This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

@@ -8,7 +8,7 @@
> “Cybersecurity is how individuals and organisations reduce the risk of cyber attack.
>
> Cybersecurity's core function is to protect the devices we all use (smartphones, laptops, tablets and computers), and the services we access - both online and at work - from theft or damage.
> Cybersecurity's core function is to protect the devices we all use (smartphones, laptops, tablets and computers), and the services we access - both online and at work - from theft or damage.
>
> It's also about preventing unauthorised access to the vast amounts of personal information we store on these devices, and online” - UK National Cyber Security Centre www.ncsc.gov.uk/section/about-ncsc/what-is-cyber-security
@@ -17,19 +17,19 @@
- A statement of overall intent and commitment to security
- Provides a *foundation* for other aspects
- High level policy applies to the organisation and everyone in it
- more focused policies may apply to specific departments, systems etc
- more focused policies may apply to specific departments, systems etc
- Identifies what but not how
- the *how* part would be covered by accompanying guidelines
- the *how* part would be covered by accompanying guidelines
#### Characteristics of a good policy
- Is short and backed from the top of the organisation
- Ensure everyone reads it
- Ensure everyone reads it
- Recognises that information is critical & must be protected
- Emphasises the importance of security awareness & training
- Emphasises compliance with legal and regulatory requirements
- Emphasises relations with third parties
- States roles and responsibilities for information security
- States roles and responsibilities for information security
- Outlines standards and procedures
- States the consequences of violations and non-compliance
@@ -39,7 +39,7 @@ Note the lack of policies on personally owned devices, considering ~100% of peop
**Removal**
System is modified so that a particular feature, and the associated risk is removed.
System is modified so that a particular feature and the associated risk are removed.
**Reduction**
@@ -51,7 +51,7 @@ Nothing is done - the risk is small and insignificant
**Relocation**
The system is unchanged, but risk is transferred to another party e.g. an insurance
The system is unchanged, but risk is transferred to another party e.g. an insurer
###### Management need to know
@@ -63,25 +63,25 @@ The system is unchanged, but risk is transferred to another party e.g. an insura
### Baseline Security
- A minimum level of protection that should be considered by all organisations ulitilising IT systems
- Although many organisation will require protection considerably above baseline
- Can provide a *common* basis for mutual trust
- A minimum level of protection that should be considered by all organisations utilising IT systems
- Although many organisations will require protection considerably above baseline
- Can provide a *common* basis for mutual trust
###### Cyber Essentials
- Enables organisations to be certified independently for having met a good practice standard in cyber security
- Addresses five technical control themes:
1. Firewalls
2. Secure configuration
3. User access control
4. Malware protection
5. Security Update management
1. Firewalls
2. Secure configuration
3. User access control
4. Malware protection
5. Security Update management
###### ISO 27001
- the central element of the ISO 27000 series
- describes best practice for an ISMS (information security management system)
- outlines of each aspect of an ISMS, and other standards provide further detail (e.g. 27002 for controls, 27003 for implementation, 27004 for evaluation)
- outlines each aspect of an ISMS, and other standards provide further detail (e.g. 27002 for controls, 27003 for implementation, 27004 for evaluation)
###### ISO 27002
@@ -90,6 +90,6 @@ The system is unchanged, but risk is transferred to another party e.g. an insura
### The need for Professional Skills
- Although simplified at the abstract level, actually following even the baseline controls is non-trivial
- Simply knowing about them does not tell you *how* to comply
- Still requires the ability to assess the current environment and understand the appropriate protection and how to apply it
- Organisations require professionals with appropriate security knowledge, skills and competence.
- Simply knowing about them does not tell you *how* to comply
- Still requires the ability to assess the current environment and understand the appropriate protection and how to apply it
- Organisations require professionals with appropriate security knowledge, skills and competence.