Материал: Крючков Фундаменталс оф Нуцлеар Материалс Пхысицал Протецтион 2011

Внимание! Если размещение файла нарушает Ваши авторские права, то обязательно сообщите нам

Information Protection Association, account for 39% of computer system faults. A physical influence can be staged with the aid of high-tech electronic devices that are capable of intercepting hardware signals and stealing so information. It is possible to disable signals and compromise hardware systems by insertion of data intercepting devices in workrooms. A database can be destroyed by elementary influences, such as fire or flooding of hardware. This case does not necessarily require any influence on the room or the hardware which stores data. It will be enough, say, to set fire to a neighboring room more accessible to outsiders.

Less obvious are organizational and legal influences of threats. These influences include personnel’s or executive staff’s failures to abide by regulatory requirements or delays with adoption of regulations and rules. A failure to fulfill or absence of regulatory requirements leads frequently to other influences of threats coming into being. Threats may also come from purchases of outdate equipment, unauthorized restriction of access to data and so on.

Prevention, suppression or neutralization of threats to information security is implemented through information security features based on developed and introduced countermeasures to various information security threats. Information security features include organizational, technical, cryptographic and software means designed to protect limitedly accessible data, as well as the software and hardware in which this is realized. Besides, these also include information protection efficiency controls.

Efficient and all-round protection of information against potential threats requires a variety of countermeasures to said threats and techniques to be used to prevent these from being enabled. Threats can be prevented, suppressed or neutralized by organizational, legal, physical protection and software/hardware methods.

Organizational and legal methods primarily suggest development of a set of regulatory legal acts and bylaws to govern information relations of guides and procedural regulations for information security support purposes. These regulations form the basis on which an information security licensing system is established, and information security techniques and facilities are standardized. In turn, organizations need to form and provide operations of the sensitive and confidential data security systems. These systems are subject to certification and qualification based on information security guide requirements. A major procedure involved in the development of automated NM A&C systems is generation of personnel job descriptions and regulations governing personnel behaviors

381

in various situations. Operations require these instructions to be strictly observed.

Physical protection of rooms, communication lines, data transmission channels and information carriers must be organized to prevent information from being physically infiltrated, stolen or intercepted. Physical protection is highly instrumental to information security. We shall see when looking into the classification of computerized NM A&C systems that it is exactly physical protection that enables base software certified to information security class 3 to be used for NM accounting purposes.

Finally, design and creation of computer networks immediately requires employment of softwareand hardware-based countermeasures to information security threats. These countermeasures have increased roles in overt data transmission channels. In a brief account, the following measures are used:

∙avoidance of unauthorized access to data;

∙prevention of special influences leading to destruction, elimination and corruption of information or malfunctions of equipment using information technologies;

∙detection of inserted software and hardware bugs;

∙use of data security features, including cryptographic ones, for transmission of information over communication channels.

Planning of countermeasures to purposeful information security threats need to take into account that, despite an increased publicity given by media to outside attacks on computer systems, much greater security damage may come from internal security violations. The data provided by a computer crime research center [10] says 70% of security violations in 2002 took place within organizations, having been often caused by discontented staff members. So crucial in this respect is a bona fide manning policy and correct distribution of personnel responsibilities to avoid cases of security depending on one person.

8.4. Standards on information security in automated NM A&C systems

There is rather an extensive list of Rosatom’s documents pertaining to information security in automated systems of the ministry’s enterprises and organizations. These are listed in the industry standard on equipment of NM accounting and control systems [1]. As such, the industry standard contains provisions that deal with security of information both in terms of data access security and reliability of data storage. This section will consider Russian standards in the field of information access security

382

expected to guide developers of NM A&C systems in designing data security features. The prime document that establishes the classification of NM A&C systems and governs requirements to information access security in these is a guide of Russia’s State Technical Commission (Gostekhkomissiya) and Ministry for Atomic Energy (Minatom) entitled “Requirements to Information Access Security in Aut omated Nuclear Material Accounting and Control Systems”, approved in January 1997 [9]. This document also contains requirements to certification of information security features for such systems and qualification requirements to NM A&C systems.

