Add the rest of university notes
This commit is contained in:
366 files changed
+9844
-110
No files matched your search
@@ -0,0 +1,95 @@
|
||||
# Security Management
|
||||
|
||||
> “Information security is the protection of information from a wide range of threats in order to ensure business continuity, minimise business risk, and maximise return on investments and business opportunities” - ISO/IEC 17799 Code of practice for information security management, 2005
|
||||
|
||||
> “The concepts, techniques, technical measures, and administrative measures used to protect information assets from deliberate or inadvertent unauthorised acquisition, damage, disclosure, manipulation, modification, loss, or use” - IBM Dictionary of Computing, 1994
|
||||
|
||||
**Informational Security:** preservation of **confidentiality**, **integrity** and **availability** of information. In addition, other properties such as authenticity, accountability, non-repudiation and reliability can also be involved
|
||||
|
||||
> “Cybersecurity is how individuals and organisations reduce the risk of cyber attack.
|
||||
>
|
||||
> Cybersecurity's core function is to protect the devices we all use (smartphones, laptops, tablets and computers), and the services we access - both online and at work - from theft or damage.
|
||||
>
|
||||
> It's also about preventing unauthorised access to the vast amounts of personal information we store on these devices, and online” - UK National Cyber Security Centre www.ncsc.gov.uk/section/about-ncsc/what-is-cyber-security
|
||||
|
||||
### Security Policy
|
||||
|
||||
- A statement of overall intent and commitment to security
|
||||
- Provides a *foundation* for other aspects
|
||||
- High level policy applies to the organisation and everyone in it
|
||||
- more focused policies may apply to specific departments, systems etc
|
||||
- Identifies what but not how
|
||||
- the *how* part would be covered by accompanying guidelines
|
||||
|
||||
#### Characteristics of a good policy
|
||||
|
||||
- Is short and backed from the top of the organisation
|
||||
- Ensure everyone reads it
|
||||
- Recognises that information is critical & must be protected
|
||||
- Emphasises the importance of security awareness & training
|
||||
- Emphasises compliance with legal and regulatory requirements
|
||||
- Emphasises relations with third parties
|
||||
- States roles and responsibilities for information security
|
||||
- Outlines standards and procedures
|
||||
- States the consequences of violations and non-compliance
|
||||
|
||||
Note the lack of policies on personally owned devices, considering ~100% of people have one or more.
|
||||
|
||||
### Recognising Risk
|
||||
|
||||
**Removal**
|
||||
|
||||
System is modified so that a particular feature, and the associated risk is removed.
|
||||
|
||||
**Reduction**
|
||||
|
||||
Security measures are used to reduce risk to an acceptable level.
|
||||
|
||||
**Retention**
|
||||
|
||||
Nothing is done - the risk is small and insignificant
|
||||
|
||||
**Relocation**
|
||||
|
||||
The system is unchanged, but risk is transferred to another party e.g. an insurance
|
||||
|
||||
###### Management need to know
|
||||
|
||||
- What’s at risk
|
||||
- The cost incurred if the risk becomes a breach
|
||||
- Safeguards that can be implemented
|
||||
- The cost of safeguards
|
||||
- The risk reduction that will result from implementation of specific safeguards
|
||||
|
||||
### Baseline Security
|
||||
|
||||
- A minimum level of protection that should be considered by all organisations ulitilising IT systems
|
||||
- Although many organisation will require protection considerably above baseline
|
||||
- Can provide a *common* basis for mutual trust
|
||||
|
||||
###### Cyber Essentials
|
||||
|
||||
- Enables organisations to be certified independently for having met a good practice standard in cyber security
|
||||
- Addresses five technical control themes:
|
||||
1. Firewalls
|
||||
2. Secure configuration
|
||||
3. User access control
|
||||
4. Malware protection
|
||||
5. Security Update management
|
||||
|
||||
###### ISO 27001
|
||||
|
||||
- the central element of the ISO 27000 series
|
||||
- describes best practice for an ISMS (information security management system)
|
||||
- outlines of each aspect of an ISMS, and other standards provide further detail (e.g. 27002 for controls, 27003 for implementation, 27004 for evaluation)
|
||||
|
||||
###### ISO 27002
|
||||
|
||||
- provides advice on how to implement security controls listed in Annex A of ISO 27001
|
||||
|
||||
### The need for Professional Skills
|
||||
|
||||
- Although simplified at the abstract level, actually following even the baseline controls is non-trivial
|
||||
- Simply knowing about them does not tell you *how* to comply
|
||||
- Still requires the ability to assess the current environment and understand the appropriate protection and how to apply it
|
||||
- Organisations require professionals with appropriate security knowledge, skills and competence.
|
||||
Reference in new issue
Block a user