Computer Science WK1 Assignment

profileCyberSter
Information_Security_Fundamentals_----_Chapter_2_Organization_of_Information_Security.pdf

1

Chapter 2

Organization of Information Security

Patrick D. Howard

The sixth clause of ISO 27002 focuses on the information security responsibili- ties of management within an organization. Specifically, it emphasizes the neces- sity of management commitment to the security of the organization’s information resources. The importance of this topic is revealed in a cursory review of the 10 crit- ical success factors identified in ISO 27002. Organizing for information security is

Contents The Internal Information Security Organization ..................................................18 Management Support ..........................................................................................22 Information Security Coordination and Communications ..................................24

Information Security Coordination .................................................................24 Contact with Authorities ............................................................................26 Contact with Special Interest Groups .........................................................27

Information Security Roles and Responsibilities ..................................................27 Management Authorization .................................................................................29 Confidentiality Agreements .................................................................................29 Information Security Program Review .................................................................30 External Parties....................................................................................................31

Assessment of External Risks ...........................................................................32 Addressing Security When Dealing with Customers .......................................33 Third-Party Agreements ................................................................................. 34

Summary .............................................................................................................35

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

2  ◾  Information Security Fundamentals

directly related to four of these critical success factors, whereas the need of an orga- nization to properly organize for its information security efforts indirectly relates to the remaining six as well. This chapter focuses on creation of a management framework to allow the organization to meet its information security objectives.

The Internal Information Security Organization To protect their information assets, public and private organizations need to con- sider how best to manage their information security efforts. To ensure comprehen- sive protection for all the organization’s information, the approach should address information security comprehensively, organization-wide. An enterprise-wide approach also facilitates management oversight and coordination of information

ISO 27002 CRITICAL SUCCESS FACTORS DIRECTLY RELATED TO ORGANIZING FOR INFORMATION SECURITY

◾ An approach and framework to implementing, maintaining, monitor- ing, and improving information security that is consistent with the organizational culture

◾ Visible support and commitment from all levels of management ◾ Process for funding of information security management activities ◾ Implementation and use of a system to measure information security

management performance

SECONDARILY RELATED TO THE INFORMATION SECURITY ORGANIZATION

◾ Information security policy, objectives, and activities that reflect busi- ness objectives

◾ A good understanding of the information security requirements, risk assessment, and risk management

◾ Effective marketing of information security to all managers, employees, and other parties to achieve awareness

◾ Distribution of guidance on information security policy and standards to all managers, employees and other parties

◾ Providing appropriate awareness, training, and education ◾ Establishing an effective information security incident management

process

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Organization of Information Security  ◾  3

security efforts. The design of the information security management framework should ensure it is properly tuned to the operational needs of the organization, which should primarily focus on the management of risks to its information assets. The satisfaction of organizational business needs will result in an information secu- rity function that is appropriately staffed, linked to the organization’s strategic plan, integrated with organizational processes, and situated to optimize its visibility. It is impractical to stipulate minimum staffing level or organizational structure for the information security function. Consequently, each generic organization must assess its specific business needs related to the performance levels of tasks and imple- mentation of processes normally associated with an information security function, which is described in the following paragraphs.

The design of the information security function must provide a manage- ment framework that permits effective initiation, implementation, and control of information security activities within the organization. This includes planning, coordination, and management of major information security projects, as well as monitoring, measuring, tracking, and overseeing the implementation of all aspects of the organization information security program. At a minimum, information security program management must include approval of information security requirements through their definition in an organization-wide information secu- rity policy, assignment of security roles and responsibilities, coordination of infor- mation security implementation throughout the organization, and an ongoing review of the adequacy and effectiveness of the program. The information security management function designed to meet these requirements must be appropriately positioned to serve as the arm of organizational management having the author- ity to develop and either approve or coordinate approval of an organization-wide information security policy, has the authority to define and assign or recommend assignment of information security roles, and is authorized to ensure coordination and implementation of organization-wide information security efforts.

The tasks the information security function is required to perform will also drive the design of the information security organization, and will normally include security program management, policy compliance monitoring and oversight, devel- opment and maintenance of security policy, security training and awareness, inci- dent response and situational awareness, security architecture development and technical evaluation, and administration. The IT security organization should be designed to support the requirements of each of these functional areas, and distinct capabilities should be established for each.

