# Security Management > “Information security is the protection of information from a wide range of threats in order to ensure business continuity, minimise business risk, and maximise return on investments and business opportunities” - ISO/IEC 17799 Code of practice for information security management, 2005 > “The concepts, techniques, technical measures, and administrative measures used to protect information assets from deliberate or inadvertent unauthorised acquisition, damage, disclosure, manipulation, modification, loss, or use” - IBM Dictionary of Computing, 1994 **Informational Security:** preservation of **confidentiality**, **integrity** and **availability** of information. In addition, other properties such as authenticity, accountability, non-repudiation and reliability can also be involved > “Cybersecurity is how individuals and organisations reduce the risk of cyber attack. > > Cybersecurity's core function is to protect the devices we all use (smartphones, laptops, tablets and computers), and the services we access - both online and at work - from theft or damage. > > It's also about preventing unauthorised access to the vast amounts of personal information we store on these devices, and online” - UK National Cyber Security Centre www.ncsc.gov.uk/section/about-ncsc/what-is-cyber-security ### Security Policy - A statement of overall intent and commitment to security - Provides a *foundation* for other aspects - High level policy applies to the organisation and everyone in it - more focused policies may apply to specific departments, systems etc - Identifies what but not how - the *how* part would be covered by accompanying guidelines #### Characteristics of a good policy - Is short and backed from the top of the organisation - Ensure everyone reads it - Recognises that information is critical & must be protected - Emphasises the importance of security awareness & training - Emphasises compliance with legal and regulatory requirements - Emphasises relations with third parties - States roles and responsibilities for information security - Outlines standards and procedures - States the consequences of violations and non-compliance Note the lack of policies on personally owned devices, considering ~100% of people have one or more. ### Recognising Risk **Removal** System is modified so that a particular feature and the associated risk are removed. **Reduction** Security measures are used to reduce risk to an acceptable level. **Retention** Nothing is done - the risk is small and insignificant **Relocation** The system is unchanged, but risk is transferred to another party e.g. an insurer ###### Management need to know - What’s at risk - The cost incurred if the risk becomes a breach - Safeguards that can be implemented - The cost of safeguards - The risk reduction that will result from implementation of specific safeguards ### Baseline Security - A minimum level of protection that should be considered by all organisations utilising IT systems - Although many organisations will require protection considerably above baseline - Can provide a *common* basis for mutual trust ###### Cyber Essentials - Enables organisations to be certified independently for having met a good practice standard in cyber security - Addresses five technical control themes: 1. Firewalls 2. Secure configuration 3. User access control 4. Malware protection 5. Security Update management ###### ISO 27001 - the central element of the ISO 27000 series - describes best practice for an ISMS (information security management system) - outlines each aspect of an ISMS, and other standards provide further detail (e.g. 27002 for controls, 27003 for implementation, 27004 for evaluation) ###### ISO 27002 - provides advice on how to implement security controls listed in Annex A of ISO 27001 ### The need for Professional Skills - Although simplified at the abstract level, actually following even the baseline controls is non-trivial - Simply knowing about them does not tell you *how* to comply - Still requires the ability to assess the current environment and understand the appropriate protection and how to apply it - Organisations require professionals with appropriate security knowledge, skills and competence.