User Domain Policies
Contents
Preface
Acknowledgments
PART ONE The Need for IT Security Policy Frameworks
CHAPTER 1 Information Systems Security Policy Management
What Is Information Systems Security?
Information Systems Security Management Life Cycle
What Is Information Assurance?
Confidentiality
Integrity
Nonrepudiation
What Is Governance?
Why Is Governance Important?
What Are Information Systems Security Policies?
Where Do Information Systems Security Policies Fit Within an Organization?
Why Information Systems Security Policies Are Important
Policies That Support Operational Success
Challenges of Running a Business Without Policies
Dangers of Not Implementing Policies
Dangers of Implementing the Wrong Policies
When Do You Need Information Systems Security Policies?
Business Process Reengineering (BPR)
Continuous Improvement
Making Changes in Response to Problems
Why Enforcing and Winning Acceptance for Policies Is Challenging
CHAPTER SUMMARY
KEY CONCEPTS AND TERMS
CHAPTER 1 ASSESSMENT
CHAPTER 2 Business Drivers for Information Security Policies
Why Are Business Drivers Important?
Maintaining Compliance
Compliance Requires Proper Security Controls
Security Controls Must Include Information Security Policies
Relationship Between Security Controls and Information Security Policy
Mitigating Risk Exposure
Educate Employees and Drive Security Awareness
Prevent Loss of Intellectual Property
Protect Digital Assets
Secure Privacy of Data
Lower Risk Exposure
Minimizing Liability of the Organization
Separation Between Employer and Employee
Acceptable Use Policies
Confidentiality Agreement and Nondisclosure Agreement
Business Liability Insurance Policies
Implementing Policies to Drive Operational Consistency
Forcing Repeatable Business Processes Across the Entire Organization
Differences Between Mitigating and Compensating Controls
Policies Help Prevent Operational Deviation
CHAPTER SUMMARY
KEY CONCEPTS AND TERMS
CHAPTER 2 ASSESSMENT
ENDNOTES
CHAPTER 3 U.S. Compliance Laws and Information Security Policy Requirements
U.S. Compliance Laws
What Are U.S. Compliance Laws?
Why Did U.S. Compliance Laws Come About?
Whom Do the Laws Protect?
Which Laws Require Proper Security Controls to Be Included in Policies?
Which Laws Require Proper Security Controls for Handling Privacy Data?
Aligning Security Policies and Controls with Regulations
Industry Leading Practices and Self-Regulation
Some Important Industry Standards
Payment Card Industry Data Security Standard (PCI DSS)
Statement on Standards for Attestation Engagements No. 16 (SSAE16)
Information Technology Infrastructure Library (ITIL)
CHAPTER SUMMARY
KEY CONCEPTS AND TERMS
CHAPTER 3 ASSESSMENT
ENDNOTES
CHAPTER 4 Business Challenges Within the Seven Domains of IT Responsibility
The Seven Domains of a Typical IT Infrastructure
User Domain
Workstation Domain
LAN Domain
LAN-to-WAN Domain
WAN Domain
Remote Access Domain
System/Application Domain
Information Security Business Challenges and Security Policies That Mitigate Risk Within the Seven Domains
User Domain
Workstation Domain
LAN Domain
LAN-to-WAN Domain
WAN Domain
Remote Access Domain
System/Application Domain
CHAPTER SUMMARY
KEY CONCEPTS AND TERMS
CHAPTER 4 ASSESSMENT
CHAPTER 5 Information Security Policy Implementation Issues
Human Nature in the Workplace
Basic Elements of Motivation
Personality Types of Employees
Leadership, Values, and Ethics
Organizational Structure
Flat Organizations
Hierarchical Organizations
The Challenge of User Apathy
The Importance of Executive Management Support
Selling Information Security Policies to an Executive
Before, During, and After Policy Implementation
The Role of Human Resources Policies
Relationship Between HR and Security Policies
Lack of Support
Policy Roles, Responsibilities, and Accountability
Change Model
Responsibilities During Change
Roles and Accountabilities
When Policy Fulfillment Is Not Part of Job Descriptions
Impact on Entrepreneurial Productivity and Efficiency
Applying Security Policies to an Entrepreneurial Business
Tying Security Policy to Performance and Accountability
CHAPTER SUMMARY
KEY CONCEPTS AND TERMS
CHAPTER 5 ASSESSMENT
ENDNOTE
PART TWO Types of Policies and Appropriate Frameworks
CHAPTER 6 IT Security Policy Frameworks
What Is an IT Policy Framework?
What Is a Program Framework Policy or Charter?
Industry-Standard Policy Frameworks
What Is a Policy?
What Are Standards?
What Are Procedures?
What Are Guidelines?
Business Considerations for the Framework
Roles for Policy and Standards Development and Compliance
Information Assurance Considerations
Confidentiality
Integrity
Availability
Information Systems Security Considerations
Unauthorized Access to and Use of the System
Unauthorized Disclosure of the Information
Disruption of the System or Services
Modification of Information
Destruction of Information Resources
Best Practices for IT Security Policy Framework Creation
Case Studies in Policy Framework Development
Private Sector Case Study
Public Sector Case Study
Private Sector Case Study
CHAPTER SUMMARY
KEY CONCEPTS AND TERMS
CHAPTER 6 ASSESSMENT
CHAPTER 7 How to Design, Organize, Implement, and Maintain IT Security Policies
Policies and Standards Design Considerations
Architecture Operating Model
Principles for Policy and Standards Development
The Importance of Transparency with Regard to Customer Data
Types of Controls for Policies and Standards
Document Organization Considerations
Sample Templates
Considerations for Implementing Policies and Standards
Building Consensus on Intent
Reviews and Approvals
Publishing Your Policies and Standards Library
Awareness and Training
Policy Change Control Board
Business Drivers for Policy and Standards Changes
Maintaining Your Policies and Standards Library
Updates and Revisions
Best Practices for Policies and Standards Maintenance
Case Studies and Examples of Designing, Organizing, Implementing, and Maintaining IT Security Policies
Private Sector Case Study
Public Sector Case Study
CHAPTER SUMMARY
KEY CONCEPTS AND TERMS
CHAPTER 7 ASSESSMENT
CHAPTER 8 IT Security Policy Framework Approaches
IT Security Policy Framework Approaches
Risk Management and Compliance Approach
The Physical Domains of IT Responsibility Approach
Roles, Responsibilities, and Accountability for Personnel
The Seven Domains of a Typical IT Infrastructure
Organizational Structure
Organizational Culture
Separation of Duties
Layered Security Approach
Domain of Responsibility and Accountability
Governance and Compliance
IT Security Controls
IT Security Policy Framework
Best Practices for IT Security Policy Framework Approaches
What Is the Difference Between GRC and ERM?
Case Studies and Examples of IT Security Policy Framework Approaches
Private Sector Case Study
Public Sector Case Study
Critical Infrastructure Case Study
CHAPTER SUMMARY
KEY CONCEPTS AND TERMS
CHAPTER 8 ASSESSMENT
ENDNOTE
CHAPTER 9 User Domain Policies
The Weakest Link in the Information Security Chain
Social Engineering
Human Mistakes
Insiders
Seven Types of Users
Employees
Systems Administrators
Security Personnel
Contractors
Vendors
Guests and General Public
Control Partners
Contingent
System
Why Govern Users with Policies?
Acceptable Use Policy (AUP)
The Privileged-Level Access Agreement (PAA)
Security Awareness Policy (SAP)
Best Practices for User Domain Policies
Understanding Least Access Privileges and Best Fit Privileges
Case Studies and Examples of User Domain Policies
Government Laptop Compromised
The Collapse of Barings Bank, 1995
Unauthorized Access to Defense Department Systems
CHAPTER SUMMARY
KEY CONCEPTS AND TERMS
CHAPTER 9 ASSESSMENT
CHAPTER 10 IT Infrastructure Security Policies
Anatomy of an Infrastructure Policy
Format of a Standard
Workstation Domain Policies
LAN Domain Policies
LAN-to-WAN Domain Policies
WAN Domain Policies
Remote Access Domain Policies
System/Application Domain Policies
Telecommunications Policies
Best Practices for IT Infrastructure Security Policies
Case Studies and Examples of IT Infrastructure Security Policies
Private Sector Case Study
Public Sector Case Study
Critical Infrastructure Case Study
CHAPTER SUMMARY
KEY CONCEPTS AND TERMS
CHAPTER 10 ASSESSMENT
CHAPTER 11 Data Classification and Handling Policies and Risk Management Policies
Data Classification Policies
When Is Data Classified or Labeled?
The Need for Data Classification
Legal Classification Schemes
Military Classification Schemes
Business Classification Schemes
Developing a Customized Classification Scheme
Classifying Your Data
Data Handling Policies
The Need for Policy Governing Data at Rest and in Transit
Policies, Standards, and Procedures Covering the Data Life Cycle
Identifying Business Risks Related to Information Systems
Types of Risk
Development and Need for Policies Based on Risk Management
Risk and Control Self-Assessment
Risk Assessment Policies
Risk Exposure
Prioritization of Risk, Threat, and Vulnerabilities
Risk Management Strategies
Vulnerability Assessments
Vulnerability Windows
Patch Management
Quality Assurance Versus Quality Control
Best Practices for Data Classification and Risk Management Policies
Case Studies and Examples of Data Classification and Risk Management Policies
Private Sector Case Study
Public Sector Case Study
Private Sector Case Study
CHAPTER SUMMARY
KEY CONCEPTS AND TERMS
CHAPTER 11 ASSESSMENT
CHAPTER 12 Incident Response Team (IRT) Policies
Incident Response Policy
What Is an Incident?
Incident Classification
The Response Team Charter
Incident Response Team Members
Responsibilities During an Incident
Users on the Front Line
System Administrators
Information Security Personnel
Management
Support Services
Other Key Roles
Business Impact Analysis (BIA) Policies
Component Priority
Component Reliance
Impact Report
Development and Need for Policies Based on the BIA
Procedures for Incident Response
Discovering an Incident
Reporting an Incident
Containing and Minimizing the Damage
Cleaning Up After the Incident
Documenting the Incident and Actions
Analyzing the Incident and Response
Creating Mitigation to Prevent Future Incidents
Handling the Media and Deciding What to Disclose
Business Continuity Planning Policies
Dealing with Loss of Systems, Applications, or Data Availability
Response and Recovery Time Objectives Policies Based on the BIA
Best Practices for Incident Response Policies
Disaster Recovery Plan Policies
Disaster Declaration Policy
Assessment of the Disaster’s Severity and of Potential Downtime
Case Studies and Examples of Incident Response Policies
Private Sector Case Study
Public Sector Case Study
Critical Infrastructure Case Study
CHAPTER SUMMARY
KEY CONCEPTS AND TERMS
CHAPTER 12 ASSESSMENT
PART THREE Implementing and Maintaining an IT Security Policy Framework
CHAPTER 13 IT Security Policy Implementations
Simplified Implementation Process
Target State
Distributed Infrastructure
Outdated Technology
Lack of Standardization Throughout the IT Infrastructure
Executive Buy-in, Cost, and Impact
Executive Management Sponsorship
Overcoming Nontechnical Hindrances
Policy Language
Employee Awareness and Training
Organizational and Individual Acceptance
Motivation
Developing an Organization-Wide Security Awareness Policy
Conducting Security Awareness Training Sessions
Human Resources Ownership of New Employee Orientation
Review of Acceptable Use Policies (AUPs)
Information Dissemination—How to Educate Employees
Hard Copy Dissemination
Posting Policies on the Intranet
Using E-mail
Brown Bag Lunches and Learning Sessions
Policy Implementation Issues
Governance and Monitoring
Best Practices for IT Security Policy Implementations
Case Studies and Examples of IT Security Policy Implementations
Private Sector Case Study
Public Sector Case Study
CHAPTER SUMMARY
KEY CONCEPTS AND TERMS
CHAPTER 13 ASSESSMENT
CHAPTER 14 IT Security Policy Enforcement
Organizational Support for IT Security Policy Enforcement
Executive Management Sponsorship
Governance Versus Management Organizational Structure
The Hierarchical Organizational Approach to Security Policy Implementation
Front-Line Managers’ and Supervisors’ Responsibility and Accountability
Grass-Roots Employees
An Organization’s Right to Monitor User Actions and Traffic
Compliance Law: Requirement or Risk Management?
What Is Law and What Is Policy?
What Security Controls Work to Enforce Protection of Privacy Data?
What Automated Security Controls Can Be Implemented Through Policy?
What Manual Security Controls Assist with Enforcement?
Legal Implications of IT Security Policy Enforcement
Who Is Ultimately Accountable for Risk, Threats, and Vulnerabilities?
Where Must IT Security Policy Enforcement Come From?
Best Practices for IT Security Policy Enforcement
Case Studies and Examples of Successful IT Security Policy Enforcement
Private Sector Case Study
Public Sector Case Study No. 1
Public Sector Case Study No. 2
CHAPTER SUMMARY
KEY CONCEPTS AND TERMS
CHAPTER 14 ASSESSMENT
CHAPTER 15 IT Policy Compliance and Compliance Technologies
Creating a Baseline Definition for Information Systems Security
Policy-Defining Overall IT Infrastructure Security Definition
Vulnerability Window and Information Security Gap Definition
Tracking, Monitoring, and Reporting IT Security Baseline Definition and Policy Compliance
Automated Systems
Random Audits and Departmental Compliance
Overall Organizational Report Card for Policy Compliance
Automating IT Security Policy Compliance
Automated Policy Distribution
Configuration Management and Change Control Management
Collaboration and Policy Compliance Across Business Areas
Version Control for Policy Implementation Guidelines and Compliance
Compliance Technologies and Solutions
COSO Internal Controls Framework
SCAP
SNMP
WBEM
Digital Signing
Best Practices for IT Security Policy Compliance Monitoring
Case Studies and Examples of Successful IT Security Policy Compliance Monitoring
Private Sector Case Study
Public Sector Case Study
Nonprofit Sector Case Study
CHAPTER SUMMARY
KEY CONCEPTS AND TERMS
CHAPTER 15 ASSESSMENT
APPENDIX A Answer Key
APPENDIX B Standard Acronyms
Glossary of Key Terms
References
Index
CHAPTER
1 Information Systems Security Policy Management
FOR AN ORGANIZATION TO ACHIEVE ITS GOALS, business processes must be reliable, keep costs low, and obey the law. Most organizations use policies and procedures to tell employees what the business wants to achieve and how to perform tasks to get there. This way the business can achieve consistent quality in delivering its products and services.
In a perfect world, policies and procedures would always produce the perfect product. This requires employees to follow policies and procedures at all times. However, we do not live in a perfect world. Neither policies nor procedures are always perfect, nor do employees always follow them. Anyone who has cashed a check at a bank understands what a basic procedure looks like. A check-cashing procedure includes checking the person’s identification and the account balance. The bank’s policy states that when a teller follows the check-cashing procedure, and the account has sufficient funds, the teller may give the cash to the account holder. The teller must follow this procedure to protect the customer and the bank from fraud.
Business processes are highly dependent on timely information. It’s hard to find an organization that does not rely on technology, whether it sells hamburgers, cashes checks for people, or is building the next-generation airliner. Processes use technology and information to make business decisions, keep food safe, track inventory, and control manufacturing, among other things. The more complex these technologies become, the more vulnerable they become to disruptions. The more people rely on them in their daily lives, the more vulnerable they become when these technologies do not work. You can think of a policy as a business requirement on actions or processes performed by an organization. An example is the requirement to that a customer provide a receipt when returning an item to a retail store for a refund. That may be a simple example, but essentially, it places a control on the return process. In the same manner, security policies require placement of controls in processes specific to the information system.
One of the challenges organizations face is the cost of keeping pace with ever-changing technology. This includes the need to update policies at the same time the organization updates technology. Failure to do so could create weaknesses in the system. These weaknesses could make business processes and information vulnerable to loss or theft.
In the creation of information systems security policies, also called security policies, IS policies, or ISS policies, many factors drive policy requirements. These requirements include organization size, processes, type of information, and laws and regulations. Once an organization creates policies, it will face both technical and human challenges implementing them. The keys to implementing policies are employee acceptance and management enforcement. A policy is worth little or nothing if no one follows it.
Chapter 1 Topics
This chapter covers the following topics and concepts:
• What information systems security is
• How information assurance plays an important role in securing information
• What governance is
• Why governance is important
• What information systems security policies are and how they differ from standards and procedures
• Where policies fit within an organization’s structure to effectively reduce risk
• Why security policies are important to business operations, and how business changes affect policies
• When information systems security policies are needed
• Why enforcing, and winning acceptance for, security policies is challenging
Chapter 1 Goals
When you complete this chapter, you will be able to:
• Compare and contrast information systems security and information assurance
• Compare and contrast quality control and quality assurance
• Describe information systems security policies and their importance in organizations
• Describe governance and its importance in maintaining compliance with laws
• Explain what policies are and how they fit into an organization
• Compare and contrast threat, vulnerability, and risk
What Is Information Systems Security?
A good definition of information systems security (ISS) is the act of protecting information and the systems that store and process it. This protection is against risks that would lead to unauthorized access, use, disclosure, disruption, modification, or destruction of information. It’s not just the information inside a computer you need to protect. Information needs to be protected in any form. Some examples include print and removable storage such as optical DVD drives. In fact, well-structured security policies ensure protection of information in any location and in any form. Many organizations come up with effective ways of protecting buildings, people, and other physical resources. And most people understand the need to lock their doors at home at night. Yet they may not always have the same instincts or habits when it comes to handling data. And sometimes the rules for dealing with information are unclear.
Suppose your business knows a person’s name, phone number and e-mail address. How much privacy should that person expect from your business? What are you obligated by law to protect? What’s the right thing to do ethically? These are just some of the questions businesses struggle with daily. Not every employee is an expert in these matters. So organizations create policies and procedures for their employees to follow.
Sometimes these same organizations fail to properly protect the information they process. Some do not consider information important to their operations. Some believe that security measures designed to protect buildings and people will protect information. Some just do not want to spend more money. However, protecting information is vital to business operations.
Information Systems Security Management Life Cycle
Generally, in any process of importance, you would use some type of life cycle process to reduce errors and make sure all requirements are considered. It is no different for implementing security policies. Information security controls and processes use common approaches that simplify the build, and reduce mistakes. A typical life cycle process breaks up tasks into smaller, more manageable phases. The Information Systems
Audit and Control Association (ISACA) developed a widely accepted international best practices framework. This framework, called Control Objectives for Information and related Technology (COBIT), was first released in 1996. The latest version, 5.0, was released in April 2012.
NOTE
You can read more about COBIT at http://www.isaca.org/COBIT/Pages/default.aspx? cid=1003566&Appeal=PR.
COBIT is more than just a life cycle; it’s a framework for managing and governing IT processes. These types of frameworks allow businesses to align themselves to outcomes that they and their customers expect. At its core are four domains that collectively represent a conceptual information systems security management life cycle:
• Align, Plan, and Organize
• Build, Acquire, and Implement
• Deliver, Service, and Support
• Monitor, Evaluate, and Assess
The life cycle process can use these simple domains, or phases, to build policies or controls. Each phase builds on the other. A failure in one phase can lead to a weakness or vulnerability downstream. For the purposes of discussion, you will learn about the four domains from a high-level life cycle view. The COBIT framework goes into great depth to further break down these domains into detailed tasks and processes. Many organizations look at the richness of a framework like COBIT to tailor a life cycle management approach that makes sense for their business.
In 2012 COBIT 5.0 was released to the public. This version of COBIT introduced the idea that good business processes make it possible for organizations to do the following:
• Deliver value to internal and external stakeholders
• Meet organizational goals
• Practice life cycle management: building, maintaining, supporting, and disposing of products and other assets
• Learn from others so to keep abreast of industry best practices.
COBIT 5.0 was a departure from other frameworks in that it put emphasis on what enables processes to work well. In fact COBIT calls these process enablers. For example, think of a teller cashing a check. What does a bank have to think about to align, plan, and organize to achieve stakeholder value? Clearly the bank wants the customer, as the external stakeholder, to have a good experience. This will build loyalty and repeat business. But the customer needs must be balanced with the business goal of making a profit. The bank must also be aware of changing industry standards and new technology such as mobile devices.
Figure 1-1 depicts one simplified example of an ISS management life cycle.
Align, Plan, and Organize
The COBIT Align, Plan, and Organize domain includes basic details of an organization’s requirements and goals. This domain answers the questions “What do you want to do?” and “How do you want to get there?” The information in this phase is still high level. Even at a high level, it is important to understand the risks and threats clearly. You review how you are going to manage your IT investment such as contracts, service level agreements (SLAs), and new policy ideas. An SLA is a stated commitment to provide a specific service level. For example, a SLA could state how often a supplier will provide the service or how quickly the firm will respond. For managed services, the SLA often covers system availability and acceptable performance measures. It’s also important to look at where or how the system will operate to determine the SLA. SLAs are important to ensure that all parties know their obligations. There are different types of service levels that apply to contracts versus what you need to deal with day to day. The Deliver, Service, and Support domain helps you define and manage day-to-day SLAs. In the Align, Plan, and Organize domain, you are primarily concerned with the type of equipment and services you are acquiring and how to hold a supplier accountable for those deliveries.
NOTE
Notice in Figure 1-1 that the Align, Plan, and Organize domain touches all the other domains. This is because you will determine how the project will be managed in the Align, Plan, and Organize domain. This means you need to initially decide and then adjust management and staff throughout the project.
A contract must provide the ability to ensure a supplier meets its obligations. The SLA language in a contract must provide clear monitoring and enforcement rights. For example, consider the 2013 breach of Target stores. Between November 27 and December 15, 2013, hackers accessed the credit card information of 40 million customers. Later it was discovered that an additional seventy million customers’ personal information was also accessed by hackers. It’s been widely reported the hacker gained access through the supplier who maintained the company’s heating and air conditioning systems. Simply having a contract with the supplier wasn’t enough. Target had an obligation both to limit the supplier’s access while on its network and to monitor access sufficiently to ensure the contract was being enforced. These are general industry norms. Either one or both of these did not occur.
FIGURE 1-1 A simplified ISS management life cycle using COBIT 5.0.
A key understanding in this life cycle phase is the understanding of threats, vulnerability, and risk. These three concepts are addressed in different forms throughout this text. However, a basic understanding is essential to scope the build effort. To understand these concepts consider the following high-level definitions:
• Threat—A human-caused or natural event that could impact the system
• Vulnerability—A weakness in a system that can be exploited
• Risk—The likelihood or probability of an event and its impact
As an example, a common IS threat would be a hacker trying to break into a system. A vulnerability would
be a misconfiguration of a system that allow the hacker to gain unauthorized access. A risk is a combination of the likelihood that such a misconfiguration could happen, a hacker’s exploiting it, and the impact if the event occurred. Consider a non-Internet facing system for ordering office supplies. Why might you think the risk is low? While a misconfiguration maybe possible, systems not on the Internet are less likely to be hacked. Additionally, unauthorized access to the office supply system would most likely have little long-term impact on a company.
NOTE
Generally, regardless of threat or vulnerability, there will always a chance a threat can exploit a vulnerability. Consequently, whenever you have a threat or vulnerability, you will have a risk. The key is understanding if that risk is small (unlikely) or large (probable).
Other examples may be of higher risk and require significant investment. An example of a natural threat would be a hurricane. A vulnerability may be a lack of a recovery site. If your main data center, for example, is damaged, where would you go? The risk may be high for a business that relies on Internet orders, especially if the business is located in Florida, which is prone to hurricanes.
Build, Acquire, and Implement
The COBIT Build, Acquire, and Implement domain addresses schedules and deliverables. The basic build occurs within this phase. The “build” is where the security control is built, and policies and supporting documents written. The build is based on the requirement created in the Align, Plan, and Organize phase. The quality of the security controls that are built depends on the understanding of the threats, vulnerabilities, and risks. The deeper this understanding, the better the controls.. The more detailed the requirements, the more easily the build will go. The more details included in the Align, Plan, and Organize phase, the easier the Build, Acquire, and Implement phase will be. The SLA becomes an important consideration of the build because it determines the type of solutions that will be selected.
Additionally, the ability to manage change is critical in this phase. Often changes are made to existing systems known as upgrades. That means changes have to be timed perfectly. This is to avoid disrupting current services while new services are added. Often this will occur during off-hours such as weekends or overnight. Plans have to be put in place to back out the change in the event of a major problem. Understanding the impact of change and knowing how to recover if something goes wrong are parts of change management.
By the end of the Build, Acquire, and Implement phase, you have acquired and implemented your equipment. You have controls built into the systems. You have policies, procedures, and guidelines written. You have teams trained.
