Конференция Персональные данные 2012: проблемы и решения

Вы здесь: Главная СТАНДАРТЫ ISO 27000 - Международные стандарты управления информационной безопасностью ISO/IEC 27033 Information technology. Security techniques. Network security

Вход Регистрация



Защита персональных данных
Статьи по защите персональных данных
Видео о защите персональных данных
Федеральный закон N 152-ФЗ "О персональных данных"
Федеральный закон Российской Федерации от 27 июля 2006 г. N 152-ФЗ "О персональных данных"
Об утверждении Положения об обеспечении безопасности персональных данных при их обработке в информационных системах персональных данных
Постановление Правительства РФ № 781 от 17 ноября 2007
Об утверждении Положения об особенностях обработки персональных данных, осуществляемой без использования средств автоматизации
Постановление Правительства Российской Федерации от 15 сентября 2008 г. N 687
See the entire folder …
СОФТ
Средства для оценки рисков
Средства разработки и внедрения политик безопасности
Средства мониторинга действий пользователей
Программы, предназначенные для контроля работы пользователей и администраторов за своими компьютерами и в сети Интернет. Они сообщают по сети информацию, которая интересует шефа, ему лично или уполномоченному им лицу.
Средства аудита и восстановления паролей
Шифровальщики файлов
Эти программы обеспечивают недорогое, надежное и быстрое шифрование файлов и дисков с использованием популярных алгоритмов (AES, 3DES, Blowfish, ...)
See the entire folder …

ISO/IEC 27033 Information technology. Security techniques. Network security

Send this page to somebody Print this page

Общие сведения о новом семействе стандартов в области управления сетевой безопасностью ISO/IEC 27033 "Информационные технологии. Методы обеспечения безопасности. Сетевая безопасность".

In today’s world, the majority of both commercial and government organizations have their information systems connected by networks, with the network connections being one or more of the following:
  • Within the organization
  • Between different organizations
  • Between the organization and the general public.

Further, with the rapid developments in publicly available network technology (in particular with the Internet) offering significant business opportunities, organizations are increasingly conducting electronic business on a global scale and providing online public services. The opportunities include the provision of lower cost data communications, using the Internet simply as a global connection medium, through to more sophisticated services provided by Internet service providers (ISPs). This can mean the use of relatively low cost local attachment points at each end of a circuit to full scale online electronic trading and service delivery systems, using web-based applications and services.

Additionally, the new technology (including the integration of data, voice and video) increases the opportunities for remote working (also known as “teleworking” or “telecommuting”) that enable personnel to operate away from their home work base for significant periods of time. They are able to keep in contact through the use of remote facilities to access organization and community networks and related business support information and services.Broad Type of Network Connections - BS ISO/IEC 27033-1

However, whilst this environment does facilitate significant business benefits, there are new security risks to be managed. With organizations relying heavily on the use of information and associated networks to conduct their business, the loss of confidentiality, integrity, and availability of information and services could have significant adverse impacts on business operations. Thus, there is a major requirement to properly protect networks and their related information systems and information. In other words: implementing and maintaining adequate network security is absolutely critical to the success of any organization’s business operations.

In this context, the telecommunications and information technology industries are seeking cost-effective comprehensive security solutions, aimed at protecting networks against malicious attacks and inadvertent incorrect actions, and meeting the business requirements for confidentiality, integrity, and availability of information and services. Securing a network is also essential for maintaining the accuracy of billing or usage information as appropriate.

Security capabilities in products are crucial to overall network security (including applications and services). However, as more products are combined to provide total solutions, the interoperability, or the lack thereof, will define the success of the solution. Security must not only be a thread of concern for each product or service, but must be developed in a manner that promotes the interweaving of security capabilities in the overall security solution.

The purpose of BS ISO/IEC 27033 is to provide detailed guidance on the security aspects of the management, operation and use of information system networks, and their inter-connections. Those individuals within an organization that are responsible for information security in general, and network security in particular, should be able to adapt the material in this standard to meet their specific requirements.

If you use BS ISO/IEC 27001 and BS ISO/IEC 27002  then this will be of interest. It is at a more technical level and would be of interest to IT network specialists.

What are the main objectives of BS ISO/IEC 27033?

BS ISO/IEC 27033-1, Overview and concepts: to define and describe the concepts associated with, and provide management guidance on, network security. This includes the provision of an overview of network security and related definitions, and guidance on how to identify and analyze network security risks and then define network security requirements. It also introduces how to achieve good quality technical security architectures, and the risk, design and control aspects associated with typical network scenarios and network “technology” areas (which are dealt with in detail in subsequent parts of ISO/IEC 27033).

ISO/IEC 27033-2, Guidelines for the design and implementation of network security, to define how organizations should achieve quality network technical security architectures, designs and implementations that will ensure network security appropriate to their business environments, using a consistent approach to the planning, design and implementation of network security, as relevant, aided by the use of models/frameworks (in this context, a model/framework is used to outline a representation or description showing the structure and high level workings of a type of technical security architecture/design), and is relevant to all personnel who are involved in the planning, design and implementation of the architectural aspects of network security (for example network architects and designers, network managers, and network security officers).

