Assignment

profileeko
Ch3_Compliance_StandardsRegulations_Laws.pptx

Chapter 3

Compliance with Standards, Regulations, and Laws

Copyright © 2014 by McGraw-Hill Education.

Introduction

Even those security practitioners who work in nonregulated environments are expected to follow a common set of practices, criteria, and standards.

An understanding of the laws, regulations, and standards that apply to the field of information security is essential.

Fortunately, there are substantial overlaps among the best practices commonly accepted by these laws, regulations, and standards; this chapter covers those.

Copyright © 2014 by McGraw-Hill Education.

Information Security Standards

Also known as voluntary standards, or perhaps frameworks, these sets of “best practices” have been developed and published by internationally recognized organizations and accepted by the information security profession in general. The most well-known of these are

Control Objectives for Information and related Technology (COBIT)

International Organization for Standardization (ISO) 27001 and 27002

National Institute of Standards and Technology (NIST) standards

Copyright © 2014 by McGraw-Hill Education.

COBIT

COBIT is published by ISACA, the Information Systems Audit and Control Association.

ISACA is a widely recognized independent IT governance organization, and its COBIT guidelines are used by IT management in many organizations to define and manage processes based on a maturity model like the Capability Maturity Model (CMM).

COBIT is not about information security—it is a general IT standard, but certain security practices are embedded within it.

Copyright © 2014 by McGraw-Hill Education.

COBIT Domains:

Governance:

(v5) Evaluate, Direct, and Monitor (EDM)

Management:

(v4.1) Plan and Organize (PO) and (v5) Align, Plan, and Organize (APO)

(v4.1) Acquire and Implement (AI) and (v5) Build, Acquire, and Implement (BAI)

(v4.1) Deliver and Support (DS) and (v5) Deliver, Service, and Support (DSS)

(v4.1) Monitor and Evaluate (ME) and (v5) Monitor, Evaluate, and Assess (MEA)

Copyright © 2014 by McGraw-Hill Education.

Key Information Security–related Components of COBIT

PO2.3 Establish an information classification scheme based on the criticality and confidentiality of data, and include ownership information, protection, retention, and destruction requirements.

PO4.8 Establish an IT security and risk management function at a senior level of an organization’s management.

PO6, PO7.4 Implement a security awareness program along with formal security training for employees, service providers, and third parties.

PO9 Perform risk assessment and management via a risk management program that analyzes and communicates risks and their potential impact on business processes.

PO10.12 Ensure that security requirements are embedded into the project management process.

Copyright © 2014 by McGraw-Hill Education.

Key Information Security–related Components of COBIT

AI2.4 Include security requirements in the application development process to ensure security and availability in line with the organization’s objectives.

AI3.2, AI3.3 Implement security in the configuration, integration, and maintenance of hardware and software to provide availability and integrity.

AI5.2 Ensure that third-party suppliers of IT infrastructure, facilities, hardware, software, and services comply with the organization’s security requirements; this should be reflected in contracts with those third parties.

AI7.1–AI7.9 Follow a well-defined change control process that includes testing, production migration, and backout planning.

Copyright © 2014 by McGraw-Hill Education.

Key Information Security–related Components of COBIT

DS1.3, DS2.2 Include security requirements in service level agreements (SLAs).

DS4.1–DS4.10 Perform business continuity planning (BCP) with periodic testing, and ensure that backups are preserved in a safe offsite location.

DS5.1–DS5.11 Manage security according to a specific plan, perform identity management and user account management, perform security testing and monitoring, perform incident detection and response, implement security protections, employ cryptographic key management, protect against malicious software, secure the network, and protect data exchanges.

DS12.1–DS12.5 Control physical security and access to important assets with access controls, escorts, and monitoring of activities.

Copyright © 2014 by McGraw-Hill Education.

ISO 27000 Series

ISO 27001 is a high-level specification for the management of an information security program.

ISO 27002 is a detailed set of information security controls that would ideally be driven by the output of the risk assessment performed as part of ISO 27001.

ISO 27003 is intended to provide recommendations and best practices to implement the ISMS management controls defined by ISO 27001

ISO 27004 covers measurement of effectiveness, using metrics and key performance indicators to describe how well the information security controls are operating.

ISO 27005 defines a risk management framework for information security that can be used to inform the decisions within ISO 27001 that lead to selection of controls for ISO 27002.

ISO 27006 provides guidelines for professional organizations that provide certification to be properly accredited.

Copyright © 2014 by McGraw-Hill Education.

