The ten-step strategy of the Self-security inspection mechanism

Source: Internet
Author: User

The explosive development of network applications in the past 10 years has led to some IT factors for enterprises that have grown to the top 500 companies in the world, to a certain extent.

Every enterprise has its own valuable IT assets, such as computers, networks and data. To protect these assets, large and small enterprises must have their own independent security review mechanisms, so that they can promptly discover the security problems faced by enterprises and how to deal with risks.

The following 10 suggestions will show you how to implement the most basic IT check. Although these suggestions are not as broad as professionals do, they allow you to get started on the road to security protection.

1. Scope of building security audit: list assets and security scope

The first step of the security review is to list the computer assets before we know what needs to be protected. Listing tangible assets is simple, such as computers, servers, and folders. However, the list of intangible assets is not that easy. The scope of security review is useful to ensure the continuity of the List of listed intangible assets.

What is the scope of security review?

The scope of security review is both a physical and conceptual boundary. Security Review focuses only on what falls within the boundary, and what falls beyond the boundary is irrelevant to security review. Of course, the final scope of security review is yours, but in general, security scope should be the smallest limit, only including assets necessary to control your enterprise's security.

Assets to be considered

Once you determine the security scope, you need to complete the asset list. We need to consider all potential assets and determine whether those assets should be included in the security scope. Generally, the following assets must be listed:

1. desktop and notebook

2. Routers and Network Tools

3. Printer

4. Videos, whether digital or similar, and photos containing sensitive company data

5. sales data, customer information data, and employee information data

6. Company smart phones and handheld computers

7. VoIP Phone, ip pbx (private branch (telephone) exchange dedicated group switch) and related servers

8. Call records for VoIP or regular phones

9. Email

10. logs of employees' daily work arrangements and activities

11. webpage, especially those requests for user information, and database access requests supported by web scripts

12. Network Server

13. Monitoring video

14. Employee Exit Permit

15. Access Points (for example, access control system scanners)

This clearance list does not cover all assets. You have to think twice about the data that has not been included. The more detailed the list of listed assets, the better. This will help you more accurately recognize the risks that the computer is facing.

------------------------------- Pagination bar -------------------------------

2. Create a "dangerous list"

Only knowing that assets are insufficient for protection, but they also need to be at risk. This step mainly lists some of the risks you may face at this stage.

What risks should be included?

If your dangerous list is too general, you should pay special attention to the security issues at the bottom. When you decide which risks should be included in the list, you should test them based on the scale. For example, if you consider whether a hurricane will affect your server, you should consider both of them. Although the risk is small, the risk will be fatal. If the risk is high enough to affect your business, no matter how small the risk is, it should be included in the list.

What are the general "risks?

The following common risks can be used as a reference when you build a risk list:

1. computer and network password. Is there a log containing everyone's password? How secure is the Access Control List (ACL) List? Is the current password safe enough?

2. real assets. Will desktops and laptops be taken out of the workplace by visitors or employees?

3. Records of real assets. Do they exist? Backup?

4. Data Backup. Which virtual assets need to be backed up, how to back up, where to store, and who will manage the backup?

5. network access logs. When someone accesses the data, whether the access is recorded, who, when, and where.

6. Access to sensitive customer information, such as credit card information. Who can access it? How to implement access control? Can I access networks outside of my company?

7. Access to the customer list. Does the website allow access to the client database through a backdoor? Will it be hijacked?

8. Long-distance dialing. Will long-distance dialing be restricted, or will all dialing be free of charge? Should I be restricted?

9. Email. Are the spam filters properly arranged? Do employees need to educate on spam and phishing? Shouldn't the emails sent by the company contain some form of hyperlinks?

3. Expired detection and prediction of the future

At this stage, you need to edit the current dangerous list, but what about the risks that have not been discovered, or those that have not yet been developed? A good security check is not only about reality, but also needs to predict future risks.

Learn from history

To predict the future, you must first understand the dangerous history of the past. Many risks have repeatedly appeared in history. They classify past risks and include them in your risk list, this gives you a more comprehensive understanding of computer vulnerabilities.