Policy compliance and oversight activities should focus on management autho- rization activities, compliance reporting, information asset (system and facility) definition and inventory, security categorization/classification, plan of action and milestones (POA&M) and remediation tracking, interconnection agreement development and tracking, oversight of contractor operated systems, periodic inde- pendent review, and common controls definition. Necessary policy and training- related capabilities include development of policies, procedures, guidelines, and

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

4  ◾  Information Security Fundamentals

standards; managing exceptions and waivers; interpretation of policies; publication of policy notices; training and awareness for general users; provision of role-based and specialized security training; publication of periodic refresher messages; and dissemination of policy updates on current topics. Situational awareness and inci- dent response capabilities should include containment, reporting, investigating, and coordinating the response to incidents, including the protection of evidence, as well as testing and evaluation of controls, system engineering, security architec- ture integration, consultation on system design, conducting threat analyses, vulner- ability identification and tracking, trend analysis, assessment of new technology, interfacing with security operations, conducting penetration testing, vulnerability scanning, and performing forensic analysis.

To have the requisite level of authority, the information security function must be led by a member of the organization’s management staff, and must be positioned in the organizational management structure where the visibility of information security can be ensured. Today, leadership of the information security organiza- tion resides at the executive level with most large organizations. The position of the Chief Information Security Officer (CISO) is widely recognized in both public and private sectors denoting the importance of information security in those agencies and companies. The appointment of a CISO or information security manager rec- ognizes the need for dedicated leadership of an organization’s information security efforts.

The process of organizing information security must address factors such as its mission, its composition, its placement within the organizational structure, its authority vis-à-vis other elements of the organization, its responsibilities, the functions it must perform, and its lines of communication and coordination. This process should begin with the identification of requirements for the information security function, which may include a review of the organization’s mission, stra- tegic plan, and legislation, contracts, and other external directives and regulations that may potentially drive information security efforts. Directions and observations from senior agency executives should also be considered as part of the requirements identification.

An inventory of all security-related activities and resources in the organiza- tion should be developed to understand who is currently performing information security roles and functions. A determination of where information security is per- formed in the organization and those who are performing information security tasks serves as a basis for the formulation of a coherent strategy and for the design of an effective information security function. Introduction of benchmarking and leading practices can then be used to define the organization’s approach to informa- tion security management and permits the identification of the target information security function according to known requirements affecting information security. Based on knowledge of the current state of the organization’s information security posture, as well as the future state, organizations must then perform a gap analysis to identify unmet requirements, and a path forward for meeting them.

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Organization of Information Security  ◾  5

The organization should clearly define the boundaries of the information security function to address interfaces with other internal elements that perform security-related functions. These may include, for example, information technol- ogy operations, personnel security function, privacy staff, and the physical security office. These relationships should be documented in coordinated operational agree- ments (i.e., charters, concepts of operations or CONOPs, procedures, etc.).

The CISO or information security program manager must have the authority to task other elements of the organization to perform certain security functions defined by the organization. For example, the manager must have the authority to direct business units to periodically update security documentation, or to per- form security activities following defined processes. Their authority must include investigation of incidents and security violations when they occur. The informa- tion security management function should be able to enforce information security requirements, or at least be able to rely on the organizational managers to take corrective action when violations or incidents occur. With the latter arrangement, the CISO must establish strong working relationships with business unit manage- ment to ensure that proper disciplinary action is taken in response to violations to prevent their reoccurrence.

Visibility of the information security program is a major factor in determin- ing where the information security function should be organizationally located. Organizational placement influences the ability of the CISO to gain access to upper management. To ensure the proper level of visibility, the information security func- tion cannot be buried deep within the organizational structure, and the CISO should not have to struggle to obtain the attention of upper management.

In larger organizations, the need for independence of the information security function must be considered. Because of compliance responsibilities, the infor- mation security function should be fully independent of organizational elements subject to the security policy. This separation is essential for providing assurance that business units are not capable of hindering compliance monitoring activities. Consequently, the independence of the information security function should be evident throughout the organization. Information security function independence should also include control of its own budget and resources, as well as a separate operating space to permit proper protection of its own sensitive data.

To formalize the information security organization, consideration should be given to developing several key documents consistent with the organization’s proce- dures and culture. A mission statement should be used to document what the office is chartered to accomplish. The CISO or information security manager should cre- ate a vision statement to define how they envision accomplishment of the mission. A documented value proposition helps set the expectations for those affected by the information security function, and provides a benchmark on which to evaluate the information security services performed. To establish how the office will function, standard operating procedures are required to provide members of the information security organization steps necessary to perform routine, recurring tasks. To guide

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

6  ◾  Information Security Fundamentals

external customers, a documented concept of operations is necessary to address activities such as penetration testing, weakness remediation, contingency planning and testing, and annual controls testing. An operating plan for the function defines the goals and objectives to be achieved over a relatively long period of time, nor- mally 3 to 5 years. It provides milestones to be achieved and establishes priorities and sequences for tasks that the organization must perform. Development of the operating plan must be consistent with the overall agency strategic plan and IT strategic plan.

