4.2 KiB
Security Management
“Information security is the protection of information from a wide range of threats in order to ensure business continuity, minimise business risk, and maximise return on investments and business opportunities” - ISO/IEC 17799 Code of practice for information security management, 2005
“The concepts, techniques, technical measures, and administrative measures used to protect information assets from deliberate or inadvertent unauthorised acquisition, damage, disclosure, manipulation, modification, loss, or use” - IBM Dictionary of Computing, 1994
Informational Security: preservation of confidentiality, integrity and availability of information. In addition, other properties such as authenticity, accountability, non-repudiation and reliability can also be involved
“Cybersecurity is how individuals and organisations reduce the risk of cyber attack.
Cybersecurity's core function is to protect the devices we all use (smartphones, laptops, tablets and computers), and the services we access - both online and at work - from theft or damage.
It's also about preventing unauthorised access to the vast amounts of personal information we store on these devices, and online” - UK National Cyber Security Centre www.ncsc.gov.uk/section/about-ncsc/what-is-cyber-security
Security Policy
- A statement of overall intent and commitment to security
- Provides a foundation for other aspects
- High level policy applies to the organisation and everyone in it
- more focused policies may apply to specific departments, systems etc
- Identifies what but not how
- the how part would be covered by accompanying guidelines
Characteristics of a good policy
- Is short and backed from the top of the organisation
- Ensure everyone reads it
- Recognises that information is critical & must be protected
- Emphasises the importance of security awareness & training
- Emphasises compliance with legal and regulatory requirements
- Emphasises relations with third parties
- States roles and responsibilities for information security
- Outlines standards and procedures
- States the consequences of violations and non-compliance
Note the lack of policies on personally owned devices, considering ~100% of people have one or more.
Recognising Risk
Removal
System is modified so that a particular feature, and the associated risk is removed.
Reduction
Security measures are used to reduce risk to an acceptable level.
Retention
Nothing is done - the risk is small and insignificant
Relocation
The system is unchanged, but risk is transferred to another party e.g. an insurance
Management need to know
- What’s at risk
- The cost incurred if the risk becomes a breach
- Safeguards that can be implemented
- The cost of safeguards
- The risk reduction that will result from implementation of specific safeguards
Baseline Security
- A minimum level of protection that should be considered by all organisations ulitilising IT systems
- Although many organisation will require protection considerably above baseline
- Can provide a common basis for mutual trust
Cyber Essentials
- Enables organisations to be certified independently for having met a good practice standard in cyber security
- Addresses five technical control themes:
- Firewalls
- Secure configuration
- User access control
- Malware protection
- Security Update management
ISO 27001
- the central element of the ISO 27000 series
- describes best practice for an ISMS (information security management system)
- outlines of each aspect of an ISMS, and other standards provide further detail (e.g. 27002 for controls, 27003 for implementation, 27004 for evaluation)
ISO 27002
- provides advice on how to implement security controls listed in Annex A of ISO 27001
The need for Professional Skills
- Although simplified at the abstract level, actually following even the baseline controls is non-trivial
- Simply knowing about them does not tell you how to comply
- Still requires the ability to assess the current environment and understand the appropriate protection and how to apply it
- Organisations require professionals with appropriate security knowledge, skills and competence.