Discussion and Replies
125
8
Organization of Information Security
The “Organization of Information Security” clause is particularly important to the overall information security initiative because controls within this section set the expectation for management’s commitment and involvement with information secu- rity. In addition, information security as it relates to external parties is clearly defined and presented in a series of controls.
To a large degree, information security is about continually assessing risks that are applicable to the environment under review, associating threats, and determining a likelihood of a vulnerability being exploited. Any organization must implement a series of controls and safeguards to protect its assets. The balance and exact controls that are implemented should be the result of a detailed and customized risk analysis process. Management should control the design and implementation of controls within the organization.
From an organizational perspective, management should establish and provide an approval mechanism for the information security policy as discussed in the previous chapter and guide the implementation of information security across the organization. People within the organization must know and understand their respon- sibilities to information security.
You may be beginning to understand how each of the control areas and controls are interrelated. In the previous chapter an outline and detailed explanation was provided on the information security policy document. The “Organization of Infor- mation Security” area builds on the controls set within the security policy area by suggesting that management provide organizationwide support by providing an approval mechanism and guiding the implementation of information security across the entire organization.
Within the “Organization of Information Security” control area, another objec- tive is for an organization to establish and maintain relationships with external information security specialists. It is impossible for anyone or any single group to be completely versed and operate at peak levels within every area of information security. The key is for an organization to establish specific relationships with external firms and subject matter experts/consultants to stay up-to-date on all appli- cable issues and trends that apply to their business model.
For example, an organization may be exposed or required to adhere to legal or regulatory requirements for information security. It is highly unlikely that all orga- nizations will employ full-time subject matter experts on the associated legal and regulatory requirements and understand how to apply them within the context of the information security strategy and program. This is one of the fundamental reasons
AU7087_C008.fm Page 125 Friday, April 28, 2006 9:34 AM
Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-04-25 00:13:54.
C op
yr ig
ht ©
2 00
6. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
126
Information Security
for establishing and maintaining relationships with third parties to monitor, review, and assist the organization with matters such as this.
The “Organizing Information Security” clause also suggests that organizations have a multifaceted approach to their information security program. The approach should include a wide array of organizational members including senior manage- ment, managers, system administrators, application developers, internal audit, infor- mation technology professionals, legal, system users, human resources, facilities, enterprise risk management, etc.
INTERNAL ORGANIZATION
Simply stated, management must be actively involved in the information security effort on many different levels to ensure the program’s accuracy and effectiveness as it relates to the requirements of the organization.
Management should establish a methodology and framework to implement infor- mation security within the organization in a way that is conducive and effective based on organizational culture and business objectives and requirements. Visible management support and leadership should be developed and implemented to approve information security policies, procedures, guidelines, and objectives. The key to success is organizationwide deployment and acceptance of this approach. Information security should become part of the cultural norm and integrated at every stage of the business process including concept, functional specification, design, implementation, and integration.
As needed, information security subject matter experts should be utilized to assist at any level. Everyone in the organization, ranging from end users to managers to developers to information technology staff to senior and executive management, should be actively involved in the information security journey.
The associated controls for organizational security are not technology related or driven. It is about everyone in the organization taking responsibility for the infor- mation security mission and integrating it into their functional areas. This all begins with executive sponsorship and strong management support at the ground level.
6.1.1
—
M
ANAGEMENT
COMMITMENT
TO
INFORMATION
SECURITY
Scope:
The title for this control is very straightforward and captures the spirit of the control. It is clear that management must be actively involved and committed to information security or failure is inevitable. Management support has many dimen- sions. Some of the basic commitments include the following: review and approve information security policy; provide resources required for information security; participate and sponsor information security awareness and training programs; ensure that information security is consistent across the entire organization by actively monitoring and assessing the various elements and controls of the informa- tion security program; ensure that information security is integrated into business processes and that all users within the organization understand the relevancy and importance of information security to the overall mission of the organization.
Key Risk Indicator:
Yes
AU7087_C008.fm Page 126 Friday, April 28, 2006 9:34 AM
Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-04-25 00:13:54.
C op
yr ig
ht ©
2 00
6. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Organization of Information Security
127
Control Class:
(M) Management
Key Questions:
• How does management clearly support information security within the organization?
• What formal programs exist today for information security? • How frequently does management engage external information security
resources to help with advice or to make assessments?
External References:
ISO/IEC 13335-1:2004
Additional Information:
It is important to remember that the level of commitment and the role of management are likely different for each organization. There are too many variables to list or quantify. The key to success is linking information security to the business model and management supporting this relationship in an active and visible manner.
6.1.2
—
I
NFORMATION
SECURITY
COORDINATION
Scope:
Information security requires people to take responsibility and their actions must be coordinated and driven by management.
Key Risk Indicator:
No
Control Class:
(O) Operations
Key Questions:
• What groups or roles are actively involved in information security within the organization?
