| Preface to the Third Edition |
|
xiii | |
| Preface to the Second Edition |
|
xv | |
| Acknowledgments |
|
xvii | |
| PART I THE THREAT TO COMPUTER SECURITY |
|
|
Essentials of Computer Security |
|
|
3 | (26) |
|
Unique EDP Security Problems |
|
|
3 | (5) |
|
EDP Security in a Nutshell |
|
|
8 | (5) |
|
Computers and Crime; Know Your Enemy! |
|
|
13 | (7) |
|
The Anatomy of Computer Crime |
|
|
20 | (9) |
|
Computer Crime and the Law |
|
|
29 | (36) |
|
|
|
29 | (3) |
|
|
|
32 | (3) |
|
|
|
35 | (7) |
|
|
|
42 | (2) |
|
|
|
44 | (1) |
|
|
|
44 | (2) |
|
|
|
46 | (1) |
|
|
|
47 | (18) |
|
|
|
59 | (6) |
| PART II SECURITY MANAGEMENT CONSIDERATIONS |
|
|
Organizing for EDP Security |
|
|
65 | (14) |
|
EDP Security in the public Sector |
|
|
65 | (1) |
|
EDP Security in the Private Sector |
|
|
66 | (3) |
|
|
|
69 | (3) |
|
Duties of the Security Coordinator |
|
|
72 | (2) |
|
Principles of Security Management |
|
|
74 | (2) |
|
New Challenges for IT Security Management |
|
|
76 | (3) |
|
Protection of Information |
|
|
79 | (20) |
|
Classification---The Government Model |
|
|
79 | (4) |
|
Classification---The Corporate Model |
|
|
83 | (2) |
|
Special Problems with EDP |
|
|
85 | (1) |
|
Marking Classified Matter |
|
|
86 | (2) |
|
Storing Classified Matter |
|
|
88 | (1) |
|
Destroying Classified Matter |
|
|
89 | (1) |
|
Residual Memory in Magnetic Media |
|
|
90 | (2) |
|
Procedural Safeguards for Classified Matter |
|
|
92 | (3) |
|
|
|
95 | (4) |
|
Screening and Management of Personnel |
|
|
99 | (16) |
|
Management Responsibility |
|
|
102 | (1) |
|
|
|
102 | (1) |
|
Categories of Security Clearance |
|
|
103 | (1) |
|
Security Screening of Employees |
|
|
104 | (4) |
|
Personnel Security Policies |
|
|
108 | (3) |
|
|
|
111 | (4) |
| PART III PHYSICAL SECURITY |
|
|
|
|
115 | (16) |
|
|
|
115 | (1) |
|
|
|
116 | (4) |
|
|
|
120 | (1) |
|
Concentric Controlled Perimeters |
|
|
120 | (1) |
|
|
|
121 | (1) |
|
|
|
122 | (1) |
|
Control of Access to Restricted Areas |
|
|
123 | (3) |
|
Material Control in Restricted Areas |
|
|
126 | (1) |
|
Computer Room Access Control |
|
|
127 | (4) |
|
|
|
131 | (14) |
|
|
|
131 | (2) |
|
|
|
133 | (1) |
|
|
|
134 | (2) |
|
|
|
136 | (3) |
|
Restricted Area Perimeter |
|
|
139 | (3) |
|
|
|
142 | (3) |
|
|
|
145 | (12) |
|
|
|
145 | (4) |
|
|
|
149 | (1) |
|
|
|
150 | (2) |
|
|
|
152 | (1) |
|
|
|
153 | (4) |
|
|
|
157 | (20) |
|
Locating the Computer Center |
|
|
157 | (3) |
|
Protecting the Computer Center |
|
|
160 | (5) |
|
|
|
165 | (2) |
|
General Fire-Safety Planning |
|
|
167 | (2) |
|
|
|
169 | (8) |
| PART IV COMMUNICATIONS SECURITY |
|
|
|
|
177 | (22) |
|
Communications Security Subfields |
|
|
177 | (1) |
|
Security of Communications Cables |
|
|
178 | (4) |
|
Interior Communications Lines |
|
|
182 | (1) |
|
Telephone Instrument Security |
|
|
183 | (5) |
|
Additional Line Security Considerations |
|
|
188 | (1) |
|
|
|
189 | (6) |
|
|
|
195 | (4) |
|
|
|
199 | (16) |
|
|
|
199 | (1) |
|
|
|
200 | (6) |
|
|
|
206 | (4) |
|
|
|
210 | (3) |
|
|
|
213 | (2) |
|
|
|
215 | (36) |
|
Introduction to Cryptology |
|
|
215 | (1) |
|
|
|
216 | (3) |
|
|
|
219 | (5) |
|
|
|
224 | (11) |
|
Network Communications Security |
|
|
235 | (1) |
|
|
|
236 | (2) |
|
|
|
238 | (3) |
|
|
|
241 | (2) |
|
|
|
243 | (1) |
|
|
|
244 | (2) |
|
|
|
246 | (3) |
|
|
|
249 | (2) |
|
|
|
251 | (16) |
|
|
|
251 | (2) |
|
Probability of Interception |
|
|
253 | (1) |
|
|
|
254 | (2) |
|
Mesuring Electromagnetic Emanation Levels |
|
|
256 | (4) |
|
|
|
260 | (5) |
|
Defense Against Acoustical Emanations |
|
|
265 | (2) |
|
|
|
267 | (14) |
|
Victimization of EDP Centers |
|
|
267 | (1) |
|
