<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: suggest an appropriate security standard, for an ACL system ? in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/suggest-an-appropriate-security-standard-for-an-ACL-system/m-p/20860#M1071</link>
    <description>&lt;P&gt;Why don't you use an application aware white listing approach?&amp;nbsp; Or a full Role Base Access Control system, which you can manage centrally by policy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
    <pubDate>Sat, 06 Apr 2019 07:04:31 GMT</pubDate>
    <dc:creator>Caute_cautim</dc:creator>
    <dc:date>2019-04-06T07:04:31Z</dc:date>
    <item>
      <title>suggest an appropriate security standard, for an ACL system ?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/suggest-an-appropriate-security-standard-for-an-ACL-system/m-p/20710#M1055</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am starting to develop a security system, which is basically a big ACL (access control list) management system. I wonder if anyone could suggest any relevant standards or recommendations ?&lt;/P&gt;&lt;P&gt;Or suggest another place I should ask!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To describe the system...&lt;/P&gt;&lt;P&gt;The ACL list will be automatically maintained by some rules, and sometimes manually. The ACL is one way to control access to a large business system. There are other ways also. The list will be big, probably millions or entries.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;JM&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 18:24:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/suggest-an-appropriate-security-standard-for-an-ACL-system/m-p/20710#M1055</guid>
      <dc:creator>John_M</dc:creator>
      <dc:date>2019-04-02T18:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: suggest an appropriate security standard, for an ACL system ?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/suggest-an-appropriate-security-standard-for-an-ACL-system/m-p/20730#M1056</link>
      <description>&lt;P&gt;ok,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The moment I saw the word "millions" next to ACL, I got cold feet and ran away to a far away land.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maintaining that level of access control in a list will in my opinion bring about a huge amount of problems.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How will you browse the list in order to find mistakes ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How easy would it be to make a mistake if the system is both manual and automated ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, it's unclear what you want the ACL for, or where it will be run (Switches ? FW's ? IPS ?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So a bit more information would be helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In general, that level of list is impossible to control as I see it.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 05:22:20 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/suggest-an-appropriate-security-standard-for-an-ACL-system/m-p/20730#M1056</guid>
      <dc:creator>MikeGlassman</dc:creator>
      <dc:date>2019-04-03T05:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: suggest an appropriate security standard, for an ACL system ?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/suggest-an-appropriate-security-standard-for-an-ACL-system/m-p/20740#M1059</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks Mike for your message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you point out, the ACL will be far too big for manual, visual inspection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically, the ACL data is divided up, and owners of individual areas will browse. Each area will be a manageable size. Also, most entries will be automatically added and removed, based on business rules. Also, I plan to have an automated process which checks for anomalies. The ACL is there to control access to data in a large business system. That is, access to financial data etc. It’s based on Java, and runs in WebLogic. I think that’s about all the information I can give on a public forum!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’m now at the point of figuring what anomalies to check for, and what error scenarios to anticipate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Great if anyone knows relevant industry standards or recommendations.&amp;nbsp; I’ll hit the NIST website anyway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;JM&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 14:01:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/suggest-an-appropriate-security-standard-for-an-ACL-system/m-p/20740#M1059</guid>
      <dc:creator>John_M</dc:creator>
      <dc:date>2019-04-03T14:01:15Z</dc:date>
    </item>
    <item>
      <title>Re: suggest an appropriate security standard, for an ACL system ?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/suggest-an-appropriate-security-standard-for-an-ACL-system/m-p/20741#M1060</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/341872409"&gt;@MikeGlassman&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How will you browse the list in order to find mistakes ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How easy would it be to make a mistake if the system is both manual and automated ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, it's unclear what you want the ACL for, or where it will be run (Switches ? FW's ? IPS ?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So a bit more information would be helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In general, that level of list is impossible to control as I see it.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;As Mike has stated, when I read your request, I also turned on my heals and ran to a safe place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe making your request clearer as per Mike's note might help us help you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you doing this for your employer or for something you plan on selling?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ACLs are complicated and a number of folks prefer not to use them&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Diana&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 14:09:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/suggest-an-appropriate-security-standard-for-an-ACL-system/m-p/20741#M1060</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2019-04-03T14:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: suggest an appropriate security standard, for an ACL system ?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/suggest-an-appropriate-security-standard-for-an-ACL-system/m-p/20747#M1061</link>
