170 likes | 290 Views
Assuring Reliable and Secure IT Services. Chapter 6. Availability Math. Availability of components in series. High-availability Facilities. Uninterruptible electric power delivery Physical security Climate control and fire suppression Network connectivity
E N D
Assuring Reliable and Secure IT Services Chapter 6
Availability Math • Availability of components in series
High-availability Facilities • Uninterruptible electric power delivery • Physical security • Climate control and fire suppression • Network connectivity • Help desk and incident response procedures
Classification of Threats • External attacks • Intrusion • Viruses and worms
Defensive Measures • Security policies • Firewalls • Authentication • Encryption • Patching and change management • Intrusion detection and network monitoring
A Security Management Framework • Make deliberate security decisions. • Consider security a moving target. • Practice disciplined change management. • Educate users. • Deploy multilevel technical measures, as many as you can afford.
HIGH High Consequence High Consequence Low Probability High Probability CRITICAL THREATS Consequences PRIORITIZE THREATS Low Consequence Low Consequence Low Probability High Probability LOW MINOR THREATS 0 Probability 1 Managing Infrastructure Risks: Consequences and Probabilities Source: Applegate, Lynda M., Robert D. Austin, and F. Warren , Corporate Information Strategy and Management . Burr Ridge, IL: McFarlan McGraw - Hill/Irwin, 2002. Chapter 6 Figure 6 - 9
Incident Management and Disaster Recovery • Managing incidents before they occur. • Sound infrastructure design • Disciplined execution of operating procedures • Careful documentation • Established crisis management procedures • Rehearsing incident response • Managing during an incident. • Managing after an incident.