Files
notes/docs/lectures/security/02_security_management.md
T

95 lines
4.2 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Security Management
> “Information security is the protection of information from a wide range of threats in order to ensure business continuity, minimise business risk, and maximise return on investments and business opportunities” - ISO/IEC 17799 Code of practice for information security management, 2005
> “The concepts, techniques, technical measures, and administrative measures used to protect information assets from deliberate or inadvertent unauthorised acquisition, damage, disclosure, manipulation, modification, loss, or use” - IBM Dictionary of Computing, 1994
**Informational Security:** preservation of **confidentiality**, **integrity** and **availability** of information. In addition, other properties such as authenticity, accountability, non-repudiation and reliability can also be involved
> “Cybersecurity is how individuals and organisations reduce the risk of cyber attack.
>
> Cybersecurity's core function is to protect the devices we all use (smartphones, laptops, tablets and computers), and the services we access - both online and at work - from theft or damage.
>
> It's also about preventing unauthorised access to the vast amounts of personal information we store on these devices, and online” - UK National Cyber Security Centre www.ncsc.gov.uk/section/about-ncsc/what-is-cyber-security
### Security Policy
- A statement of overall intent and commitment to security
- Provides a *foundation* for other aspects
- High level policy applies to the organisation and everyone in it
- more focused policies may apply to specific departments, systems etc
- Identifies what but not how
- the *how* part would be covered by accompanying guidelines
#### Characteristics of a good policy
- Is short and backed from the top of the organisation
- Ensure everyone reads it
- Recognises that information is critical & must be protected
- Emphasises the importance of security awareness & training
- Emphasises compliance with legal and regulatory requirements
- Emphasises relations with third parties
- States roles and responsibilities for information security
- Outlines standards and procedures
- States the consequences of violations and non-compliance
Note the lack of policies on personally owned devices, considering ~100% of people have one or more.
### Recognising Risk
**Removal**
System is modified so that a particular feature, and the associated risk is removed.
**Reduction**
Security measures are used to reduce risk to an acceptable level.
**Retention**
Nothing is done - the risk is small and insignificant
**Relocation**
The system is unchanged, but risk is transferred to another party e.g. an insurance
###### Management need to know
- What’s at risk
- The cost incurred if the risk becomes a breach
- Safeguards that can be implemented
- The cost of safeguards
- The risk reduction that will result from implementation of specific safeguards
### Baseline Security
- A minimum level of protection that should be considered by all organisations ulitilising IT systems
- Although many organisation will require protection considerably above baseline
- Can provide a *common* basis for mutual trust
###### Cyber Essentials
- Enables organisations to be certified independently for having met a good practice standard in cyber security
- Addresses five technical control themes:
1. Firewalls
2. Secure configuration
3. User access control
4. Malware protection
5. Security Update management
###### ISO 27001
- the central element of the ISO 27000 series
- describes best practice for an ISMS (information security management system)
- outlines of each aspect of an ISMS, and other standards provide further detail (e.g. 27002 for controls, 27003 for implementation, 27004 for evaluation)
###### ISO 27002
- provides advice on how to implement security controls listed in Annex A of ISO 27001
### The need for Professional Skills
- Although simplified at the abstract level, actually following even the baseline controls is non-trivial
- Simply knowing about them does not tell you *how* to comply
- Still requires the ability to assess the current environment and understand the appropriate protection and how to apply it
- Organisations require professionals with appropriate security knowledge, skills and competence.