In the following paragraphs, critical components of an organization-wide infor- mation security function are described. This includes a discussion of the importance of management support for information security, mechanisms for coordination and communication of information security requirements, assignment of information security roles and responsibilities, management authorization of information sys- tems, development and use of confidentiality agreements, the independent infor- mation security review process, and considerations for dealing with external parties having access to organization information.

Management Support ISO 27002 emphasizes the importance of management support in paragraph 6.1.1, referring to it as “management commitment to information security.” It establishes the need for active management support organizational information security efforts by providing clear direction, demonstrating its commitment to information secu- rity, explicitly assigning information security responsibilities, and by acknowledging its own responsibilities for information security. Support that meets this standard must be visible, effective, focused, outcome-oriented, and its existence should be obvious across the organization. Management must provide information security direction that is expressed in understandable terms and is consistent over time. Organization management can demonstrate its commitment by following up on its policy pronouncements with observable action. Management must show interest in information security and maintain appropriate involvement in program initiatives and activities. Management must show active support by willfully assigning infor- mation security responsibilities to organization personnel to establish accountability for the accomplishment of key duties and tasks. Management must also recognize its own responsibility for information security by communicating this fact both in written and oral means. Management support that does not meet this standard could result in less than necessary emphasis on the importance of information secu- rity to the organization and its mission, thereby diminishing its effectiveness.

The means by which management can ensure that it provides adequate support to information security can be promoted through management actions in the areas of planning, policy, visibility, resources, accountability, awareness, and efficiency. Specific management support considerations are as follows:

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Organization of Information Security  ◾  7

◾ It is within management’s purview to ensure that the goals for the security of organization information are established through strategic and tactical plan- ning, and are maintained, emphasized, and measured. These goals must serve to address organizational business requirements, must be both realistic and achievable, and must be regularly measured to ensure that they are in tune with enterprise risk management and mission requirements. Management should also ensure that security goals are considered in capital investment planning, project management, organizational staffing, acquisitions, perfor- mance measurement, and other organizational processes.

◾ Management must act to ensure the organization has a mechanism for creating an information security policy that facilitates goal achievement. Management must also ensure that the policy is properly coordinated across the organization, and is properly vetted and approved. These actions ensure that the policy satisfies organization level, enterprise-wide business requirements.

◾ Management must ensure the approved information security policy is prop- erly implemented and consequently must take action to ensure that it has a mechanism for monitoring implementation activities for effectiveness. This is the policy oversight and compliance function facilitated by activities of the information security organization and management’s own program oversight committee. Such oversight bodies are most effective when formally chartered, and when membership, authority, and goals are defined.

◾ Organizational management must render appropriate direction and support for initiatives relating to its information security program. This may be an awareness campaign, rollout of a new security strategy, or introduction of a new security process or solution. The information security function will define aspects of the security initiative in its plans and will present them to management for approval as a basis for management support. Once manage- ment concurs with the objectives and parameters for the initiative, it should be visibly involved in ensuring the initiative’s success according to the plans developed to meet those objectives. Through such efforts, management can promote and foster a culture of security.

◾ On the basis of the approved plans, management should provide additional support to information security initiatives through the provision of neces- sary resources, for both funding and personnel. This may also include giving priority to information security by directing other organizational elements to support information security requirements initiatives. This may include actions related to the completion of information security training, adher- ence with processes, compliance with policy, and implementation of security controls. To facilitate management support of this nature, the information security function must adhere to organizational requirements for obtaining resources such as budget formulation, manpower planning, capital invest- ments, etc.

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

8  ◾  Information Security Fundamentals

◾ Organizational management must support information security efforts by defining in policy or through other formal means the roles and responsibilities for the entire agency, and also establishing information security requirements and qualifications for the assignment of personnel. This may involve publica- tion of assignment orders, appointment memos, and integration of informa- tion security responsibilities in job descriptions and performance plans. These actions permit the establishment of accountability for information security.

◾ Ongoing awareness of information security must be emphasized by organiza- tion management to recognize the importance of personnel in the security of information. Management is responsible for ensuring the existence of plans and programs for making this happen. Plans may include the identification of audi- ences, topics, frequency, type, and duration of awareness training. Programs may include mechanisms for testing awareness and updating training content to ensure that it is realistic, responsive to existing threats, and meets current busi- ness needs. Management should recognize that awareness efforts can enhance security by increasing user engagement with the information security program.

◾ Management is also responsible for ensuring that security controls are imple- mented in a coordinated fashion organization-wide. Effective coordination can result from the actions of the information security function supported by the oversight/steering committee and other lower level, cross-organization coordination committees or working groups. The identification and imple- mentation of common controls for the protection of multiple systems and information assets also fosters effective coordination by meeting the objec- tives of consistency, efficiency, cost-effectiveness, and interoperability of con- trols. Management can also foster effective information security coordination by stressing the importance of sound project management and integration of information security into the organization’s system development life cycle methodology and practices.