Check security trends

It is of great benefit to learn about some popular network security risks through the network and major security portals.

Coordinated Operation

In the face of external risks, some competitors often become the biggest assets of the other party. Building a good relationship with competitors can help you gain a comprehensive understanding of network security risks. We need to share security threat information with our competitors.

------------------------------- Pagination bar -------------------------------

4. Security Classification

Now you have listed the list of risks and assets to be protected. However, these lists need to be prioritized. In this step, you need to determine which risks are the greatest so that the steel can be used easily.

Use risk assessment and probability calculation tools

The higher the risk, the higher the security level. The risk calculation formula is as follows:

Risk = Possibility multiplied by hazard

This formula is to multiply the possibility of hazard and danger. The result is the risks faced by the enterprise.

Computing possibilities

Possibility refers to the possibility that a danger actually occurs. Unfortunately, there is no book on the market that teaches you how to calculate the possibility of a website being hijacked, so you have to calculate it on your own.

The first step in computing possibility is to conduct a systematic research on the company's historical threats, including the competitor's history and some historical threat analysis faced by other companies. Finally, you will get an estimate. Generally, the more accurate the estimation, the more accurate the risk assessment.

Computing hazards

What are the threats? There are many ways to calculate the potential harm of threats. You can convert your company's income loss and assets into currencies. Or compute the labor cost for restoring the normal state. No matter what computing method you use, you must identify the most important security elements.

Develop Security Threat Response Mechanisms

After a security level list is created, there are many response measures in response to security risks. The following describes the six main response methods. However, this is by no means the most important method.

5. Execute network access control

Network Access Control (NAC) can be used to check the security of any network users. For example, if you find that your competitors use the company's secret website to steal your information, you can use NAC. This is an excellent choice.

An effective part of NAC is the access control list (ACL), which can determine which network resources are open to users. NAC should also include the following steps: encryption, digital signal, ACL, confirm IP address, user name, and check the cookies of web pages.

6. Use Intrusion Prevention

NAC is mainly used to deal with unauthorized customers. IPS (Intrusion Prevention System) is used to prevent more dangerous hackers.

The most common IPS is the second generation firewall. Unlike the first-generation firewall, the first-generation firewall seldom uses content filters, and the second-generation Firewall adds content filters.

● Content-based. This type of Firewall uses a deeper information packet check, that is, it fully checks the content of the application to find out whether there is danger.

● Based on evaluation. The second generation Firewall uses more advanced analysis methods to analyze website or network traffic or application content check, so as to identify some exceptions.

------------------------------- Pagination bar -------------------------------

7. Use identity/Access Management (IAM)

To put it simply, IAM controls users to access specific network resources. Under IAM management, users must first obtain a license to access resources. Once authorized, users can access the authorized resources.

IAM is useful when managing information access permissions of enterprise employees. For example, if an employee wants to steal users' credit card information, IAM is the best choice.

8. Use Backup

When we think of IT security risks, we first think of computer hijacking. However, the biggest risk for enterprises is the loss of information. Although the backup seems not very good, the simplest way to deal with information loss is data backup. Note the following when using backup:

● Online storage. There are several types of online storage: mobile hard disks or disk storage within a fire-proof space. The same data can be stored in the hard disk, but is separated from the outside by DMZ.

● Offline storage. Some confidential information should be stored offline as a supplement to online storage. Make the worst plan: Will your hard disk or digital disk be safe in the event of a fire? What if a hurricane or earthquake occurs? You can use removable media or VPN (virtual personal network) to store data offline.

● Secure access to backup data. Sometimes, access to backup data is also on the rise. Security should be ensured for access to offline data centers or access through VPN. You can use keys, RFID smart cards, VPN passwords, and security combinations.

● Scheduled backup. Backup should be automated as much as possible. There should be a backup plan within the company, not affected by human factors. When determining the backup frequency, make sure that the backup is feasible.

9. Email protection and filtering

Every day, 55 billion million spam mails are generated worldwide. To limit the risks of spam, as part of enterprise security, spam filters and well-trained employees are required. Therefore, in order to effectively cope with spam

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.