Deliver, Service, and Support
In the COBIT Deliver and Support domain, the staff tunes the environment to minimize risks. It is in this phase that you collect lessons learned. By running the systems, you learn what’s working and what isn’t. This is where you apply those lessons learned to improve operations. This could mean adjusting controls, policies, procedures, contracts, and SLAs. It is here you analyze data from the prior phase and compare it with day-to- day operations. You also perform internal and external penetration testing and, based upon the results of those tests, make critical adjustments in areas such as perimeter defense, remote access, and backup procedures. You review contracts and SLAs for validity and modify them as needed.
This phase requires regular meetings and good communications with your vendor. You must quickly identify any issues with the vendor’s ability to meet SLAs. Typically, the vendor provides its record on meeting
SLAs. You compare the vendor’s report to your organization’s internal reports. If you rely heavily on the vendor, you should meet monthly to compare records and recap incidents during the month.
In this phase, the day-to-day operation is managed and supported. You manage problems, configurations, physical security, and more. If you planned correctly and implemented the right solution, your organization sees value.
Monitor, Evaluate, and Assess
After evaluating the ISS management life cycle, you see that ISS focuses on specific types of controls at specific points within the system. Testing and monitoring of controls occur and the results analyzed for effectiveness. The oversight of the COBIT Monitor, Evaluate, and Assess domain looks at the big picture. Are your controls and supporting policies and procedures keeping pace with changes in technology and in your environment? This phase looks at specific business requirements and strategic direction, and determines if the system still meets these objectives.
Internal and external audits occur during the evaluation phase. Audits also take place through all testing in this and prior phases to ensure requirements are being met. This may include penetration testing by a third- party trusted agent. The testing performed during this phase must be comprehensive enough to encompass the entire ISS environment. The level of additional security testing will depend on business requirements and complexity. For example, if your requirements include regulatory compliance, include appropriate control tests. You should also evaluate the incident response process.
Audits are independent assessments. The more robust the self-assessment process, the fewer the problems that will be discovered by an audit. Independence is a relative term. No one is truly independent. Consider this: Everyone belongs to a family. Everyone lives in a town or city. Everyone has a multitude of private and business relationships. People may feel comfortable criticizing politicians but suddenly uncomfortable criticizing a teacher who has the power over their final grade. It’s human nature that the closer the relationship, or the more control someone has over your well-being, the less likely you are to criticize. Yet in business, this honest view of mistakes is essential to success.
The concept of independent audits (or assessments) is that the further one is away from the actual transaction, the more unbiased and independent the opinion that can be obtained. In other words, it’s hard to criticize your own work. However, the more you understand the work, the better your chances are, generally, of finding out what went wrong. To balance these potentially competing interests, there is usually a series of assessments and audits. The following lists the most common types of assessments and audits:
• Self-Assessment—This is typically in the form of quality assurance (QA) and quality control (QC).
• Internal Audit—This consists of reports to the board of directors and assesses the business.
• External Audit—This is done by an outside firm hired by the company to validate internal audit work and perform special assessment, such as certifying annual financial statements.
• Regulator Audit—This is an audit by government agencies that assess the company’s compliance with laws and regulations.
What Is Information Assurance?
Too often you will hear the terms “information systems security” and “information assurance” interchangeably. They are not the same thing. Information assurance (IA) grew from information systems security. The high-level difference is that ISS focuses on protecting information regardless of form or
process, whereas IA focuses on protecting information during process and use. You can see some these differences as you examine the security tenets, also known as “the five pillars of the IA model”:
• Confidentiality—Generally accepted as ISS and IA tenets
• Integrity—Generally accepted as ISS and IA tenets
• Availability—Generally accepted as ISS and IA tenets
• Authentication—Generally accepted as an IA tenet
• Nonrepudiation—Generally accepted as an IA tenet
This is not to suggest that authentication and nonrepudiation are not information security concerns. The goals are similar. It’s the approach and focus that are different. IA imposes controls on the entire system regardless of the format or media. In other words, IA ensures data is protected while being processed, stored, and transmitted. This ensures the confidentiality, integrity, availability, and nonrepudiation of the data.
Confidentiality
Confidentiality is the goal of ensuring that only authorized individuals are able to access information. A user should be granted access only to the specific information necessary to complete his or her job.
Typical users do not need unlimited access to all systems and all data. In fact, in regulated environments, if ordinary users had such access, this would be viewed as a compliance issue and a violation of law. Many organizations have adopted the need to know principle. In brief, this means that you gain access only to the systems and data you need to perform your job. For example, payroll personnel may need your employee and personal information, such as salary and Social Security number. Your manager may need access to your salary for budgeting but not your Social Security number. By restricting access you maintain confidentiality.
NOTE
Another consideration of confidentiality is how to protect data in the event of a breach or unauthorized access. One way to resolve this issue is to use encryption. This is considered a security layered approach. A breach in one layer will be caught by another. In this case, even if data is improperly accessed, it still cannot be read.
Figure 1-2 depicts the confidentiality tenet. The figure represents three users—two are regular users; one is a privileged user. User A and User B have limited access rights to data. User A can read only data stored in the product list, whereas User B can read and update all data in the database. The privileged user has elevated database administration privileges; however, even he or she might not have access to all data.
Integrity
Integrity ensures that information has not been improperly changed. In other words, the data owner must approve any change to the data or approve the process by which the data changes. There are several ways to ensure that data is protected. Many operating systems allow permissions on data files and directories to provide restricted access. These containers typically reside on a server that requires users to log on and authenticate to gain approved access. This ensures that only users who have the data owner’s permission can change the information. Often access is limited to an application. In this way a user does not access data directly. The user accesses the application. The application access the data. So the application acts as a gateway. This allows for more fine-grained granting of access, often referred to as entitlement. This way you
can restrict the type of access a user has. For example, the application can allow a user to approve a payment but limit the about to less than $1,000. Encryption also ensures integrity as well as confidentiality. Encryption protects data from being viewed or changed by unauthorized users. Only users with the proper key can change or view encrypted data. Encryption is often used to protect data being transmitted or moved. Encryption can also be used to protect data at rest.
Figure 1-3 depicts the integrity tenet. There are two users, an application, a database management system (DBMS), and the data. The application control limits the type of change a user can make. The DBMS rules prevent unauthorized changes to data. User A can change data. User B can only retrieve data.
FIGURE 1-2 The confidentiality tenet.
FIGURE 1-3 The integrity tenet.
Authentication
Authentication is the ability to verify the identity of a user or device. You probably see authentication in use
every day. For example, you might use an online e-mail system such as Google Gmail or Yahoo! Mail. What protects your e-mail is your user ID and password, which you selected when you signed up for the service. This user ID and password is your authentication approach to accessing your e-mail service.
It’s not just humans who need their identities verified. Computers often exchange information or process transactions on our behalf. While you are asleep, a computer system may by printing your payroll check. Many of these functions are sensitive. As a security professional, you should ensure that only these authorized processes are accessing this sensitive information. This means these computers and automated processes need to be authenticated. Just like an individual, their identity is verified before being granted access to data. For example, services running in Microsoft Windows Server could have an ID assigned. Network devices can exchange information at a network protocol level to verify identity. These non-human IDs typically have elevated rights. This means they have lots of authority to access data across multiple systems. It’s important that access to these nonhuman accounts be tightly controlled.
There is a lot involved in maintaining good authentication processes, such as forcing users to change their passwords periodically and forcing rules on how complicated passwords should be. These housekeeping tasks are becoming easier and more automated. One of the more critical keys to success is having credentials that are hard to forge or guess. A good example is a strong password known only to the user. Additionally, these credentials must not be transmitted in the clear over the network. Passwords sent over the network in plaintext, for example, can be observed with network sniffers. In a typical business environment, if these two goals are accomplished as well as many of the housekeeping items previously discussed, you begin to have reasonable assurance you know who is accessing your computer systems.
Availability
Availability ensures information is available to authorized users and devices. A major challenge to availability is the spread of denial of service (DoS) attacks. The technological sophistication and intensity of DoS attacks have increased significantly in recent years. These attacks flood a server with information to overwhelm its ability to process to make the server crash. Thus the service becomes unavailable. But the point of the attack is not to steal information but to crash the system. DoS attacks are often measured by the amount of information flooding the server. The typical measurement is in Gbps (gigabits per second). In 2013, DoS attacks reached record levels of 300 Gbps. In 2014, it’s anticipated even these records will be broken with attacks nearing 400 Gbps.
Initially, the information owner must determine availability requirements. The owner must determine who needs access to the data and when. Is it critical that data be available 24/7 or is 9 to 5 adequate? Does it need to be available to remote or only local users? The raw business requirements would then be translated into technical and operational commitments, such as hours of operations when the systems would be available.
Once availability requirements are determined, then you must assess the threats and implement appropriate controls. Associated with the servers is all the network equipment that provides interconnectivity and remote access. Proper configuration of these devices will allow access to the information when needed.
Nonrepudiation
Nonrepudiation is both a legal term and a concept within information security. The idea is simple; nonrepudiation is the assurance that an individual cannot deny having digitally signed a document or been party to a transaction. As a legal concept, it is the sum total of evidence that proves to the court’s satisfaction that only one person could have executed that transaction.
Well before the Internet, individuals struggled with this question. When you sign a legal document, often you need a notary. That notary is there to be part of the nonrepudation process of gathering evidence. He or she takes copies of your identification and matches signatures. Some even take a thumbprint. All this effort is so
that later you cannot claim it wasn’t you who signed.
So how do you sign a document electronically? A leading method is to use a digital signature. If used properly, the electronic signature cannot be forged and is digitally timestamped. Most important, the receiver of the document can verify it is your digital signature. But even a digital signature relies on a private key that must be protected. It’s worth noting that these digital signatures are legally binding under the U.S. Federal ESIGN Act of 2000.
However, many final electronic transactions do not use digital signatures. In fact, often online banking transactions, money transfers, or buying and selling stock rely on other technology, including strong authentication. Ultimately you want to prove that only that person could have executed that transaction. A leading vendor in this space is IBM, whose flagship product for secure messaging is called Websphere. IBM defines nonrepudiation as an end-to-end service that “can be viewed as an extension to the identification and authentication service.” While secure messaging ensures the collection and delivery of the transaction, the application that consumes the message still has to be proven as secure.
Since no one technology is foolproof, many security experts believe that applying multiple security services collectively that tie the transaction back to a single individual is the best way to meet business needs. The simple fact is the more evidence you gather, the harder it for that person to deny it. Ideally, businesses want to prove it was your computer, your ID, your digital signature, and your transaction that cannot be repudiated.
NOTE
The Federal ESIGN Act defines an electronic signature as an “electronic sound, symbol, or process, attached to or logically associated with a contract or other record and executed or adopted by a person with the intent to sign the record.” To learn more go to http://csrc.nist.gov/drivers/documents/esign-guidance.pdf.
What Is Governance?
Governance is both a concept and a set of specific actions an organization takes to ensure compliance with its policies, processes, standards, and guidelines. The goal is to meet business requirements. However, the focus of governance is ensuring everyone is following established rules. What is assumed in governance is that these business objectives were well understood and baked into the rules. Thus, by following the rules, you achieve these business goals. Good governance should include a good understanding of the business, so when enforcement of a rule doesn’t make sense, adjustments to the governance process can take place.
Governance in the real sense is much more than a concept. An organization puts formal processes in place and committees to act as gateways. These are tangible acts that collectively define the governance structure of an organization. Governance is a collection of checkpoints that perform either a quality control (QC) or quality assurance (QA) function. In this context, if the governance body must approve an action, then it’s a QA function. If the governance body reviews actions after the fact, then it’s a QC function. This distinction is critical in understanding how controls are managed. These terms are often misunderstood:
• Quality assurance functions act as a preventive control. When QA works well, it prevents mistakes from happening.
• Quality control functions act as a detective control. When QC works well, it improves the quality over time by affording opportunities to learn from past mistakes.
Think of this from the perspective of the forest and the trees. When you think about QA, think about looking at each tree to see if its healthy. In contrast, when you think about QC, you check to see if the forest is
healthy.
Governance includes a series of oversight processes and committees. Collectively, governance ensures accountability, monitors activity, and records what is going on. What is also implied is that the governance structure will take action when the rules are ignored or not properly applied.
Why Is Governance Important?
Good governance provides assurance and confidence that rules are being followed. Who needs that assurance? First, senior management needs to know that its business objectives are being met. If the rules are being followed, there is some assurance the value promised to the business is being delivered. Also, senior management needs to know that the investment the organization has made is being properly managed. Second, regulators look at the governance structure for assurance that risks to shareholders, customers, and the public are being properly managed.
Effective governance embraces QA and QC as part of the culture. By embedding these concepts throughout, the organization promotes awareness and provides evidence of control. This is particularly important to regulators. Regulators want to see controls consistently applied. They want to know that management is aware of problems and that the company does take shortcuts than can lead to breaking the law. Generally, the more confidence regulators have that a company has strong governance, the less regulatory oversight is used. This is especially true in highly regulated industries like healthcare and financial services. Failure to have strong governance means less opportunity to expand into new markets. Conversely, good governance means expanded business opportunities.
It’s not unusual to assess the governance process of an organization. These assessments can either be self- assessment, internal audits, or regulatory reviews. For example, operational risk or compliance functions within an organization may perform a review.
For example, the importance of governance is evident in a configuration management process. By controlling system configuration, previously mitigated vulnerabilities remain in check. This results in greater uptime rates. Change management often employs both QA and QC functions. QA governance routines review and approve each change. While the QC function reviews the number of the outages caused by change and tries to improve the record, the QA function benefits from lessons learned. Governance is important to the daily operation of an organization and should not be viewed as an occasional occurrence. Integrating the annual cost of governance into business as usual (BAU) budgets keeps the benefits governance provides from being viewed as an unexpected expense.
What Are Information Systems Security Policies?
Security policies are actually a collection of several documents. They generally start with a set of principles that communicate common rules across the enterprise. It is these principles that governance routines use to interpret more detailed policies. Principles are expressed in simple language. An example may be an expression of risk appetite by employing the “need to know” approach to the granting of access. From these security principles flow security policies that detail how the principles are put into practice.
When combined, these policy documents outline the controls, actions, and processes to be performed by an organization. An example is the requirement that a customer provide a receipt when returning an item to a retail store for a refund. That may be a simple example of a policy, but essentially, it places a control on the return process. In the same manner, ISS policies require placement of controls in processes specific to the information system. ISS policies discuss the types of controls needed but not how to build the controls. For example, a security policy may state that some data can be accessed only from the office. How the security control would be built to prevent remote access, for example, would not appear in the policy.
ISS policies should cover every threat to the system. They should include protecting people, information, and physical assets. Policies should also include rules of behavior such as acceptable use policies. The policies must also set rules for users, define consequences of violations, and minimize risk to the organization. Enforcement will depend on the clarity of roles and responsibilities defined in policies. Remember, you need to hold people accountable for policies. When it’s unclear who is accountable, a policy becomes unenforceable. Other documents in the policy framework provide additional support.
There are typically six different types of documents in a framework:
• Principles—Establish the tone at the top and the authority by which policies are enforced
• Policy—A document that states how the organization is to perform and conduct business functions and transactions with a desired outcome
• Standard—An established industry norm or method, which can be a procedural standard or a technical standard implemented organization-wide
• Procedure—A written statement describing the steps required to implement a process
• Guideline—A parameter within which a policy, standard, or procedure is suggested but optional
• Definitions—Statements that define the terms used in the policy documents and set the context in which the policies documents are interpreted
Many people refer to all these documents as “security policies.” But they aren’t necessarily. Figure 1-4 depicts the relationship of these six types of documents. The figure shows that procedures and guidelines support policies. In addition, the figure indicates that standards influence policies. The six documents fall into two groups: internal and external. Standards are external documents. The other five are internal documents.
NOTE
Standards become the measuring stick by which an organization is evaluated for compliance. The Federal Information Processing Standards (FIPS) publications are examples of standards. You can view FIPS publications online at http://itl.nist.gov/fipspubs/.
A standard can be a process or a method for implementing a solution. This involves technology, hardware, or software that has a proven record of performance. This can be a procedural or implementation standard or a technical deployment standard implemented company-wide. For the purposes of ISS, a standard is the set of criteria by which an information system must operate. Standards exert external influence on the creation of policies. An organization can have internal standards. Often these standards are tailored to the organization based on some external best practice. The proper application of standards provides assurance that lessons learned within the industry have been considered.
FIGURE 1-4 Internal versus external documents.
A policy principles document communicates general rules that cut across the entire organization. Principles are written in plain English and focus on key risks or behaviors. When reading security principles, think of them as senior executives expressing their goals and objectives. They express core values of the organization that often include the areas where there will be zero tolerance for transgression.
A policy is a document that states how the organization is to perform. It describes how to conduct business functions and transactions with a desired outcome. It sets the stage for secure control of information. It is the “who does what to whom and when” document. It should reflect what leadership commitments are to protecting information. Defined roles and responsibilities lay the foundation for enforcing the policy.
NOTE
A policy is often approved by the most senior levels of management. A procedure or guideline is often approved by lower-level management responsible for the implementation of policies.
A procedure is a written statement describing the steps required to implement a process. Remember that procedures support policies and standards. Procedures describe how to accomplish specific tasks. A more detailed procedure produces a more error-free result. Procedures are not written just for humans to follow. Well-written procedures are often used to document requirements for automated processes.
A guideline sets the parameters within which a policy, standard, or procedure can be used. A guideline is optional. It is a policy-support document. Similar to procedures, guidelines help businesses operate more smoothly. They are not as rigid. Although optional, they set a direction to be taken whenever possible. Once the new approach has been widely adopted, a guideline can transition into a policy.
A policy definitions document is often overlooked, yet it’s enormously important. It’s often used by auditors and regulators when evaluating the soundness of controls. Think of it this way: If you and someone else were speaking two different languages, you might recognize some of the other person’s words. Yet, the depth of the meaning of these words could easily get lost. Even common words can have many meanings in the context of a policy. For example, if a policy refers to a user ID, does the policy apply to nonhuman and human IDs equally? If the term platform is used, does it mean desktop or server or router? Words in policies must be rich in meaning, clear, and concise. A well-constructed policy dictionary is key to achieving this goal.
How Policies and Standards Differ
Now that you know what policies are, let’s discuss the difference between policies and standards. Policies implement controls on a system to make it compliant to a standard. Standards influence the creation of
policies. Standards often determine a minimum requirement but can be very detailed in nature. Laws or agreed-upon practices produce standards. Standards then become the criteria for governance or certification and accreditation.
Standards often start with industry norms. Over time, organizations that represent the industry develop and publish standards. These standards often become the measuring stick by which regulators judge organizations. It’s not uncommon for a company to adjust standards to meet specific needs, and then republish them internally as a company standard or internal policy.
Be cautious when deviating too far from industry standards. There are both civil and legal penalties for not following them. Consider the Payment Card Industry Data Security Standard (PCI DSS). It calls for the following penalties:
• Fines of $500,000 per data security incident
• Fines of $50,000 per day for noncompliance with published standards
How Policies and Procedures Differ
In a similar manner, you can contrast the difference between policies and procedures. As a reminder, policies are requirements placed on processes. Procedures are the technical steps taken to achieve those policy goals. Procedures can contain step-by-step instructions on the performance of a task. They can also identify how to respond to an incident.
Within a policy framework, there could exist a policy stating the requirement for disaster recovery planning. A separate procedural document would call out specific tasks to provide recovery services. In other words, procedures are the how-to document.
Where Do Information Systems Security Policies Fit Within an Organization?
Governance over information security policies fits at more management levels. Consequently, both business and technology leaders work closely together to ensure value is delivered. However, the actual implementation of information security policies is far more complex and requires deep technical knowledge. The implementation of ISS policies often falls to the technology teams of an organization. With technology ingrained into today’s society, protecting information is everyone’s concern. As you discovered about information systems security, there is more to consider than just the wires and computers.
Organizations rely as much on information systems as they do on human resources. In a production facility, computers control most manufacturing devices. In a nuclear power plant, electrical generation and contamination containment rely on controlling systems to ensure the flow of power keeps the lights on safely. In a legal office, an aide researches thousands of documents and case law through a remote vast online database. These are just a few examples of the impact information systems have on a daily basis. As you can see, technology continues to become a greater part of our daily lives.
FIGURE 1-5 The seven domains of a typical IT infrastructure.
Figure 1-5 shows the seven domains of a typical IT infrastructure. Each domain provides unique policy requirements. Within each domain, ISS policies are vital to maintaining a secure work environment that protects the information resources critical to their individual requirements. It is becoming harder and harder to understand and protect networks when outside vendors are involved, such as a cloud service provider. You may not have direct access to vendor systems that support your network. So you may not have the assurance that your network is fully protected.
Why Information Systems Security Policies Are Important
ISS policies ensure the consistent protection of information flowing through the entire system. Information is not always static and often changes at its processed. The information must be protected throughout the process at all times. Physical and logical access controls must work together to protect the data. However, that is not always the case. What about a disgruntled employee with elevated access privileges? How do you protect resources from someone with this kind of authorized access? Physical security has limits and should be viewed as one of several layers of control.
The following are foundational reasons for using and enforcing security policies:
• Protecting systems from the insider threat—The “insider threat” refers to users with authorized access. These are privileged users who would have the ability and access to wreak havoc on the system. The insider threat is probably the most significant threat to any information system. Policies help monitor authorized user activity.
• Protecting information at rest and in transit—Data is generally in one of two states—data at rest, such as on a backup tape, or data in transit, such as when traveling across a network. Essentially, policies help to protect data all the time.
• Controlling change to IT infrastructure—Change is good. Managing change is better. This reduces the risk of vulnerabilities being introduced to the system.
• Defending the business—Ensuring that the business can deliver reliable products and/or services will protect the company’s brand.
Security polices strengthen an organization’s ability to protect its information resources at all times while providing secure access to employees when they need it. Policies allow for control of the system, changes to the system, and reduction of much of the risk to the system.
Policies That Support Operational Success
The definition of operational success may vary from one organization to another. Governments may view stakeholder success differently from private industry. But all kinds of organizations have a common concern: Is there a cost involved? Cost can be measured by either the cost of deploying policies or the cost of not having the policy in place. The cost of lacking a policy is often measured in terms of fines and legal expenses.
A very effective way of expressing cost is through risk. By spending X you can reduce Y amount of risk. For example, it would be reasonable to spend $50,000 to reduce a high risk of getting a $500,000 fine. This also allows for change in a controlled manner. It ensures that only policies that add true value are adopted. A good policy includes support for incident handling. Containing an incident can help reduce an exposure time to the organization. Identification of the reason for the incident can begin immediately and attackers potentially determined. A solution is more forthcoming, allowing the resource to be made available in a shorter amount of time. As most business folks will tell you, “Time is money.”
By controlling costs and focusing on the most important risks, an organization can eliminate waste and support operational success. The key risks to the organization are reduced over time through continuous improvement achieved in part by having a good post-incident handling process.
Challenges of Running a Business Without Policies
When an organization lacks policies, its operations become less predictable. Individuals will operate based on what they think is a good idea at the time. Imagine a rowing team without direction. Everyone has an oar and tries to arrive at a destination and avoid obstacles along the way. Even if you managed to arrive, think of the waste of going in circles as one side of the boat rows faster and with more urgency than the other. This assumes you can get the team to row at the same time. It’s no different with polices. Policies allow an organization to row in the same direction applying the same rules, priorities, and business goals across the teams. Here are a few challenges you can expect without policies:
• Higher costs—Due to wasted efforts and a lot of rework
• Customer dissatisfaction—Unable to produce quality because individuals make their own judgment as to what is right or good
• Lack of regulatory compliance—Individuals decide when and how to follow legal mandates
The result may well be legal action amounting to fines and loss of business. Depending on the industry, regulators may have the authority to close a business.
Let’s look at a typical credit card breach. Assume a hacker gains access to data for 1 million credit cards. Additionally, assume the hacker accesses personal information such as Social Security numbers. Also,
assume the company was out of compliance with industry norms in protecting its systems. The lack of security policies and resulting lack of methodical ways to manage risks allow vulnerabilities to these systems to go undetected. This could lead to lawsuits by customers and shareholders.
Dangers of Not Implementing Policies
If security policies are to ensure information is properly protected, failing to implement policies leaves information vulnerable. The information may be vulnerable to an attack or mishandling. Some employers say “Our employees are the smartest in their fields.” Or “We’ve been operating like that for years without a single problem (knock on wood).” These are also responses to the question, “Why implement policies?”
The dangers of not implementing policies are unexpected and undesirable outcomes. In the event of an ISS incident, employees will not know what to do, how to react, or whom to notify. This will lead to general confusion. As they’re trying to figure out the answers to those questions, an attacker may be copying more information from the system.
Good security policies include creating awareness of security’s benefits. This includes benefits to the employee. When good policies are implemented, they protect both customer and employee. With good policies in place, even if there is a data breach, the damage may be limited.
