savings of control.<\/li>\n<\/ol>\n<table>\n<tbody>\n<tr>\n<td><strong>you can view video on Administering security<\/strong><\/td>\n<td><a href=\"https:\/\/youtu.be\/kwjH3g6JWSk\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-120\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"\" width=\"36\" height=\"36\" \/><\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Suggested Reading:<\/strong><\/p>\n<ol>\n<li>Cryptography and Network Security Principles and Practice by William Stallings, sixth Edition, PEARSON.<\/li>\n<li>Security in Computing by Charles Pfleeger &amp; Shari Lawrence Pfleeger, fourth Edition, PEARSON.<\/li>\n<li>Network Security by Charlie Kaufman, Radia Perlman, Mike Speciner, second Edition, PHI.<\/li>\n<li>The Complete Reference \u2013 Network Security by Roberta Bragg, Mark Rhodes-Ousley &amp; Keith Strassberg, Tata McGraw Hill<\/li>\n<li>Network Security Bible by Eric Cole, Ronald Krutz, James Conley, Wiley<\/li>\n<li>Hacking 6 Exposed by Stuart McClure, Joel Scambray &amp; George Kurtz , Tata McGraw Hill .<\/li>\n<li><a href=\"http:\/\/www.snort.org\/\">www.snort.org<\/a><\/li>\n<li><a href=\"https:\/\/nmap.org\/\">https:\/\/nmap.org<\/a><\/li>\n<\/ol>\n","protected":false},"author":4,"menu_order":33,"template":"","meta":{"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":["miss-hiteishi-diwanji"],"pb_section_license":""},"chapter-type":[],"contributor":[58],"license":[],"class_list":["post-314","chapter","type-chapter","status-publish","hentry","contributor-miss-hiteishi-diwanji"],"part":3,"_links":{"self":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/chapters\/314","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/wp\/v2\/users\/4"}],"version-history":[{"count":4,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/chapters\/314\/revisions"}],"predecessor-version":[{"id":477,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/chapters\/314\/revisions\/477"}],"part":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/parts\/3"}],"metadata":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/chapters\/314\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/wp\/v2\/media?parent=314"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/pressbooks\/v2\/chapter-type?post=314"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/wp\/v2\/contributor?post=314"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp4\/wp-json\/wp\/v2\/license?post=314"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}