Information Security Coordination and Communications ISO 27002 emphasizes the importance of properly coordinating information secu- rity within the organization and maintaining effective contacts to effect commu- nications with external authorities, specialists, and interest groups. Sections 6.1.2, 6.1.6, and 6.1.7 detail the requirements for program coordination and communica- tion. The following paragraphs synthesize considerations for effectively coordinat- ing and communicating information security program activities.

Information Security Coordination The security of organization information requires a multidisciplinary approach involving virtually all organizational elements and personnel. Information security

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Organization of Information Security  ◾  9

activities and requirements should therefore engage expertise available within the organization to include the general counsel, public affairs, facility security and engineering, personnel security, union management, human resources, training, contracting, finance, internal audit, information technology operations, system development, capital planning, insurance, enterprise architecture, privacy, and records management. Representatives of these activities who are assigned relevant roles and job functions should be involved in the coordination of information secu- rity activities and, where necessary, should be formally assigned security roles and responsibilities as detailed below. Representatives [e.g., information system secu- rity officers (ISSOs), system administrators, developers, auditors, project managers, and information technology operations personnel] should be provided specialized information security training to better prepare them to perform their responsibili- ties. In large organizations, information security coordination may be facilitated through an existing management group such as an information technology gov- ernance committee or through a specialized information security committee (e.g., ISSO forum). In smaller organizations, this coordination may be performed by another management group or an individual manager.

The objective of cross-organization coordination should be collaboration and cooperation. The objective is to effectively integrate information security into the operations of all elements of the organization, and the information security func- tion must collaboratively work together with business units to obtain their input to inform decisions regarding the definition of requirements, priorities, strategies, and timetables. Coordination of this type should result in joint identification of and consensus in goals established for the information security program. Other considerations for information security program coordination include

◾ All information security–related activities should adhere to the information security policy. To ensure consistency of performance and compliance with established requirements, the information security function should be in a position to review all activities against the policy.

◾ Coordination activities should assure that the policy is enforced through the development of coordinated processes for identifying, communicating, and dealing with policy violations and situations involving noncompliance.

◾ All information security methodologies and processes such as risk assessment, information classification, vulnerability remediation, and system authoriza- tion should be coordinated across the organization to ensure that they meet organizational needs and requirements, are based on leading practices, and are consistent with the information security policy. To achieve this goal, the organization must ensure that there are mechanisms for their development, dissemination, review, validation, finalization, and maintenance.

◾ The organization must have the capability to identify significant changes in threats to its information and to coordinate a unified response to them with all affected organizational elements. This threat identification capability must

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

10  ◾  Information Security Fundamentals

ensure that threats are assessed, prioritized, communicated, and countered with the degree of urgency warranted by the threat.

◾ Implementation of information security controls and assessment of their ade- quacy requires effective coordination focused on compliance with the policy, reliance on approved security mechanisms and procedures, and recognition of the inherent risks involved. The information security function must ensure that the efforts of system owners, ISSOs, engineers, developers, auditors, and program managers lead to effective implementation and maintenance of con- trols protecting the organization’s information.

◾ Effective coordination ensures that information security education, training, and awareness activities are promulgated throughout the organization. This ensures consistency in the performance of organization personnel in informa- tion security and fosters an organizational culture of security.

◾ The capability to coordinate the results of information security–related moni- toring and review activities leads to the effective implementation of appropriate actions in response to security incidents and identified vulnerabilities. A process such as this ensures that the organization is able to apply lessons learned enterprise- wide to effectively respond to situations and avoid their recurrence elsewhere.

Contact with Authorities

The organization should establish contacts with relevant authorities to keep up with industry trends, to monitor standards, to gain knowledge of security meth- odologies and processes, and to provide liaison points for handling information security incidents. These contacts may be formed on the basis of formal contractual arrangements, subscriptions, membership, or may be informal in nature consist- ing of personal contacts, calls, and meeting attendance. Contacts with authorities may include industry groups; incident response authorities (e.g., the U.S. Computer Emergency Readiness Team or US-CERT); consulting houses; higher headquarters; Federal, State, and local law enforcement officials; and relevant sister organizations.