Dangers of Implementing the Wrong Policies
Similar to not implementing policies is implementing the wrong policies. You should create policies to address the proper processes, or detrimental consequences can occur.
For example, consider a policy that states all employees should be granted administrator privileges to a system. Under this policy, the basic tenets of information assurance cannot be guaranteed. Users will have access to all information, which is probably not intended, nor is it a best security practice. As security policy is often a family of policies, be sure they do not conflict with one another. In the event of a data breach, all employees with access immediately become suspect. This can often delay investigations.
When Do You Need Information Systems Security Policies?
“Timing is everything.” This is most likely the No. 1 tenet of comedians. The same applies to the timeliness of policies. Why implement a policy on milking cows when your business model raises chickens? The possibility exists that your farm will expand operations one day, but there is no reason to write policies until that expansion occurs.
There will be times when the need for an ISS policy is evident. There is always a need for foundational security policies. This includes defining basic data handling and acceptable use policies. Security policies need to ensure that new technology is not introduced without a supporting set of policies in place. Another consideration is that you may have a process that occurs daily and all the involved employees are aware of that process. The employees may modify the process. But without configuration management control, modifications can make secure systems nonsecure. Or an important process may be undocumented, even though employees know all the steps. This is the perfect opportunity to formalize a written procedure.
Business Process Reengineering (BPR)
Business processes are constantly under scrutiny for improvement. As that business process life cycle is accomplished, the process is improved and changed. However, the associated policies must also be changed and updated. Typically, the associated policies and procedures recognized during the life cycle are operational in nature. Policies that support operations, like security policies, are not always considered.
Failing to update those policies and procedures leaves a window of opportunity for error or disaster.
The process change could be dramatic enough to introduce new security vulnerabilities. If the equipment operating within the process completely changes, old security vulnerabilities reappear. Therefore, it is imperative to ensure that when reengineering any business process you also review security. This will ensure that business process reengineering (BPR) includes ISS concerns, and those policies and procedures are updated as needed.
Figure 1-6 shows the four phases of BPR. Phase 1 is the planning phase. Phase 2 sees the creation or modification of the process baseline. Research and benchmarking happen in Phase 3. Phase 4 develops the future process; it is during this phase that new policies are written or current ones updated.
Continuous Improvement
You can view continuous improvement as finding a better way or as a lesson learned. As employees find new ways to improve a system or process, you need to have a way to capture their ideas. The concept of continuous improvement applies to all aspects of ISS and IA. For example, when looking at availability issues, you may come across an authentication weakness. Regardless of how the weakness or risk was found, you need to capture the information, assess the importance, and apply an improvement. Often lessons learned flow from effective governance. Quality control will reflect what worked well and what didn’t. The part that didn’t work well represents the lessons learned. Sometimes this means changing policy. When policy goals cannot be achieved, enforcement becomes impossible and the overall security policy framework is weakened.
The driver for “finding a better way” should not be a system crash or breach. In those cases, you may have to deal with lessons learned from the incident. Think of continuous improvement as a suggestion box. Employees identify needed changes and write a suggestion. The suggestion is either accepted or rejected. If accepted, it enters the formal reengineering process.
Making Changes in Response to Problems
Even with a sound policy framework, issues will occur. Depending on the criticality of the issue, policy implementation or change can occur at any time in the process. Policy changes brought about in this manner help avoid future incidents. In a perfect environment, policies fall into place before incidents occur. However, most organizations do not operate in a perfect environment. Once an event not covered by a policy occurs, an event analysis takes place and a recommendation is drafted. For events that are noncritical in nature, policy drafting comes about in concert with the remediation process. If it is more critical in nature, remediation should occur prior to writing the policy.
FIGURE 1-6 Basic business process reengineering.
Why Enforcing and Winning Acceptance for Policies Is Challenging
There are many barriers to policy acceptance and enforcement. Without acceptance and enforcement of policies, employees could operate in a laissez-faire state. This runs counter to the business goals. It will inevitably lead to an employee not taking policy seriously. Employees taking shortcuts or ignoring policy can have serious impacts. Within an organization, there must be support at all levels, from the top to the bottom. Employees must have a stake in ISS. They must understand how those policies and procedures affect them and their business area. If they have a stake in creating or approving policies, they will be more likely to
accept those policies. The following is a list of policy acceptance challenges:
NOTE
The biggest hindrance to implementation of policies is the human factor.
• Organizational support at all levels—Without cohesive support from all levels of the organization, acceptance and enforcement will fail.
• Giving employees a stake—There must be something to motivate employees to buy in to the process. This could be some kind of award for participating, or disciplinary action if they don’t.
• Policy awareness and understanding—Employees must know a policy exists and understand what it means. Crafting the document to make this easy can be very challenging.
• Rewarding and recognizing behavior—Employees must see good examples to model their behavior after.
• Hold individuals accountable—Employees must know there is a consequence for repeated noncompliance.
Enforcement of policies can be just as difficult as policy acceptance. There are several reasons why enforcement is challenging. The language in which policies are written can be vague enough to be unenforceable. Infractions are not reported, which is often a key contributor to the lack of enforcement. Other business areas in the organization, such as human resources or the legal department, might not be part of the enforcement process. This can give employees license to either disregard the policies or perform actions contrary to them. The following list recaps policy enforcement challenges:
• Poorly written policies
• Failure to report infractions
• Lack of involvement in enforcement of key departments and management
• Lack of clearly defined roles and responsibilities
CHAPTER SUMMARY
This chapter defined foundational ISS concepts and key terms. You read about the key tenets of ISS management to ensure confidentiality, integrity, availability, authentication, and nonrepudiation. Additionally, you read that information systems security (ISS) and information assurance (IA) are two separate but similar concepts. Associated with IA and ISS is governance. Governance ensures people are following the rules, such as policies, regulations, standards, and procedures. You read about the importance of quality control and quality assurance.
You read about several situations when security policies are to be considered. Opportunities include:
• New business processes
• Changes in current business processes
• Business process reengineering (BPR)
• Incident occurrence
You read about where policies fit within an organization to meet operational and governance requirements. These include all seven domains, across the business spectrum. ISS policies are important for several reasons. A primary reason is controlling authorized access to information. Another reason is to control change to systems. You read about how to express risk in terms of threats and vulnerabilities. Finally, you read about policy acceptance and enforcement, and factors that make those processes difficult. Employee support is required at all levels for policy buy-in and enforcement. Enforcement also hinges on effective policy writing.
KEY CONCEPTS AND TERMS
Authentication
Availability
Business as Usual (BAU)
Business process reengineering (BPR)
Change management
Confidentiality
Continuous improvement
Data at rest
Data in transit
Entitlement
Governance
Guideline
Information assurance
Information systems security (ISS)
Information systems security management life cycle
Information systems security policies
Integrity
Need to know
Nonrepudiation
Policy
Policy definitions document
Policy framework
Policy principles document
Procedure
Quality assurance (QA)
Quality control (QC)
Risk
Service level agreement (SLA)
Standard
Threat
Vulnerability
CHAPTER 1 ASSESSMENT
1. John works in the accounting department but travels to other company locations. He must present the past quarter’s figures to the chief executive officer (CEO) in the morning. He forgot to update the PowerPoint presentation on his desktop computer at the main office. What is at issue here?
A. Unauthorized access to the system
B. Integrity of the data
C. Availability of the data
D. Nonrepudiation of the data
E. Unauthorized use of the system
2. Governance is the practice of ensuring an entity is in conformance to policies, regulations, ________, and procedures.
3. COBIT is a widely accepted international best practices policy framework.
A. True
B. False
4. Which of the following are generally accepted as IA tenets but not ISS tenets? (Select two.)
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
E. Nonrepudiation
5. Greg has developed a document on how to operate and back up the new financial sections storage area network. In it, he lists the steps required for powering up and down the system as well as configuring the backup tape unit. Greg has written a ________.
6. When should a wireless security policy be initially written?
A. When the industry publishes new wireless standards
B. When a vendor presents wireless solutions to the business
C. When the next generation of wireless technology is launched
D. After a company decides to implement wireless and before it is installed
7. A toy company is giving its Web site a much-needed facelift. The new Web site is ready to be deployed. It’s late October, and the company wants to have the site ready for the holiday rush. The year-end holiday season accounts for 80 percent of its annual revenue. What process would be of particular importance to the toy company at this time?
A. Continuous improvement
B. Business process reengineering
C. Change management
D. Information security system life cycle
8. Implementation and enforcement of policies is a challenge. The biggest hindrance to implementation of policies is the ________ factor.
9. Information systems security policies should support business operations. These policies focus on providing consistent protection of information in the system. This happens by controlling multiple aspects of the information system that directly or indirectly affect normal operations at some point. While there are many different benefits to supporting operations, some are more prevalent than others. Which of the following are aspects of ISS policies that extend to support business operations?
A. Controlling change to the IT infrastructure
B. Protecting data at rest and in transit
C. Protecting systems from the insider threat
D. B and C only
E. All the above
10. Ted is an administrator in the server backup area. He is reviewing the contract for the offsite storage facility for validity. This contract includes topics such as the amount of storage space required, the pickup and delivery of media, response times during an outage, and security of media within the facility. This contract is an example of information security.
A. True
B. False
11. A weakness is found in a system’s configuration which could expose client data to unauthorized users. Which of the following best describes the problem?
A. A new threat was discovered.
B. A new vulnerability was discovered.
C. A new risk was discovered.
D. A and B
E. B and C
F. A, B, and C
CHAPTER
2 Business Drivers for Information Security Policies
TECHNOLOGY PLAYS A VITAL ROLE in business. Around the world, business has become dependent on technology—so much so that if it were taken away, many business operations would stop. Almost all businesses and governments use technology to support their operations, from the most basic to the most complex. Dependence on information technology has grown so rapidly over the past decades that it’s hard for people to envision their lives without it. Consider what it would be like to disconnect from technology for week. No cell calls. No GPS to find that new restaurant. No Internet. It’s not only the products people use or consume but the way they get these products. Without technology, delivery of products and services often would not be possible. Whether in the public or private sector, the threat of information being stolen or unauthorized access is a major concern. When you reduce these types of risks to information assets, you reduce risks to the business as well. Security policies let your organization set rules to reduce risks to information assets.
It is impossible to eliminate all business risks. In fact, you would not want to. Taking risks and making a return on those risks are essential to business. How you manage that risk is what makes businesses successful. A good policy can reduce the likelihood of risk occurring or reduce its impact. A business must find a way to balance a number of competing drivers. Some of these drivers include:
• Cost—Keep costs low.
• Customer satisfaction—Keep customer satisfaction high.
• Compliance—Meet regulatory obligations.
• Measurement—Be self-aware and avoid surprises.
Security policies define how to protect and handle information. These security policies should be brief and concise. They should define in simple terms how information should be handled and processed to meet business goals. Aligning security policies with business objectives makes policies easier to understand and more likely to be followed.
This chapter provides an overview of concepts that can reduce business risk. Although the term business is used, the concepts apply equally to both public and private organizations, and for-profit as well as nonprofit entities. When the term risk is used, it refers only to the risk to information assets. It is impossible to discuss all potential business drivers to reduce risk for every organization. This chapter focuses on key risk areas.
Chapter 2 Topics
This chapter covers the following topics and concepts:
• What a business driver is and why business drivers are important
• What it means to maintain compliance
• What business risk exposure is
• What business liability is
• What operational consistency is and why it is important
Chapter 2 Goals
When you complete this chapter, you will be able to:
• Describe basic business risks
• Explain the difference between business risk exposure and business liability
• Describe some techniques the business uses to reduce risk
• Explain the important issues related to operational consistency
• Describe the relationship between business risks and security policies
Why Are Business Drivers Important?
Computer systems continue to evolve and become more complex. This makes it hard for the business to understand the technology that supports it. Yet a security breach can have a significant impact on the bottom line. The following are two examples of why organizations need good security policies:
NOTE
The business refers to the operations of either a public or private sector organization.
NOTE
A breach is a confirmed event that compromises the confidentiality, integrity, or availability of information.
The national retailer Target Corporation, with more than 1,700 stores in the United States, suffered a major data breach during the 2013 holiday shopping season. This breach put at risk the financial information of an estimated 40 million customers. The costs incurred to companies involved in this fiasco reached upwards of $200 million.
The health care provider BlueCross BlueShield of Tennessee in 2009 suffered a theft of hard drives. It reported 57 hard drives stolen. The company had to notify 220,000 members that their personal information might have been compromised. BlueCross reported spending more than $7 million. Customers were offered free credit monitoring for two years.
Both these cases resulted from a security policy failure. In 2011, the Poneman Institute conducted a study of the cost and cause of data breaches for that year. Organizations reported that 39 percent of the data breaches were attributed to negligence. While the exact percentage may vary each year, the point is that having good policies isn’t enough. Businesses must be self-aware and measure whether those policies are being followed. Businesses cannot afford data breaches resulting from employees’ failure to follow good policies.
Organizations are increasingly concerned with how information risks are managed and reduced. Security policies are not considered solely a technology issue anymore. Organizations also expect security policies to reflect how they want information handled. An organization’s security policies, taken collectively, show its commitment to protect information. Good security policies keep the business healthy. Some of the basic concerns with implementing such a policy include:
• Cost—Cost of implementing and maintaining controls
• Impact—Impact on the ability of the business to serve the customer
• Regulation—The organization’s ability to defend its policies and practices before regulators, should the need arise
• Adoption—The degree to which employees understand and are willing to follow policies—“to make them their own,” in other words
Policies are effective only if they are enforced. Managers dislike surprises. Finding out later that security policies are too costly or that they negatively impact customers is not acceptable. To avoid this, management needs to take part in creating and implementing security policies. Even in the best of situations data can be stolen. By having good security policies, the organization is better positioned to defend its actions to the public and in the courts. For example, an e-mail security policy that warns employees that their messages may be monitored can help defend against a lawsuit for violation of privacy.
WARNING
Developing policy statements on legal and regulatory issues is highly sensitive work. Be sure to have your legal department review draft policy wording. Also, find out how the department wants working copies of policies labeled—as “draft” or “confidential draft,” for instance.
Maintaining Compliance
The term compliance refers to how well an individual or business adheres to a set of rules. Security policy compliance means adhering to security policies. It is difficult to know whether an organization complies with every security policy. To state that an organization is compliant, you must be able to validate that the requirements within security policies have been applied to security controls and information. Difficulties arise due to the sheer volume of digital information. Even a relatively small business with only a few hundred employees could have tens of thousands of files. These files travel between servers, desktops, laptops, backup media, universal serial bus (USB) drives, and more. The issue becomes even more complex in large organizations with thousands of employees and millions of files. Knowing exactly what data is captured where and how it is used in an ever-growing complex environment is difficult. Businesses are concerned with not only files that employees can access but also with files exposed to vendors and suppliers.
Compliance Requires Proper Security Controls
The key to security policy is being able to measure compliance against a set of controls. Security controls define how you protect the information. The security policies should define why you set the goal. This effectively bridges business requirements with security controls. The security policies also define what type of protection will be achieved. How you implement the security policy can vary. For example, implementing strong authentication depends on several factors. Do you understand what is meant by “strong authentication?” Are you aware of the technology choices available given your specific application? Within those choices, does your organization prefer to keep things standardized? Has the choice you made been properly approved? How do you measure that the right choices were made? How do you measure whether both the policy and the right processes were followed?
TIP
Make your security policies relevant to business needs. They stand a better chance of being followed.
Table 2-1 provides a conceptual example of a high-level security policy and control statement. A policy must describe a clear set of actions needed to be compliant. Vague or open-ended statements create confusion.
They may lead people to make incorrect choices. However, policies that are too detailed cannot be applied broadly. So some situations can arise to which no policy applies. Again, this can be confusing and lead people to wrong choices. A well-written policy should follow a few basic guidelines. It is critical that a policy strike the right balance. It must be clear and concise. It must lead to specific outcomes and embody principles that can be applied broadly. Writing good policy is an art as much as a science.
To know whether an organization is complying with security policies, you must measure the level of compliance. The level of compliance can change depending on what exactly is measured. Consider the example in Table 2-1. You could perform a simple measurement of compliance by verifying that firewall rules exist. However, simple measurements can be less accurate or misleading. For example, assume four firewalls allow the traders access to the Internet. You check each firewall and find that three contain the proper firewall rule described in Table 2-1. At first glance, a simple measurement indicates the business is 75 percent compliant with this policy. On further inspection, you discover that the fourth firewall does not follow the required rule. This firewall represents 70 percent of the traders’ Internet traffic. This new fact could mean the business is only 30 percent compliant.
TABLE 2-1 An example of security policy and control components.
POLICY OR CONTROL
ANSWERS ISSUE
Security policy Why Securities and Exchange Commission (SEC) under rule 17A-4 requires stock traders’ conversations with clients to be recorded and retained. In this case the purpose is to ensure a detailed record of transactions with the client. Establishing a record allows regulators to audit for compliance with disclosure rules.
Security policy What To ensure compliance, all traders should communicate with clients only through company telephones or the company’s e-mail system.
Security control
How Using the firewall, stop all traffic for traders to the Internet except for Web browsing and company e-mail.
Security control
Measuremen t
All attempts by traders to use the Internet should be logged. Each trader’s log should be reviewed by a manager at least monthly to ensure compliance.
TABLE 2-2 Control measurement benefits.
CONTROL MEASUREMENT CONSIDERATION BENEFIT TO THE BUSINESS
Determine which security controls to measure. Defines the scope of the compliance being measured
Verify these controls are working. Defines the effectiveness of the controls being measured
Express compliance in terms of adherence to policy, not controls.
Defines what business goals are to be achieved
Express compliance in terms of potential impact to the business.
Defines the impact to the business if the goals are not achieved
Ensure there is a way to measure compliance. Defines how the policy will be enforced
A more accurate measurement gives the business more confidence to understand its risks. This clarity of thought on risk often leads to a consensus on a solution. Even when no solution is available, this strong understanding of risk can help an organization prepare if an incident occurs. It is not possible to measure compliance to each individual policy. With thousand or millions of transaction daily, not every employee action can be logged. So taking measurements and reviewing logs often focus on high-risk activities, those activities that would lead to significant impact if the policy was not followed.
NOTE
Employees must be aware of and formally educated on all company policies. Awareness is the first step in ensuring policies are followed.
Table 2-2 illustrates what can be achieved with good policy compliance measurements.
Security Controls Must Include Information Security Policies
Security controls are the means of enforcing security policies that reflect the organization’s business requirements. These controls ensure the confidentiality, integrity, and availability of the information. These controls can be used to protect physical resources, including worker safety. They are also the means to measure security compliance. You should build security controls based on the security policies. If you know the security controls work, you know you are complying with security policies.
TIP
Reducing the frequency of security policy changes makes policies easier to enforce. It’s also easier to train employees.
Security policies do not contain security controls. However, a security control may have to change if the related security policy changes. By treating them separately, you can change the control to meet the security policy. This is an advantage as technology evolves. For example, suppose you have six separate IDs and passwords to access six different systems. Let’s assume technology is introduced to allow all six systems to recognize one ID and password. Much of the security policy on password controls may not change: You still know to keep your password a secret and how to select a complex password. When security policies are well established and understood by employees, they are more easily enforced. When policies change too frequently, they become confusing.
A number of classifications can be applied to security controls. The three most common are:
• Physical control—As the name implies, this refers to some physical device that prevents or deters access. A locked door, a camera, an electric fence, and a security guard are all examples of physical controls.
• Administrative control—Also known as a “procedural control,” relies on a human to take some action. A few examples of a procedural control could be providing security awareness training or having a manager check an employee’s work.
• Technical control—Refers to software that creates a logical control. Passwords and antiviral software are examples of technical controls. Dedicated hardware, such as a firewall, would be considered a technical control because it contains the necessary software to create the logical control.
Security controls also follow three unique design types—preventive, detective, and corrective, as shown in
Figure 2-1.
FIGURE 2-1 Three unique security control design types.
Preventive Security Controls
A preventive control stops incidents or breaches immediately. As the name implies, it’s designed to prevent an incident from occurring. A firewall ideally would stop a hacker from getting inside the organization’s network. This kind of control is an automated control.
An automated control has logic in software to decide what action to take. With an automated control, no human decisions are needed to prevent an incident from occurring. The human decisions occurred when designing the security control.
Detective Security Control
A detective control does not prevent incidents or breaches immediately. Just as a burglar alarm might call the police, a security control alerts an organization that an incident might have occurred. When you review a credit card statement, your review is a detective control. You review the statement for unauthorized charges. The process of reviewing the statement did not prevent the unauthorized charge from occurring. The review, however, triggers corrective action if needed.
A detective control is considered a manual control. A manual control relies on a human to decide what action to take. Still, manual controls can have automated components. For example, a system administrator could automatically receive a cell phone text when the number of invalid logon attempts reaches some threshold on a server. The administrator still needs to take some manual action.
NOTE
If human action is required, the control is considered manual. If no human action is required, the control is automated.
Corrective Security Control
A corrective control does not prevent incidents or breaches immediately. A corrective security control limits the impact to the business by correcting the vulnerability. How quickly the business can restore its operations determines the effectiveness of the control.
For example, backing up files to enable data restoration after a system crash is a corrective security control. A corrective control is either automated or manual. For instance, you may automatically mirror (create exact copies of) files and then restore them in the event of hard drive failure. This is an automated control. If a human is required to decide when to restore the backup, that is a manual control.
Mitigating Security Controls
To appreciate and understand how data is protected, you must look beyond a single control. It is important to look at how preventive, detective, and corrective controls work together. For example, assume someone entered the wrong Social Security number by accidentally reversing two of the digits. There may not be a control in place to catch this mistake as it’s entered. However, later in the process, a corrective control may catch and correct it. When considering how well protected the system is, look at the process end to end. While there may be a lack of control on the front end, there may be something that stops it on the back end. That back-end control would mitigate any negative impact and so would be considered a mitigating control. Mitigating controls can be preventive, detective, or corrective.
FIGURE 2-2 Key relationships of security policies.
Relationship Between Security Controls and Information Security Policy
Security policies and security controls have a mutual relationship. Security policies rely on security controls to enforce their rules. A security control is based on security policy goals. Without security controls, you could not enforce security policies. Without security policies, you could not systematically put controls in place that protect business information adequately. You rely on both to prevent a breach or restore operations after a breach. Figure 2-2 illustrates these key relationships.
It’s possible to have too many security controls and policies too complicated to follow. A security control is not effective when it cannot distinguish between good and bad behavior. Security policies are not effective when they’re too confusing to follow. If the policy is not clear, you cannot build reliable security controls. This is less of an issue if the resulting control built from the policy has been automated. In other words, if the
computer prevents something or alerts you when something is wrong, then complexity is not such a problem. But when you expect a human to take an action, the complexity and volume matter. If a policy is too long, it is simply hard to understand. It also becomes a challenge to train employees.
A simple example of this human nature is origami. Most people have made paper airplanes. Usually that can be done with a simple four- to six-step process that anyone can easily learn. Now try to teach the same person to make a swan using a 30- to 40-step process. Then apply that knowledge across thousands of employees. Your likelihood of success goes way up if you teach the people to make paper airplane rather than the swan. Keep policies as simple as possible.
The most important relationship between controls and policy is the business requirement. A common error is to overlook the business context. Knowing the context helps you keep competing priorities in balance. Equally important, when an incident occurs, you can better understand the impact if you know the business context.
Mitigating Risk Exposure
How can information security policies help? Well-defined security policies balance business requirements and limit behavior. The policy reflects how the business wants to manage its risks. The importance placed on such issues as customer privacy and protecting company secrets directly influences employee behavior.
NOTE
Tone at the top refers to a company’s leaders making sure every employee knows the priorities. In this case, it means senior management’s stated commitment to security policies. Beyond words, the actions taken by senior managers to implement and enforce policies build trust with the public and with regulators.
Security policies must drive a culture that mitigates risk exposure. Policies, and the way they are enforced, reflect the business perception of risk. They are more than just simple business requirements that translate into security controls. Policies can reduce business risks by setting the tone at the top and promoting a risk- aware culture.
Educate Employees and Drive Security Awareness
Security is ultimately a function of people, processes, and technology working well together. A well- educated employee goes a long way toward reducing risk. Policies cannot define every risk. Unlike automated security controls, which look only for specific risks, an aware employee can better detect unusual activity. This ability to detect and deal with the unexpected makes employees extremely valuable in reducing business risk.
A good security awareness program makes employees aware of the behaviors expected of them. All security awareness programs have two enforcement components, the carrot and the stick. The carrot aims to educate the employee about the importance of security policies. You can use rewards to motivate compliance. The stick reminds the employees of the consequences of not following policy. Motivation is a powerful tool in any environment. Positive reinforcement often yields better results than negative consequences. Unfortunately, you need both components to implement a successful security policy program.