      <description>&lt;P&gt;&amp;gt;&amp;gt;&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;Are you doing this for your employer or for something you plan on selling?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;It's for employer. Objective is to control access to an existing system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is to control 'record-level access'. That is, allowing users to see some records, not others.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And as mentioned above-&lt;/P&gt;&lt;P&gt;The ACL will be far too big for manual, visual inspection. So,&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;the ACL data is divided up, and owners of individual areas will browse. Each area will be a manageable size. Also, most entries will be automatically added and removed, based on business rules. Also, I plan to have an automated process which checks for anomalies. The ACL is there to control access to data in a large business system. That is, access to financial data etc. It’s based on Java, and runs in WebLogic.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’m now at the point of figuring what anomalies to check for, and what error scenarios to anticipate&lt;/P&gt;&lt;P&gt;Sorry my description is minimal!&amp;nbsp; I conscious of this being a public forum.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Great if anyone can just relevant standards I should look at, or specific problems to expect!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;JM&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 15:04:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/suggest-an-appropriate-security-standard-for-an-ACL-system/m-p/20747#M1061</guid>
      <dc:creator>John_M</dc:creator>
      <dc:date>2019-04-03T15:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: suggest an appropriate security standard, for an ACL system ?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/suggest-an-appropriate-security-standard-for-an-ACL-system/m-p/20783#M1066</link>
      <description>&lt;P&gt;ACL's how quaint! Is this 1990? Look into SELinux or other alternatives like AppArmor or grsecurity and implement mandatory access control. That is the best multi-layered defense for user privileges and processes.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 13:57:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/suggest-an-appropriate-security-standard-for-an-ACL-system/m-p/20783#M1066</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2019-04-04T13:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: suggest an appropriate security standard, for an ACL system ?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/suggest-an-appropriate-security-standard-for-an-ACL-system/m-p/20787#M1067</link>
      <description>&lt;P&gt;The first thing I would do is check with your vendor regarding limits.&amp;nbsp; A quick glance indicates that some routers only allow 128 entries in an ACL and only 10,000 entries across the entire&amp;nbsp; router.&amp;nbsp; Then, you need to consider processing requirements.&amp;nbsp; Every connection will need to scan the entire ACL, which risks responsiveness issues as the list gets long and traffic volumes grow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also suggest that as compliance/security requirements grow, so does the thought that you should not be developing your own software.&amp;nbsp; Primarily because as more people use a given software package, it lessens your odds of being patient zero.&amp;nbsp; Also, the commercial tools generally offer certified compliance, whereas home-grown gets much closer auditor scrutiny and leaves the blame-game focused squarely on you when the inevitable breach hits the newspapers.&amp;nbsp; For "free" router ACL management at the scale you propose, you might consider fwbuilder (poorly maintained) or capirca (no gui).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My final (for now) thought is that one needs "millions of entries", there might just be a better approach to solve the problem at hand.&amp;nbsp; If nothing else, "millions of entries" risks auditing and troubleshooting both becoming difficult/expensive.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 14:15:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/suggest-an-appropriate-security-standard-for-an-ACL-system/m-p/20787#M1067</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2019-04-04T14:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: suggest an appropriate security standard, for an ACL system ?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/suggest-an-appropriate-security-standard-for-an-ACL-system/m-p/20860#M1071</link>
      <description>&lt;P&gt;Why don't you use an application aware white listing approach?&amp;nbsp; Or a full Role Base Access Control system, which you can manage centrally by policy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Sat, 06 Apr 2019 07:04:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/suggest-an-appropriate-security-standard-for-an-ACL-system/m-p/20860#M1071</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-04-06T07:04:31Z</dc:date>
    </item>
  </channel>
</rss>