• How does your organization identify significant threats and vulnerabili- ties?
• Describe how information security controls are formulated and imple- mented within the organization.
• How are existing information security controls and safeguards assessed for adequacy and effectiveness?
• Does your organization have a formal information security awareness and education program led by an assigned individual or group?
• Describe how information security incidents are coordinated.
Additional Information:
For small organizations, it might not be possible to have clear delineation of responsibilities between individuals, and that is to be expected. The real key is ownership and responsibility. The degree of coordination is likely relative to the size of the organization.
6.1.3
—
A
LLOCATION
OF
INFORMATION
SECURITY
RESPONSIBILITIES
Scope:
The scope of this control is very simple and clear: information security responsibilities should be defined in writing by management.
Key Risk Indicator:
Yes
AU7087_C008.fm Page 127 Friday, April 28, 2006 9:34 AM
Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-04-25 00:13:54.
C op
yr ig
ht ©
2 00
6. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
128
Information Security
Control Class:
(M) Management
Key Questions:
• Does the information security policy define the requirements for informa- tion security responsibilities?
• Describe and list any documented guidelines that exist today that users are required to follow when dealing with specific instances within the organization.
• Does your organization allow delegation of information security respon- sibilities? If so, describe the process they are required to follow when delegating.
• How does management define who is responsible for specific assets?
Additional Information:
Information security responsibility definition should start within the job description and be extended into each role as appropriate.
6.1.4
—
A
UTHORIZATION
PROCESS
FOR
INFORMATION
PROCESSING
FACILITIES
Scope:
Management should develop and publish a formal process to allow new information systems into the network and environment. This will have to be accom- plished all the way down to the department level.
Key Risk Indicator:
No
Control Class:
(M) Management, (O) Operations
Key Questions:
• Describe what actions, if any, are required to connect a new system or host to the company network.
• If an individual connected a personal laptop computer to the company network from his or her desk, would the system have access to the network?
• Describe any controls that exist to keep unidentified network systems or devices from connecting to the company network.
Additional Information:
Authorization has both technical and operational dimen- sions.
6.1.5
—
C
ONFIDENTIALITY
AGREEMENTS
Scope:
Organizations should create and require confidentiality or nondisclosure agreements to protect confidential information as defined by appropriate legal coun- sel. Legal resources must be consulted to ensure that the agreements are enforceable.
Key Risk Indicator:
No
Control Class:
(M) Management
Key Questions:
AU7087_C008.fm Page 128 Friday, April 28, 2006 9:34 AM
Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-04-25 00:13:54.
C op
yr ig
ht ©
2 00
6. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Organization of Information Security
129
• Has management defined “confidential information”? If so, where is the information documented and who is responsible for its upkeep and main- tenance?
• In the terms of the confidentiality agreement, is the duration of the agree- ment clearly stated?
• Has management included the right to audit and monitor external parties when confidential information is involved?
• Does the confidentiality agreement clearly state the actions required in the event of an unauthorized breach of information?
Additional Information:
Confidentiality and nondisclosure agreements can be com- plex and must adhere to all applicable legislation and regulations. Management should employ the services of internal or external legal advisers to help ensure that these types of agreements are accurate and reflect the requirements of the organization.
6.1.6
—
C
ONTACT
WITH
AUTHORITIES
Scope:
Contact with local authorities (police, fire, FBI, etc.) should be developed and maintained to ensure a quick response in the event a negative or unlawful incident occurs.
Key Risk Indicator:
No
Control Class:
(O) Operations
Key Questions:
• What relationships does information security have with local authorities (fire, police, FBI, etc.)?
• Is the contact information for local police, fire, FBI, etc., included in the organization’s security incident procedures?
Additional Information:
Contact with other critical providers such as telecommu- nications and Internet service providers is a good idea as well.
6.1.7
—
C
ONTACT
WITH
SPECIAL
INTEREST
GROUPS
Scope:
This control strongly suggests that information security professionals within the organization establish contact with special interest groups within information security that could benefit the organization. Also, professional associations should be established and maintained.
Key Risk Indicator:
No
Control Class:
(O) Operations
Key Questions:
• What associations or special interest groups do information security man- agement belong to or attend?
AU7087_C008.fm Page 129 Friday, April 28, 2006 9:34 AM
Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-04-25 00:13:54.
C op
yr ig
ht ©
2 00
6. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
130
Information Security
• Describe how your organization receives early warnings or advisories that specifically apply to your assets.
• How does the information security staff stay current on the latest tech- nologies?
• How does your organization match common vulnerabilities in information systems with potential threats?
6.1.8
—
I
NDEPENDENT
REVIEW
OF
INFORMATION
SECURITY
Scope:
To ensure effectiveness and applicability of control and safeguards, manage- ment should engage external subject matter experts to review controls, control objectives, policies, procedures, etc., at planned intervals and when significant changes occur within the environment or operations.
