Page 171 - CISSO_Prep_ Guide
P. 171

Networks and Communications Security

            Networks are the lifeblood of nearly every line of business
            today. It is through networks that applications, manufacturing
            machines, shipping, payroll, and finance all operate. Secure and
            reliable networks are required to provide communications
            services that are accurate, available, and confidential.

            When protecting networks, it must be remembered that network
            defense has two components. The network itself must be
            protected against attacks that would disable or affect network
            operations; network defense must also protect the devices
            attached to the network since the network is often the
            mechanism used to direct an attack towards a network-enabled
            device.

            A network is created when any two devices can communicate.
            Therefore networks can be as small as a personal area network -
            a person with a Bluetooth headset talking to the phone on their
            bed or a network can span the globe with thousands of devices
            all sharing the same network infrastructure.
            Several models are used to manage network communications.
            The OSI (Open Systems Interconnect) model is the ISO7498
            standard. The OSI model divides the process of communications
            into seven layers - each layer with a defined purpose and
            function. As each layer fulfills its purpose, it wraps the data to
            be sent to the layer above or below it in a process called
            encapsulation. Each layer can perform its function
            independently of the other layers.

            The layers are as follows:
            Application - the layer that interfaces with the application being
            used by the user. It is not the application itself. This layer
   166   167   168   169   170   171   172   173   174   175   176