logical access control

18

Upload: himanshu-gond

Post on 13-Nov-2014

38 views

Category:

Documents


6 download

DESCRIPTION

Logical Access Control

TRANSCRIPT

Page 1: Logical access control
Page 2: Logical access control

Presentation Content

Access Control

Logical Access Control

Logical Access Control Component

Logical Access Control Examples.

Physical Access Control

Page 3: Logical access control

Purpose of Physical Access Control

Measure of Physical Access Control

Biometrics

Cross Error Rate/ Equal Error Rate

Page 4: Logical access control

Access Control

Access is the flow of information between subject and

object.

Subject: User, Program, Process or Device.

Object: Computer, Computer program, Database File.

Access Control are collection of mechanisms that work

together to protect the information assets and resources of

an organization from an unauthorized access.

Page 5: Logical access control

Access Control enable management to:

Specify which users can access the information and

uses the resources of an organization.

Specify what resources they can use.

Specify what operations they can perform.

Provide individual accountability.

Cont.….

Page 6: Logical access control

Access Control

Administrative Control

Logical Control

Physical Control

Page 7: Logical access control

Logical access control are the tools used to allow or

restricts subject access to objects on the basis:

Identification

Authentication

Authorization

Accountability

Page 8: Logical access control

Identification

A user accessing a computer system would present credentials or identification, such as a username, user ID.

Authentication

Checking the user’s credentials to be sure that they are authentic and not fabricated, usually using a password, pin, biometric etc.

Authorization

Granting permission to take the action on certain services or applications in order to perform their duties.

Accountability

Audit logs and monitoring to track subject activities with objects

Page 9: Logical access control

Logical Access Control

component

System Access

Network Architecture

Network Access

Encryption and

Protocols

Auditing

Page 10: Logical access control

Type of Control Preventive Detective Corrective Recovery Compensative

ACLs

Routers

Encryption

Audit Logs

IDS

Antivirus Software

Server images

Smart cards

Dial up-Call back

Data backup

Page 11: Logical access control

PHYSICAL ACCESS CONTROL

Physical access control is a matter of :-

- WHO

- WHERE &

- WHEN

Historically this was partially accomplished through keys and

locks.

In some cases, physical access control systems are integrated

with electronic ones

Page 12: Logical access control

PURPOSE OF PHYSICAL ACCESS CONTROLS

These entail controlling individual access into the: facility and different departments removing unnecessary CD-ROM drives, protecting the perimeter of the facility, monitoring for the intrusion environmental controls.

Page 13: Logical access control

MEASURES TO ACHIEVE PHYSICAL ACCESS CONTROLS

Physical access controls can be achieved by the following

means:

Humans (Guards etc)

Mechanical means (Lock and Keys)

Electronic access control

Biometrics

CCTV

Page 14: Logical access control
Page 15: Logical access control

BIOMETRICS

It is broken into two categories:

1. Physiological

2. Behaviorial

Two types of biometric errors:

3. Type 1 errors (False Rejection Rate)

4. Type 2 errors (False Acceptance Rate)

Page 16: Logical access control

CROSS ERROR RATE/EQUAL ERROR RATE

This rating is rated as a percentage and represents the

point at which the false rejection rate is equal to the

false acceptance rate.

This rating is the most important measurement when

determining the system’s accuracy.

Page 17: Logical access control
Page 18: Logical access control