Applications accessible via public networks are subject to a range of network related threats,
such as fraudulent activities, contract disputes or disclosure of information to the public.
Therefore, detailed risk assessments and proper selection of controls are indispensable.
Controls required often include cryptographic methods for authentication and securing data
transfer.
Application services can make use of secure authentication methods, e.g. using public key
cryptography and digital signatures to reduce the risks. Also, trusted third parties can be used,
where such services are needed. (NL ISO/IEC, 2015)
10. Protecting Application Services Transactions
Information involved in application service transactions should be protected to prevent
incomplete transmission, miss-routing, unauthorized message alteration, unauthorized
disclosure, unauthorized message duplication or replay.
Information security considerations for application service transactions should include the
following:
a) the use of electronic signatures by each of the parties involved in the transaction;
b) all aspects of the transaction, i.e. ensuring that:
1) user’s secret authentication information of all parties are valid and verified;
2) the transaction remains confidential;
3) privacy associated with all parties involved is retained;
c) communications path between all involved parties is encrypted;
d) protocols used to communicate between all involved parties are secured;
e) ensuring that the storage of the transaction details is located outside of any publicl y
accessible environment, e.g. on a storage platform existing on the organizational
intranet, and not retained and exposed on a storage medium directly accessible
from the Internet;
f) where a trusted authority is used (e.g. for the purposes of issuing and maintaining
digital signatures or digital certificates) security is integrated and embedded
throughout the entire end-to-end certificate/signature management process.
(NL ISO/IEC, 2015)
11. Planning Information Security Continuity
The information security continuity should be embedded in the organization’s business
continuity management systems.
The organization should determine its requirements for information security and the continuity
of information security management in adverse situations, e.g. during a crisis or disaster.
An organization should determine whether the
continuity of information security is captured within
Lebanese National Security Policy Guidelines v1.7
Page
“Failing to plan is planning to fail.”
– Alan Lakein– American writer
50 |