The Security Wheel

The implementation of a security policy typically involves four steps: Step 1 Develop the security policy.

Step 2 Implement the security products called for by the security policy. Step 3 Inspect the policy periodically. Step 4 Handle incidents as they occur.

This process does not provide for the continual adaptation of the security policy to changes in the network environment. The Security Wheel concept treats network security as a continuous process that is built around the corporate security policy. This process is divided into four stages:

1. Securing the network.

2. Monitoring the network.

3. Testing the security of the network.

4. Improving the security of the network.

During the first phase of the Security Wheel, security solutions are implemented. This process involves deploying firewalls, VPN devices, intrusion detection systems (IDSs), and authentication systems and patching any systems that require a patch. These systems are deployed to stop or prevent unauthorized access or activities.

The second phase in the Security Wheel involves monitoring the network to detect violations of the security policy. Monitoring includes system auditing and real-time intrusion detection. This step is designed to validate the security implementation that is conducted in the first stage.

The testing phase of the Security Wheel involves validating the effectiveness of the security policy implementation. Validation is done through system auditing and vulnerability scanning.

In the fourth phase of the Security Wheel, the information gathered during the monitoring and testing phases is used to improve the security implementation of the network. At this phase, adjustments can be made to the security policy as vulnerabilities (both new and old) and risks are identified.

The fourth phase feeds back into the first and the process begins anew. Figure 5-1 illustrates the Security Wheel concept.

Figure 5-1 The Security Wheel

Figure 5-1 The Security Wheel

Wheel Security Cisco

Continue reading here: IIS Directory Traversal Vulnerability

Was this article helpful?

0 0

Readers' Questions

  • Taina
    Which four are involved in a security wheel?
    7 months ago
  • The four components involved in a security wheel are:
    1. Prevention: This involves implementing proactive measures to prevent security breaches and vulnerabilities. It includes actions such as implementing strong access controls, firewalls, antivirus software, and user training.
    2. Detection: This focuses on identifying potential security breaches or incidents in real-time. It involves utilizing tools like intrusion detection systems (IDS), security information and event management (SIEM) systems, and monitoring network traffic and system logs.
    3. Response: This component involves taking immediate action once a security breach or incident has been detected. It includes activities such as isolating affected systems, conducting forensic analysis, and applying patches or updates to mitigate the impact.
    4. Recovery: This involves restoring normal operations after a security incident. It includes activities such as restoring data from backups, implementing additional security measures, and conducting post-incident analysis to identify areas of improvement.