The document was developed based on the 1992 information security guides of Russia’s Gostekhkomissiya [4–8]. Preceden ts exist when computerized NM A&C systems were qualified based on these criteria rather than on the 1997 requirements. Finally, it was on 1 January 2004 that a new standard, ISO/MEC 15408–99 [11–13], developed based on the international Common Criteria, was put into operation in Russia. This was an important step in the development of an information security regulation framework because it introduced up-to-date approaches and requirements to security of information systems in Russia. Prospectively, steps towards harmonizing domestic and international requirements in the field will make it possible for Russian software developers to enter foreign software market. Still, the introduction of new standards does not make the requirements of Gostekhkomissiya’s guides null and void.

In near term, the state of art in the field of regulatory computer security requirements is thought to be greatly influenced by the Federal Technical Regulation Law that took effect on 1 July 2003. Hereinafter, we shall discuss in brief the concerns and tasks arising out of the newly adopted law.

8.4.1. Requirements to information access security in automated NM A&C systems

This document has been developed by the Russian Federal Nuclear Center – All-Russian Research Institute for Experim ental Physics (RFNCVNIIEF) and the Pacific Northwest National Laboratory (PNNL), the USA, as part of an agreement to upgrade physical protection, accounting and control of nuclear material in Russian Federation. The document’s prime objective is to form a regulatory framework for certification, subject to information security requirements, of automated NM A&C system software developed based on Microsoft’s commercial software products. The

383

document introduces a classification of automated NM A&C systems, defines requirements to information access security features depending on the class of the NM A&C system and, finally, specifies certification and qualification requirements to information security features.

Classification of NM A&C systems

Classification of NM A&C systems is introduced for the purpose of developing and employing valid measures to achieve the required level of information security. The security class is determined by the NM A&C system user and developer with involvement of information security experts. The following system features are used as criteria in establishing the class of security:

∙presence in the NM A&C system of information of different secrecy levels;

∙level of the user authority for access to classified information;

∙procedures and conditions for the deployment and operation, and the physical security status the NM A&C system computers.

Based on the estimates for these factors, the requirements establish three security classes for automated NM A&C systems. The highest of these is Class 1.

Class 3 includes NM A&C systems which are characterized by:

∙the presence of information of strictly one secrecy level;

∙all access subjects (except the administrator) having equal rights (powers) of access to the NM A&C system information;

∙all NM A&C computes installed within a controlled area and having no external physical information communications (leading to beyond the controlled area).

Class 2 includes NM A&C systems which are characterized by:

∙the presence of information of several secrecy levels;

∙subjects of access having different rights of access to the NM A&C system information;

∙all NM A&C system computers installed within one or more controlled areas and having no open external physical information communications.

Class 1 includes NM A&C systems which are characterized by:

∙the presence of information of several secrecy levels;

∙subjects of access having different rights of access to the NM A&C system information;

384

∙ the NM A&C system computers installed within a controlled area and having external physical information communications with computers other than in NM A&C system.

All currently certified base software falls only into Class 1. Table 8.1 presents software products certified for use in computerized NM A&C systems.

Table 8.1

Base software certified for use in computerized NM A&C systems

Software type

Description

Operating systems

MS Windows NT 4.0 Workstation

 

(Russian) with the SP 3 or SP 5 update

 

package

 

MS Windows NT 4.0 Server with the SP

 

3 and SP 5 update package

 

MS Windows NT 4.0 Server Enterprise

 

Edition with the SP 5 update package

Database management systems

Microsoft SQL Server, version 6.5., with

(DBMS)

the SP 4 or SP 5а update package

 

Oracle7 Server and Workgroup Server,

 

version 7.3.4.0.0

 

Oracle8i Enterprise Edition, version

 

8.1.7.0.0

The major problem that hampers the evolution of computerized accountancy at this state of the Federal Information System development is the absence of base software certified higher than to Class 3. An NM A&C system falling into Class 3 is expected to contain information of only one secrecy level. Still, the industry’s enterprises often use materials of different secrecy levels. In this case, the fulfillment of Gostekhkomissiya’s requirements is expected to lead to either the creation of not less than two segregated local area networks to account for materials of different secrecy levels or to all materials having their secrecy level raised to the maximum. The former case entails a dramatic increase in the network creation cost, while the latter makes it much more difficult for personnel to handle material of originally low secrecy level. Finally, the last, but not the least, requirement demands that the whole of the enterprise to be based within one site. This requirement is not applicable to large-sized fuel cycle enterprises. The only solution in this case is to build computerized system

385

Источник: https://studfile.net/preview/16708779/