Thus, this principle emphasises the need to configure systems according to installation
and configuration guides. Common configuration mistakes include failure to remove
known default passwords leaving a system trivially exploitable. Thus, EAL Certification
without good configuration may provide a false sense of security. ISO/IEC 27001 and
Common Criteria (CCRA 2009) require an assessment after a major upgrade or
installation to verify that the changes have not weakened the system’s security controls.
10.2.1.8 Staff training
Staff training closely links to configuration. Technical teams are more likely to make poor
configuration choices if they lack training to enable them to understand security threats,
risks and the need for mitigating controls. As recommended elsewhere, countries should
train skilled professionals to manage assured products. The technical teams should have
a business understanding of risk and expertise to deploy technological and network
security technologies. As outlined under the Cybersecurity Skills and Training section,
your organisation should have a clear plan to ensure that the security team maintains the
requisite security skills.
10.2.1.9 Security Baselines
Service minimisation is an example of good configuration. This principle requires that
your IT teams create “Security Baselines” or “Builds” under which devices provide only
the services required for business. Thus, as part of the compliance-checking framework,
relevant stakeholders should validate that devices such as servers and end user
computers run official services only and disable anything extra. Additionally, the service
minimisation principle discourages the use of multi-purpose devices, where practical, as
this increases system vulnerability and the impact of cyber attacks. For example, running
web server, e-mail and file storage applications on a single device may appear cheap but
this practice increases the security impacts of a successful cyber attack.
10.2.1.10
Aggregation
This principle aims to prevent data aggregation risks. Data aggregation occurs when
data that individually is of low classification obtains a higher Impact Level when
combined with a large number of other data items. Aggregation occurs in two ways.
Accumulation is a situation where increasingly large amounts of information stored
together increases the overall Impact Level of compromise. Conversely, association is
where the linking of different information assets, which individually have no or low Impact
Level when compromised, but associated have a higher impact level of compromise.
58