Organizations whose responsibility is to make the contact must manage these contacts by developing procedures to specify when authorities should be contacted and the definition of the manner in which the identified information security inci- dents are to be reported, including timeframes for reporting by type of incident— particularly when laws are suspected of having been broken. Organizations must make provisions in advance by defining the process for obtaining assistance from external third parties (e.g., an Internet service provider or telecommunications operator) in the event of an attack so that they can take action against the source of attack. These processes not only support information security incident manage- ment but also business continuity and contingency planning process. Also, contacts with regulatory entities provide the organization useful information to allow antici- pation and preparation for potential changes in legislation, regulations, and guidance

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Organization of Information Security  ◾  11

that the organization must adhere to. These contacts may be with higher headquar- ters, legislative affairs organizations, industry groups, and government-wide forums. Additionally, the organization should maintain contacts with other types of authori- ties related to the security of its information, which may include utilities companies, emergency service organizations, fire departments, telecommunication providers, and emergency health and safety personnel.

Contact with Special Interest Groups

The information security organization should identify needs for both internal and external specialized information security advice and information. The organiza- tion should have a process for assuring the value and credibility of information received, and disseminating it to the appropriate recipients in a timely fashion. The information security function should be charged with maintaining ongoing con- tact with groups that provide information related to information security aware- ness, best practices, and lessons learned. This includes specialist security forums and professional associations. Examples include software vendors that provide vul- nerability and patching information regarding their products. The International Information Systems Security Certification Consortium or (ISC)2, SysAdmin, Audit, Networking, and Security (SANS) Institute, and other organization host sites wherein specialty information security advice and assistance can be located. Government and industry groups that share information security concerns are another source of specialty information, particularly with respect to compliance with legislation (e.g., Health Information Portability and Accountability Act; Federal Information Security Management Act). Also, informal contacts with counterparts outside the organization by the CISO or information security man- ager can be highly valuable in sharing experiences and best practices.

Contacts of this type gives the organization access to alerts, warnings, and patches relating to attacks on and vulnerabilities in the organization’s technolo- gies. These groups also provide information that permits an understanding of the broad information security environment including current threats, vulnerabilities, and attack trends. Specialty sources can be useful in obtaining and exchanging information regarding new security technologies, products, and processes, and in providing advice on best practices for information security and implementation of security controls. Finally, these groups provide avenues for reporting information about security incidents to foster cooperation and information sharing.

Information Security Roles and Responsibilities All information security roles and responsibilities should be formally allocated by defining them in writing using terms that are clearly understood across the organi- zation. This includes specification of responsibilities for the protection of individual

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

12  ◾  Information Security Fundamentals

assets as well as for performing specific security tasks. This will ensure that those assigned to information security–related positions are delegated the authority neces- sary to perform the work as well as the establishment of accountability for personnel assigned those tasks. Assignment of information security responsibilities also ensures consistency in the allocation of key program responsibilities throughout the entire organization. This action is one of the primary information security functions of orga- nization management and should be performed according to the information security policy. Linkage of this activity to the policy requires review of roles and responsibilities whenever the policy is updated, and although roles and responsibilities do not neces- sarily have to be a documented part of the policy, they must adhere to it.

Documentation of information security responsibilities should be spe- cific enough to define, at a high level, what the role entails. As necessary, more detailed guidance should be issued to supplement this high-level role description. Additionally, responsibilities and supplementing procedures should be tailored to the needs of specific locations, facilities, and operations as necessary. For instance, the responsibilities for the data center security manager should significantly differ from those of a network security manager. Similarly, local conditions should lead to the specification of detailed responsibilities for specific security processes such as vulnerability scanning and contingency planning. Each organizational element will ensure that information security responsibilities are appropriately modified or supplemented to meet its own local business needs.

An individual who is assigned information security responsibility may delegate security tasks to another, yet must remain responsible for ensuring that the tasks are performed correctly. For example, the owner of an information system may choose to delegate responsibility for performing system level security tasks to an ISSO. Or an authorizing official who has a multitude of other duties may delegate his or her security tasks to a designated representative for performance. In each case, the system owner and authorizing official maintain responsibility for ensuring that these delegated tasks are properly performed. This approach ensures that security tasks are performed in a responsible manner while maintaining accountability for their completion.

With respect to responsibility for areas, assets, and processes, individuals may need a clear definition for all assets and processes associated with a particular infor- mation system. This pertains to the hardware, software, procedures, user base, data, and controls within the boundaries of that system. The terms and limitations of management’s authorization of an information system or facility should also be clearly defined. How the asset will be used and its purpose will be made known to the responsible individual to ensure their understanding of their responsibilities.

In large organizations, the CISO or information security manager will be assigned overall responsibility for the information security program. Nevertheless, individual managers typically maintain responsibility for resourcing and imple- menting program requirements. The appointment of an owner for each informa- tion asset facilitates the assignment of responsibility for the ongoing security of that asset. This approach recognizes the span of control of information security

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Organization of Information Security  ◾  13

management while providing for effective security policy compliance and account- ability for the performance of security tasks.