NOTE
If policies are optional, employees might treat them as simply guidelines. If you never enforce a policy, employees might perceive it as irrelevant or unimportant.
You can implement a security awareness program in many ways. Here are some generally accepted principles:
• Repetition—Most employees do not deal with risk daily, so they need to be reminded.
• Onboarding—New employees should be told of their responsibilities immediately.
• Support—Leaders should provide visible support.
• Relevance—Rules that show awareness of the business context are more likely to be followed.
• Metrics—Test your employees’ knowledge of policies.
Security awareness is about good communication. It’s not about memorizing policy word for word. You need to focus on key concepts and teach employees when to ask for help. An employee should know what to do when encountering something suspicious or unexpected. Be sure to point out resources such as intranet sites within the organization. Most important, a security awareness program should teach an employee where to go for help. New employees especially need to know they are not alone in dealing with unexpected issues.
TIP
Refresh your security awareness training program at least once a year. Retrain employees after revising the program. It is important to connect with your audience. Just like a commercial, you are selling a message. Use whatever approach works. Humor works well.
Leaders need to provide visible support for the program. Training takes time away from employees’ regular work. Leaders need to walk the talk. They themselves need to take the training and reinforce the message with their teams. How leaders reward when policies are consistently followed or react when they are not sends a strong message. The daily message sent by leaders determines the risk culture of an organization.
A security awareness program gains credibility when the business sees a reduction of risk. Each employee plays a role in the business process. Multiple benefits come with a security awareness program that emphasizes the business risk, including:
• Value—Policies relevant to business are more likely to be followed by the business.
• Culture—Well-understood and enforced security policies promote a broad risk culture.
• Resiliency—Policies provide a basis for dealing with the unexpected.
Competence is difficult to measure. At a minimum, most programs track names of those who attended classes. However, simply taking roll is not a good way to measure competency. Many awareness programs have short quizzes to test key areas of knowledge. The challenge is that an employee may need to apply the knowledge long after the class ends. Often the best measure is noting real-world problems that occurred by not following policy. That way you can go back and continuously improve the training.
A risk-aware culture may be the critical success factor that affects the business the most. This means a culture that shares common set of values, beliefs, and knowledge about the importance of managing risks. When you develop a risk-aware culture, people want do the right thing all the time. It is second nature to follow the rules and support one another. This translates into an increased likelihood of policies being followed. When this behavior is modeled every day by everyone, it becomes the norm and defines the risk culture.
Prevent Loss of Intellectual Property
Legal-definitions.com, an online law dictionary, defines intellectual property (IP) as “any product of human intellect that is unique and un-obvious with some value in the marketplace. Intellectual property laws cover ideas, inventions, literary creations, unique names, business models, industrial processes, computer program code, and more.”1 In business, IP is a term applied broadly to any company information that is thought to bring an advantage. For instance, you need to protect secrets in order to protect your advantage over competitors. IP comes in many forms, and can be electronic or physical. Security policies should state how to protect that information regardless of format.
Protecting IP through security policies starts with human resources (HR) policies. These HR policies establish a code of conduct. They should give employees clear direction as to what the organization owns with respect to IP. The issue of IP ownership can be confusing when a new employee brings to the workplace IP acquired or created while he or she was at another firm. Employment agreements may even attempt to enforce the confidentiality of IP after an employee leaves the organization or for work performed during the employee’s spare time. These HR policies and employment agreements may or may not be enforceable, depending on current law and location. Nonetheless, when building security policies, you should take a close look at HR policy. You want to be sure there are no conflicts between HR policy and security policy.
Labeling Data and Data Classification
Once an organization clearly defines its IP, the security policies should define how to label or classify the information. There is a difference between labeling and classifying data. In both cases, a label identifies the level of protection needed. A label is typically a mark or comment placed inside the document itself; for instance, putting a “confidential” label in the footer of a document. When you classify a file in a process known as data classification, a label may or may not be applied. When data classification is applied, the sensitive file is placed in a secured location.
IP can be difficult to label or classify and even harder to inventory. IP material comes in many forms. Consider a simple document labeled as sensitive IP. Portions of the document may be cut and pasted to create new material. How much of that new material should be considered IP? Although this can be difficult, the generally accepted approach is to label what you can. Restrict access based on the label. Treat any new document containing any portion of the original IP with the same restrictions you placed on the original material.
One of the most important deliverables of security policies is the labeling and data classification approach. The approach selected will drive the cost of handling data. An employee needs to know how to handle both kinds of information—labeled and classified. Security policies instruct an employee on the proper handling depending on the business requirements. The combination of the following is a widely accepted practice to help prevent loss of IP:
• Label and classify IP data.
• Restrict access.
• Filter e-mail and other communication tools for IP data.
• Educate employees on handling IP material.
Protect Digital Assets
Digital assets are any digital content an organization owns or has acquired the right to use. PC Magazine
defines digital assets as “Any digital material owned by an enterprise or individual including text, graphics, audio, video and animations. A digital asset is owned by an organization if it was created on the computer by its employees or if it was custom developed for and purchased by the organization. Images scanned into the computer are also a digital asset if the original work was owned by the company.”2 The term “digital assets” is often inaccurately applied to all computer-related resources. This chapter will use the strict definition.
You can protect digital assets with a good inventory. Only at the moment you identify a specific digital asset and apply a label or data classification do you know where the data is. The challenge is keeping track of the information as it is moved, changed, created, and deleted. A good inventory of digital assets allows you to design security controls where the data resides. Security policies define what an asset is. They also define what label or classification should be applied. You can see these key relationships needed to protect information in Figure 2-3.
The ability to protect information starts with well-defined security policies. The definition of digital assets is so broad it is difficult to create a complete inventory. Many organizations rely on tools that scan servers, desktops, and laptops. They try to inventory sensitive information based on patterns such as Social Security numbers (SSNs). When they see a pattern match, they can determine the level of security control to apply.
FIGURE 2-3 Key components in protecting digital assets.
To protect digital assets, you need to know where your data is. You need good tools to inventory information and networks. You will need to refresh this inventory often. Finally, you need to be able to label or classify data quickly. The sooner data is labeled or classified the sooner it is protected. The ability to inventory digital assets is a major policy implementation issue.
WARNING
Creating an accurate inventory is a major problem, given the speed at which data files are created, deleted, moved, and changed. Not knowing where your highly sensitive data is at any point in time is a major risk. Mobile devices such as USB drives and smartphones that can receive e-mail compound the problem. And how do you protect information when it leaves your network? An organization should prioritize the inventory of assets, starting with the most sensitive.
Once data is inventoried, it’s fairly straightforward to apply a label or classify the data. But you need to be sure the security policies clearly define the handling for each label and data class. It’s almost impossible to classify every data file. Think of the thousands of files on a single personal computer or laptop: data in the form of documents, essays, screen shots, pictures, tax returns, and much more. Much of this is considered unstructured data. The data was not predefined or as well organized as you would find in a production environment such as a bank, which will have defined processes for transactions such as taking deposits. Production systems organize data in a well-defined manner. Their processes are unambiguous and repeatable.
Applying data classification to unstructured data is a major challenge. Often data classifications are applied to where data is stored. In other words, you may not know all the files within a user’s laptop, but you know it’s a user’s laptop. Based on that knowledge, any data placed on a laptop may have a certain data classification. This is good technique when assessing data classification at a file level is not possible.
technical TIP
Whenever possible, you should put inventory tools that automatically classify data into log mode. In log mode, the security control records only what it would have done but does not take the action. Then, by reviewing the logs with management, you can assess the impact of classifying data in that way. It is not unusual for automated tools to over-classify, locking the business out of key systems. For example, let’s assume you highly restrict access to customer addresses. Potentially, the logs would show that the customer care desk could not access the data to verify customers’ identity when they call in for help. You can avoid upset users by rehearsing log use before applying preventive controls. In this example, no actual customers or business functions would be affected. The security control could then be adjusted to include access for the customer care desk. Log mode is a good way to gain business support for implementing more restrictive security controls.
Secure Privacy of Data
It is human nature to crave privacy when it comes to our personal matters. People want their highly personal information to be secure—whether it is their medical or financial records. What many do not realize is that this information can be stored in digital files in computers anywhere in the world. Your personal information might be found with an offshore vendor in China. Regardless of where your personal data travels, securing and protecting this information is both a trust and legal obligation. This chapter focuses on United States privacy obligations. However, all developed countries throughout the world have some form of privacy laws.
NOTE
Different states have varying laws that define what is included as PII. For instance, one state may consider a person’s home address a public record, and another may not. States vary also in how they require data to be handled to protect privacy. Most large companies adopt a single policy that can be applied to multiple states.
The concept of protecting privacy starts with data that identifies people as unique individuals. In 2007, the Office of Management and Budget (OMB) defined personally identifiable information (PII) as:
Information which can be used to distinguish or trace an individual’s identity, such as their name, social security number, biometric records, etc. alone, or when combined with other personal or identifying information which is linked or linkable to a specific individual, such as date and place of birth, mother’s maiden name, etc.3
Security policies need to define PII data by business type and location. A bank, for example, follows different federal regulations than a local check-cashing service or medical clinic. The state in which you operate could have different requirements than a neighboring state. Widely accepted practices help
businesses navigate the maze of privacy regulations. For example, most states consider the combination of a person’s name and SSN as PII. With identity theft, a major concern for both businesses and consumers, you should be careful of any combination of information that could be used to open or access an account. Depending on the business, these types of data have a good chance of falling within the PII definition.
NOTE
The chief privacy officer provides direction on how to handle legal requirements regarding PII data, including how to report incidents.
Because organizations must follow many different privacy regulations, some organizations have established a chief privacy officer (CPO) position. This is the most senior leader responsible for managing an organization’s risks. The CPO is responsible for keeping up with privacy laws. The CPO also needs to understand how the laws impact business. Due to the nature of the work, many CPOs are lawyers. Although they are generally not technology people, they work closely with technology teams to create strong security policies.
You should consider the following guidelines when developing policy to secure PII data:
• Examine—Understand local state and federal requirements.
• Collaborate—Work closely with CPO.
• Align—Coordinate privacy policies with data classification policies.
• Educate—Conduct awareness training on handling of PII data.
• Retain—Ensure proper controls around data retention and destruction.
• Limit—Collect only the data from an individual you need to provide the service or product.
• Disclose—Fully disclose to the individual what data is being collected and how it will be used.
• Encrypt—Consider using encryption when storing or transmitting PII data.
Full Disclosure and Data Encryption
Privacy regulations involve two important principles. Full disclosure gives the consumer an understanding of what and how the data is collected and used. Data encryption provides a standard for handling consumer information.
NOTE
Some regulations allow companies to sell customer data if the individual gives permission through an opt-in process. Other states allow for the sale of information but require that the consumer be given a choice through an opt-out process.
The first principle—full disclosure—is the idea that an individual should know what information is being collected. They should also be told how that information is being used. Many people use the Internet as a quick-and-easy way to buy products and services. It seems just as quickly our e-mail inbox fills with offers from other companies. Did the online service collect and sell your information? Did the company fully disclose how that data was to be used? These are the issues that a privacy policy needs to address.
The second principle—data encryption—recognizes that even with the best efforts, data can fall into the wrong hands. This happens when data is stolen, lost, or accidentally accessed. Encrypted data can only be read when the user has the correct decryption key. For example, Roy has an encrypted hard drive containing his business ledgers. Moss finds Roy’s laptop but Roy’s financial information is still secure because the hard drive cannot be read without an encryption key. This provides an additional layer of security.
Encryption is a preventive security control. But encrypting data and managing encryption keys can be complicated and expensive. Although expensive, it’s often a lot less expensive than having to notify millions of customers that their personal information has been lost or stolen. Beyond loss of trust, companies may face legal penalties.
Encryption is considered an effective practice. Encrypting data when transmitting over the Internet is commonplace today. Encrypting data at rest on a server’s hard drive or mass storage array is far more complicated if multiple technologies are involved. Sometimes, encrypting data at rest is not technically possible.
technical TIP
Payment Card Industry Data Security Standard (PCI DSS) mandates the use of encryption for transmitting and storing credit card information. Companies and vendors have created materials to support these PCI requirements. Even if your organization does not process credit cards, this material could provide helpful guidance on encryption for protecting PII data. The Cisco PCI Solution for Healthcare Design and Implementation Guide, for example, outlines a conceptual model for protecting data including encryption components. The Guide is located at http://cisco.com/en/US/docs/solutions/Verticals/PCI_Healthcare/PCI_Healthcare_DIG.html.
Lower Risk Exposure
Well-defined and enforced security policies lead to well-defined controls. These controls in turn protect the information. So how do you achieve lower risk exposure? The concept of exposure relies on a calculation that estimates the losses to the business in the event the risk is realized. First you need a scale that allows you to measure risk against predicted business losses. Over time, you invest in people, processes, and technology to lower that risk to an acceptable level. That acceptable level is sometimes called your “risk appetite.”
What a risk appetite tells you is how much loss an organization is willing to accept in the normal course of business. These calculations are made in many different businesses and industries. Credit card companies estimate losses from fraud and invest in countermeasures. As the fraud rises, so does the spending to stop it and lower the risk exposure. You calculate the loss if these events occur and invest in programs to lower the risk exposure. For example, most banks today have changed their security policies to require much more rigorous screening of calls to the customer service desk. It’s not unusual for a customer to be asked more detailed questions than just their name, account number, and SSN. A customer could be asked current balances, last transactions, and other details in an attempt to reduce risks of fraud.
There is no easy way to calculate risk to the business in the event of a security breach. Ideally, you should calculate risk exposure in terms of total potential losses in financial terms. Given that security breaches could also result in reputation damage, it is hard to calculate that in financial terms.
Some organizations take an easier approach. They calculate risk exposure in terms of security policy compliance. This approach takes a leap of faith that if you comply with good security policies, you are adequately controlling the risk. This approach lets you lower risk exposure to the business by measuring and improving policy compliance over time.
Regardless of approach, you cannot rely exclusively on risk score. A risk score is quantitative and as such is
a numerical representation of multiple factors. It does not replace risk judgment. Nor can it replace a person making a qualitative judgment through experience and common sense. Risk scores are based on factors people think they understand at a moment in time. But the risk scores may not keep up with changes in the environment, technology, or the market. The danger is in blindly following the numbers (the quantitative judgment) when common sense and experience (the qualitative judgment) say the risk is much higher. Think of the financial crisis of 2007–2008, with trillions of dollars in losses and millions put out of work. Many risks were considered low. This is an oversimplified example, but generally quantitative scores for many banks assumed that housing prices would continue to rise forever. So it didn’t matter how much you loaned, there would always be buyers for properties and homeowners would always have equity. The qualitative side, the human judgment and common sense, was missing. As a result the United States endured the worst financial crisis since the Great Depression of the 1930s.
Minimizing Liability of the Organization
A business liability emerges when an organization cannot meet its obligation or duty. Business liability is a subset of an organization’s overall risk exposure. An obligation can be either a legal or a promised commitment.
If a business fails to follow the law, it has violated its legal obligation. This liability leaves the organization open to potential fines or limits how it conducts business. In rare cases, an organization can be found to have engaged in criminal conduct. Its officers could then face criminal charges.
NOTE
Business liability occurs when a company fails to meet its obligation to its employees and community. A business’s legal obligation is an action it is required to take in compliance with the law.
A business not living up to promised commitments loses the trust of customers. When a business fails to deliver the product or service it promised, the liability is lost business. Customers post complaints on the Internet, creating the potential for lawsuits and more business loss. Customer opinions are easily and widely spread today via social media, postings on product review sites, and the like. It increasingly important that businesses live up to their commitment to customer service.
The role of security policies is to reduce these liability risks. When hackers breach a company’s security, for example, you often have both trust and regulatory issues to deal with. Each event has potential liabilities. Reviewing past events to predict future situations will help you gauge overall risk exposure and specific business liabilities. Policies must define the proper handling of each of these types of events.
Separation Between Employer and Employee
It is important that an employer act quickly when a known violation occurs. The employer may not be responsible for an employee’s action. But the employer’s failure to act will create the impression that, despite written policy, the employer condones the employee’s action. This could create legal liability for the employer. It’s not enough just to have a written policy. The policy must be enforced. Employees must be held accountable and, as needed, disciplined for noncompliance. This protects the customer and the employer.
Policies make clear to an employee what acceptable behavior is. Policies also provide a degree of separation from employees who fail to follow rules. A business can point to its policies as a statement of what should have occurred. The ability to defend the organization’s position to the public and regulators is an important byproduct of security policies.
However, just having security policies will not create this separation. The business is obligated to take steps to implement and enforce the policy. Some of these reasonable steps include:
• Policy—Have clear security policies on the handling of customer information.
• Enforce—Express strong disapproval when policy is not followed.
• Respond—Quickly respond to incidents to minimize the impact to customers.
• Analyze—Understand what happened.
• Educate—Improve employee training.
TIP
Be sure to work with in-house legal counsel on policy strategies to lay the foundation for defending the organization in the event of an incident.
These steps will minimize losses and show a commitment to customers. When challenged by the public or regulators, this will also help separate the employer’s actions from a rogue employee.
Acceptable Use Policies
Acceptable use policies (AUPs) are formal written policies describing employee behavior when using company computer and network systems. Most AUPs outline what is acceptable and unacceptable behavior. They also need to outline the disciplinary process when an employee violates policy. Because the disciplinary process could lead to termination, the policy must be clear and concise. Many companies require the employee to sign the AUP to acknowledge receipt of the rules. Both the legal and HR departments always approve final draft policies. It is important that an AUP keep up with technology changes. It must be clear when personal devices are allowed during business hours. In particular, mobile phone use is covered in many company policies today. Often, these policies also include an overview of the use of cameras. However, today few policies cover the use of the wearable devices that are becoming available. Google Glass, for example, can take a picture with a blink of an eye.
The AUP is an important tool to create a legal separation between the employer and employee. Little tolerance exists for employees who create unnecessary liability for the organization. For example, using company computers to harass or threaten others, or view obscene materials, could result in termination.
Confidentiality Agreement and Nondisclosure Agreement
A confidentiality agreement (CA), also known as a nondisclosure agreement (NDA), is a binding legal contract between two parties. It is a promise not to disclose to any third-party information covered by the agreement. The agreement needs to clearly define the information covered. This reduces problems that may arise between the two parties or any other party asked to resolve legal disputes.
These types of employment agreements are often made at the time of hire. They outline what information should not be disclosed outside the company. These agreements could bind the employee from disclosing company information after employment terminates.
The CA or NDA is often used to explore business opportunities before buying a product or service. Let’s say a company wants to hire a consultant to redesign a major computer application. Both parties would sign a CA. The company could then disclose its problems and the consultant would have more precise information
to base an estimate. The CA would bind both parties even if the company decided not to hire the consultant.
NOTE
Not all CAs and NDAs are written the same way. They can be one-sided, granting excessive rights or penalties to one side. They should be reviewed by the legal department before being signed.
Security policies typically include guidance when a CA or NDA should be required. Most security policies require such agreements to be in place before any data can be exchanged. This includes requiring such agreements to cover employees and non-employees, such as temporary or contract workers. This is especially important for non-employees who may not go through the company’s normal security awareness training.
Business Liability Insurance Policies
Business liability insurance lowers the financial loss to the business in the event of an incident. Even when a business has well-defined security policies, problems can still occur. Business liability insurance will pay for losses within the limits of the policy.
Business liability insurance can be issued to both organizations and individuals. For example, a computer engineer performing consulting services could obtain professional liability insurance. Such a policy would cover any successful claims that the engineer was negligent or made errors. The same type of coverage would apply to large companies facing claims that their product or services were negligent or in error. The provisions of the coverage need to be examined closely. For instance, coverage may be dependent on the company complying with industry norms. What does that mean? Let’s say you are maintaining a company Web site. Standards in your particular industry may dictate that you must perform annual penetration testing. Failure to perform the test or to comply with your own policies could lead to your insurance claim being denied.
An important benefit of this insurance coverage is the payment of legal fees. Even when a company is found innocent, the legal costs can be substantial. These policies do have limits, conditions, and requirements that the policyholder must meet. These policies also have exclusions. They do not protect a company that has committed illegal acts. Overall these policies are another tool to further reduce the risk.
Implementing Policies to Drive Operational Consistency
Operational consistency means ensuring that an organization’s processes are repeatable and sustainable. The business goal is to have these processes executed each time with the same consistency and quality. This reliability allows the business to continuously improve quality. Processes evolve over time and the more repeatable a process can be, the more likely it is that risks can be detected and removed.
You can implement security policies the same way. This ensures that the same consistency and quality are applied to protection of information. What is meant by “a repeatable process” or “consistency”? It means when a particular risk is found again and again, the same process is used to address it each time. This consistent execution is often referred to as operational consistency.
Forcing Repeatable Business Processes Across the Entire Organization
Operational efficiency means lower costs to the business. By applying this principle across the enterprise, greater quality results can be achieved at a lower cost. For organizations with multiple divisions, developing processes once and repeating them saves time and resources. This approach also allows the organization to develop centers of excellence. These centers are typically small teams with very deep knowledge of a subject area.
An enterprise view allows senior leaders to understand how risk affects the entire organization. Someone with an enterprise view can see past the individual part to the entire structure. Such a person can see the forest and not just the trees. A single tree or group of trees might have root rot. However, the overall health of the forest may be good. This means you have a problem, but it is localized. Conversely, individual process failures may seem insignificant, but collectively they may indicate a systemic problem.
This is particularly important when it comes to security policies. Leadership needs a high level of certainty that there is operational consistency in how information is protected. Leadership is often asked by regulators to attest to security controls. For example, the chief information officer (CIO) under the Sarbanes-Oxley (SOX) Act is required to describe IT security controls goals. Many CIOs point to their company’s enforced security policies.
Policies Are Key to Repeatable Behavior
To achieve this repeatable behavior, you must measure both consistency and quality. Additionally, you will need to measure whether the implemented policy is achieving the desired results. It is not surprising to find processes that run for years while providing no real value. A typical example might be a report that was specially designed for an executive who has since left the company. The new executive continues to receive the report. He or she may even occasionally review it out of curiosity. But the executive never leverages its content for any real purpose. This report might be highly repeatable and sustainable but does not provide value.
Security policies drive operational consistency by enforcing how information is handled the same way within business processes. Policies also force close oversight and measurement of the processes. Security policies often outline oversight requirements. They explain which measurements should be captured and how often reporting is required. The following oversight phases are typically found when trying to achieve operational consistency:
• Manage—Manage process execution and note exceptions to standard procedures.
• Measure—Measure volume, consistency, and quality.
• Review—Periodically assess to ensure desired results are achieved.
• Track—Track defects, errors, and incidents.
• Improve—Improve quality continuously by making adjustments as needed.
TIP
Be sure to interview the individuals who perform the process. They will have insights beyond the measurements.
Differences Between Mitigating and Compensating Controls
A mitigating control limits the damage caused by not having a control in place. It assumes the absence or breakdown of a primary control. It is a control after the fact. For example, suppose someone enters an invalid account number. Either a control did not exist to prevent this, or that control did not work. Either way, as long the account number is validated before further action can be taken, there is a mitigating control in place. A mitigating control, however, may not achieve the full intent of a policy.
In contrast, a compensating control achieves the desired outcome and policy intent. It doesn’t necessarily
achieve it the way the policy says to do it. But the outcome is the same. Back to the example: Suppose before the account number can be entered, a master list of accounts is checked manually. Ideally the error would be caught immediately. But the manual check is still a preventive control. If the policy required an automated validation of all account numbers at time of entry, the system would be out of compliance. However, the manual check is a compensating control, and the risk is mitigated.
Understanding mitigating and compensating controls is essential in granting exceptions. What you must figure out is how much risk is left and whether that risk is acceptable.
Policies Help Prevent Operational Deviation
Operational deviation is inevitable. It’s important the intent be clear in a policy. From clearly communicated intent comes a better understanding of the desired outcome. Intent also helps employees know better what risks the company is not willing to take. It is impossible to foresee every possible circumstance. For one thing, security policies tend to cover broad topics. Second, technology is always evolving. Good policies allow the employee to apply the intent and understanding of risk to situations not explicitly outlined.
Operational deviation from policy in itself may not be a problem when there is a solid business reason. However, as the number of exceptions grows, the policy’s credibility is potentially reduced. Security policies are put in place to reduce risk. Deviating from those policies could increase the risk and prevent meeting legal obligations.
To balance these interests, most organizations have an exception process. This is also called a waiver process. Typically you submit a waiver request to a centrally managed team that reviews and approves the deviation. The waiver process examines the business rationale and tries to determine if the exception is necessary or not. When implementing a waiver process, the following should be considered:
• Independence—Be independent of the business unit seeking approval.
• Impact—Examine the risk to the entire organization.