ISO 27002 Domains

Risk Assessment and Treatment: The use of risk assessment as a basis for selecting appropriate security controls.

Security Policy: The clear expression of management intent for information protection.

Organization of Information Security: Defining and staffing the roles and functions needed by the security program.

Asset Management: The responsibility and classification of assets, including data.

Human Resources Security: Ensuring that the behaviors of trusted inside employees don’t defeat the security controls, because the majority of security problems come from insiders, not outsiders.

Physical and Environmental Security: Creating secure areas and protecting equipment.

Copyright © 2014 by McGraw-Hill Education.

ISO 27002 Domains

Communications and Operations Management: Maintaining a safe, reliable, and correct IT environment (including the parts outside the direct control of the organization, provided by third parties. Malware protection, backups, and network security are included here.

Access Control: User controls and responsibilities, including access controls for the networks, operating systems, and applications, along with mobile computing.

Information Systems Acquisition, Development, and Maintenance: Security requirements, ensuring integrity and confidentiality, change management in development and support processes, and vulnerability management.

Information Security Incident Management: Reporting security issues and vulnerabilities, and managing incidents.

Business Continuity Management: Information security aspects of business continuity.

Compliance: Legal requirements, compliance with policies, standards, and specifications, and audit considerations.

Copyright © 2014 by McGraw-Hill Education.

Key ISO 27002 Sections

4.1, 4.2 Establish a formal risk management program to assess and treat risks to the organization’s assets.

5.1 Publish an information security policy that reflects senior management’s expectations with regard to security, and make sure it is available to all stakeholders.

6.1 Establish an internal security organization with appropriate, well-defined responsibilities and relationships with third parties.

6.2 Use confidentiality agreements to protect information when working with third parties to protect access to confidential information.

7.1 Identify and document assets, assign ownership, classify according to criticality, and establish an acceptable use policy.

7.2 Establish an information classification scheme that includes labeling and handling guidance.

Copyright © 2014 by McGraw-Hill Education.

Key ISO 27002 Sections

8.1–8.3 Perform background checks on employment candidates, communicate security responsibilities to all employees, provide information security awareness and training, and ensure that the correct security behaviors are enforced through a disciplinary process.

9.1, 9.2 Establish physical security controls, including perimeters, access controls, separation of critical areas, and protection of equipment.

Copyright © 2014 by McGraw-Hill Education.

Key ISO 27002 Sections

10.1 Establish a change control process along with separation of duties to separate development and production environments and activities.

10.2 Manage third-party service delivery.

10.3 Perform capacity planning and resource monitoring for proactive allocation of resources.

10.4 Protect against malware.

10.5 Establish reliable backups.

10.6 Establish network security controls.

10.7 Manage the handling and disposal of data and the media it resides on, and transport data securely so it can’t be intercepted.

10.9 Protect online systems, data, and transactions and maintain accurate audit logs to identify issues.

Copyright © 2014 by McGraw-Hill Education.

Key ISO 27002 Sections

11.2–11.6 Manage user access rights to control access to data.

12.2 Make sure that applications are correctly processing information and that they check their inputs to avoid misuse, and use encryption to protect that information.

12.5 Manage source code development and access, and use a formal change control process to promote code from development into the production environment.

12.6 Establish a vulnerability management program.

13.1, 13.2 Establish an incident response program.

14.1 Perform business continuity management, including regular testing.

15.1–15.3 Establish a compliance management program to comply with all legal and regulatory requirements. Perform audits to ensure compliance.

Copyright © 2014 by McGraw-Hill Education.

NIST

Access Control

Awareness and Training

Audit and Accountability

Security Assessment and Authorization

Configuration Management

Contingency Planning

Identification and Authentication

Incident Response

Maintenance

Media Protection

Physical and Environmental Protection

Planning

Personnel Security

Risk Assessment

System and Services Acquisition

System and Communications Protection

System and Information Integrity

Program Management

800-53 is organized into 18 “security control families,” which are conceptual categories that represent important components of a complete security program.

Copyright © 2014 by McGraw-Hill Education.

