Page 171 - CISSO_Prep_ Guide
P. 171
Networks and Communications Security
Networks are the lifeblood of nearly every line of business
today. It is through networks that applications, manufacturing
machines, shipping, payroll, and finance all operate. Secure and
reliable networks are required to provide communications
services that are accurate, available, and confidential.
When protecting networks, it must be remembered that network
defense has two components. The network itself must be
protected against attacks that would disable or affect network
operations; network defense must also protect the devices
attached to the network since the network is often the
mechanism used to direct an attack towards a network-enabled
device.
A network is created when any two devices can communicate.
Therefore networks can be as small as a personal area network -
a person with a Bluetooth headset talking to the phone on their
bed or a network can span the globe with thousands of devices
all sharing the same network infrastructure.
Several models are used to manage network communications.
The OSI (Open Systems Interconnect) model is the ISO7498
standard. The OSI model divides the process of communications
into seven layers - each layer with a defined purpose and
function. As each layer fulfills its purpose, it wraps the data to
be sent to the layer above or below it in a process called
encapsulation. Each layer can perform its function
independently of the other layers.
The layers are as follows:
Application - the layer that interfaces with the application being
used by the user. It is not the application itself. This layer