Add the rest of university notes

This commit is contained in:
John Gatward committed 2026-10-04 14:02:35 +01:00
1 parent c1b84c7f7d
commit d0f27f276b
366 files changed
+9844 -110

No files matched your search

@@ -0,0 +1,95 @@
# Security Management
> “Information security is the protection of information from a wide range of threats in order to ensure business continuity, minimise business risk, and maximise return on investments and business opportunities” - ISO/IEC 17799 Code of practice for information security management, 2005
> “The concepts, techniques, technical measures, and administrative measures used to protect information assets from deliberate or inadvertent unauthorised acquisition, damage, disclosure, manipulation, modification, loss, or use” - IBM Dictionary of Computing, 1994
**Informational Security:** preservation of **confidentiality**, **integrity** and **availability** of information. In addition, other properties such as authenticity, accountability, non-repudiation and reliability can also be involved
> “Cybersecurity is how individuals and organisations reduce the risk of cyber attack.
>
> Cybersecurity's core function is to protect the devices we all use (smartphones, laptops, tablets and computers), and the services we access - both online and at work - from theft or damage.
>
> It's also about preventing unauthorised access to the vast amounts of personal information we store on these devices, and online” - UK National Cyber Security Centre www.ncsc.gov.uk/section/about-ncsc/what-is-cyber-security
### Security Policy
- A statement of overall intent and commitment to security
- Provides a *foundation* for other aspects
- High level policy applies to the organisation and everyone in it
- more focused policies may apply to specific departments, systems etc
- Identifies what but not how
- the *how* part would be covered by accompanying guidelines
#### Characteristics of a good policy
- Is short and backed from the top of the organisation
- Ensure everyone reads it
- Recognises that information is critical & must be protected
- Emphasises the importance of security awareness & training
- Emphasises compliance with legal and regulatory requirements
- Emphasises relations with third parties
- States roles and responsibilities for information security
- Outlines standards and procedures
- States the consequences of violations and non-compliance
Note the lack of policies on personally owned devices, considering ~100% of people have one or more.
### Recognising Risk
**Removal**
System is modified so that a particular feature, and the associated risk is removed.
**Reduction**
Security measures are used to reduce risk to an acceptable level.
**Retention**
Nothing is done - the risk is small and insignificant
**Relocation**
The system is unchanged, but risk is transferred to another party e.g. an insurance
###### Management need to know
- What’s at risk
- The cost incurred if the risk becomes a breach
- Safeguards that can be implemented
- The cost of safeguards
- The risk reduction that will result from implementation of specific safeguards
### Baseline Security
- A minimum level of protection that should be considered by all organisations ulitilising IT systems
- Although many organisation will require protection considerably above baseline
- Can provide a *common* basis for mutual trust
###### Cyber Essentials
- Enables organisations to be certified independently for having met a good practice standard in cyber security
- Addresses five technical control themes:
1. Firewalls
2. Secure configuration
3. User access control
4. Malware protection
5. Security Update management
###### ISO 27001
- the central element of the ISO 27000 series
- describes best practice for an ISMS (information security management system)
- outlines of each aspect of an ISMS, and other standards provide further detail (e.g. 27002 for controls, 27003 for implementation, 27004 for evaluation)
###### ISO 27002
- provides advice on how to implement security controls listed in Annex A of ISO 27001
### The need for Professional Skills
- Although simplified at the abstract level, actually following even the baseline controls is non-trivial
- Simply knowing about them does not tell you *how* to comply
- Still requires the ability to assess the current environment and understand the appropriate protection and how to apply it
- Organisations require professionals with appropriate security knowledge, skills and competence.