Key NIST Publications

SP 800-153: Guidelines for Securing Wireless Local Area Networks (WLANs)

SP 800-147: BIOS Protection Guidelines

SP 800-144: Guidelines on Security and Privacy in Public Cloud Computing

SP 800-133: Recommendation for Cryptographic Key Generation

SP 800-128: Guide for Security-Focused Configuration Management of Information Systems

SP 800-124: Guidelines on Cell Phone and PDA Security

SP 800-123: Guide to General Server Security

SP 800-122: Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)

SP 800-121: Guide to Bluetooth Security

SP 800-119: Guidelines for the Secure Deployment of IPv6

SP 800-118: Guide to Enterprise Password Management

SP 800-115: Technical Guide to Information Security Testing and Assessment

SP 800-114: User’s Guide to Securing External Devices for Telework and Remote Access

SP 800-113: Guide to SSL VPNs

SP 800-111: Guide to Storage Encryption Technologies for End User Devices

SP 800-101: Guidelines on Cell Phone Forensics

SP 800-100: Information Security Handbook: A Guide for Managers

SP 800-98: Guidelines for Securing Radio Frequency Identification (RFID) Systems

SP 800-95: Guide to Secure Web Services

SP 800-94: Guide to Intrusion Detection and Prevention Systems (IDPS)

SP 800-92: Guide to Computer Security Log Management

SP 800-84: Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities

SP 800-83: Guide to Malware Incident Prevention and Handling

SP 800-77: Guide to IPsec VPNs

SP 800-72: Guidelines on PDA Forensics

SP 800-69: Guidance for Securing Microsoft Windows XP Home Edition: A NIST Security Configuration Checklist

SP 800-68: Guide to Securing Microsoft Windows XP Systems for IT Professionals

SP 800-66: An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule

SP 800-64: Security Considerations in the System Development Life Cycle

SP 800-63: Electronic Authentication Guideline

SP 800-58: Security Considerations for Voice Over IP Systems

SP 800-55: Performance Measurement Guide for Information Security

SP 800-50: Building an Information Technology Security Awareness and Training Program

SP 800-45: Guidelines on Electronic Mail Security

SP 800-44: Guidelines on Securing Public Web Servers

SP 800-41: Guidelines on Firewalls and Firewall Policy

SP 800-40: Creating a Patch and Vulnerability Management Program

SP 800-30: Guide for Conducting Risk Assessments

SP 800-14: Generally Accepted Principles and Practices for Securing Information Technology Systems

SP 800-12: An Introduction to Computer Security: The NIST Handbook

Copyright © 2014 by McGraw-Hill Education.

Regulations

Gramm-Leach-Bliley Act (GLBA) Applies to the financial sector, including banks and lenders, for the protection of customer and financial information

Sarbanes-Oxley Act of 2002, Section 404 (SOX 404 or Sarbox) Applies to all publicly traded companies to guarantee data integrity against financial fraud

Health Insurance Portability and Accountability Act (HIPAA) and companion HiTECH Act Applies to the healthcare sector, regarding the protection of patient information

North American Electric Reliability Corporation Critical Infrastructure Protection reliability standards (NERC CIP) Applies to electric service providers such as utility companies, solar and wind power generators, and nuclear power generators

Payment Card Industry (PCI) Data Security Standard (DSS) Applies to any organization that processes, transmits, or stores credit card information

Copyright © 2014 by McGraw-Hill Education.

Laws

The Computer Fraud and Abuse Act

The USA PATRIOT Act

The Electronic Communications Privacy Act (ECPA)

The Economic Espionage Act

State-specific information security law

Other criminal and civil law relating to theft and abuse

Regulated industry-specific requirements

Law enforcement requirements

Copyright © 2014 by McGraw-Hill Education.

Hacking Laws

The Computer Fraud and Abuse Act

USA PATRIOT Act (Sections 808, 814, 816)

Copyright © 2014 by McGraw-Hill Education.

The Computer Fraud and Abuse Act

Access without or in excess of authorization

Damage or loss

Copyright © 2014 by McGraw-Hill Education.

“Damage” Is Defined as

Loss to one or more persons affecting one or more protected computers aggregating to at least $5000

Any modification or potential modification to the medical diagnosis, treatment, or care of one or more individuals

Physical injury to any person

A threat to public health or safety

Damage affecting a computer system used by government for administration of justice, national defense, or national security

Copyright © 2014 by McGraw-Hill Education.

USA PATRIOT Act (Sections 808, 814, 816)

Section 808 adds certain computer fraud and abuse offenses to the list of violations that may constitute a federal crime of terrorism.

Section 814 increases the penalties for certain computer fraud and abuse offenses.

Section 816 encourages the establishment of additional computer forensic laboratories.

Copyright © 2014 by McGraw-Hill Education.

Electronic Communication Laws

The Electronic Communications Privacy Act

USA PATRIOT Act (Sections 105, 202, 210, 216, 220)

Copyright © 2014 by McGraw-Hill Education.

