21. Administrative Personnel Controls Flashcards

1
Q

Administrative Personnel Controls

Administrative Security

A

Means to control peoples operational access to data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Administrative Personnel Controls

Least privilege

A

Minimum necessary access - No more, no less

  • exactly the access rights they need
  • Go through the adminsitrative process in the future if change of access is required in the future
  • Requires a lot of time and effort to maintain - not ideal for emergency situations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Administrative Personnel Controls

Need to know

A

Even if you have access, you do not need to know, you should not have access

*

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Administrative Personnel Controls

Separation of Duties

A

Internal control inteded to prevent fraud and error

  • Large organisations. Same person entering a purchase order does not issue the check
  • If one person can do all the admin controls himself, fraud is more likely
  • Exam assumes large organisation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Administrative Personnel Controls

Job Rotation

A

Detect Errors and Frauds

  • Less change of collusion between individuals if they rotate jobs
  • Helps avoid employee burnout
  • Can be cost prohibitive IRL
  • EXAM HINT: make sure cost justifies the benefit
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Administrative Personnel Controls

Mandatory Vacations

A

Ensure one person is not always performing the same task

  • Accounts can be locked and audited
  • Audit will discover fraud if employee has been covering it up
  • Give little or not notice
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Administrative Personnel Controls

Minimise insider threats with the 5 controls

A
  1. Least privilege
  2. Need to know
  3. Seperation of duties
  4. Job rotation
  5. Mandatory Vacations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Administrative Personnel Controls

NDA

New Employee

A

Non Disclosure Agreement

  • Clauses restricting employees use and dissemination of company owned confidential information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Administrative Personnel Controls

Background Checks

New Employee

A
  1. References
  2. Degrees
  3. Employment
  4. Criminal
  5. Credit history

  • Typically for sensitive positions
  • Can be an ongoing process
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Administrative Personnel Controls

Privilege Monitoring

New Employee

A

Monitoring highly privileged employees

  • The more privilege an employee has, the more we need to keep an eye on them
  • More access = more responsibility = more scrutiny
  • Privileged employees can expose more risks
  • Should be automated as much as possible
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Administrative Personnel Controls

PAM

A

Privileged Account/Access Management

  • Account - Account safeguarded
  • Access - What the account has access to
  • Monitor What, when, how, why, where

PAM LIFECYCLE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Administrative Personnel Controls

Regular Users

PAM Monitoring

A

Analyse Performance
Improve Efficiency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Administrative Personnel Controls

Privileged Users

PAM Monitoring

A

Access Matrix
(what changed?)

  • what was done, why, where, when
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Administrative Personnel Controls

All Users

PAM Monitoring

A
  1. Sensitive Data
  2. Critical Systems
  3. Insider/Outsider threats
  4. Compliance/regulatory requirements
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Administrative Personnel Controls

Systems

PAM Monitoring

A
  1. All servers (incl Jumpboxes)
  2. Endpoints
  3. Remote workstations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Administrative Personnel Controls

Full Monitoring

A
  1. MFA changes
  2. Remote connections
  3. Logs and records
  4. Anomaly detection
  5. Full visibility of admins
17
Q

Administrative Personnel Controls

Logging and Monitoring Activity

A
  1. Logging - Raw data. Logs from apps and infrastructure
  2. Monitoring - Ensure apps and infrastructure are available on request, alert of any issues

  • logging is raw data only, we dont do anything
  • Monitoring is admins making sure infrastructure and apps are available. Use of the raw data
  • You cannot have monitoring without logging
18
Q

Administrative Personnel Controls

Threat Intelligence

A
  1. Threat Feeds
  2. Threat Hunting

Threat Feeds
* raw data on current and potential threats
* Usable data such as suspicous domains, malware, hases, potential malicious code, flagged IPs

Threat Hunting
* Assume attackers are abel to access our network undetected

19
Q

Administrative Personnel Controls

UEBA

A

User and Entity Behaviour Analytics

  • Machine/deep learning model
  • Typical and atypical user behaviour, set baselines
  • Deviations from baselines detects anomalies
20
Q

Administrative Personnel Controls

3 things required for UEBA

A
  1. Use Cases
  2. Data Sources
  3. Analytics

  1. Use Cases - what normal user activity looks like
  2. Data Sources - Data source i.e. data lake/warehouse or SIEM
  3. Analytics - Build baselines to detect anomalies
    * remember different users have different use cases
    * use automation to look for anything our of the ordinary
    * early on in implementation, there will be a lot of fasle positives