Control SuspendInsecureServiceChannel

URI: SuspendInsecureServiceChannel

Package: ProcessComms

< prev | next >

Description: Applies to an inferred Service Channel asset representing the privileged path from client to service. Signifies that the service channel may be temporarily disabled, i.e. policy exceptions allowing client-service messages to pass through default firewall rules are switched off. This represents a contingency plan which will compromise availability, to an extent based on the likelihood of the attack.

ServiceChannel

Represents a communication path through the network between a Client and a Service. This channel is privileged, in the sense that where default firewall rules would block connections from the Client to the Service, they are enabled by an exception to the default rules.

CSG-SuspendInsecureServiceChannel

Firewall rules that normally allow access from client Client to service Service may be temporarily switched off by manager HostManager of the service host SHost if the network path is subject to snooping. This strategy represents a contingency plan, which can be used to reduce risk from some threats but it also triggers other threats representing possible side effects, depending on how likely it is that the contingency plan will need to be activated.

CSG-SuspendInsecureServiceChannel-Implementation-Runtime

Firewall rules that normally allow access from client Client to service Service have been switched off by manager HostManager of the service host SHost to prevent snooping. This strategy represents activation of a contingency plan at runtime, and can be selected to discover what effect this would have on risk levels, allowing this to be used for decision support calculations. To activate it at runtime, user HostManager who is responsible for managing SHost should arrange for firewall policies to be switched off. The Disable Service Channel control should be deselected only when access is enabled again.

CSG-SuspendInsecureServiceChannel-Trigger

Firewall rules that normally allow access from client Client to service Service may be temporarily switched off by manager HostManager of the service host SHost if the network path is subject to snooping. This strategy represents a contingency plan, which can be used to reduce risk from some threats but it also triggers other threats representing possible side effects, depending on how likely it is that the contingency plan will need to be activated.