EBA欧洲银行-6Annex-1-controls_against_malicious_code_10页_200kb
报告摘要
European Commission - Information System Security Policy: Standard on Controls Against Malicious Code
Core Content
This document outlines the European Commission's Security Standard on Controls Against Malicious Code, adopted on 21 June 2011 by Mrs. Irene Souka, Director-General of DG Human Resources and Security. It is based on Commission Decision C(2006) 3602, which establishes the framework for information system security across the Commission.
The standard focuses on preventing, detecting, and correcting malicious code (also known as malware) within the Commission's information systems. It defines key terms such as malware, virus, Trojan horse, worm, spyware, adware, and keylogger, and explains their characteristics and potential threats.
The scope is limited to anti-virus software and related controls for protecting information systems from malicious code. It does not cover other issues like spam or mobile code, which are addressed in separate standards. The standard also does not include broader measures such as intrusion detection/prevention systems, patch management, or firewalls, though it briefly mentions incident management and vulnerability patching.
Main Concerns and Objectives
The primary objective of the standard is to implement permanent controls to prevent and detect the introduction of malicious code. These controls include:
- Preventive and detective/corrective measures.
- User awareness and training.
- Regular scanning and updating of virus protection software.
- Centralized logging and monitoring of antivirus activity.
- Clear procedures for handling virus incidents and reporting.
Key Information and Requirements
5.1. Risks Targeted
The standard targets the following threats:
- Computer viruses
- Network worms
- Trojan horses
It acknowledges that some threats, such as those from interpreted language applications (e.g., Java) or cross-site scripting, are not covered by this standard.
5.2. Security Controls Statements
5.2.1. Configuration
- Virus protection software must be configured to scan computer memory, executable files, data files, and removable storage media.
- It must be set to on-access scanning and provide alerts when a virus is detected.
- The software must comply with a standard reference configuration and update virus recognition files automatically.
- End users must not disable or change the configuration of the virus protection software.
5.2.2. Installation and Procedures
- Virus protection software must be installed on all computers, including servers, gateways, NAS, mail gateways, and workstations.
- Traffic must be scanned by at least two different software products at different layers of the network.
- Emergency procedures for virus incidents must be in place.
- Procedures for reporting virus samples and virus attack handling must be documented.
- Security settings should be configured to reduce the risk of infections (e.g., disable autorun).
5.2.3. Checks
- Regular checks must ensure that virus protection software is functioning correctly.
- Checks should include verifying that:
- Software is not disabled.
- Configuration remains correct.
- All updates are applied effectively.
- Emergency procedures are in place.
- Reports are sent to relevant personnel.
- Effectiveness of protection is maintained through monitoring and corrective actions.
5.2.4. Protection at the Network Level
- Gateway-level virus protection must be configured to scan and filter incoming and outgoing traffic.
- This includes email and internet downloads.
5.3. Roles and Responsibilities
The following roles are involved in implementing and managing controls against malicious code:
- System Owner – Accountable for the security of the system.
- IT Service Provider – Responsible for implementing and maintaining the virus protection software.
- Information Resource Managers (IRMs) – Responsible for managing and configuring the software.
- Local Informatics Security Officer (LISO) – Responsible for monitoring and reporting.
- Security Directorate – Provides guidance and oversight.
- Users – Must be trained and follow procedures.
A RACI chart is used to assign roles:
- Responsible: Carries out the actual work.
- Accountable: Approves the completed work.
- Consulted: Must be consulted beforehand.
- Informed: Informed about progress and results.
Related Standards and Guidelines
- Standard on Network Security Management
- Standard on Information System Security Incident Management
- Standard on Information Security Risk Management
References
- Commission Decision C(2006) 3602 (16 August 2006)
- Implementing rules for Commission Decision C(2006) 3602
- International standards:
- ISO/IEC 27001 (Second edition, 2005-06-15)
- ISO/IEC 17799 (Second edition, 2005-06-15)
This standard emphasizes a multi-layered approach to security, combining technical, procedural, and user-related controls to ensure robust protection against malicious code.
试读结束,高清完整版pdf/doc/ppt,请点下载