• Benefits—Understand the business benefits.
• Mitigation—Identify security controls outside policy.
• Approvals—Residual risk should be formally accepted by management.
Residual risk is the risk that remains after security controls have been applied. When the business cannot comply with policy, the residual risk needs to be measured and compensating controls considered. A compensating control can reduce the same risk identified by policy but in a different way from what is outlined in policy. Ideally you want to implement compensating controls that reduce the same amount of risk identified in policy. If not, at least reduce some of the risk. When you cannot implement a preventive control as required by policy, consider using a detective control. These compensating controls may be outside policy but may be able to reduce some or all of the risk. Any remaining risk would then have to be properly approved. Proper approval includes vetting residual risk with those leaders who would be held accountable in the event the risk is realized. For example, if the application could not meet security policy requirements on protecting PII data, the CPO needs to approve the exception. Ultimately, if PII data is lost or stolen because of the policy exception, the CPO may have to explain to regulators why the exception was permitted.
CHAPTER SUMMARY
People manage risk every day of their lives. They choose when to go bed, when to wake up, what foods to eat, what route to drive their cars, and much more. Each decision has risk and rewards attached. This is no different in the business world. Many decisions face people daily. They often operate with incomplete information. They are faced with critical deadlines that could be more easily met by sharing information outside policy guidelines. As you gain experience, these decisions become more instinctive.
For business, it is daily processes and decisions that control risk. Policies provide guidance on how to think about risk. Policies and their related controls detail how to prevent, detect, and correct errors. This landscape of controls and processes makes risk management real for every employee. Most important, it encourages behavior that positively drives the organization’s risk culture.
KEY CONCEPTS AND TERMS
Acceptable use policies (AUPs)
Automated control
Breach
Chief privacy officer (CPO)
Compensating control
Confidentiality agreement (CA)
Corrective control
Data classification
Data encryption
Detective control
Digital assets
Full disclosure
Intellectual property (IP)
Label
Manual control
Mitigating control
Nondisclosure agreement (NDA)
Operational deviation
Personally identifiable information (PII)
Preventive control
Public record
Residual risk
Risk culture
Security awareness program
Security policy compliance
CHAPTER 2 ASSESSMENT
1. What is policy compliance?
A. The effort to follow an organization’s policy
B. When customers read a Web site policy statement
C. Adherence to an organization’s policy
D. Failure to follow to an organization’s policy
2. What is an automated control?
A. A control that stops behavior immediately and does not rely on human decisions
B. A control that does not stop behavior immediately and relies on human decisions
C. A control that does not stop behavior immediately but automates notification of incident
D. A control that stops behavior immediately and relies on human decisions
3. Which of the following is not a business driver?
A. Ability to acquire the newest technology
B. Cost of maintaining controls
C. Ability to legally defend
D. Customer satisfaction
4. A firewall is generally considered an example of a ________ control.
5. What is an information security policy?
A. A policy that defines acceptable behavior of a customer
B. A policy that defines what hardware to purchase
C. A policy that defines how to protect information in any form
D. A policy that defines the type of uniforms guards should wear
6. Which of the following is not a type of security control?
A. Preventative
B. Correlative
C. Detective
D. Corrective
7. Tone at the top refers to:
A. A company’s leaders making sure every employee knows the priorities
B. Senior leaders implementing and enforcing policies
C. Senior managers building trust with the public and with regulators
D. All of the above
8. Privacy regulations involve two important principles: full disclosure and data encryption.
A. True
B. False
9. What are the benefits to having a security awareness program emphasize the business risk?
A. Risk becomes more relevant to employees
B. Security policies are more likely to be followed
C. Provides employees a foundation to deal with unexpected risk
D. All of the above
10. Which of the following is not a guideline to be considered when developing policy to secure PII date?
A. Align—Coordinate privacy policies with data classification policies
B. Retain—Ensure proper controls around data retention and destruction
C. Disclose—Fully disclose to the individual what data is being collected and how it will be used
D. Resiliency—Policies provide guidelines for the unexpected
11. Information used to open or access a bank account is generally considered PII data.
A. True
B. False
12. Which of the following is not a benefit of having an acceptable use policy?
A. Outlines disciplinary action for improper behavior
B. Prevents employees from misusing the Internet
C. Reduces business liability
D. Defines proper behavior while using the Internet
13. Mitigating controls always meet the full intent of the policy.
A. True
B. False
14. Which of the following do you need to measure to achieve operational consistency?
A. Consistency
B. Quality
C. Results
D. All of the above
15. Well-defined and properly implemented security policies help the business in which of the following ways?
A. Maximize profit
B. Reduce risk
C. Produce consistent and reliable products
D. All of the above
ENDNOTES
1. “Intellectual Property Law Definition.” (Legal-definitions.com, n.d.). http://www.legal- definitions.com/IP/intellectual-property-law.htm (accessed March 5, 2010).
2. “Definition of: digital asset.” (Pcmag.com, 2010). http://www.pcmag.com/encyclopedia_term/0,2542,t=digital+asset&i=41283,00.asp (accessed March 5, 2010).
3. “Safeguarding Against and Responding to the Breach of Personally Identifiable Information.”
(Whitehouse.gov, Office of Management and Budget memorandum, May 22, 2007). http://www.whitehouse.gov/omb/memoranda/fy2007/m07-16.pdf (accessed March 6, 2010).
CHAPTER
3 U.S. Compliance Laws and Information Security Policy Requirements
IN RECENT YEARS globalization has been driven by technology and the growth of the Internet. More than 2.3 billion people worldwide have access to the Internet, according to a Brookings Institution report published in February 2013.1 Equally impressive, in 2013, 77 percent of individuals in developed countries had access to the Internet, according to the SUNY Levin Institute.2
Additionally, the expansion of Internet access continues to grow rapidly in developing countries. The Internet’s explosive reach has created global economic opportunity never seen before. You can see this in products you buy every day. Technology has helped create a global supply chain that delivers, to consumers worldwide, an array of low-cost goods that would have been unimaginable just a few years ago.
But all this has come at a price. Privacy has become an issue. People may feel, not unreasonably, that every action they take is being captured. Cellphones leave computer records of who called whom. Social media provide channels for cyberbullying in schools. Hackers have been able to steal massive amounts of credit card information through the Internet. And countries have used the Internet to launch attacks on other countries.
In February 2014, President Obama declared, “Cyberterrorism is [the] country’s biggest threat.”3 In general, cyberterrorism, or cyberwarfare, refers to an attempt to cause fear or major disruptions in a society through hacking computers. The idea is to attack government computers, major companies, or key areas of the economy. Such attacks can come from terrorist groups or individuals, as well as nation-states (sovereign countries). But given the resources involved, it shouldn’t be surprising that cyberterrorism is often sponsored by nation-states.
No government can sit on the sidelines with so much at stake. In the United States, the federal and state governments establish laws that define how to control, handle, share, and process the sensitive information that this new economy relies on. Much of that information is about you. It’s personal data about your finances, health, buying habits, and more. To these laws are added regulations, typically written by civil servants to implement the authority of the law. Regulators are the individuals or entities who help enforce these rules. Industry groups also try to self-regulate, which means they create standards their members must follow. Failure to follow regulations or industry standards can result in fines or limits placed on a company’s ability to operate. Gross violations of regulations can be seen as violation of criminal law. These violations can result in the arrest of officers of the company and possible jail time.
This chapter discusses major government laws and their compliance requirements. When the term regulations appears in this chapter, it means those that relate to U.S. laws. You will read how these requirements will influence security policies. You will read about major drivers for the regulations and the importance of protecting personal privacy. You will see how to create compliant polices, standards, procedures, and guidelines. The chapter also examines industry standards that drive security policies. Any one of these laws or standards could take up the pages of an entire book. But the focus here is on high-level principles that drive security policies and controls.
Chapter 3 Topics
This chapter covers the following topics and concepts:
• What U.S. compliance laws are and why they are important
• Who is protected by these laws
• How security policies are influenced by the laws
• What approaches are used to make security policies, standards, procedures, and guidelines comply with regulations
• What industry leading practices are
• Why industry standards are important
Chapter 3 Goals
When you complete this chapter, you will be able to:
• Compare and contrast different U.S. compliance laws
• Describe regulations and their importance in organizations
• Describe government drivers to implement regulations and their importance in maintaining compliance with laws
• Define cyberterrorism and the nation-state threat
• Explain approaches to align policies with regulations
• Explain leading practices and how they fit into the industry
U.S. Compliance Laws
Tremendous economic benefits flow from private markets. These benefits often rely on the use of technology. There is no single way of looking at government’s role in regulating or intervening in these markets. However, government is concerned with consumer protection, promoting a stable economy, and maintaining a reliable source of tax revenue. The government must balance these needs against the threat of cyberterrorism. All of these drivers are linked. If people feel safe using the Internet to buy goods and services, a stable economy emerges. People also have to trust the government to keep them safe. When you have a stable sector of the economy, government has a reliable source of tax revenue. It is good to understand what drives government regulations. In the end, government regulations are mandates. Security policies must achieve their goals while balancing business needs. You will see that organizations put stronger security in areas where the perceived threats to resources or employees are greater.
When you implement security policies, remember that there are pressures and tradeoffs. For example, you may have to place restrictive controls on data to comply with a regulation that limits how your business operates. If your company is part of the country’s critical infrastructure, there may be certain security policies it must comply with. As you balance competing interests, you must talk to business leaders to understand their priorities and issues. Security policies reflect how the business wishes to balance competing interests.
NOTE
Key elements of the country’s transportation, energy, communications, and banking systems are referred to as its critical infrastructure. Examples are power companies, oil and gas pipelines, and large banks.
FIGURE 3-1 Pressures on security policies.
Shareholders of a company are investors who expect to make money. Maximizing profit and maintaining a healthy stock price is a business concern. The government focuses more on fairness, health, and safety issues. One of the challenges organizations face is the cost of keeping pace with ever-changing technology. This includes the need to update policies at the same time the organization updates technology. Failure to do so could create weaknesses in the system. These weaknesses could make business processes out of compliance with industry and government regulations. The role of well-defined security policies is to be clear and concise on how these goals and vulnerabilities will be addressed. Figure 3-1 illustrates these competing interests—shareholder value, technology vulnerabilities and limitations, and regulations.
Government agencies that regulate information handling exist at the federal and state levels. These agencies sometimes have competing interests. As a result, laws often overlap requirements but are written from different perspectives. A federal banking regulation, for example, might define data privacy differently than a state law does. Competing regulatory agencies may have different missions and use different enforcement tools. Compliance can be difficult and costly with conflicting language and different interpretations. For example, a large U.S.-based bank needs to comply with hundreds of regulations.
Staying compliant means incurring the cost to keep up with changes in many laws, continually documenting evidence of compliance, and dealing with onsite visits of regulators. Staying compliant with regulations can be a distraction for businesses and the technology teams that support them. Yet they are very important. In large companies, compliance teams act as a go-between for the technical staff and regulators. These compliance teams know the regulations and requirements. They obtain information from the technical teams. The compliance teams meet with regulators. These are usually specially trained individuals who know company policy, the company’s technological capability, and the law. This allows the technical staff to stay focused primarily on delivering technological solutions.
What Are U.S. Compliance Laws?
What are the major concerns of U.S. regulations? How do you manage competing interests in security policies? As much as these regulations might differ, there are also common concepts. In recent years there has been increased partnership between the U.S. government and private companies. This partnership comes in many forms, such as the sharing of good security policies and the sharing of resources to investigate hacking incidents. Most notably, the government now shares intelligence information about threats and the type of attacks that might occur. In February 2013 the White House issued an executive order for key agencies to share cyberthreat information with private companies.4 This sharing of cyberthreat information
helps companies better defend themselves.
The best approach to regulatory compliance is common sense. Rather than building rules into security policies for each regulation, you should build in the key control concepts found in many regulations. By mapping these key control concepts to specific security policies, you can quickly demonstrate compliance across a broad set of regulations. If you can master these concepts, you can learn how to recognize these principles in regulations. This gives you the basic tools needed to keep your security policies compliant.
In this chapter, it’s not possible to discuss all key concepts for information security in every U.S. regulation. Instead, you will learn about several major regulations. These regulations deal with consumer rights and personal privacy. These laws protect consumers from potential scams and ensure the privacy of personal information. Consumer rights in e-commerce broadly deal with creating rules on how to handle a consumer’s transaction and other information. Personal privacy in e-commerce broadly deals with how to handle personal information and what it is used for. Table 3-1 identifies key concepts found in many regulations that influence what will appear in your security policies.
Federal Information Security Management Act (FISMA)
The Federal Information Security Management Act (FISMA) is a good example of government self- regulation. The federal government is unique in that it can identify the standards it wants to follow and passes laws requiring the standards to be followed. FISMA was put into law in 2002.
FISMA requires government agencies to adopt a common set of information security standards. Some parts of the government go beyond these standards, such as the military. For many government agencies, FISMA creates mandatory requirements to ensure the integrity, confidentiality, and availability of data. If your organization processes data for the government, you may be required to follow these same standards. FISMA also requires that agencies send annual reviews to the Office of Management and Budget (OMB). For example, an audit of the Veterans Affairs (VA) Department in 2012 found 15,000 security policy violations. As a result the VA was found to be noncompliant with FISMA.
The National Institute of Standards and Technology (NIST) is responsible for developing FISMA-mandated information security standards and procedures. Each agency is then responsible for adopting them as part of their agency’s information security policies. NIST standards, processes, and guidelines are available at http://csrc.nist.gov/publications/PubsSPs.html.
TABLE 3-1 Key concepts contained in U.S. compliance laws affecting information security policies.
CONCEPT OBJECTIVE
Full disclosure The concept that individuals should know what information about them is being collected. A company must give written notice on how it plans to use your information.
Limited use of personal data
The key idea is that the company can use the information collected only for the immediate service provided, or transaction made, such as a purchase. For example, assume a bank just approved your credit card purchase of ski equipment. In most states the bank could not then share that information with someone who will try to sell you a ski vacation.
Opt-in/opt-out The practice of asking permission on how personal information can be used beyond its original purpose. For example, a real estate company might ask permission of someone who sold their home if their information can be shared with a moving company.
Data privacy A company must tell an individual how personal information will be protected and limits
placed on how the data will be shared.
Informed consent
The concept that someone is of legal age, has the needed facts, and is without undue pressure to make an informed judgment.
Public interest The concept that an organization has an obligation to the general public beyond its self- interest. It’s a vague term, but it’s not unusual for regulators to look at the impact an organization has on the industry or the economy in general.
NIST publications outline a complete set of security standards and processes. To be compliant, your policies must include key security control requirements. Some of these key requirements include:
• Inventory—The NIST standards require an inventory of hardware, software, and information. The inventory identifies the type of information handled, how data passes to the systems, and special attention to national security systems.
• Categorize by risk level—The NIST standards require the inventory to be classified. The idea is that this classification will highlight higher-risk areas that need more protection.
NOTE
The difference between opting in and opting out generally refers to clicking a box on a Web page. In an opt- in process, unless the consumer clicks the “Yes” box, no additional service is offered. In an opt-out process, the consumer is automatically enrolled in a service unless he or she clicks the “No” box or de-selects the “Yes” box.
• Security controls—The NIST standards outline which controls should be applied and when. They outline how these controls are documented and approved. It is a risk-based approach giving some flexibility to the agency to tailor controls to meet its operational needs.
• Risk assessment—The NIST standards require risk assessments to be performed. Risk assessments are an essential part of a risk-based security approach. The risk assessment results drive the type of security controls to be applied.
• System security plan—The NIST standards require a formal security plan for major systems and for the system or application owner. The security plan serves as a road map. It is updated to keep current with threats and is an important part of a certification and accreditation process.
• Certification and accreditation—This process occurs after the system is documented, controls tested, and risk assessment completed. It is required before going live with a major system. Once a system is certified and accredited, responsibility shifts to the owner to operate the system. This process is also referred to as the “security certification” process.
• Continuous monitoring—All certified and accredited systems must be continuously monitored. Monitoring includes looking at new threats, changes to the system, and how well the controls are working. Sometimes a system has so many changes that it must be re-certified.
Health Insurance Portability and Accountability Act (HIPAA)
The Health Insurance Portability and Accountability Act (HIPAA) became law in 1996. The law protects a person’s privacy. If you handle someone’s health records, you must adhere to HIPAA. This includes doctor’s offices, hospitals, clinics, and insurance companies. The law recognizes that digital data exchange of health
records, such as between insurance companies and doctor’s offices, is a necessity. But in 2013 new restrictions were placed on access to health records by subcontractors and vendors. The law wants to make sure that patient privacy is maintained.
The HIPAA law defines someone’s health record as protected health information (PHI). The term PHI refers to both digital and physical paper copies of health records. Electronic PHI (EPHI) refers to just the electronic form of PHI records. HIPAA establishes privacy rules that outline how EPHI can be collected, processed, and disclosed. There are significant penalties for violating these rules. In 2013 these fines were increased to a maximum of $1.5 million per violation. This regulation applies to any covered entity that manages health records, including:
FYI
The U.S. Department of Health and Human Services has several publications on HIPAA privacy and security standards at http://www.cms.hhs.gov/HIPAAGenInfo/04_PrivacyandSecurityStandards.asp.
• Health care providers—Doctors, hospitals, clinics, and others
• Health plans—Those that pay the cost for the medical care such as insurance companies
• Health care clearinghouses—Those that process and facilitate billing
• “Business associates”—Vendors and subcontractors of any covered entity
NOTE
In January 2013, new HIPAA rules were issued to improve privacy rights. Key provisions of these new rules are:
• Increased fines, of up to $1.5 million per violation
• New requirements on sharing information with contractors
• Stricter requirements on reporting breaches
• Requirements for improved privacy notices
For your security policies to be HIPAA-compliant, they must include the following key control requirements:
• Administrative safeguards—Refers to the formal security policies and procedures that map to HIPAA security standards. It also refers to the governance of the security policies and their implementation.
• Physical safeguards—Refers to the physical security of computer systems and the physical health records.
• Technical safeguards—Refers to the controls that use technology to protect information assets.
• Risk assessment—Refers to a standard requirement of a risk-based management approach to information security.
Gramm-Leach-Bliley Act (GLBA)
The Gramm-Leach-Bliley Act (GLBA) became law in 1999. The law is not focused on technology. Rather, it was meant to repeal existing laws so that banks, investment companies, and other financial services companies could merge. Prior to GLBA, banks, for example, were restricted on the types of products they could offer. However, under what is known as Section 501(b), the law outlines information security requirements for the privacy of customer information.
The law is enforced through regulators who are members of the Federal Financial Institutions Examination Council (FFIEC). The FFIEC publishes booklets of what type of computer security policies and controls must be in place for an institution or company to be compliant with GLBA. These booklets define availability, integrity, confidentiality, accountability, and assurance as key objectives.
FYI
The FFIEC booklets are used by many government agencies. They are available to the public. Aligning security policies to these booklets will help keep a company compliant with government regulations. See http://ithandbook.ffiec.gov/it-booklets/information-security/information-security-strategy/architecture- considerations/policies-and-procedures.aspx.
FYI
GLBA applies to any financial institution defined as “any institution the business of which is engaging in financial activities as described in section 4(k) of the Bank Holding Company Act (12 U.S.C. § 1843(k)).” This is broadly defined to mean any organization that lends, exchanges, transfers, invests, or safeguards money or securities. Generally any company that deals in credit or loans would be covered. This includes businesses offering payment plans, such as car dealerships commonly offer.
The FFIEC booklets are publicly available through the council’s Web site. The following Web site introduces the 501(b) rules: http://ithandbook.ffiec.gov/it-booklets.aspx.
To be GLBA-compliant, your security policies must include the following key components:
• Governance—Requires a strong governance structure in place. This includes designating someone in an organization as accountable for information security. This is often the chief information security officer (CISO) or chief information officer (CIO). Most boards receive formal GLBA reporting through the audit committee. The head of information security usually writes this report each quarter.
• Information security risk assessment—Requires a well-defined information security risk assessment to identify threats, potential attacks, and impacts to the organization.
• Information security strategy—Requires a formal security plan to reach compliance.
• Security controls implementation—Requires a process to properly design and install security controls that meet the security plan objectives.
• Security monitoring—Requires continuous monitoring of security controls. This is to ensure that the design meets the objectives. This is event-based monitoring and includes incident response.
• Security monitoring and updating—Requires monitoring of trends, incidents, and business strategies, and appropriate updates to the security plan.
Sarbanes-Oxley (SOX) Act
The Sarbanes-Oxley (SOX) Act became law in 2002. The law was enacted in reaction to a series of accusations of corporate fraud. Some companies were accused of “cooking the accounting books” or making illegal loans to their top executives. Companies such as Enron and WorldCom became symbols of corporate greed and corruption. Enron filed for bankruptcy in 2001 amid accusations of cooking the books to inflate its stock price. WorldCom filed for bankruptcy in 2002 amid accusations of illegal loans to its chief executive officer (CEO), as well as billions in accounting fraud to inflate the stock price. These two highly visible corporate fraud cases shook shareholder and public confidence. SOX was enacted to restore confidence in the markets.
NOTE
SOX requires annual testing of controls. It not enough, under SOX, to have security policies. SOX also requires that the controls in the security policies be tested to ensure they are working. SOX does not apply to privately held companies.
SOX goes well beyond information security policies. It also describes how a company should report earnings, valuations, corporate responsibilities, and executive compensation. The act is intended to improve the financial accuracy and public disclosure to investors. In fact, some argue the act goes too far and is too costly. This chapter focuses on those portions that affect security policies known as SOX 404.
The basic idea behind SOX 404 is to require security policies and controls that provide confidence in the accuracy of financial statements. In other words, security policies must ensure the integrity of the financial data. Independent testing of these controls is required. Additionally, top executives are required to sign off quarterly that these controls meet SOX 404 requirements or explain why they did not.
One of the challenges of SOX is cost. It is very expensive and nearly impossible to test all a company’s controls. This test of all possible controls drew many complaints from companies. So in 2007, the government changed the rules for SOX. The change allowed companies to limit testing to only the most important controls—those in areas of high risk. This lowered costs for many companies. It also made it easier for a company to prove it was compliant. All security controls are important. Well-written security policies highlight key controls to indicate which are most important.
The act created the Public Company Accounting Oversight Board (PCAOB). The PCAOB sets accounting and auditing standards. The Securities and Exchange Commission (SEC) is responsible for enforcing SOX. The challenge for information security is that SOX 404 sets broad IT objectives. It does not define how to comply. Rather than developing new information security and control standards, the PCAOB and SEC have endorsed using industry best practice frameworks. The following are endorsed frameworks that companies commonly use to meet SOX 404 requirements. These frameworks are widely used by external auditors as well to certify SOX compliance:
• Committee of Sponsoring Organizations (COSO)—As it relates to security policies, this organization creates rules for implementing internal controls and governance structures.
• Control Objectives for Information and related Technology (COBIT)—Created by ISACA, formerly known as the Information Systems Audit and Control Association. This framework is an internationally recognized best practice.
FYI
ISACA has a number of publications publicly available through its Web site. You can find an executive summary of COBIT 5.0 at http://www.isaca.org/COBIT/Pages/default.aspx?cid=1003566&Appeal=PR.
COBIT in many ways is “one-stop shopping” for SOX security policies and controls. The controls within COBIT are a rich range of activities: strategic planning, governance, life cycle, implementation, production support, and monitoring. The framework fits in and supports the COSO framework. The COBIT framework allows COSO to focus on the business side while COBIT focuses on the IT side. By leveraging both, you are able to bridge control requirements, technology issues, business risk, and shareholder concerns. The reason the framework is so popular among regulators, auditors, and IT risk professionals is that if you implement the COBIT framework, you are most likely SOX 404-compliant.
Family Educational Rights and Privacy Act (FERPA)
The Family Educational Rights and Privacy Act (FERPA) was put into law in 1974. This law applies to educational institutions such as college and universities. Any educational institution must protect the privacy of its student records and must provide students access to their own records. This gives students a way to correct errors and control disclosure of their records.
The Family Policy Compliance Office of the U.S. Department of Education enforces the act. The law broadly defines education records as any information related to the educational process that can uniquely identify the student. This has been widely interpreted as any student information from financial means to class lists to grades. The student records can be in any form from handwritten notes to digital files. There are exclusions such as law enforcement or campus security records. For the purpose of this discussion, the important point is that this broad set of student records (in any form) must be protected.
To be FERPA-compliant, security policies must contain the following key elements:
• Awareness—The school must post its FERPA security policies and provide awareness of them.
• Permission—Generally, schools must have recorded permission to share the student’s education records.
• Directory information—The school can make directory information (such as name, address, telephone number and date of birth) about the student publicly available but must provide the student with a chance to opt out of such public disclosure.
