Tidy up
This commit is contained in:
103 files changed
+3663
-3779
No files matched your search
@@ -8,7 +8,7 @@
|
||||
|
||||
> “Cybersecurity is how individuals and organisations reduce the risk of cyber attack.
|
||||
>
|
||||
> Cybersecurity's core function is to protect the devices we all use (smartphones, laptops, tablets and computers), and the services we access - both online and at work - from theft or damage.
|
||||
> Cybersecurity's core function is to protect the devices we all use (smartphones, laptops, tablets and computers), and the services we access - both online and at work - from theft or damage.
|
||||
>
|
||||
> It's also about preventing unauthorised access to the vast amounts of personal information we store on these devices, and online” - UK National Cyber Security Centre www.ncsc.gov.uk/section/about-ncsc/what-is-cyber-security
|
||||
|
||||
@@ -17,19 +17,19 @@
|
||||
- A statement of overall intent and commitment to security
|
||||
- Provides a *foundation* for other aspects
|
||||
- High level policy applies to the organisation and everyone in it
|
||||
- more focused policies may apply to specific departments, systems etc
|
||||
- more focused policies may apply to specific departments, systems etc
|
||||
- Identifies what but not how
|
||||
- the *how* part would be covered by accompanying guidelines
|
||||
- the *how* part would be covered by accompanying guidelines
|
||||
|
||||
#### Characteristics of a good policy
|
||||
|
||||
- Is short and backed from the top of the organisation
|
||||
- Ensure everyone reads it
|
||||
- Ensure everyone reads it
|
||||
- Recognises that information is critical & must be protected
|
||||
- Emphasises the importance of security awareness & training
|
||||
- Emphasises compliance with legal and regulatory requirements
|
||||
- Emphasises relations with third parties
|
||||
- States roles and responsibilities for information security
|
||||
- States roles and responsibilities for information security
|
||||
- Outlines standards and procedures
|
||||
- States the consequences of violations and non-compliance
|
||||
|
||||
@@ -39,7 +39,7 @@ Note the lack of policies on personally owned devices, considering ~100% of peop
|
||||
|
||||
**Removal**
|
||||
|
||||
System is modified so that a particular feature, and the associated risk is removed.
|
||||
System is modified so that a particular feature and the associated risk are removed.
|
||||
|
||||
**Reduction**
|
||||
|
||||
@@ -51,7 +51,7 @@ Nothing is done - the risk is small and insignificant
|
||||
|
||||
**Relocation**
|
||||
|
||||
The system is unchanged, but risk is transferred to another party e.g. an insurance
|
||||
The system is unchanged, but risk is transferred to another party e.g. an insurer
|
||||
|
||||
###### Management need to know
|
||||
|
||||
@@ -63,25 +63,25 @@ The system is unchanged, but risk is transferred to another party e.g. an insura
|
||||
|
||||
### Baseline Security
|
||||
|
||||
- A minimum level of protection that should be considered by all organisations ulitilising IT systems
|
||||
- Although many organisation will require protection considerably above baseline
|
||||
- Can provide a *common* basis for mutual trust
|
||||
- A minimum level of protection that should be considered by all organisations utilising IT systems
|
||||
- Although many organisations will require protection considerably above baseline
|
||||
- Can provide a *common* basis for mutual trust
|
||||
|
||||
###### Cyber Essentials
|
||||
|
||||
- Enables organisations to be certified independently for having met a good practice standard in cyber security
|
||||
- Addresses five technical control themes:
|
||||
1. Firewalls
|
||||
2. Secure configuration
|
||||
3. User access control
|
||||
4. Malware protection
|
||||
5. Security Update management
|
||||
1. Firewalls
|
||||
2. Secure configuration
|
||||
3. User access control
|
||||
4. Malware protection
|
||||
5. Security Update management
|
||||
|
||||
###### ISO 27001
|
||||
|
||||
- the central element of the ISO 27000 series
|
||||
- describes best practice for an ISMS (information security management system)
|
||||
- outlines of each aspect of an ISMS, and other standards provide further detail (e.g. 27002 for controls, 27003 for implementation, 27004 for evaluation)
|
||||
- outlines each aspect of an ISMS, and other standards provide further detail (e.g. 27002 for controls, 27003 for implementation, 27004 for evaluation)
|
||||
|
||||
###### ISO 27002
|
||||
|
||||
@@ -90,6 +90,6 @@ The system is unchanged, but risk is transferred to another party e.g. an insura
|
||||
### The need for Professional Skills
|
||||
|
||||
- Although simplified at the abstract level, actually following even the baseline controls is non-trivial
|
||||
- Simply knowing about them does not tell you *how* to comply
|
||||
- Still requires the ability to assess the current environment and understand the appropriate protection and how to apply it
|
||||
- Organisations require professionals with appropriate security knowledge, skills and competence.
|
||||
- Simply knowing about them does not tell you *how* to comply
|
||||
- Still requires the ability to assess the current environment and understand the appropriate protection and how to apply it
|
||||
- Organisations require professionals with appropriate security knowledge, skills and competence.
|
||||
Reference in new issue
Block a user