Management Authorization Organizations should establish and implement a process for management to authorize the use of critical information assets. This typically pertains to information processing facilities, information systems, and applications. It may also include capabilities and processes considered to pose an increased risk to information (e.g., remote access and use of personally owned assets). This provides a means for management to exercise its responsibility for ensuring it has considered the risks associated with its most important assets and most risky operations. In most organizations, the CISO or information secu- rity manager defines, implements, and maintains oversight of the authorization process.

Management authorization is implemented in the U.S. Federal Government through the designation of authorizing officials who are senior management officials empowered to authorize the operation of government information systems. Each agency must identify who performs the authorizing officials’ function and must prepare them to perform this role. The number of authorizing officials depends chiefly on the number of information systems an agency has and how the agency is organizationally structured. To be effective, authorizing officials must be familiar with the requirements of their role to include knowledge of the agency’s business processes and understanding risk management principles. The CISO must ensure that each authorizing official is aware of the critical aspects of the position by docu- menting requirements, providing training upon their initial assignment to the role, and then keeping them apprised of changes in the threat environment.

Where information assets are interconnected or are otherwise interdependent, authorization should consider the effect such assets may have on the organization’s level of risk. Authorization should take place before use to ensure that relevant security requirements are met and risks are identified and mitigated.

Confidentiality Agreements According to ISO 27002, confidentiality and nondisclosure agreements are designed to protect an organization’s information and inform those signing the agreement of their responsibility for the information’s responsible and authorized protection, use, and disclosure. They provide management another control mechanism to exercise its information security responsibilities. Directed at the internal workforce, nondisclo- sure agreements specify the organization’s requirements for protecting its information against unauthorized disclosure. This serves as an effective means for organizations having a need for protection of information confidentiality, but does not address requirements for maintaining its integrity or availability. Such agreements provide

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

14  ◾  Information Security Fundamentals

a basis for legal action in the event of unauthorized disclosure, which may include administrative penalties, termination, lawsuit, or criminal prosecution.

The contents of the confidentiality agreement should include the specification of its scope (i.e., classified, sensitive, restricted, related to a specific project, etc.); the terms of the agreement (for example, upon declassification of the information, 1 year following termination, etc.); specific actions to be taken upon its termination (e.g., notifications, information disposition, etc.); specific responsibilities of employees or other signatories to protect the confidentiality of information against unauthor- ized disclosure; specifying who “owns” the information and therefore who can make decisions about its protection requirements, disposition, handling, disposal, mark- ing, downgrade, modification, alteration, etc.; specifying the limits over the use of the information; definition of the notification and reporting process for disclosure breaches, and procedures for notification in the case of violations of the agreement; and stipulation of the right to audit and monitor security involving confidential infor- mation. Once the agreement is signed, the receiving party agrees to allow its activities to be audited and monitored to provide assurance that confidentiality is protected.

The organization’s general consul or legal department should review all nondis- closure agreements to ensure that they comply with all applicable laws and regula- tions. The organization should periodically review its requirements for confidentiality agreements and also when changes occur to influence requirements.

Information Security Program Review Organization management has an obligation to ensure that efforts to protect its infor- mation are adequate. A process for reviewing the information security program is essential to ensuring that compliance with established information security require- ments is maintained, gaining assurance that relevant risks are addressed, and main- taining awareness of the effectiveness of program controls. This process should focus on periodic review of the program by an independent entity as well as when significant changes affecting security occur. The scope of this review should include the imple- mentation of security controls, processes, and procedures with respect to how they meet established information security policy requirements. To optimize scheduling and to establish clear authority, organization management is responsible for directing program reviews, and for addressing the resulting findings and recommendations.

The scope and methodology used in reviews should be tailored to organiza- tional needs, which vary over time. Application of a variety of assessment approaches focused on various components of the information security program or information assets is advisable. For instance, penetration testing may be employed to determine the effectiveness of specific perimeter-protective mechanisms in preventing or detect- ing external attacks, or may include evaluation of all perimeter controls. This should be augmented by regular security controls testing of particular information systems, components, or facilities. Additionally, a periodic review of the entire information

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Organization of Information Security  ◾  15

security program ensures that all aspects of the organization’s information security efforts are comprehensively reviewed for adequacy. A broad-based program review of this type is normally performed by the internal audit function. Management must ensure that personnel conducting information security reviews are independent of the subject of the review and have the appropriate skills and experience necessary to perform the review, including expertise in the technologies to be reviewed, and in accepted assessment and audit methods. This is achieved through definition of skills and independence requirements and validation by the information security function. The results of the review should be formally documented to demonstrate the organi- zation’s due diligence, and reported to management for review upon conclusion of review activities.

