Files
notes/docs/lectures/security/02_security_management.md
T

4.2 KiB
Raw Blame History

Security Management

“Information security is the protection of information from a wide range of threats in order to ensure business continuity, minimise business risk, and maximise return on investments and business opportunities” - ISO/IEC 17799 Code of practice for information security management, 2005

“The concepts, techniques, technical measures, and administrative measures used to protect information assets from deliberate or inadvertent unauthorised acquisition, damage, disclosure, manipulation, modification, loss, or use” - IBM Dictionary of Computing, 1994

Informational Security: preservation of confidentiality, integrity and availability of information. In addition, other properties such as authenticity, accountability, non-repudiation and reliability can also be involved

“Cybersecurity is how individuals and organisations reduce the risk of cyber attack.

Cybersecurity's core function is to protect the devices we all use (smartphones, laptops, tablets and computers), and the services we access - both online and at work - from theft or damage.

It's also about preventing unauthorised access to the vast amounts of personal information we store on these devices, and online” - UK National Cyber Security Centre www.ncsc.gov.uk/section/about-ncsc/what-is-cyber-security

Security Policy

  • A statement of overall intent and commitment to security
  • Provides a foundation for other aspects
  • High level policy applies to the organisation and everyone in it
    • more focused policies may apply to specific departments, systems etc
  • Identifies what but not how
    • the how part would be covered by accompanying guidelines

Characteristics of a good policy

  • Is short and backed from the top of the organisation
    • Ensure everyone reads it
  • Recognises that information is critical & must be protected
  • Emphasises the importance of security awareness & training
  • Emphasises compliance with legal and regulatory requirements
  • Emphasises relations with third parties
  • States roles and responsibilities for information security
  • Outlines standards and procedures
  • States the consequences of violations and non-compliance

Note the lack of policies on personally owned devices, considering ~100% of people have one or more.

Recognising Risk

Removal

System is modified so that a particular feature, and the associated risk is removed.

Reduction

Security measures are used to reduce risk to an acceptable level.

Retention

Nothing is done - the risk is small and insignificant

Relocation

The system is unchanged, but risk is transferred to another party e.g. an insurance

Management need to know
  • What’s at risk
  • The cost incurred if the risk becomes a breach
  • Safeguards that can be implemented
  • The cost of safeguards
  • The risk reduction that will result from implementation of specific safeguards

Baseline Security

  • A minimum level of protection that should be considered by all organisations ulitilising IT systems
    • Although many organisation will require protection considerably above baseline
    • Can provide a common basis for mutual trust
Cyber Essentials
  • Enables organisations to be certified independently for having met a good practice standard in cyber security
  • Addresses five technical control themes:
    1. Firewalls
    2. Secure configuration
    3. User access control
    4. Malware protection
    5. Security Update management
ISO 27001
  • the central element of the ISO 27000 series
  • describes best practice for an ISMS (information security management system)
  • outlines of each aspect of an ISMS, and other standards provide further detail (e.g. 27002 for controls, 27003 for implementation, 27004 for evaluation)
ISO 27002
  • provides advice on how to implement security controls listed in Annex A of ISO 27001

The need for Professional Skills

  • Although simplified at the abstract level, actually following even the baseline controls is non-trivial
    • Simply knowing about them does not tell you how to comply
    • Still requires the ability to assess the current environment and understand the appropriate protection and how to apply it
  • Organisations require professionals with appropriate security knowledge, skills and competence.