• Exclusions—The school can share information without permission for legitimate education evaluation reasons as well as for health and safety reasons.
Security policies must ensure records are kept when student permissions are not obtained under the exclusions. In addition, policies must ensure that opt-in and opt-out records are properly maintained for historical purposes to record student permissions.
FYI
The U.S. Department of Education provides a general and detailed FERPA publications Web site at http://www2.ed.gov/policy/gen/guid/fpco/ferpa/index.html.
In January 2013, two important changes were made to the law. First, it became easier to share records with child welfare agencies. For example, this would allow child welfare agencies to confirm that children under foster care are actively attending school. Second, the change eliminates some requirements to notify parents when school records are being released—to a court, for example.
Children’s Internet Protection Act (CIPA)
The Children’s Internet Protection Act (CIPA) was put into law in 2000. The law tells schools and libraries
that receive federal funding that they must block pornographic and explicit sexual material on their computers. The law attempts to limit children’s exposure to such material.
The Federal Communications Commission (FCC) establishes the rules that schools and libraries must follow. The CIPA regulation was challenged in a lawsuit. The Supreme Court heard the lawsuit. The basis of the challenge is that restricting access to information is unconstitutional. Additionally, there were questions about whether the technology would end up blocking sites not originally intended by the law. The result of the court challenge was mixed. The court held that the CIPA law was constitutional. However, the courts do require schools and libraries to unblock sites when requested by an adult. The FCC has several publications on CIPA available at http://www.fcc.gov/cgb/consumerfacts/cipa.html.
Here are key CIPA components that your security policies must include:
• Awareness—The school or library must post its CIPA security policies and provide awareness of them.
• Internet filters—Best efforts must be made to keep Internet filters current so that only the targeted material intended by CIPA is blocked.
• Unblocking—There must be a process to allow the filter to be unblocked or disabled for adults who request access to blocked sites.
• Education—Children must be provided education on Internet safety and on cyberbullying and how to respond.
FYI
In 2012 the CIPA was changed to include requirements to educate young people about Internet safety. The changed law said, “Beginning July 1, 2012, schools’ Internet safety policies must provide for educating minors about appropriate online behavior, including interacting with other individuals on social networking Web sites and in chatrooms and cyberbullying awareness and response.”
Why Did U.S. Compliance Laws Come About?
These laws recognize the power of information. The more personal the data, the more powerful the information. Many changes in law relate to privacy. These changes range from how personal information is collected to how it is used, and what type of written notice must be given. The power comes from the impact that personal information has in our lives. It affects what type job we can get, the car we can buy, and the home we can afford. It also determines the quality of medical care we receive. The misuse and abuse of this information is equally powerful and can make our lives miserable. Identity theft is a major problem. It can take years of effort to restore a credit rating. You’ve surely heard stories of millions of credit cards stolen each year. While slow to react, the government does respond to emerging national threats and public pressure.
Many of these laws have come about to protect our personal privacy and to limit how companies can use the information they collect. On the other hand, the sharing of information across government agencies has increased. When millions of citizens’ personal data is lost or stolen, many questions are raised. It’s hard to know exactly how many breaches occur each year. It is estimated that in the United States alone, there have been more than 4,000 data breaches since 2005. This has resulted in more than 600 million records containing personal information being stolen. A host of personal information is associated with these records, including Social Security numbers, bank account information, health records, and more. Even if these numbers are wrong (and many believe they are too low), they reflect the real danger facing society. The cost to business is high, and so is the cost to individuals. As a result, a number of regulations in recent years have come about to require organizations to do what they can to prevent such breaches. These regulations hold an
organization accountable when breaches occur.
Whom Do the Laws Protect?
Is an individual’s privacy the government’s sole concern? No, it is not. These laws have four major beneficiaries:
• Individuals—A number of laws focus on protecting an individual’s private information.
• Shareholders—A number of laws are designed to provide confidence in the markets. When investors feel that a company’s financials and risks are properly managed, the investors feel they can make informed judgments. This promotes a healthy economy.
• The public interest—This term reflects the idea that an organization has an obligation to the general public beyond their self-interest. Although this is a vague term, regulators often look at the impact a company has on the industry group or the economy in general.
• National security—The idea is that cyberterrorism threatens not only the company being targeted but also the country’s critical infrastructure.
To be clear: The world is not perfect, and the goals of regulations are not always achieved. In fact, sometimes regulations get in the way of doing the right thing when outdated regulation gets in the way of good security policies. Regardless of the value you place on regulations, you shouldn’t treat them as abstract concepts. Regulations do affect security policies. They limit how business can collect, store, and process information. Security policies are looked to as a way to ensure compliance with government mandates.
It’s an accepted concept that when everyone has to follow the same rules, the playing field is level. Without regulation, companies feel the pressure to take shortcuts to maintain competitive advantage. Regulations remove some of this pressure because everyone must comply. In other words, doing the “right thing” becomes not a matter of cost or advantage, but part of the business culture and the law.
Which Laws Require Proper Security Controls to Be Included in Policies?
You cannot design effective security controls without good security policies. It’s important to create and enforce policies that demonstration compliance with regulations. This is true of organizations of all types, including business and government. But there is no cookie-cutter approach—each entity will have its own way of implementing and enforcing policies.
Regardless of the information being protected, a security control needs to be designed and implemented to enforce the control. If a law requires any type of information protection, the law requires proper security controls. This includes physical security controls to protect information in physical form such as paper reports.
NOTE
Every regulatory requirement on the handling of data should map to one or more security policies.
Which Laws Require Proper Security Controls for Handling Privacy Data?
This is a trick question. As a general rule, you should consider that all laws in some way require controls over the handling of data. They may vary, though, in their requirements and specific obligations. Well- written policies, rather than focusing on one law, will tend to satisfy regulatory requirements by fostering
sound security practices across the enterprise. Additionally, always remember you have both a legal and an ethical responsibility to your customers. And you have an obligation to shareholders to protect the company. This includes protecting customers’ personal information, even when a law doesn’t explicitly call for privacy controls. As a practical matter, a breach of customer information could leave the company facing a long and costly lawsuit. Consequently, it’s simply good business to protect customers’ personal information. Security policies should reflect this thinking—for example, a need-to-know policy, which would limit access to data to just those employees who require the information to perform their jobs. This is a simple security principle that shows customers you are protecting their interest.
A good rule of thumb is whenever your organization handles personal information, you should be sure your security policies and controls protect privacy. If you are not currently obligated to do so, there’s a good chance at some point you will be, whether at a state or federal level. Over time, it’s far less expensive and easier to implement core privacy principles, such as those in Table 3-1, and then to implement specific controls to keep pace with each changing law. One can also argue it’s simply the right thing to do.
The only conflict comes when an organization wants to use the information beyond the scope of these core principles. At that point, management should determine if using the information violates current law. Another key consideration is whether the use of the data violates the trust agreement with the customer. This includes both the privacy notice given to the customer and the organization’s core values. If the law allows, and customer trust is deemed not at risk, then a determination can be made to either change the core principles or make an exception. This pushback from business to use information beyond the core principles is healthy. It results in a candid conversation with the business about current regulations and the values the organization wants to embrace. The approach results in better understanding of the law, greater awareness of core organizational values, and a stronger foundation of controls.
TIP
An organization’s privacy or compliance officer is a good source for determining what should be in security policies to meet regulatory requirements.
Aligning Security Policies and Controls with Regulations
You have reviewed six major laws at a high level and their affects on security policies and controls. Depending on your organization, you may have hundreds of laws to deal with. So how do you cope? There are many factors you must consider to ensure your security policies and controls align with regulations, such as the following:
• Inventory—Make sure you have a solid inventory of hardware, software, and information. You need know to where the information is collected, stored, and processed.
• Business requirements—Your business is ultimately accountable to regulators. Ensure the business understands the data handling requirements of each regulation. Ensure that there is an acceptable use policy for the handling of different kinds of data. For example, is the customer presented with an opt-in or opt-out check box? Even these simple choices may have regulatory implications.
• Security policies—Security policies need to reflect these business requirements. It’s equally important to establish a core set of principles, such as those in Table 3-1. These core principles allow you to educate the business and address a significant number of regulations.
• Security framework—The selection of a security framework allows you to show regulators that you are using best practices. Use widely accepted standards, procedures, and guidelines.
• Security control mapping—When you build security controls, be sure to map them to the related policy or policies. Policies also map to regulations. Security control mappings are important to demonstrate coverage of regulatory requirements. They show the importance of each security control. Ideally, you also want to map security controls to the security framework. This will provide a comprehensive end-to-end overview of security.
• Monitoring and testing—Your organization must monitor and test any security control related to regulatory compliance. You should try to monitor and test all security controls. If you cannot, prioritize the controls starting with the most important ones.
• Evidence—At some point you will be required to provide regulators with evidence. Regulators want to see a well-thought-out approach to compliance. The security policies, framework, and control mapping is a good start. The mapping demonstrates a thorough understanding and intent to comply. Your monitoring and testing efforts also provide evidence that things are working as planned.
You learned earlier in the chapter that COSO and COBIT are widely accepted frameworks. Other frameworks are equally important. You should also be familiar with the publications from the International Organization for Standardization (ISO). Another important framework is the Information Technology and Infrastructure Library (ITIL). ITIL is a set of practices and predefined procedures for managing specific IT services such as change management. You will learn about ITIL later in this chapter.
Let’s look at how these frameworks help you build security policies and controls. Make sure you understand the security requirements for each regulation and your business. Also be sure to work with your compliance and legal department. It’s important that the policies reflect current regulatory requirements. Specialists in the compliance and legal department usually keep track of changing laws. Then you can start building or updating security policies, standards, controls, and procedures. The following is one approach:
1. Document the concepts and principles you will adopt.
2. Apply them to security policies and standards.
3. Develop security controls and procedures.
The typical approach involves moving from core security principles to implementing specific controls. Figure 3-2 illustrates this point using COSO, COBIT, and ITIL. In this example, COSO provides the necessary governance structure. Although COBIT defines policies and controls requirements, you can then define your procedures using ITIL predefined libraries.
The ability to map to existing standards and frameworks is powerful. This approach leverages years of experience across industries. It also provides confidence to regulators and auditors that you are properly managing risks. Even if you fail to document a risk, there’s a strong likelihood that the layered nature of the controls will mitigate the threat. It also reduces implementation time and produces high-quality policies, procedures, and security controls.
FIGURE 3-2 Security policies and controls mapping to frameworks.
The approach is straightforward. The ability to implement quickly is not. The challenge is not in the approach but in volume. As mentioned, you might have hundreds of regulations to follow. Consider even a small company may have hundreds of applications, while Fortune 500 companies will have thousands of applications. Multiply that by the number of users, the number of files, the number of devices, and the number of Internet connections and you begin to see the difficulties. You might have an untold number of controls. Suddenly the volume can get overwhelming. That’s why it’s important not to take shortcuts with the key considerations listed above. It’s important that a policy outline the governance and oversight requirements for maintaining those controls. You also need a rigorous process for building, inventorying, and maintaining security controls.
Industry Leading Practices and Self-Regulation
You learned how news stories and public pressure drive government regulations. They also drive many industries to more self-regulation. The hope is to demonstrate to the government and the public that these industries are aware of the problem and are taking action. An industry prefers to self-regulate for two key reasons, cost and flexibility. There’s a perception that regulations increase cost because they can be restrictive and require lots of compliance evidence to be collected. Additionally, regulations can require specific solutions to a problem. Retaining the flexibility to select from an array of solutions and apply new technology is one reason given to avoid regulations. The counterargument is that, without laws, industries won’t fully address problems.
Regardless of your viewpoint on the merits of regulation, the result is that industries create standards over time that may become best practices. The term best practices is commonly understood. However, it can be confusing when trying to understand industry standards. The term is overused and difficult to quantify. What does “best” compare with? Is a simple solution best because it costs the least? Or is a solution better because it is more reliable? Another term with more precision is leading practice, which is easier to quantify. If most members of an industry adopt a method, it’s considered to be “leading.” It might be the best solution, but that’s not always the case.
NOTE
Most information security professionals belong to associations or regional groups. There are also online communities. These communities share solutions and publish survey results. It’s important to take advantage of this knowledge to understand if you are using leading practices.
Regulated companies look to leading practices as one way to shield themselves from regulators. If regulators have confidence in a leading practice by virtue of adopting it, a company should be confident it is complying with the law. You may not always be able to apply the best solution, but it’s important to be able to tell a regulator that you do conform to industry norms.
Some Important Industry Standards
Payment Card Industry Data Security Standard (PCI DSS)
Payment Card Industry Data Security Standard (PCI DSS) is a worldwide information security standard that describes how to protect credit card information. If you accept Visa, MasterCard, or American Express, you are required to follow PCI DSS. These card companies formed the Payment Card Industry Security Standards Council to create the standard. The PCI DSS standard was released in 2006. The current version of PCI DSS is 3.0, released in 2013. The standard applies to every organization that stores, processes, or
exchanges cardholder information.
NOTE
In February 2014 PCI DSS 3.0 was released in nine languages. PCI is considered a global standard.
The standard requires an organization to have specific PCI DSS security policies and controls in place. The organization must also have these controls validated. If you are small merchant, you can perform a Self- Assessment Questionnaire (SAQ). Large-volume merchants must obtain their validation through a Qualified Security Assessor (QSA). Failing to validate, or failing the validation, can result in fines from the credit card companies. In extreme cases of noncompliance, you may be prevented from handling credit cards. Taking credit cards away could put you out of business.
The PCI DSS is an information security framework, so it contains a lot of technical requirements. Two in particular have been a challenge for organizations to implement: network segmentation and encryption. PCI DSS strongly encourages isolating credit card systems at a network layer. For many open network designs and shared systems, this is a challenge. If you cannot segment the systems that contain cardholder data, PCI DSS requires that all systems on that segment must comply with PCI DSS. This means if you have 20 systems on a segment and one processes credit card information, all 20 systems should comply with PCI DSS standards. This could be expensive. The second major challenge is encrypting data at rest. Encrypting data in transit is common over the Internet and public networks. Encrypting data at rest, however, can be technically challenging and at times not feasible.
TIP
The PCI DSS materials are free and publicly available through the PCI Security Standard Council Web site at https://www.pcisecuritystandards.org/.
There are six control objectives within the PCI DSS standard. To be compliant, you need to include these control objectives in your security policies and controls. These control objectives are:
• Build and maintain a secure network—Refers to having specific firewall, system password, and other security network layer controls.
• Protect cardholder data—Specifies how cardholder data is stored and protected. Also sets rules on the encryption of the data.
• Maintain a vulnerability management program—Specifies how to maintain secure systems and applications, including the required use of antivirus software.
• Implement strong access control measures—Refers to restricting access to cardholder data on a need-to- know basis. It requires physical controls in place and individual unique IDs when accessing cardholder data.
• Regularly monitor and test networks—Requires monitoring access to cardholder. Also requires periodic penetration testing of the network.
• Maintain an information security policy—Requires that security policies reflect the PCI DSS requirements. Requires these policies are kept current and an awareness program is implemented.
Statement on Standards for Attestation Engagements No. 16 (SSAE16)
The American Institute of Certified Public Accountants (AICPA) created the Statement on Standards for
Attestation Engagements No. 16 (SSAE16). It was issued in April 2010, replacing the widely accepted auditing standard referred to as SAS 70. An SSAE16 audit examines an organization’s control environment. This usually includes an audit of the information security controls. An SSAE16 allows an independent auditor (called a service auditor) to review an organization’s control environment. The service auditor then issues an independent opinion in a cover letter. The actual audit report and opinion is provided to the organization being examined.
NOTE
The AICPA has free publications available at http://www.aicpa.org/Research/Standards/AuditAttest/Pages/SSAE.aspx.
The popularity of an independent audit comes from the use of the opinion letters. Anyone trying to buy services from a vendor should ensure the data is protected. Organizations often request an opinion letter from a vendor to help build that confidence. Vendors often promote how well they passed an SSAE16 audit as a way of selling their services.
There is a mutual benefit in having an independent audit performed. To the customer, it provides some assurance that their vendor’s control environment has been audited. And the vendor can say there’s been independent opinion that the customer’s data is protected. A key area of examination is security policies. Having well-defined policies and evidence of their effectiveness is required as part of an SSAE16 review.
technical TIP
The opinion of the auditor depends in part on the scope of the SSAE16 review. When requesting the opinion, be sure to ask for the scope of the examination. This helps you understand the context of the opinion. For example, if you are concerned with whether a vendor can recover the system in case of an outage, be sure to ask whether backup and recovery controls were in the scope of the SSAE16 review. Simply obtaining an opinion that controls are working is not enough. You need to know which controls were tested.
Does an SSAE16 truly test if controls provide adequate safeguards to protect data? That depends in part on the type of SSAE16 audit performed. There are two types of SSAE16 audits:
• Type I—This is basically a design review of the controls. The auditor’s opinion would note if the controls are designed well. The audit also looks at documented policies and procedures. The opinion states if the policies, controls, and procedures could meet the control objective stated. This doesn’t mean the controls are working. It simply says that if the controls are executed, then they should work.
• Type II—Includes everything in Type I. In addition, the controls are actually tested to see if those controls are properly installed and working effectively.
Information Technology Infrastructure Library (ITIL)
The Information Technology Infrastructure Library (ITIL) is a series of books that describe IT practices and procedures. The collection of books originally came from a British government initiative. The first version was published in 1989 as ITIL v1.0. The current version as of this writing is ITIL 2011, which was published in 2011.
ITIL has evolved over time from over 30 booklets on different topics to a unified IT service management (ITSM) approach. ITIL focuses on the entire service life cycle. It outlines goals, activities, tasks, inputs, and outputs. It is seen as outlining the best management practices for IT.
The ITL official Web site states “ITIL provides a cohesive set of best practices, drawn from the public and private sectors internationally.”5 The concept behind ITSM is to use ITIL to optimize the IT infrastructure, lower costs, and improve quality.
FYI
ITIL is not free, and it can be expensive to buy the entire library. You can purchase just the ITIL books of specific interest. The official Web site has some free material at http://www.itil- officialsite.com/home/home.asp.
ITIL has five core books called volumes. The following outlines each of the five volumes:
• Service Strategy—Relates to how to define the governance and portfolio of services. This includes aligning to the business and IT finance requirements.
• Service Design—Relates to the actual design of the service and controls. Here is where you take into account all the business and technology concerns. For example, risk management, capacity management, availability, information security, and compliance are among the elements considered.
• Service Transition—Relates to the transition of services into production. For example, validation testing, release management, and change management are among the elements considered.
• Service Operation—Relates to ongoing support of the service. For example, incident and problem management, and access management, are among the elements considered.
• Continual Service Improvement—Relates to continuous improvement of the service. For example measuring, reporting, and managing service level agreements (SLAs) are among the elements considered.
CHAPTER SUMMARY
You learned in this chapter how important it is to conform to U.S. compliance laws. The chapter examined how technology and the Internet are driving globalization. With broad use of the Internet come new threats. You also learned the importance of compliance to the economy and how it serves the public interest. The chapter examined a number of major compliance regulations. From these examples, you can see an increasing government need to regulate. Sometimes regulations result from public pressure when something goes wrong. The chapter examined these pressures and motivations of both the government and the industry. The chapter also discussed how the industry tries to self-regulate to avoid government regulation to keep costs down and retain flexibility. You also read that the country faces new threats from nation-states trying to attack the country’s critical infrastructure.
The chapter also examined how security policies, controls, and procedures need to align with regulations. You read how to create this alignment. The chapter also examined how to show evidence of compliance to a regulator. You read about the challenges to comply with regulation and industry standards. You also read about the need to align security policies to both legal requirements and the company’s core values. Finally, a key lesson in this chapter is not to chase laws by building specific security policies and controls tailored to each new regulation. Rather, you should base policies on key concepts that address a broad range of regulatory concerns such as consumer protection and privacy.
KEY CONCEPTS AND TERMS
Chief information officer (CIO)
Chief information security officer (CISO)
Consumer rights
Critical infrastructure
Cyberterrorism
Data privacy
Evidence
Globalization
Information security risk assessment
Information Technology and Infrastructure Library (ITIL)
Internet filters
Nation-states
Opt-in
Opt-out
Payment Card Industry Data Security Standard (PCI DSS)
Personal privacy
Risk assessment
Security control mapping
Shareholder
Statement on Standards for Attestation Engagements No. 16 (SSAE16)
CHAPTER 3 ASSESSMENT
1. When creating laws and regulations, the government’s sole concern is the privacy of the individual.
A. True
B. False
2. Which of the following are pressures on creating security policies?
A. Shareholder value
B. Regulations
C. Technology vulnerabilities and limitations
D. B and C only
E. All of the above
3. Which of the following laws require proper security controls for handling privacy data?
A. HIPAA
B. GLBA
C. FERPA
D. B and C Only
E. All of the above
4. Which of the following are control objectives for PCI DSS?
A. Maintain an information security policy
B. Protect cardholder data
C. Alert when credit cards are illegally used
D. A and B only
E. None of the above
5. Nation-state attacks that try to disrupt the country’s critical infrastructure are sometimes referred to as ________.
6. Health care providers are those that process and facilitate billing.
A. True
B. False
7. The law that attempts to limit children’s exposure to sexually explicit material is ________.
8. The only consideration in protecting personal customer information is legal requirements.
A. True
B. False
9. You should always write new security policies each time a new regulation is issued.
A. True
B. False
10. What should you ask for to gain confidence that a vendor’s security controls are adequate?
A. An SSAE16 Type I audit
B. An SSAE16 Type II audit
C. A list of all internal audits
D. All of the above
11. Why is it important to map regulatory requirements to policies and controls?
A. To demonstrate compliance to regulators
B. To ensure regulatory requirements are covered
C. To demonstrate the importance of a security control
D. All of the above
12. Who typically writes a report to the board of directors on the current state of information security within a company?
A. Chief risk officer
B. Chief information officer
C. Chief information security officer
D. A and B
E. B and C
F. A, B, and C
ENDNOTES
1. Meltzer, Joshua, “The Internet, Cross-Border Data Flows and International Trade,” Issues in Technology Innovation, No. 22, February 2013, the Brookings Institution, http://www.brookings.edu/~/media/research/files/papers/2013/02/25%20international%20data%20flows %20meltzer/internet%20data%20and%20trade%20meltzer.pdf, p. 2, accessed March 9, 2014.
2. Globalization 101, “Advances in Information Technology,” SUNY Levin Institute, http://www.globalization101.org/advances-in-information-technology/, accessed March 20, 2014.
3. Harress, Christopher, “Obama Says Cyberterrorism Is Country’s Biggest Threat, U.S. Government Assembles “Cyber Warriors,” International Business Times, February 18, 2014, http://www.ibtimes.com/obama-says-cyberterrorism-countrys-biggest-threat-us-government-assembles- cyber-warriors-1556337, accessed March 9, 2014.
4. “Executive Order—Improving Critical Infrastructure Cybersecurity,” The White House, Office of the Press Secretary, February 12, 2013, http://www.whitehouse.gov/the-press-office/2013/02/12/executive-order- improving-critical-infrastructure-cybersecurity, accessed March 10, 2014.
5. ITIL, http://www.itil-officialsite.com/home/home.asp (accessed March 22, 2010).
CHAPTER
4 Business Challenges Within the Seven Domains of IT Responsibility
ORGANIZATIONS OF ANY SIZE can have millions of transactions occurring every day between customers, employees, and suppliers. Today, many systems are automated. They generate their own transactions in the form of online product queries, searches, inventory checks, authorization checks, and log entries. Tracking of product, pricing, invoicing, service calls, e-mail, instant messages, support tickets, and order processing all require data. One touch of a keyboard generates potentially hundreds of transactions in today’s complex business environment. All of this information needs to be protected. Whether the data is stored at rest on a hard drive or in transit over the network, regardless of form or method of access, threats to the information must be considered.
Reports predict that over 40 zettabytes of data will be stored digitally worldwide by 2020. A zettabyte is unit of measure equivalent to 1021 bytes of data. In context, 42 zettabytes is equivalent to storing every word spoken by every human in history.
The expanded use of social media, more widespread cloud and mobile computing, and increasing government surveillance programs are a few of the factors contributing to this growth. And future technologies just now being envisioned mean this growth trend will not stop in the foreseeable future. The large accumulation of data is often referred to as Big Data. The global society is wired. Among the items going into the vast global store of data may be a Tweet, a copy of an e-mail, an Internet search, or a copy of a receipt from retail store. This vast array of data is often unstructured, and for a market researcher or a government snoop, it may be a treasure trove of information that reveals a lot about an individual: his or her habits, interests, gender, associations, opinions, and much more.