Management’s response to independent reviews should focus on determining the effectiveness and adequacy of the organization’s approach to managing and implementing information security according to its stated security policy and cur- rent view of risks to the organization’s information. Management should require corrective action to be taken to address all identified weaknesses, and must insist on a process for tracking the status of completion.

External Parties Special provisions need to be taken to protect organizational data in cases where it must be accessed, processed, communicated to, or managed by external parties. This may be through formal relationships with customer organizations, arrange- ments with supporting vendors, communications with a superior organization, or any other external entity with which information is exchanged. ISO 27002 provides examples of external parties, including service providers (ISPs, network provid- ers, telephone services, and maintenance and support services); managed security services; customers; providers of facilities or operations (IT systems, data collec- tion services, and call center operations); business consultants and auditors; devel- opers and suppliers of software products and IT systems; cleaning, catering, and other outsourced support services; and temporary personnel, students, and other short-term personnel. Arrangements along these lines generally do not include information exchanges with entities within the same management authority and organizational structure. The guiding principle for dealing with external parties of this type is to ensure that the security of the organization’s information and information processing facilities is not to be diminished through the introduction of external party activities, products, or services. Should this occur, the agreement with the external party should be suspended or terminated immediately to prevent further risk to the organization’s information. To prevent these risks, any access to the organization’s information by external parties should be fully understood and controlled because surrender of control by the information owner means there is no assurance that security is maintained.

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

16  ◾  Information Security Fundamentals

Before engaging in an arrangement for external data access (e.g., cloud solu- tions and services), management must determine that there is a bona fide business requirement for external parties to have access to the organization’s information assets, or to begin use of a product and service provided by an external party. Management must ensure it is aware of the security impacts of such an arrange- ment before making such a decision, and a risk assessment should be conducted to establish the implications and requirements associated with the potential relation- ship. The risks associated with these arrangements need to be formally addressed by the use of an acceptable risk assessment methodology. The purpose of the risk assessment is to ensure that the organization understands the security impacts of the proposed connection/exchange, and to identify requirements for security con- trols. Alternatively, changes in the conditions for the use of an established informa- tion system or facility may be addressed in a security impact assessment of changes brought on by the external connection or information access.

On the basis of the risk assessment, requirements for the protection of the orga- nization’s information can then be documented in interconnectivity agreements, contract provisions, and security clauses of memoranda of understanding for orga- nizations and agreements on rules of behavior for access by individuals such as customers, consultants, vendors, and staff of supporting organizations.

Assessment of External Risks When identifying risks related to access by external parties, organizations should com- plete that activity and implement necessary controls before actually granting access to its information. This minimizes the risk of introducing a new threat without the organization first having assessed and countered it. The organization granting access to its information has the responsibility of determining the appropriateness of controls and whether or not to grant access without first having all necessary controls in place. Management’s responsibility also includes continuing actions to ensure that the terms of the agreement are met, and that the security of its information is maintained.

The assessment should consider all facilities and assets to be affected when assessing the risks associated with access by external entities. All hardware, soft- ware, processes, and facilities must be included in the scope of the risk assessment. The nature of the information access that the external party will have (physical access, logical access, direct system connectivity, remote access, on-site and off-site access, etc.) should also be a focus of the assessment. The criticality and sensitivity of the information to be externally accessed according to its need for confidential- ity, integrity, and availability should be a significant aspect of the risk assessment. The risk assessment effort must identify the controls needed to restrict external access to organization information not within the scope of the proposed agree- ment to ensure its protection through segregation. The effort must address the risks of personnel who will have access to the organization’s information and the pro- cess for ensuring their trustworthiness on a continuing basis through management

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Organization of Information Security  ◾  17

authorization, need to know, and continuous evaluation. Consideration must be given to assessing the mechanisms and controls used by the external entity to store, process, communicate, and exchange information to ensure it meets the organiza- tion’s minimum security requirements.

Other considerations to be taken into account as part of the risk assessment effort should include the identification of the effect on the organization of the non- availability of externally provided products and services, or loss of data integrity, caused by inaccurate or misleading information. Processes that the external entity has established to identify and respond to security incidents should also be assessed to ensure that information about the incident is reported to the information owner should an incident take place. This process should include provisions for identifying conditions for suspending access in the event of a serious information breach. The assessment must address the legal, regulatory, and contract-related risks that may have an effect on external entity access to the organization’s information. For exam- ple, the external party may need to implement controls to report security compli- ance, which have been mandated by government statute. The risk assessment should also evaluate how access by the external entity may affect other organizational ele- ments, such as other business partners with whom information is already exchanged.