ISO/IEC 27033-3, Risks, design techniques and control issues for reference network scenarios, to define the specific risks, design techniques and control issues associated with typical network scenarios. It is relevant to all personnel who are involved in the planning, design and implementation of the architectural aspects of network security (for example network architects and designers, network managers, and network security officers).

It is emphasized that ISOI/IEC 27033 provides further detailed implementation guidance on the network security controls that are described at a basic standardized level in ISO/IEC 27002.

Contents of BS ISO/IEC 27033-1 include:

  • Scope
  • Normative references
  • Terms and definitions
  • Abbreviated terms
  • Structure
  • Overview
  • Background
  • Network Security Planning and Management
  • Identifying Risks and Preparing to Identify Security Controls
  • Information on Current and/or Planned Networking
  • Information Security Risks and Potential Control Areas
  • Supporting Controls
  • Management of Network Security
  • Technical Vulnerability Management
  • Identification and Authentication
  • Network Audit Logging and Monitoring
  • Intrusion Detection and Prevention
  • Protection against Malicious Code
  • Cryptographic Based Services
  • Business Continuity Management
  • Guidelines for the Design and Implementation of Network Security
  • Network Technical Security Architecture/Design
  • Reference Network Scenarios – Risks, Design, Techniques and Control Issues
  • Internet Access Services for Employees
  • Enhanced Collaboration Services
  • Business to Business Services
  • Business to Customer Services
  • Outsourcing Services
  • Network Segmentation
  • Mobile Communications
  • Network Support for Traveling Users
  • Network Support for Home and Small Business Offices 
  • ‘Technology’ Topics – Risks, Design Techniques and Control Issues
  • Develop and Test Security Solution 
  • Operate Security Solution 14 Monitor and Review Solution Implementation
  • Technology’ Topics – Risks, Design Techniques and Control Issues
  • Cross-references Between ISO/IEC 27001/27002 Network Security Related
  • Controls and ISO/IEC 27033-1 Clauses
  • Example Template for a SecOPs Document

If there are other parts in the future, these will be relevant to all personnel who are involved in the detailed planning, design and implementation of the network aspects covered by those parts (for example network architects and designers, network managers, and network security officers).

It should be noted that BS ISOI/IEC 27033 is not a reference or normative document for regulatory and legislative security requirements. Although it emphasizes the importance of these influences, it cannot state them specifically, since they are dependent on the country, the type of business, etc.

Unless otherwise stated, throughout this part of ISO/IEC 27033 the guidance referenced is applicable to current and/or planned networks, but will only be referenced as “networks” or “the network”.

It is proposed that future parts of ISO/IEC 27033 will address the following topics.

ISO/IEC 27033-4, Risks, design techniques and control issues for securing communications between networks using security gateways, to define the specific risks, design techniques and control issues for securing information flows between networks using security gateways. It will be relevant to all personnel who are involved in the detailed planning, design and implementation of security gateways (for example network architects and designers, network managers, and network security officers).

ISO/IEC 27033-5, Risks, design techniques and control issues for securing virtual private networks, to define the specific risks, design techniques and control issues for securing connections that are established using virtual private networks (VPNs). It will be relevant to all personnel who are involved in the detailed planning, design and implementation of VPN security (for example network architects and designers, network managers, and network security officers).

ISO/IEC 27033-6, IP convergence, to define the specific risks, design techniques and control issues for securing IP convergence networks, i.e. those with the convergence of data, voice and video. It will be relevant to all personnel who are involved in the detailed planning, design and implementation of security for IP convergence networks (for example network architects and designers, network managers, and network security officers).

ISO/IEC 27033-7, Wireless, to define the specific risks, design techniques and control issues for securing wireless and radio networks. It will be relevant to all personnel who are involved in the detailed planning, design and implementation of security for wireless and radio networks (for example network architects and designers, network managers, and network security officers).


30-05-2012
Positive Hack Days 2012
Москва, Центр Digital October, Берсеневская наб., 6, стр. 3
30-05-2012
VIII-й Специализированный форум «Современные системы безопасности — Антитеррор»
Россия, Красноярск, ул. Авиаторов, 19, МВДЦ «Сибирь».
31-05-2012
Информационная безопасность: новые потребности рынка
07-06-2012
IT & Security Forum 2012 Kazan
Казань, отель Корстон, ул. Николая Ершова 1А
07-06-2012
8-й Евразийский форум информационной безопасности и электронного взаимодействия «ИНФОФОРУМ-Евразия»
Москва, здание Правительства Москвы (ул. Новый Арбат, 36)

< Май 2012 >
Пн Вт Ср Чт Пт Сб Вс
12 3456
78910111213
1415 16 17 18 19 20
21222324252627
282930 31
Рассылка

Пресс-релизы компаний
Новости портала
Антивирусный вестник



©2003 - 2012 GlobalTrust
Разработка сайта: Maximaster
Рейтинг@Mail.ru Rambler's Top100 Yandex