What does this mean for business? It means new opportunities and new challenges. Businesses that understand how to mine this data will understand their customer needs. Companies that lose control over their data will put their customers and businesses at risk. This data is accumulated over years and is relatively static. Yet the law is not static. For example, as privacy laws change, what was once considered acceptable business use may now be illegal. Security policies must keep up with these ever-changing legal requirements or run the risk of exposing the business to legal penalties.
This chapter divides the IT environment into seven logical domains. Each domain represents a logical part of the technology infrastructure. You will follow the data through these seven domains to understand the business challenges collecting, processing, and storing information. You will also consider the business, technical, and security policy challenges that affect organizations.
Chapter 4 Topics
This chapter covers the following topics and concepts:
• What the seven domains of a typical IT infrastructure are
• How security policies mitigate risk within the seven domains
• What the different methods of building access control are
Chapter 4 Goals
When you complete this chapter, you will be able to:
• Identify the seven domains of typical IT infrastructure
• Identify the risks and concerns involved with the various domains
• Describe the top business risks within each of the seven domains
• Understand the difference between role based access control (RBAC) and attribute based access control (ABAC)
• Understand how security policies map to business requirements
• Understand the role security policies play in mitigating business risks within the domains
The Seven Domains of a Typical IT Infrastructure
Examining risk from a data perspective means to follow data through an end-to-end process. As you move through your technology infrastructure, you’ll find similar risk and policies issues. There are many ways to group security policies. A common method is to group common risks and related policy issues into domains. These domains share similarities but are distinctive enough to allow logical separation into more manageable secure areas. An advantage of this method is that each domain typically focuses on a different target audience. This means security awareness and training can be more precisely targeted.
In this section of the chapter, you will learn the definition of these domains. This section examines the attributes of each domain so you can gain a better understanding of the issues. Later in the chapter, you will examine the business issues and policy challenges of these problems, along with risk mitigation techniques.
Figure 4-1 illustrates seven typical domains of an IT infrastructure, which include:
• User—This domain refers to any user accessing information. This includes customers, employees, consultants, contractors, or any other third party. These users are end users.
• Workstation—This domain refers to any endpoint device used by end users. This can mean any smart device in the end user’s physical possession. For the purposes of this chapter, it’s any device accessed by the end user, such as a smartphone, laptop, workstation, or mobile device.
• LAN—This domain refers to the organization’s local area network (LAN) infrastructure. A LAN connects two or more computers within a small area. The small area could be a home, office, or group of buildings.
• WAN—A wide area network (WAN) covers a large geographical area. The Internet is an example of a WAN. A private WAN can be built for a specific company to link offices across the country or globally. Many business use the Internet for communicating between offices and regions. The Internet has become so inexpensive and reliable that it is often the first choice of businesses. Communications are typically secured through the use of encryption.
• LAN-to-WAN—This domain refers to the technical infrastructure that connects the organization’s LAN to a WAN. This allows end users to access the Internet. Communications flow in both directions in the LAN- to-WAN Domain.
• Remote Access—This domain refers to the technologies that control how end users connect to an organization’s LAN. A typical example of remote access is someone connecting to the office network from a home computer. End users can use a WAN to access a LAN. For example, an end user could use the Internet to create a private and secure session to connect with the office through a virtual private network (VPN)
connection.
• System/Application—This domain refers to the technologies needed to collect, process, and store information. The System/Application Domain includes hardware and software.
FIGURE 4-1 The seven domains of a typical IT infrastructure.
While there are many advantages to grouping policies this way, it can be hard to understand how data is controlled. In other words, it could be challenging to understand the end-to-end layers of controls. One way to overcome this challenge is to map business requirements by examining each of these logical segments. These requirements provide constraints upon end users and ultimately determine how security controls are designed.
Take a look at each of the seven domains to better understand how data is treated and how many common constraints are placed on them by the business.
User Domain
The User Domain refers to any end user accessing information in any form. This includes how end users handle physical information such as reports. Control of physical information starts well before someone ever touches a keyboard. It must start with end user awareness of policies and on-the-job training. As good as an awareness program is, formal education programs are no substitute for the experience gained from on-the-job training. Onboarding refers to new employee training. Even if your organization doesn’t have a formal on- the-job training program, something as simple as giving someone a “buddy” to show him or her how the area operates often achieves many of the same goals.
There are several key policies that an end user must be familiar with before accessing company information. Some of the more important policies you should include in an awareness training program include:
• Acceptable use policy—An acceptable use policy (AUP) establishes a broad set of rules for acceptable conduct when a user accesses information on company-owned devices. For example, this policy may set rules on what type of Web site browsing is permitted or if personal e-mails over the Internet are allowed.
• E-mail policy—An e-mail policy discusses what’s acceptable when using the company e-mail system. The policy is much more specific than the broad statements found in an AUP policy.
WARNING
How coworkers treat data can significantly influence an employee’s behavior beyond any formal awareness training. Regardless of training, if coworkers and management treat policies as unimportant, a new employee might treat policies as unimportant as well.
• Privacy policy—A privacy policy addresses the importance the organization places on protecting privacy. It also discusses the regulatory landscape and government mandates. This policy discusses how to handle customer data as well as the individual obligation to protect the information.
• System access policy—A system access policy includes rules of conduct for system access. This policy covers end user credentials like IDs and passwords. The policy may also be specific to the business or application.
• Physical security and clean desk policy—The physical security and clean desk policy outlines conduct in the workplace. It typically covers the expectation that employees will lock up sensitive information before going home at the end of the workday. This is what the term clean desk refers to.
• Corporate mobility policy—An organization’s corporate mobility policy sets expectations on the use and security of mobile devices. This policy could also set requirements on using personal devices to access company systems. For example, there is a growing trend of allowing personal smartphones to access company e-mail systems. This reduces costs because the company does not have to issue phones. But it also creates new risks, as companies have less control over devices they do not own.
• Social networking policy—The social networking policy has emerged as a type of code of conduct. With the rise of social media, many businesses are concerned about employees posting information about the company on these sites. This policy provides guidance to employees. For many organizations, posting any information about the business beyond the employee’s name and title is strictly forbidden.
Authentication is one of the most important components of the User Domain. You must determine an authentication method that makes sense for your organization. Your authentication method must also meet business requirements.
The use of user IDs and passwords remains a minimum standard for many organizations. It is considered a foundational control for many businesses. The ID and password can be widely used, and a password can be easily reset in the event an end user forgets it.
The low cost and high efficiency of this method of authenticating users also represent its greatest weakness. Because IDs and passwords have been used throughout the history of modern computing, exploits of this authentication method continue to be refined.
For many businesses, however, IDs and passwords alone are not enough. Authenticating the end user device in combination with the ID and password provides a stronger authentication method. For example, access may be restricted only to work hours on devices issued by the business for employees with a valid ID and password. Although the ID and password may be compromised, the risk is reduced because access would be
denied on non-company computers.
The best method for ensuring you know who is being authenticated is to restrict access to an ID and password to a single individual and force individuals to change their password often. The key lesson is that authentication must make sense in the business context in which you use it.
Another key component is authorization. Authorization is especially important in large complex organizations with thousands of employees and hundreds of systems. The authorization method must clearly define who should have access to what. One popular method is role based access control (RBAC). In this method, instead of granting access to individuals, you assign permissions to a role. Then you assign one or more individuals to that role.
The huge advantage of RBAC is speed of deployment and clarity of access rights. Let’s assume you hire an accountant named Nikkee and you grant her access to 12 systems, many spreadsheets, e-mail folders, and more. If you had to grant that access to her individual ID, it could take you days or even weeks. Given the complexity of a system, you may need to grant hundreds of permissions. The volume of permissions means there is a good chance of an error by missing something or granting too many rights. Now let’s assume you hire a second accountant named Vickee. You would have to start the process over again to grant her rights to the systems, spreadsheets, and so on. What’s even more time consuming is if one of these individuals leaves, you have to go through a similar process to remove her access.
Instead, let’s assume you previously set up a role called “Accountant” and granted all necessary permissions to this role. Creating a new account would take the same time as creating a single user without RBAC. But creating a role is a onetime event. When you hire Nikkee and Vickee, you can connect their IDs to the Accountant role, quickly giving them access to the systems, spreadsheets, and e-mail folders they need to perform their jobs. Now let’s say Vickee is promoted. You can quickly remove her ID from the Accountant role and place her ID in a Senior Accountant role. You reduced deployment time for these individuals from days or weeks to hours or minutes. By listing the people connected to the roles and the permissions within the roles, you can clearly see who has access to what business resources. This clarity of access helps an organization control access to its critical processes, manage its risk, and prove to regulators that it manages customer data properly. Figure 4-2 illustrates the RBAC concept.
FIGURE 4-2 Role based access control concept.
Several emerging variations of the RBAC model have recently been published. In January 2014, NIST issued publication 800-162, entitled “Guide to Attribute Based Access Control (ABAC).” Attribute based access control (ABAC) relies on dynamic roles, rather than the static roles found in the RBAC model. In an RBAC model, you build a static role. In an ABAC model you build an expression of attributes that describes the role that is built dynamically at run time. For example, “All accountants from the regional offices can post deposits.” This assumes you have assigned attributes that define “accountant,” “regional offices,” and “posting deposits.”
Both RBAC and ABAC can provide the same access. The advantage of ABAC is that roles are expressed more in business terms and thus may be more understandable. The other advantage that ABAC has is that roles are dynamically built, unlike RBAC, which requires resources to engineer roles. The disadvantage of ABAC is that it requires an application to use a central rules engineer at run time. Most legacy applications do not have this capability. Consequently, adoption of ABAC will be slow. Many organizations that want to adopt ABAC will have both RBAC and ABAC deployments for the foreseeable future.
Workstation Domain
The Workstation Domain includes any computing devices used by end users. Usually, the term workstation refers to a desktop or laptop computer. However, a workstation in the context of this chapter can be any end user device that accesses information. Control on your handheld device, like a smartphone, would fall within this domain.
NOTE
For the purposes of this chapter, the term workstation refers to any end user device that accesses information.
Usually, when an end user seeks to access information, he or she authenticates in the User Domain. Once he or she is known, the end user is often authorized to the workstation itself. Each workstation has an identity much like an end user. Not only can you restrict end users to specific workstations, you can also restrict what workstations are allowed on your network. This is particularly important when connecting to a network wirelessly because wireless access may be available to the public. Most wireless access points restrict which devices can access the internal network. Wireless access points also should encrypt the traffic between the authorized wireless device and the access point into the LAN.
NOTE
Authentication of a workstation and encryption of wireless traffic are Workstation Domain and LAN Domain issues. The assignment of a workstation identity and configuration of the wireless protocol is a Workstation Domain issue. The authentication and encryption of the traffic is a LAN Domain issue.
The Workstation Domain defines the controls within the workstation itself, such as limiting who can install software on the workstation. Some end users share a workstation. Therefore, it is important that settings be stable, and that one end user not be able to affect another. To achieve this, end users often have limited rights on workstations. That means they can typically access the software that’s been installed, and they have some rights to configure the software to their needs, but they do not have unlimited rights to make changes that could affect another user. This also ensures that an end user does not inadvertently infect the workstation with a virus or malware. Most domain controls ensure that appropriate antivirus software is loaded and runs on each workstation.
A central management system typically manages workstations such as Microsoft System Center Configuration Manager. These management systems have evolved over time and help an organization save time, money, and greatly improve response time. Can you imagine having to visit hundreds or thousands of
desktops individually to apply a patch or install a piece of software? Fortunately, those days are long over. Regardless of the management software used, different brands all generally share many of the same capabilities. The key functionalities to look for are these:
• Inventory management—An inventory management system tracks devices as they connect to the LAN. This builds an inventory of which devices are on the network and how often they connect to the LAN. Information inventories are useful for investigating security incidents and ensuring regulatory compliance.
• Discovery management—Detects software that is installed on a device. Discovery management can also detect information on a workstation. This is highly specialized software that is not routinely used.
• Patch management—A patch management system ensures that current patches are installed on devices. It’s particularly important to apply security patches in a timely manner to address known vulnerabilities.
• Help desk management—A help desk management system provides support to end users through a help desk. Help desk technicians may remotely access a device to diagnose problems, reconfigure software, and reset IDs.
• Log management—A log management system extracts logs from a device. Typically, log management software moves logs to a central repository. Typically, the volume of logs is so large that it takes special software to automatically search and highlight potential risks. Administrators scan these logs to find security weaknesses or patterns of problems.
• Security management—A security management system manages workstation security. This may include ensuring end users have limited rights and that new local administrator accounts are not present. The unexpected addition of local administrator accounts may be an indication that a security breach has occurred.
LAN Domain
The LAN Domain encompasses the equipment that makes up the LAN. A LAN typically has network devices that connect a local office or buildings. A LAN can be either simple or complex. If you have a wireless network device at home, you have a simple LAN. Let’s say you have a home cable modem connected to a wireless device, which is usually called a wireless router. The wireless router creates a LAN, bridging your cable modem to your home computer. This wireless router is your LAN access point to the Internet. The following are definitions for common network devices found on LANs:
• Switch—A switch is similar to a hub but can filter traffic. You can set up rules that control what traffic can flow where. Unlike hubs, which duplicate traffic to all ports, a switch is typically configured to route traffic only to the port to which the system is connected. This reduces the amount of network traffic, thus reducing the chance that someone will intercept communications. The ability to configure a switch to control traffic is a real advantage over a hub. Many organizations do not allow the use of hubs and prefer switches for enhanced security.
• Router—A router connects LANs, or a LAN and a WAN.
• Firewall—A firewall is a software or hardware device that filters traffic in and out of a LAN. Many can do deep-packet inspection, in which the firewall examines the contents of the traffic as well as the type of traffic. You can use a firewall internally on the network to further protect segments. Firewalls are most commonly used to filter traffic between the public Internet WAN and the internal private LAN.
A LAN in the business world is far more complex than a home LAN, and has many layers of controls. Let’s look at two general types of LANs, flat and segmented networks.
A flat network has few controls, or none, to limit network traffic. When a workstation connects to a flat network, the workstation can communicate with any other computer on the network. Think of a flat network as an ordinary neighborhood. Anyone can drive into the neighborhood and knock on any door. This doesn’t mean whoever answers the door will let the visitor in. However, the visitor has the opportunity to talk his or her way in. In the case of flat networks, you can talk your way in by being authorized or by breaching a server, for instance, by guessing the right ID and password combination. Flat networks are considered less secure than segmented networks because they rely on each computer (i.e., each home on the block) to withstand every possible type of breach. They are also less secure because every computer on the network can potentially see all the network traffic. This means a computer with a sniffer can monitor a large portion of the communication over a LAN. A sniffer can record the traffic on a network. This includes recording IDs and passwords in the clear. So if there’s a special code, secret knock, or handshake at the door, it has also been recorded. That’s why most security policies require passwords to be encrypted when passed through the network.
A segmented network limits what and how computers are able to talk to each other. By using switches, routers, internal firewalls, and other devices, you can restrict network traffic. Continuing the analogy from the previous paragraph, think of a segmented network as a gated community. To access that neighborhood, you must first approach a gate with a guard. The guard opens the gate only for certain traffic to enter the community. Once inside, you can knock on any door. A segmented network acts as a guard, filtering out unauthorized network traffic.
NOTE
Many standards require network segmentation. Payment Card Industry Data Security Standard (PCI DSS), for example, requires network segmentation to further protect credit cardholder information.
Why do you want to segment a network? The basic idea is that by limiting certain types of traffic to a group of computers, you are eliminating a number of threats. For example, if you have a database server with sensitive information that by design should receive only database calls (such as Structured Query Language [SQL] traffic), why allow File Transfer Protocol (FTP) traffic? If the server is not properly configured, the FTP service could be used as a way to break into the computer. By eliminating the FTP traffic, you have effectively eliminated that particular threat. You should still make sure the server is properly configured to prevent such an attack. However, you reduced the likelihood of a successful breach because the attacker must first breach the segment (i.e., get by the guard at the gate) and then breach the database server (i.e., break down the door). Security is never absolute, but segmenting your network makes it more difficult to breach a computer.
LAN-to-WAN Domain
The LAN-to-WAN Domain is the bridge between a LAN and a WAN. A LAN is efficient for connecting computers within an office or groups of buildings. However, to connect offices across the country or globally you need to connect to a WAN. Generally, routers and firewalls are used to connect a LAN and WAN. The Internet is a WAN. The Internet, like many WANs, is public and considered unsecure. Figure 4-3 illustrates the basic LAN-to-WAN network layers.
How do you move data from an unsecure WAN to a secure LAN? Typically, you begin by segmenting a piece of your LAN into a demilitarized zone (DMZ). The military uses the term DMZ to describe a buffer between two opposing forces. The DMZ sits on the outside of your private network facing the public Internet. Servers in the DMZ provide public-facing access to the organization, such as public Web sites. They are especially hardened against security breaches because the servers are easily accessible to the public and hackers. Sitting between the DMZ and internal network are firewalls that filter traffic from the DMZ servers to the private LAN servers. Often, the DMZ sits between two layers of firewalls. The first firewall allows
limited Internet traffic into the DMZ, and the second highly restricts traffic from the DMZ servers into the private network.
FIGURE 4-3 Basic LAN-to-WAN network layers.
There are a number of different network architecture designs that can be used to connect your internal private LAN with the external Internet WAN. The key point is to understand that you need some layer of firewalls to limit traffic between these domains. Creating a network segment like the DMZ as buffer between the LAN and WAN is a good way to protect your private network.
In recent years some firewalls have added behavior and heuristic checks. Basically, this means the firewalls learn over time what “normal” looks like. By recording volume and type of traffic, they create a pattern. When these behaviors change dramatically, firewalls can limit traffic and alert the security teams. For example, assume typical overseas customers represent 3 percent of your Web site’s traffic, but then suddenly turn into 99 percent of your traffic. This could be an indication of a potential breach, especially if that country of origin is known to be a source for hacks. Although each individual transaction looks valid, collectively the pattern can trigger firewall rules to restrict access.
WAN Domain
The WAN Domain, for many organizations, is the Internet. Alternately, large organizations can lease dedicated lines and create a private WAN. However, as connectivity to the Internet has become more reliable, many organizations have switched from private WANs to using the Internet to connect offices over all over the world.
A challenge for companies using the Internet to connect offices is how to keep communications secure and private. A common solution is a virtual private network (VPN). By setting up network devices at both offices, you can create an encrypted tunnel through the Internet. The tunnel protects communication between
the offices from eavesdropping. You can use a dedicated network device whose only function is to create and manage VPN traffic. These devices are VPN concentrators. Many firewalls also have the capability to create and maintain a VPN tunnel.
Organizations can lower communication costs by using VPN tunnels instead of leasing private lines for WANs. Beyond cost there’s also the issue of time. Leased lines for WANs can take weeks to months to order, contract for, install, and set up. Most companies already have an Internet connection. They can add VPN-compatible devices at both ends to establish a VPN tunnel in days. For small and medium-size companies, it’s the only practical solution given the cost and technical complexities.
Cloud computing has emerged as a major technology. Forbes estimates that in 2014 businesses in the United States will spend more than $13 billion on products and services related to the cloud. Most projections show that this expenditure will substantially grow in coming years.
Think of cloud computing as way of buying software, infrastructure, and platform services on someone else’s network. You rent this capability when you need it and stop paying when you are done. It’s like renting a car: If you have out-of-town guests, you might rent a large van while they are in town. Your costs are incurred during their stay. When your guests leave, you return the van and go back to driving your two-seat sports car. Likewise, cloud computing allows you to rent additional computing power when you need it and release it when the demand is low. Access to cloud computing is typically through the WAN (i.e., Internet).
Remote Access Domain
The Remote Access Domain is nothing more than an enhanced User Domain. The only difference is that you are traveling from a public unsecure network into the private secure company network. You have all the issues you have in the User Domain plus special remote authentication and network connectivity issues.
Remote authentication has always been a concern because the person is coming from a public network. Do you truly know that individual is an employee, or is he or she a hacker pretending to be an employee? There’s less of a concern when accessing the network within the office. The office might have guards at the entrance, locked doors, badges, and visibility of people sitting at workstations. Over the Internet, how do you know who’s on the other side of the wire? Most organizations today feel that an ID and password combination is not an adequate authentication method for remote access.
Many companies require two-factor authentication for remote access. Two-factor authentication requires an end user to authenticate his or her identity using at least two of three different types of credentials. The three most commonly accepted types of credentials are as follows:
• Something you know—Refers to something only you are supposed to know, such as your ID and password combination. You should never share your password with anyone.
• Something you have—Refers to a unique device that you must have in your physical possession to gain access. This physical device could be your computer itself. In general terms, all devices have identities, from your laptop to your phone. The physical device you are logged on with can be used as a way of verifying your identity.
• Something you are—Refers to some sort of biometric feature such as a fingerprint scanner.
technical TIP
There are many ways to verify a computer’s identity. A common method is using certificates. In general terms, the certificate acts like a digital fingerprint. No two computers have the same certificate or digital
fingerprint. This is useful in verifying that the user is on a specific computer. For example, suppose a bank wants to make sure any money wired is sent from only one computer in a locked room. That would provide both a physical and logical control over sending money. The wire application could verify the digital fingerprint of the remote computer to verify that any wire request is coming from a specific authorized computer.
Many organizations today require two-factor authentication for remote users. The authentication factors may be an ID/password combination (something you know) plus some type of token or smart card (something you have) to authenticate remote access. This provides a high level of confidence that the remote user is an employee. Some tokens can be loaded directly to the company laptop. The laptop becomes something you must have to connect remotely.
NOTE
In 2012, the Federal Financial Institutions Examination Council (FFIEC) issued guidance entitled “Authentication in an Electronic Banking Environment.” It requires financial institutions go beyond using just IDs and passwords. It required banks to use multifactor authentication more widely.
Remote network connectivity has the issues previously discussed with WAN Domains: how to keep communications secure and private. A VPN is typically the solution. You can configure a VPN to permit only predefined workstations to be connected. Each site has a dedicated hardware device that creates an encrypted tunnel through the Internet. This is typically called a site-to-site VPN connection. A remote user can also create a VPN tunnel. Instead of having VPN hardware at home, you have a desktop or laptop with software called a VPN client. This VPN client communicates with the VPN hardware to create the same type of encrypted tunnel through the Internet. This is typically called a client-to-site VPN connection. In both cases VPN is used to secure the communication through the Internet. Figure 4-4 illustrates the site-to-site and client-to-site connectivity.
FIGURE 4-4 Basic types of VPN connectivity.
The combination of enhanced remote authentication and network connectivity can be powerful tools to
ensure a network’s protection. Yet these tools also extend the business network anywhere in the world. Consider this scenario: Don, an executive, receives a call on a Saturday to approve a change to a vital business shipment. For Don to approve the shipment, he must review the changes on an internal system and electronically sign off on the changes. However, he is away for the weekend with his family.
Fortunately, Don has his laptop in the hotel and he has an Internet connection. He signs onto his company laptop and connects to the network using his ID/password and a token he carries on his key chain. A VPN tunnel is established, and his laptop is authorized onto the network. Don can now access the system the same way he does from his desk in the office. The encrypted communications are secure and private. He can review the shipment change and approve its release. The use of the ID/password and token achieves authentication and nonrepudiation for any transactions Don decides to execute. The confidentiality and integrity of the communication is achieved through encrypting the tunnel.
System/Application Domain
As complex as networks are, they essentially secure communication between an end user and some application software. What collects, processes, and stores data is ultimately software. Business software is typically an application. System software, such as a server operating system, runs business applications. The System/Application Domain refers to all the system and application software-related issues.
Application software is at the heart of all business applications. Application software can run on a workstation or server. For example, an application can display a screen by which customers and employees can select products and enter data. Once the information is collected, the application transmits the transaction to a server. The server stores the information in a database to be processed later or instantly processes the transaction, stores the results, and displays information back to the end user. Later an employee can extract data from this ordering application into a spreadsheet to track the total number of orders each month by product type. The application that took the orders, the spreadsheet that tracked the orders, and perhaps the e- mail client used to announce record sales for the month, are all examples of application software.
FYI
People often use the terms system software and application software interchangeably. They are not the same. Generally, any business software that an end user (including customers) touches is an application. This includes e-mail, word processing, and spreadsheet software. The operating system, which is the software that runs applications, and software that allows a computer to communicate over a network, are system software.
Information Security Business Challenges and Security Policies That Mitigate Risk Within the Seven Domains
The previous section provided a foundational understanding of each of the seven domains. In this section, you will examine the business challenges and risks in each domain. You will also learn how the proper application of security policies can mitigate many of these risks.
User Domain
For an organization to be efficient requires the proper alignment of people, processes, and technology. As with most technology problems that are enormous in size, scope, and complexity, the best approach to finding a solution is to break down the problem into manageable pieces. In this case, the goal for business is to have this alignment to produce consistent, repeatable, high-quality results. The challenge is that humans are not always predictable and consistent. So any process that relies on humans must reinforce good behavior and verify results often. This reinforcement of education, monitoring, and adjusting behaviors is a never- ending cycle in implementing security policies.
