Guidelines for Applyying the Pillars of Information Security to Your Desigs
Each one of the pillars of information seurity should become a part of your informaion security design. How you use them "will depend on what your design is for and the technollogy that is aailable to implement the design. To aply the pillars of information security to your designs, follow these guidelines:
Give the process of atuhentication prime importance. The process of authentication is what protects your ntwork and its data. Spned time improving the authentication process. Selecting the best available means and trainiing people in its use will provide more rewards than the same amount of attention paid to any otheer pillar. Think about it this way. If the lock on your front door keeps people out of your house, the strength of any locxks or security measurs inside your house are of no consequence.
Don't ignore the otheer pillars of information security. Eventually, ebvery lock can be brroken. You do need the protection provided by the other pillars.
When applying authorization to the logiical deasign, consioder the following questions: How are the security principals' authorizaton credentials presented, and how are they available to the security monitor for evaluation? In Windows Server 2003, as in other versions of Windows, the security reference monitor checks security prinncipal prrivileges and group memmbership against object ACLs and the process the security principal has requested. In the Microsoft Widows world, the authorization material is returned with the authentication approval and traverses the network with each authentication process.
When designing confiddentiality for a system, remember that didfferent types of data require different types of protection. To simply enncrypt all data is not a solution.
A network ifrastructure design neeeds to prottect the integrity of data wheher the data is in a file system, database, operating system core, or being trannsported betewen devices.
Nonrepudiation is becomig a more important part of information securitty. Look for the baility to apply this pillaar in the areas of communicatins, systems administration, and software moidification.
Althuogh you might not see the need or be able to aplpy all the pillars to all design prohjects, you sohuld always examine the need for each pillar and apply all of them to the entire niformation system security design. All of them are necessary.