Recommended Controls for Risk Control Policies

When auditing an object using the Relational Security Assessment Model, there are many different types of controls that can be checked. Policies should be developed that dictate minimums level of controls for objects of certain risk levels. Table C.1 includes some common controls that should be audited:

Table C.1. Example Risk Controls Sorted by Object Type
All Objects
Local authenticationTo gain direct access to the object, what level of authentication is required?
Remote authenticationTo gain remote access to the object, what level of authentication is required?
Level of loggingTo what degree are the subject's actions logged?
Level of monitoringTo what degree are such logs monitored?
Internal redundancyWhat level of redundancy exists internal to the object (such as a RAID configuration)?
External redundancyAre there other objects that are fully redundant to this object?
Backup/Recovery controlIf the object was destroyed, how much could be recovered and how quickly?
Routers and Other Network Devices
Level of hardeningTo what degree have hardening tasks been performed? Have services been disabled, patches applied, accounts locked down?
Degree of maintenanceHow often is this object audited and updated for new vulnerabilities?
Servers
Antivirus software installedIs antivirus software installed and running?
Antivirus software updatedIs the antivirus software updated regularly and automatically?
Level of hardeningTo what degree have hardening tasks been performed? Have services been disabled, patches applied, accounts locked down?
Degree of maintenanceHow often is this object audited and updated for new vulnerabilities?
Physical Areas
Room constructionIs the room secure enough to store equipment of this risk level?
Degree of disaster preventionAre there adequate fire controls and other safety precautions?
Environmental conditionsIs the environmental conditioning adequate for a room of this risk level?

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.17.167.114