EBA欧洲银行-Annex-4-Standard-on-Controls-Against-Malicious-Code_10页_200kb
报告摘要
European Commission - Information System Security Policy: Standard on Controls Against Malicious Code
Core Content
This document outlines the European Commission's Security Standard on Controls Against Malicious Code, adopted on 21/06/2011 by Mrs. Irene Souka, Director-General of DG Human Resources and Security. It is based on Commission Decision C(2006) 3602, which establishes the framework for information system security within the European Commission.
The standard focuses on implementing effective and efficient prevention, detection, and correction measures against malicious code, including viruses, worms, and Trojans. It does not cover all types of malicious code, such as interpreted language applications (e.g., Java) or cross-site scripting.
Main Concerns
The main objective of this standard is to prevent and detect the introduction of malicious code through a combination of technical, procedural, and organizational controls. It emphasizes the need for user awareness and multi-layered protection across the network, servers, and endpoints.
Key Information
Scope
- The standard applies to anti-virus software and other tools used to protect information systems against malicious code.
- It does not cover spam, mobile code, or other related threats, which are addressed in separate standards.
- It also does not include intrusion detection/prevention systems, patch management, network authentication, or firewalls, although it briefly touches on incident management and patching.
Risks Targeted
- Computer viruses
- Network worms
- Trojan horses
- Other related threats such as data corruption, software tampering, and data disclosure are also addressed, as outlined in the "Standards on Risk Management (Appendix B)".
Security Controls
The standard defines several types of controls:
5.2.1. Configuration
- Virus protection software must be configured to scan computer memory, executable files, data files, and removable media.
- It must be set to on-access scanning, provide alerts, and disinfect, delete, rename, or quarantine identified threats.
- User configuration changes must be prevented or restricted.
- Updates must be automated and distributed within a critical timescale.
- Logs must be maintained and reported regularly.
5.2.2. Installation and Procedures
- All computers and systems (servers, gateways, NAS, mail gateways, workstations, etc.) must be equipped with virus protection software.
- Traffic passing through different layers must be scanned by at least two software products.
- Emergency procedures for virus incidents must be implemented.
- Virus samples must be reported and handled by the IT service provider.
- Security settings in the reference configuration must be recommended and enforced.
- End users must be trained and warned about virus risks and must report incidents to a single point of contact and not attempt self-repair.
5.2.3. Checks
- Regular checks must be performed to ensure:
- Virus protection software is not disabled.
- The configuration is correct.
- All updates are applied.
- Emergency procedures are in place.
- Reports are sent to relevant personnel.
- The effectiveness of virus protection is monitored and corrective actions are taken.
5.2.4. Network Level Protection
- Gateway-level virus protection must be configured to filter incoming and outgoing traffic and email messages.
- It should support multi-layered scanning to ensure comprehensive coverage.
Roles and Responsibilities
The following roles are involved in the implementation and management of controls against malicious code:
| Controls | System Owners | IT Service Providers | Information Resource Managers | Security Directorate | LISO | Users |
|---|---|---|---|---|---|---|
| Configuration | A | R | R | C | C | - |
| Installation and Procedures | A | R | R | C | C | R |
| Checks | A | R | R | - | C | - |
| Network Protection | A | R | - | C | C | - |
RACI Chart Explanation:
- Responsible (R): Carries out the actual work.
- Accountable (A): Approves the completed work and is fully accountable.
- Consulted (C): Must be consulted beforehand.
- Informed (I): Informed about progress and results.
References
- Commission Decision C(2006) 3602 (16/8/2006)
- Implementing rules for Commission Decision C(2006) 3602
- ISO/IEC 27001 (Second edition, 2005-06-15)
- ISO/IEC 17799 (Second edition, 2005-06-15)
Related Standards and Guidelines
- Standard on Network Security Management
- Standard on Information System Security Incident Management
- Standard on Information Security Risk Management
试读结束,高清完整版pdf/doc/ppt,请点下载