Addressing Security When Dealing with Customers Information access by customers is subject to several special considerations. Organizations should ensure all identified security requirements are addressed before granting customers access to its information assets. Requirements for con- trolling customer access should include procedures for protecting assets from known vulnerabilities, mechanisms for ensuring compromises to organization information are reported, and restrictions on copying and disseminating infor- mation. Requirements may be documented in customer agreements, and rules of behavior, as well as warning messages and log-on banners.

Customers must clearly understand the service or product to be provided, and the purpose, requirements, and benefits for permitting their access to organization information. The organization should also ensure that customers are aware of its access control policy including access methods allowed (on-site or off-site, wired or wireless, physical or logical, etc.) and how customers are to control log-on credentials. There must be an explicit customer authorization process in place to regulate and control user access and assignment of privileges. Customers must be made to understand, prefer- ably by signing a statement, that they are not permitted access to any information asset to which they are not specifically authorized. Organizations must also implement a process for revocation of customer access and disconnection of system interconnec- tions in the event of a breach or violation. Customers must be aware of the organiza- tion’s right to monitor and revoke as necessary any activity related to its information.

Reporting, notification, and investigation of data integrity issues, security incidents, and security breaches must be documented to guide customer actions.

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

18  ◾  Information Security Fundamentals

Responsibilities of both the organization and the customer should also be made known to customers, including responsibilities for legal matters and protection of intellectual property.

Third-Party Agreements All relevant security requirements should be covered in agreements with third par- ties that involve accessing, processing, communicating, or managing organization information or information assets. Third-party agreements must leave no room for misunderstanding between the organization and the third party. Consequently, organizations should consider the following items identified in ISO 27002 for inclusion in third-party agreements.

◾ Reference to and applicability of the information security policy to the third- party arrangement

◾ Identification of controls to ensure that assets are properly protected to include procedures for the security of hardware and software, physical security, pro- tection against malware, compromise identification, return or destruction of information and assets when no longer required, protection of confidential- ity, integrity and availability, and restrictions on information copying and disclosing information and use of confidentiality agreements

◾ User and administrator training and their awareness of information security responsibilities and issues

◾ Personnel management (assignment, transfer, and termination) ◾ Hardware and software installation and maintenance responsibilities ◾ Change management process ◾ Access control policy, including reasons, requirements, and benefits of third-

party access; approved access methods, and the control and use of unique identifiers such as user IDs and passwords; authorization process for user access and privileges; requirements for maintenance of an authorized user’s list specifying services, rights, and privileges; statement that all access that is not explicitly authorized is forbidden; and an access/connection revocation process

◾ Provisions for reporting and responding to information security incidents and violations of the third-party agreement

◾ Identification of the product or service to be provided ◾ Description of the information to be made available along with its security

classification ◾ Expected level of service and definition of unacceptable levels of service ◾ Definition of verifiable performance measures and how they will be moni-

tored and reported ◾ Stipulation of the organization’s right to monitor, and revoke, any activity

related to its information assets

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Organization of Information Security  ◾  19

◾ The right of the organization to conduct inspections and audits of activities related the agreement, through the use of independent auditors, following directions specified by the organization

◾ An escalation process for resolving identified problems ◾ Measures for ensuring service continuity according to the organization’s

operational priorities ◾ Specification of the liabilities of both parties to the agreement ◾ Responsibilities for meeting legal requirements such as data protection

legislation ◾ Intellectual property rights, copyrights, and protection of collaborative work ◾ Control of subcontractor use of organization information ◾ Conditions for renegotiation and termination of the agreements

In addition to the third-party agreement itself, risks, security controls, and spe- cific requirements can be detailed in an accompanying security management plan to ensure a clear definition of security responsibilities and how the organization’s information will be protected.

Summary Organizations can greatly improve their ability to secure information and infor- mation assets by establishing an effective information security function tailored according to the business needs for managing information security across the orga- nization. An effective information security function significantly improves the organization’s capability to implement, maintain, monitor, and improve security, and to be able to do so in a manner that is consistent with its organizational culture, mission, risk appetite, and priorities. To optimize organization-wide information security efforts, all levels of organization management must render the program visible support and commitment, including the timely provision of resources neces- sary to carry out information security activities. Finally, the information security function moving forward with solid management backing will be able to ensure that information security management requirements are properly identified and implemented, and that the performance of information security management activities is monitored and measured for adequacy and effectiveness.

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .

Peltier, Thomas R.. Information Security Fundamentals, Auerbach Publishers, Incorporated, 2013. ProQuest Ebook Central, http://ebookcentral.proquest.com/lib/apus/detail.action?docID=1375200. Created from apus on 2025-04-08 02:10:31.

C op

yr ig

ht ©

2 01

3. A

ue rb

ac h

P ub

lis he

rs , I

nc or

po ra

te d.

A ll

rig ht

s re

se rv

ed .