Key Risk Indicator:
Yes
Control Class:
(M) Management, (O) Operations
Key Questions:
• When was the last time your management hired external subject matter experts to review the organization’s information security posture?
• Does your organization have an internal audit department? If so, when was the last time they reviewed the organization’s information security controls to ensure that they are still suitable, adequate, and effective for the organization’s approach to managing information security?
• Does the information security policy require independent review of infor- mation security?
Additional Information:
Depending on the size of the organization and other variables such as industry or regulatory drivers, it may be appropriate to have internal audit and external resources review the information security practices and operations. In other cases, the internal audit function may be sufficient.
EXTERNAL PARTIES
External parties, including third-party vendors and business partners, are very com- mon today for organizations, and they are a source of unidentified risk in many cases. There are many different dimensions to identifying and managing information security risks of external parties. The controls within this sub-clause will help management identify some of the most common and most critical elements to assess within their own operations and environment.
6.2.1
—
I
DENTIFICATION
OF
RISKS
RELATED
TO
EXTERNAL
PARTIES
Scope:
Information security risks should be identified before engaging into opera- tions with external parties. Controls should be developed as a result of the risk assessment process and implemented prior to operations.
Key Risk Indicator:
Yes
AU7087_C008.fm Page 130 Friday, April 28, 2006 9:34 AM
Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-04-25 00:13:54.
C op
yr ig
ht ©
2 00
6. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
Organization of Information Security 131
Control Class: (M) Management Key Questions:
• Does your organization have a formal information security risk assessment process for external parties, third-party vendors, and business partners?
• Describe the scope of the information security risk assessment process for external parties, if one exists.
• Has management performed an impact analysis in the event the external party does not follow the information security policy and guidelines?
• Does management allow an external party, third-party vendor, or business party to connect to the network prior to a formal information security risk assessment?
• Describe how external parties and partners are made aware of their infor- mation security responsibilities as they relate to your organization.
External References: NIST 800-30, ISO/IEC 13335
6.2.2 — ADDRESSING SECURITY WHEN DEALING WITH CUSTOMERS
Scope: This control deals with addressing all of the information security risks that were identified as part of the risk assessment process before permitting client access to organizational information or resources. Key Risk Indicator: No Control Class: (M) Management, (O) Operations Key Questions:
• Describe any documented procedures or guidelines that you must follow prior to allowing an external party access to organizational information or resources.
• Is the information security team required to perform a formal information security risk assessment before allowing external parties access to orga- nizational information and resources? If so, who approves access?
• Does your organization have a formal access control policy? If so, does it include language for external parties, third-party vendors, or clients?
Additional Information: Many times a legal agreement is required between the organization and external party. It is advisable that the scope of this control be part of this agreement.
6.2.3 — ADDRESSING SECURITY IN THIRD-PARTY AGREEMENTS
Scope: Written agreements with external parties including access, processing, net- working, or third-party management should include the organization’s information security requirements. Key Risk Indicator: No Control Class: (M) Management
AU7087_C008.fm Page 131 Friday, April 28, 2006 9:34 AM
Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-04-25 00:13:54.
C op
yr ig
ht ©
2 00
6. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .
132 Information Security
Key Questions:
• In third-party contracts or agreements, does your organization include requirements for information security?
• Is the organization’s information security policy provided to all third-party vendors and partners?
• Is any type of information security awareness training required of third- party vendors and clients?
Additional Information: The issue of addressing information security requirements in legal agreements can be complex. In some cases it may make sense to have a separate agreement specifically addressing information security requirements for third parties and have the main agreement call out to this agreement. Consult legal counsel that has specific experience in dealing with information security matters.
SUMMARY
The “Organization of Information Security” clause helps organizations evaluate internal and external aspects of information security. Internally, the expectation that management must be directly involved and committed to information security is established, and responsibility for information security must be documented and communicated. Information security requirements should be included in internal and external agreements to ensure that the organization’s information security policy is upheld. When dealing with external parties, a formal risk assessment process should be a part of normal business operations before allowing access to organizational information and resources.
REFERENCES
ISO/IEC 17799:2005 Information Technology — Security Techniques — Code of Practice for Information Security Management, International Organization for Standardiza- tion, 2005.
AU7087_C008.fm Page 132 Friday, April 28, 2006 9:34 AM
Layton, Timothy P.. Information Security : Design, Implementation, Measurement, and Compliance, Auerbach Publishers, Incorporated, 2006. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=267956. Created from apus on 2025-04-25 00:13:54.
C op
yr ig
ht ©
2 00
6. A
ue rb
ac h
P ub
lis he
rs , I
nc or
po ra
te d.
A ll
rig ht
s re
se rv
ed .