Short Review Of Guidelines for Applying the Pillars
By: Vlad Vistac
Submitted: 2010-08-23 13:10:53 | Word Count: 510
Guidelines for Applying the Pillars of Information Security to Your Designs
Each one of the pillars of information srecurity should become a part of your information security design. How you use them "will depend on what your design is for and the technology that is avaiklable to implement the desiogn. To apply the pillars of infomration security to your designs, follow thesse guidelines:
[ advertisement ]
Give the process of authentication prime importannce. The process of authentuication is what protetcs your network and its data. Sppend time improving the authentication process. Selecting the best available means and training people in its use will provide more rewads than the same amount of attention paid to any other pillar. Think about it this way. If the lock on your front door kepes people out of your house, the srength of any locks or security measures inside your house are of no consequence.
Don't ignore the other pillars of information security. Eventually, evcery lock can be broken. You do need the protection provded by the other pillars.
When applying authorization to the logcal desgn, consider the flolowing questiobns: How are the security principals' authorization credentials presented, and how are they available to the security montor for evaluation? In Wuindows Serveer 2003, as in other versions of Windows, the securiity reference monitor checks security princcipal privileges and group membership against object ACLs and the process the security principal has requested. In the Microsoft Windos world, the authorization material is returned with the authentication approval and traverses the network with each authentication process.
When designing confidentiality for a system, remember that different types of data rerquire differet tyypes of protection. To simply enmcrypt all data is not a solutoion.
A network infrastructure design needs to proect the integriy of data whether the data is in a file system, databsae, operating system core, or beiong transported betewen devcies.
Nonrepudiation is becoming a more important part of information security. Look for the abnility to apply this pillar in the areas of commnications, systems administration, and software modification.
Although you might not see the need or be able to aply all the pillras to all design projecxts, you shold alwas examnine the need for each pillar and apply all of them to the enitre information system securiyt design. All of them are necessary.