Categories of Technical Surveillance |
|
|
268 | (1) |
|
Defenses Against Technical Surveillance |
|
|
269 | (4) |
|
Types of Intrusion Devices |
|
|
273 | (8) |
| PART V SYSTEMS SECURITY |
|
|
|
|
281 | (26) |
|
Introduction to Systems Security |
|
|
281 | (5) |
|
Guidelines for a Trusted Computing Base |
|
|
286 | (5) |
|
|
|
291 | (7) |
|
Other User Identification Systems |
|
|
298 | (1) |
|
Identifying Specified Assets |
|
|
298 | (4) |
|
|
|
302 | (1) |
|
|
|
302 | (2) |
|
|
|
304 | (3) |
|
Isolation in Computer Systems |
|
|
307 | (22) |
|
|
|
307 | (1) |
|
|
|
308 | (2) |
|
|
|
310 | (2) |
|
|
|
312 | (1) |
|
|
|
312 | (13) |
|
|
|
325 | (1) |
|
|
|
326 | (1) |
|
Virtual Machine Isolation |
|
|
327 | (1) |
|
|
|
327 | (2) |
|
|
|
329 | (24) |
|
Basic Principles of Access |
|
|
329 | (3) |
|
|
|
332 | (4) |
|
|
|
336 | (1) |
|
|
|
337 | (3) |
|
|
|
340 | (4) |
|
|
|
344 | (5) |
|
Systems Security Add-on Packages |
|
|
349 | (4) |
|
Detection and Surveillance |
|
|
353 | (16) |
|
|
|
353 | (2) |
|
|
|
355 | (6) |
|
|
|
361 | (2) |
|
|
|
363 | (2) |
|
|
|
365 | (2) |
|
The Human Factor in Computer Crime |
|
|
367 | (2) |
|
|
|
369 | (20) |
|
|
|
369 | (3) |
|
|
|
372 | (3) |
|
Privacy in Statistical Data Bases |
|
|
375 | (4) |
|
Protection of Security Functions |
|
|
379 | (2) |
|
Commercial Security Model |
|
|
381 | (2) |
|
|
|
383 | (3) |
|
|
|
386 | (1) |
|
|
|
387 | (2) |
|
Systems Reliability and Security |
|
|
389 | (14) |
|
|
|
389 | (2) |
|
|
|
391 | (1) |
|
|
|
392 | (1) |
|
|
|
392 | (3) |
|
Record-Keeping and Security |
|
|
395 | (1) |
|
|
|
395 | (2) |
|
|
|
397 | (1) |
|
|
|
398 | (1) |
|
|
|
399 | (1) |
|
|
|
400 | (3) |
|
Security and Personal Computers |
|
|
403 | (56) |
|
|
|
403 | (2) |
|
|
|
405 | (2) |
|
|
|
407 | (2) |
|
Protection of Removable Media |
|
|
409 | (3) |
|
Electromagnetic Emanations |
|
|
412 | (1) |
|
Security Attributes of Microprocessors |
|
|
412 | (5) |
|
|
|
417 | (11) |
|
Local-Area-Network (LAN) Security |
|
|
428 | (3) |
|
Security in Remote Support Programs |
|
|
431 | (3) |
|
|
|
434 | (4) |
|
Security in Application Programs |
|
|
438 | (1) |
|
|
|
439 | (4) |
|
|
|
443 | (4) |
|
Security Add-ons for Operating Systems---Trusted Computer Systems Evaluation |
|
|
447 | (6) |
|
New Thinking in PC Security |
|
|
453 | (3) |
|
|
|
456 | (1) |
|
|
|
456 | (3) |
| PART VI INFORMATION SECURITY RISK ANALYSIS |
|
|
Systems Approach to Risk Management |
|
|
459 | (18) |
|
|
|
459 | (1) |
|
Applications of Risk Analysis |
|
|
459 | (1) |
|
|
|
460 | (2) |
|
Information and Risk Analysis |
|
|
462 | (1) |
|
Information Security by Consensus |
|
|
462 | (2) |
|
State of Infosec Risk Analysis |
|
|
464 | (1) |
|
|
|
464 | (2) |
|
|
|
466 | (1) |
|
Problems in Risk Analysis |
|
|
466 | (1) |
|
Cybernetic Model of Activity |
|
|
467 | (4) |
|
Representative Risk-Analysis Packages |
|
|
471 | (2) |
|
|
|
473 | (4) |
|
|
|
477 | (14) |
|
|
|
477 | (2) |
|
|
|
479 | (3) |
|
|
|
482 | (5) |
|
|
|
487 | (4) |
|
|
|
491 | (14) |
|
|
|
491 | (1) |
|
|
|
492 | (1) |
|
|
|
493 | (1) |
|
|
|
493 | (4) |
|
|
|
497 | (3) |
|
|
|
500 | (2) |
|
|
|
502 | (3) |
|
Keeping Secrets in Computers |
|
|
505 | (42) |
|
Threats and Legal Remedies |
|
|
506 | (3) |
|
|
|
509 | (2) |
|
|
|
511 | (28) |
|
|
|
539 | (8) |
|
|
|
547 | (28) |
|
|
|
547 | (1) |
|
|
|
548 | (3) |
|
Security Inspection and Evaluation |
|
|
551 | (2) |
|
|
|
553 | (3) |
|
Life-Cycle Software Development |
|
|
556 | (1) |
|
Development of Security Software |
|
|
557 | (1) |
|
|
|
558 | (4) |
|
|
|
562 | (13) |
|
|
|
569 | (6) |
| Appendix: Sample Log Forms |
|
575 | (4) |
| Glossary |
|
579 | (50) |
| Selected Bibliography |
|
629 | (6) |
| Index |
|
635 | |