96 lines
4.2 KiB
Markdown
96 lines
4.2 KiB
Markdown
# Security Management
|
||
|
||
> “Information security is the protection of information from a wide range of threats in order to ensure business continuity, minimise business risk, and maximise return on investments and business opportunities” - ISO/IEC 17799 Code of practice for information security management, 2005
|
||
|
||
> “The concepts, techniques, technical measures, and administrative measures used to protect information assets from deliberate or inadvertent unauthorised acquisition, damage, disclosure, manipulation, modification, loss, or use” - IBM Dictionary of Computing, 1994
|
||
|
||
**Informational Security:** preservation of **confidentiality**, **integrity** and **availability** of information. In addition, other properties such as authenticity, accountability, non-repudiation and reliability can also be involved
|
||
|
||
> “Cybersecurity is how individuals and organisations reduce the risk of cyber attack.
|
||
>
|
||
> Cybersecurity's core function is to protect the devices we all use (smartphones, laptops, tablets and computers), and the services we access - both online and at work - from theft or damage.
|
||
>
|
||
> It's also about preventing unauthorised access to the vast amounts of personal information we store on these devices, and online” - UK National Cyber Security Centre www.ncsc.gov.uk/section/about-ncsc/what-is-cyber-security
|
||
|
||
### Security Policy
|
||
|
||
- A statement of overall intent and commitment to security
|
||
- Provides a *foundation* for other aspects
|
||
- High level policy applies to the organisation and everyone in it
|
||
- more focused policies may apply to specific departments, systems etc
|
||
- Identifies what but not how
|
||
- the *how* part would be covered by accompanying guidelines
|
||
|
||
#### Characteristics of a good policy
|
||
|
||
- Is short and backed from the top of the organisation
|
||
- Ensure everyone reads it
|
||
- Recognises that information is critical & must be protected
|
||
- Emphasises the importance of security awareness & training
|
||
- Emphasises compliance with legal and regulatory requirements
|
||
- Emphasises relations with third parties
|
||
- States roles and responsibilities for information security
|
||
- Outlines standards and procedures
|
||
- States the consequences of violations and non-compliance
|
||
|
||
Note the lack of policies on personally owned devices, considering ~100% of people have one or more.
|
||
|
||
### Recognising Risk
|
||
|
||
**Removal**
|
||
|
||
System is modified so that a particular feature and the associated risk are removed.
|
||
|
||
**Reduction**
|
||
|
||
Security measures are used to reduce risk to an acceptable level.
|
||
|
||
**Retention**
|
||
|
||
Nothing is done - the risk is small and insignificant
|
||
|
||
**Relocation**
|
||
|
||
The system is unchanged, but risk is transferred to another party e.g. an insurer
|
||
|
||
###### Management need to know
|
||
|
||
- What’s at risk
|
||
- The cost incurred if the risk becomes a breach
|
||
- Safeguards that can be implemented
|
||
- The cost of safeguards
|
||
- The risk reduction that will result from implementation of specific safeguards
|
||
|
||
### Baseline Security
|
||
|
||
- A minimum level of protection that should be considered by all organisations utilising IT systems
|
||
- Although many organisations will require protection considerably above baseline
|
||
- Can provide a *common* basis for mutual trust
|
||
|
||
###### Cyber Essentials
|
||
|
||
- Enables organisations to be certified independently for having met a good practice standard in cyber security
|
||
- Addresses five technical control themes:
|
||
1. Firewalls
|
||
2. Secure configuration
|
||
3. User access control
|
||
4. Malware protection
|
||
5. Security Update management
|
||
|
||
###### ISO 27001
|
||
|
||
- the central element of the ISO 27000 series
|
||
- describes best practice for an ISMS (information security management system)
|
||
- outlines each aspect of an ISMS, and other standards provide further detail (e.g. 27002 for controls, 27003 for implementation, 27004 for evaluation)
|
||
|
||
###### ISO 27002
|
||
|
||
- provides advice on how to implement security controls listed in Annex A of ISO 27001
|
||
|
||
### The need for Professional Skills
|
||
|
||
- Although simplified at the abstract level, actually following even the baseline controls is non-trivial
|
||
- Simply knowing about them does not tell you *how* to comply
|
||
- Still requires the ability to assess the current environment and understand the appropriate protection and how to apply it
|
||
- Organisations require professionals with appropriate security knowledge, skills and competence.
|