16.05.2014 Views

Wireless Security.pdf - PDF Archive

Wireless Security.pdf - PDF Archive

Wireless Security.pdf - PDF Archive

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CHAPTER 13<br />

Managing Access<br />

John Rittinghouse<br />

James F. Ransome<br />

Even the most secure of systems is vulnerable to compromise if anyone can just walk in,<br />

pick up the computer, and walk out with it. Physical prevention measures must be used<br />

in conjunction with information security measures to create a total solution. Herein, we<br />

cover the essential elements every security administrator needs to know about access<br />

control and management of passwords.<br />

13.1 Access Control<br />

According to the Information Systems <strong>Security</strong> Association (ISSA) [1] , “ access control<br />

is the collection of mechanisms for limiting, controlling, and monitoring system access<br />

to certain items of information, or to certain features based on a user’s identity and their<br />

membership in various predefi ned groups. ” In this section, we explore the major building<br />

blocks that constitute the field of access control as it applies to organizational entities and<br />

the information systems these entities are trying to protect from compromise situations.<br />

13.1.1 Purpose of Access Control<br />

Why should we have access control? Access control is necessary for several good<br />

reasons. Information that is proprietary to a business may need to be kept confidential,<br />

so there is a confi dentiality issue that provides purpose to having access controls. The<br />

information that an organization keeps confidential also needs to be protected from<br />

tampering or misuse. The organization must ensure the integrity of this data for it to be<br />

useful. Having internal data integrity also provides purpose to having access controls.<br />

When employees of the organization show up for work, it is important that they have<br />

www.newnespress.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!