Electronic Communications Privacy Act

Federal statutes protect electronic communications, including e-mail, instant messaging, and the keystrokes of network users (and sometime abusers) both from interception while they are being sent, and from access after they arrive at their destination.

Copyright © 2014 by McGraw-Hill Education.

Electronic Eavesdropping or Real-Time Interception

Practically speaking, the wiretap provisions make unlawful the use of packet sniffers or other devices designed to record the keystrokes of persons sending electronic communications, unless a legally recognized exception applies to authorize the conduct.

To preserve the right to monitor communications consent must be obtained from all users of its network. The cleanest manner of ensuring consent to record all communications on an entity’s network is to use a click-through banner as part of the login process, requiring any user of the system to accept that use of the system constitutes consent to the monitoring of all use of that network.

In the absence of such a banner, consent via organizational acceptable use policies and employee handbooks may suffice.

Copyright © 2014 by McGraw-Hill Education.

USA PATRIOT Act Section 105

Section 105 provides certain powers to the U.S. Secret Service’s Electronic Crime Task Force for investigating electronic crimes—for example “cloning” cell phones and denial-of-service attacks against online services. This section directs the director of the Secret Service to develop a national network of computer security task forces from both government and private sectors.

Copyright © 2014 by McGraw-Hill Education.

USA PATRIOT Act Sections 202 and 217

Section 202 and Section 217 allow law enforcement officials to intercept electronic communications of “computer trespassers” if they have been given legal permission by the U.S. Attorney General, or other designated officials, via a court order to intercept targeted communications.

A “computer trespasser” is defined as someone “who accesses a protected computer without authorization and thus has no reasonable expectation of privacy in any communication to, through, or from the protected computer.”

Copyright © 2014 by McGraw-Hill Education.

USA PATRIOT Act Section 210

Section 210 expands the information that law enforcement officials may obtain to include a subscriber’s or customer’s means and source of payment, as well as allowing the collection of session times and network addresses.

Copyright © 2014 by McGraw-Hill Education.

USA PATRIOT Act Section 216

Section 216 allows authorities to use pen registers and trap and trace devices with a single court order and to apply those devices to any computer or facility anywhere in the country.

Copyright © 2014 by McGraw-Hill Education.

USA PATRIOT Act Section 220

Section 220 allows a single court with jurisdiction over the offense under investigation to issue a warrant allowing the search of electronic evidence anywhere in the country, whereas previously the warrant needed to be issued by a court within the jurisdiction where the information resided.

Copyright © 2014 by McGraw-Hill Education.

Other Substantive Laws

Criminal theft of trade secrets is punishable under the Economic Espionage Act, codified at 18 U.S.C. Sections 1831–39.

Intentional electronic reproduction of copyrighted works with a retail value of more than $2500 is punishable by fine, imprisonment, or both via 18 U.S.C. Section 2319, Criminal Infringement of a Copyright.

Increasingly, content owners are also targeting private organizations, where they identify users of those networks who are actively engaging in the swapping of copyrighted materials via the organization’s network.

In such instances, the organization will generally not be held liable for the rogue actions of employees, particularly where they violate the organization’s written policies. To ensure that the organization does not risk exposure, however, it is important to respond swiftly upon discovering infringing materials on the network.

18 U.S.C. Section 2252 and 18 U.S.C. Section 2252A prohibit the “knowing” possession of child pornography.

Copyright © 2014 by McGraw-Hill Education.

State Legislation

California, S.B. 24  Requires a security breach notification

California, S.B. 1386 Security breach notification law

Illinois, H.B. 3025  Requires that certain information be provided in a disclosure notification to a state resident after a breach

Nevada, S.B. 82  Requires the chief of the Office of Information Security of the Department of Information Technology to investigate and resolve matters relating to security breaches of information systems of state agencies and elected officers

Nevada, S.B. 267 Prohibits a data collector from moving a data storage device that is used by or is a component of a multi-functional device beyond the control of the data collector

Copyright © 2014 by McGraw-Hill Education.

Summary

The information security professional must keep abreast of individual state security legislation, especially if the organization conducts business in numerous states.

Enacting and administering effective information security policies and procedures requires that information security professionals understand the laws governing cyber crime, and these laws continue to evolve.

The most significant impact of legislation is that the “techies” are no longer solely responsible for defining “best practices” and “industry standards” for information security.

Rather, defining and enforcing information security standards for consistency of practice across the United States is the province of Congress, state legislatures, and federal and state law enforcement agencies.

In this regulated environment, information security professionals can expect to be working closely with counsel, outside auditors, and corporate boards.

Copyright © 2014 by McGraw-Hill Education.