Employee efficiency starts with well-defined policies that reflect the organization’s reasonable expectations. Security policies must closely align with business requirements. This situation allows employees to understand the importance of the policy to the organization. It also ensures that security policies support business goals. One of the major business challenges is getting employees to follow policies. There are several ways good security policies can mitigate this risk, as follows:
• Awareness—Policies require employees to receive formal security awareness training. Most importantly, this training lets employees know where to go for help when the unexpected arises. The training also sets expectations on the handling of sensitive information to protect such as ensuring customer privacy.
• Enforcement—Security controls flow from security polices. These controls are designed to enforce how the business wishes to operate. Among the most important security controls are those that enforce segregation of duties. Separation of duties, or segregation of duties, means a single person cannot execute a high-risk transaction, for example, wiring large sums of money out of a bank. Typically, this requires one person to request the wire and a manager to approve the transfer.
• Reward—Refers to how management reinforces the value of following policies. An organization should put in place both disciplinary actions for not following policies and recognition for adhering to policies. This could be as simple as noting the level of compliance to policies in the employee’s annual review.
• Monitoring—It’s not enough to publish well-defined security policies. You have to know they are working. Monitoring can take many forms. Typically, it is a combination of quality assurance and quality control. Quality assurance is about verifying and approving actions before they occur. Quality control is about sampling work that has already been done to ensure that, collectively, actions meet standards. This combination of two types of monitoring can be used to drive enforcement and improve awareness.
Another business concern is handling sensitive information in physical form, such as reports. As noted earlier, many organizations have a clean desk policy. This policy generally requires employees to lock up all documents and digital media at the end of a workday and when not in use. Compliance checks are relatively easy because any report or CD left out overnight is a violation of policy. This protects customer privacy and reminds employees of the sensitivity of company information. It also sets the right image for customers and vendors who may be visiting the office.
Security policies also ensure that contractors and consultants are properly vetted before gaining access to company information. This includes performing background checks. Employees and non-employees alike must follow security policies.
Not all business processes can be standardized. Employees sometimes transfer knowledge by word of mouth, such as how to run some nonstandard transaction. The potential for significant failure in these processes may exist. At a minimum, when a failure occurs, the security policies ensure the process and related data can be restored.
Workstation Domain
Locking your front door but leaving your window wide open is not good security. Let’s assume you have good authentication and you know who is signed onto your network. However, if a workstation is breached, you could have malicious software compromising your network whenever the authorized user connects.
The ramifications of a security breach are more severe for some organizations that are regulated. There is an expectation that leading practices are being applied to prevent such breaches. Security policies help identify those practices and ensure they are applied to protecting the workstation. That includes ensuring that all workstations that access the network are patched and have antivirus software installed. The business may not be aware of many of these basic common controls expected by regulators. The security policies ensure such
controls are in place and help ensure regulatory compliance.
Effective security is often a matter of determining some basic security configuration rules and applying them consistently across your enterprise. Applying such security without disrupting the business is a concern. The days of sending a technology person to each desk to configure a workstation for most organizations are long past. Security policies can help establish a reliable automated patch management process. Security policies can specify the type and frequency of patches to apply. The policies often require IT to test patches in a lab setting before applying them to workstations. Changes are made at night so there is a minimal impact on the company’s day-to-day operations.
FYI
A botnet is a collection of computers infected by malware loaded onto them by hackers without the knowledge of the computers’ owners. What distinguishes this type of attack from others is its ability create a vast array of computers that all communicate for a single purpose. For example, a botnet can be used to launch a distributed denial of service (DDoS) attack from millions of points across the globe.
Security policies also reduce the risk of malware by limiting access to workstations. Usually an end user does not have administrative rights on a workstation. This means the end user cannot inadvertently install programs like malware that could launch a botnet attack.
If they cannot breach your company’s network directly, hackers often attempt to breach a workstation and infect it in some manner. The attempt is to either capture information from the workstation or use the workstation as a way to access the protected network. Security policies are good at outlining the rules for protecting workstations. One good example is encrypting laptop hard drives. This has become standard practice in many industries. With the increase in mobile computing, sensitive data leaves networks more easily and more often. As a result, many companies that handle sensitive information encrypt their employee’s laptop hard drives. In that way, if the laptop is lost or stolen, the sensitive data is protected.
Many security policies require the encryption of data whenever the information leaves the protection of the network. This include encrypting data over the Internet, in e-mails, and on mobile devices such as universal serial bus (USB) drives, CDs, personal digital assistants (PDAs), and laptops. Despite these efforts, 2013 was a record year for data losses due to breaches, according to a study published in February 2014. The study noted 2,164 recorded incidents, resulting in 822 million records being exposed. This illustrates the need to have strong policies, monitoring, and enforcement.
Security policies that set encryption standards need to ensure the vendors and contractors follow the same policies that employees are required to follow.
LAN Domain
Many organizations have discovered that granting mobile access to business applications can increase productivity and revenue. A LAN is all about connectivity for the business. The more easily you can be connected to a LAN, the faster you can start accessing and exchanging data. Wireless and mobile computing have changed the way people understand LANs. This new view affects the perception of LAN and Remote Access Domain issues.
Wireless connectivity allows you to view the LAN more broadly than the computer on your desktop. Handled devices allow you to extend your LAN network out of the office and into the business. In other words, you can connect to the network and access or exchange information where the product or service is being made or delivered. Here are a few examples of how using wireless technology can extend the LAN into the business:
• Health care—Health care providers can access real-time patient information or medical research from a patient’s bedside. These devices enhance collaboration for more accurate diagnoses. These devices can also track medical equipment to ensure availability at critical times.
• Manufacturing—Wireless connectivity allows employees to share real-time data on the factory floor.
• Retail—Wireless access to a LAN helps retailers place intelligent cash registers where there is no network wiring. This network access allows retailers to manage inventory, check customers out faster, and print the latest promotion coupons from the register.
Extending the LAN has many advantages over just connecting a standard PC. LANs today can carry voice, video, and traditional computer traffic. Voice over Internet Protocol (VoIP) allows you to place and receive phone calls over a LAN or WAN. This has become popular for both home and business because of the cost savings over traditional telephone systems. Rather than incurring high flat-rate fees and per-minute call charges, most VoIP services charge a low flat-rate fee. New companies continue to enter the market offering less expensive voice and video solutions over the Internet.
NOTE
LANs today often carry physical security information, such as video feeds. With this expanded capability, you can see the growing integration of logical and physical security. For example, employee card access is tightly aligned with an individual’s logical security access. These work together both to control the room one can access and to restrict the computers one can access once one is in the room.
Organizations often view LANs much like utilities such as electricity, water, or gas. The organization expects the LAN to be always available and always have capacity. It’s also thought of as a commodity that should be inexpensive to install and run. This puts tremendous pressures on LAN resources. Bandwidth within the LAN, for example, decreases as new services such as VoIP and video are offered.
NOTE
Bandwidth is a measurement that quantifies how much information can be transmitted over the network. When a LAN reaches its maximum bandwidth, it becomes susceptible to many kinds of transmission errors and delays.
It’s not uncommon to have security policies limit the use of live video, music feeds, and social media sites. They can represent hours of lost employee and contractor productivity. These feeds also take up significant bandwidth. For example, in 2012, Procter & Gamble, with 129,000 employees, used security policies to stop video and music feeds. Many such policies can be enforced at the firewall, cutting off the source of video and music from the Internet.
Even with these business challenges, the benefits of extending a LAN beyond the workstation are enormous and include enhanced productivity, collaboration, and responsiveness.
LAN-to-WAN Domain
A major concern of organizations is protection of the servers in the DMZ. In other words, are the Web site servers protected? Organizations are particularly concerned about Web site availability and integrity. The Web sites for many organizations represent their public image and, for companies, their major saleschannel.
NOTE
An organization’s reputation can be diminished by the appearance of Web graffiti on its Web site. Web graffiti is a result of Web site defacement, in which a Web site is breached and its content altered, usually in a way that embarrasses the Web site owner. Web graffiti can contain abusive language or even pornographic images.
Security policies set strict rules on how DMZ traffic should be limited and monitored. Security policies outline how the DMZ server should be configured and how often security patches should be applied. Security policies also outline how often external penetration testing is conducted. Penetration testing probes the network for weaknesses and vulnerabilities from the outside looking in. Penetration testing is required by many standards and is considered a best practice. For example, if you accept or process credit cards, PCI DSS requires penetration testing.
However, these rules and limitations put onto the DMZ create their own risks. DDoS attacks typically attempt to overwhelm the DMZ capability, resulting in the servers crashing and becoming unavailable. So the more limits put on the traffic, the more you have to test whether the systems can withstand a DDoS attack. It’s not enough just to limit traffic; the policy must also ensure that systems stay available.
WAN Domain
When it comes to WANs, an organization is generally concerned about cost, reliability, and speed. As discussed earlier in the chapter, many organizations use virtual private networking to protect and secure communications over the Internet. With most organizations having already incurred the cost of Internet connectivity, the use of secure communications over the Internet is now seen as a de facto standard.
Cost-wise, a VPN over the Internet is the right choice. The cost is fairly modest. Because most organizations already have Internet connectivity, IT can quickly deploy VPN technology. It could be as easy as installing devices and synching keys to establish a VPN tunnel.
NOTE
With virtual private networking, you “tunnel” through the public Internet to reach a specific site. Typically, two VPN devices establish a site-to-site VPN tunnel. Both devices are usually preconfigured with keys so only these devices communicate with each other. Once the tunnel is established, it can link entire LANs. A remote office, for example, can link to headquarters.
Reliability of a VPN depends on your Internet service provider (ISP). You can experience reliability issues even if your ISP guarantees a level of service while you’re traveling over a public network. Think of the Internet like a road system. You have local roads, main arteries, and superhighways. Some ISPs advertise how many hops away from the Internet backbone they are. The Internet backbone represents the superhighway in our road system and can handle the fastest traffic. In theory, the fewer hops it takes to get to the backbone, the faster your access. A hop is a term meaning generally how many routers you have to pass through to get to your destination. If you have to go through a lot of back roads to get to your destination it takes a lot longer than if you live close a superhighway. The same holds true for the Internet traffic. Many large organizations will connect to multiple ISPs. This will give the redundancy needed in the event a single ISP fails to deliver the needed connection speed.
While speed over the Internet continues to improve, it’s not an unlimited resource. To control usage, many ISPs limit bandwidth. As upper limits are reached, some customers may be transferred to slower network connections. This may be acceptable for a home user. However, for a business this could be devastating. Businesses often require consistent response times for the customer. To achieve that, they pay a premium to the ISP. This premium places the business on a less crowded network connection. This less crowded network connection has excess capacity to ensure the response level does not fall below a prescribed level. This
makes predicting reliability less of a challenge.
NOTE
Private WANs are point-to-point solutions that are not publicly shared and thus are usually not encrypted. Service providers of private WANs can guarantee upload and download bandwidth consistency.
Deciding on a public or private WAN solution for your organization depends on your requirements and budget. Small organizations have few options. For large enterprises, both WAN options are available.
Security policies outline how each connection type should be configured and protected. The security policies also outline roles and responsibilities. Keep in mind that the service provider typically configures private WAN security. Therefore, your security policies need to include how to deal with the vendor and how to validate the security configuration. Companies of any size can manage security for Internet-based VPN solutions in-house.
Remote Access Domain
When it comes to remote access, organizations are concerned about flexibility, reliability, and speed. As discussed, extending the LAN into the business where products are produced and services delivered has tremendous benefits. This is also true for extending the LAN anywhere in the world. This is where remote access concerns need to be addressed.
When it comes to flexibility, employees cannot be tethered to their desktops. Laptops have broken that tie, allowing employees to connect to the company network wherever there is an Internet connection. Wireless connections further extend the flexibility of laptops. Today, travelers and mobile employees often use a laptop with a mobile hotspot to access the Internet and work network. A mobile hotspot can be a personal device that acts like a cell phone for a laptop, allowing the end user to obtain a broadband Internet connection. These personal hotspots often support connections for typically four to eight devices. Hotspot can also refer to a fixed Internet access point available to the public. For example, coffee shops often provide hotspot access to the Internet for their customers.
Mobile devices and broadband are becoming very reliable. However, the speed and reliability with which they can access and exchange data depend on location and carrier. Much like cell phone coverage, mobile broadband coverage is spotty at times. However, despite their drawbacks, mobile devices offer many business benefits, including:
• Increased customer responsiveness
• Quick reaction to news and business-related events
• Advantage of real-time data access
Bring Your Own Device (BYOD) is a current trend within many organizations. BYOD refers to allowing employees to bring their own devices to work to access the organization’s data. For example, it could allow employees to access their company e-mail through their personal smartphones. Businesses embrace BYOD to reduce cost and expand connectivity options. Costs are reduced because a company does not have to buy and deploy company-owned mobile devices.
Security depends on your business requirements—how much data you need to send and how fast you need it to arrive. Some good examples are the use of smartphones and iPads and other tablet computers. They are very efficient for gaining access to well-defined applications such as e-mail. However, they do introduce
risks and policy questions that must be addressed. Some security policy questions that must be addressed for handheld device use include:
• Who owns the device?
• Who has the right to wipe the device if it’s lost or stolen?
• How do you encrypt data on the device?
• How do you apply patches?
• Who’s allowed to have such a device connected to the company network?
With any emerging technology, well-defined security policies help an organization think through these risk decisions. Security policies ensure risk assessments are performed and leading practices are reviewed. This is vital so the organization can understand not only the benefits of new technology but also the risks.
Security policies should focus, not on specific products, but on broader capability. A smartphone can access e-mail but also has a camera. Rather than addressing smartphones, a well-defined policy deals more broadly with mobile e-mail access and acceptable use of digital recordings. By taking this approach as new technology is introduced, the organization covers the capability in the policy.
System/Application Domain
An organization has two main concerns when it comes to information collected, stored, and processed: Is the information safe? Can you prevent confidential information from leaving the organization? These seem like fairly easy questions but are complicated to answer.
This chapter has discussed many ways to keep information safe. Security policies ensure risks are evaluated throughout the seven domains. Security policies ensure alignment to business requirements. When risks exist, security policies ensure a risk assessment is performed so that management can make a balanced decision.
In this section, you will focus on the second business concern of how to prevent confidential information from leaving the organization. Security policies define what’s often called either a data loss protection (DLP) or a data leakage protection (DLP) program. Both terms refer to a formal program that reduces the likelihood of accidental or malicious loss of data.
Company managers worry about secret business information ending up in competitors’ hands. Managers must also protect customer privacy as required by law. A hacker does not have to be physically present to steal your business secrets, especially if he or she is a disgruntled employee who might work in a data- sensitive area of the company. Your top salesperson might leave the company to work for a competitor and e- mail your entire sales database to his home Internet account. These are not theoretical losses to a business. You must ensure that all of your potential data leaks, both physical and digital, are plugged.
The concept of DLP comes from the acknowledgment that data changes form and often gets copied, moved, and stored in many places. This sensitive data often leaves the protection of application databases and ends up in e-mails, spreadsheets, and personal workstation files. Business is most concerned about data that lives outside the hardened protection of an application.
A typical DLP program provides several layers of defense to prevent confidential data from leaving the organization, including:
• Inventory
• Perimeter
• Device management
• Governance and compliance
Inventory
The DLP inventory component attempts to identify where sensitive data may be stored. This includes scanning workstations, e-mail folders, and file servers. The process requires actually inspecting the content of files and determining if they contain sensitive information such as Social Security numbers. Once data locations are identified, reports can be created to compare the security of files with security policies. For example, this helps prevent private customer information from accidentally being stored in a public e-mail folder. While this is an important capability, it has its limitations. The ability to understand the sensitivity of a file is very difficult to automate. Either you end up having too many false positives or end up missing the identification of sensitive data.
Perimeter
The DLP perimeter component ensures that data is protected on every endpoint on your network, regardless of the operating system or type of device. It checks data as it moves, including the writing of data to e-mail, CDs, USB devices, instant messaging, and print. If sensitive data is written to an unauthorized device, the technology can either stop and archive the file or send an alternate. It stops data loss initiated by malware and file sharing that can hijack employee information. Through the logging and analysis server, the DLP perimeter monitors real-time events and generates detailed forensics reports.
You can also establish and manage security policies to regulate and restrict how your employees use and transfer sensitive data. It uses the same basic technology that is applied with the inventory component. It has the same limitations. Because you are dealing with data movement, you can add rules not often found in the inventory process, such as not permitting large database files to be e-mailed. Regardless of content, these rules can stop a hacker from sending a large volume of data out the door.
Device Management
In many ways, mobile devices like smartphones and tablets are mobile external hard drives. They carry the same information that can sit on a workstation or server. When an executive receives an e-mail on an upcoming merger, or a doctor gets a message about a patient, the information needs the same protection as if it were on a workstation or server. The information on mobile devices is subject to the same regulatory requirements. This means you must also apply the same level of controls, such as encryption.
The ability to manage these devices from a central service is essential. As new threats are identified, this device management capability is essential to push out patches and ensure controls are working well.
You need a DLP program because loss of confidential data hurts the reputation of a business, discloses competitive secrets, and often violates regulation. Well-defined security policies establish a formal DLP program within an organization.
CHAPTER SUMMARY
You learned in this chapter how to break up policies into seven domains. You examined each of the domains to learn why they exist, looked at related business concerns, and learned how to mitigate common risks. You now understand that security policies have to be aligned to the business. Most important, you see how security policies can highlight regulatory and leading practice to guide the business in controlling these risks.
The chapter examined the changing nature of business through technologies such as wireless and handheld devices. You read about the differences between access methods such as RBAC and ABAC. You understand the importance of security policies keeping pace with changing technologies. You also saw what happens when security policies are not effective, as when more than 882 million customer records were exposed in 2013. You should better understand the expanding role of the LAN to establish global connectivity through WANs. You read about techniques, such as VPN, to keep this communication protected and private. Finally, you read about the importance of having a DLP program defined in your security policies. You read about the drivers for DLP, including BYOD programs. DLP programs help organizations reduce the likelihood of data loss.
KEY CONCEPTS AND TERMS
Application software
Attribute based access control (ABAC)
Bring Your Own Device (BYOD)
Data leakage protection (DLP)
Data loss protection (DLP)
Demilitarized zone (DMZ)
Discovery management
Domain
E-mail policy
File Transfer Protocol (FTP)
Firewall
Flat network
Help desk management
Inventory management
LAN Domain
LAN-to-WAN Domain
Log management
Multifactor authentication
Patch management
Privacy policy
Remote Access Domain
Remote authentication
Role based access control (RBAC)
Router
Security management
Segmented network
Sniffer
Structured Query Language (SQL)
Switch
System access policy
System software
System/Application Domain
Two-factor authentication
User Domain
Virtual private network (VPN)
WAN Domain
Web graffiti
Web site defacement
Workstation Domain
CHAPTER 4 ASSESSMENT
1. Private WANs must be encrypted at all times.
A. True
B. False
2. Which of the following attempts to identify where sensitive data is currently stored?
A. Data Leakage Protection Inventory
B. DLP Encryption Key
C. Data Loss Protection Perimeter
D. DLP Trojans
3. Voice over Internet Protocol (VoIP) can be used over which of the following?
A. LAN
B. WAN
C. Both
D. Neither
4. Which of the following is not one of the seven domains of typical IT infrastructure?
A. Remote Access Domain
B. LAN Domain
C. World Area Network Domain
D. System/Application Domain
5. Which of the seven domains refers to the technical infrastructure that connects the organization’s LAN to a WAN and allows end users to surf the Internet?
6. One key difference between RBAC and ABAC is which of the following?
A. ABAC is dynamic and RBAC is static.
B. ABAC is static and RBAC is dynamic.
C. No difference; these are just different terms to mean the same thing.
7. A ________ is a term that refers to a network that limits what and how computers are able to talk to each other.
8. A LAN is efficient for connecting computers within an office or groups of buildings.
A. True
B. False
9. What policy generally requires that employees lock up all documents and digital media at the end of a workday and when not in use?
A. Acceptable use policy
B. Clean desk policy
C. Privacy policy
D. Walk out policy
10. What employees learn in awareness training influences them more than what they see within their department.
A. True
B. False
11. What kind of workstation management refers to knowing what software is installed?
A. Inventory management
B. Patch management
C. Security management
D. Discovery management
12. Always applying the most strict authentication method is the best way to protect the business and ensure achievement of goals.
A. True
B. False
13. Generally, remote authentication provides which of the following?
A. Fewer controls than if you were in the office
B. The same controls than if you were in the office
C. More controls than if you were in the office
D. Less need for controls than in the office
14. Remote access does not have to be encrypted if strong authentication is used.
A. True
B. False
15. Where is a DMZ usually located?
A. Inside the private LAN
B. Within the WAN
C. Between the private LAN and public WAN
D. Within the mail server
16. Dedicated network devices whose only function is to create and manage VPN traffic are called VPN ________.
17. What is a botnet?
A. A piece of software the end user loads onto a device to prevent intrusion
B. A piece of software a company loads onto a device to monitor its employees
C. A piece of software a hacker loads onto a device without user knowledge
D. A piece of software used to communicate between peers
18. The minimum standard in authentication for businesses is the use of ________.
Highlight
•
?
• Delete Note • Save Note • Cancel
CHAPTER
5 Information Security Policy Implementation Issues
SUCCESSFUL IMPLEMENTATION of information security policies starts before the policies are even written. Implementation depends on how well the policy is integrated into existing business processes, and how well it is understood and embraced by leadership and employees. Implementing information security policies often results in putting in controls that slow the exchange of data. Business can see this as an unnecessary burden. Successful implementation of policies, therefore, must be viewed as a journey from conception to implementation. You must start with engagement, with creating awareness within the organization, and by building consensus on the need to implement the policy. As difficult as the technological side of information security can be, the human side, because it’s so unpredictable, can be even more challenging.
Once a security policy is created or revised, and agreed upon, the implementation process starts. The process of implementing security policies can be harder than creating the document itself. You should not underestimate this effort. Implementing security policies successfully takes a combination of soft skills in dealing with human nature and company culture and hard skills in project management. The number of tasks and considerations can seem overwhelming. It’s important to take a systematic approach that keeps the implementation moving forward and supporters engaged.
Security policies specify ways to control risk and reflect the core values of the organization. This means security policies are as much about promoting a risk-aware culture and motivating workers as they are about implementing technical business requirements. Therefore it’s important to keep in mind that a successful implementation must motivate, gain consensus, and compete with an individual’s priorities. Gaining executive support is one of the keys to success. This means you must be able to communicate the value of the security policies. You must be able to explain why the business and individuals should care. This takes skill in influencing others and marketing the value of the security policies.
In this chapter, you will review many of the issues and problems faced when implementing security policies. The chapter gives pointers on how to overcome these challenges and how to deal with human nature in the workplace. The chapter also gives guidance on how to manage security policy changes in your organization.
Chapter 5 Topics
This chapter covers the following topics and concepts:
• How to deal with human nature in the workplace
• What various organizational structures are
• How to overcome user apathy
• Why executive management support is important
• Why support from human resources policies is important
• How security policies influence roles, responsibilities, and accountability
• What happens when policy fulfillment isn’t part of the job description
• How an entrepreneurial approach affects productivity and efficiency
• Why it’s important to find the right measure of employee performance and accountability in implementing security policies
Chapter 5 Goals
When you complete this chapter, you will be able to:
• Describe what a control partner is
• Describe how people are motivated in the workplace
• Describe different workplace personality types
• Compare advantages and disadvantages of different organization structures
• Describe the basic characteristics of organizational structure
• Explain how user apathy affects security policy implementation
• Explain the importance of executive and human resources support
• Describe the importance of a change model in implementing security policies
• Describe key tasks within a change model
• Explain key roles and responsibilities in implementing security policies
• Describe attributes of an entrepreneurial business unit
Human Nature in the Workplace
A successful security policy implementation depends on people understanding key concepts and embracing the material. Understanding and influencing different personalities in the workplace will be important to achieving that success. But it’s not just the needs of the internal employee you need to consider. A variety of stakeholders will have an interest in information security policies. These include external parties such as vendors, customers, and regulators. As competition explodes globally, new channels of sales and products appear. These factors are usually accompanied by a change in technologies. Enormous efforts and resources are spent to document, debug, and map an organization’s processes to these technologies. Over time, technology, frameworks, and standards evolve to become best practices. Success does not come by technology or process alone. Successful security policy implementation depends on the correct alignment of people, processes, and technology.
How much time and resources are placed on the people element? Too often, not enough. This section explores human nature in the workplace. More precisely, it looks at different personality types and how they affect the adoption of security policies. A successful security policy implementation is defined in part when an employee understands the key concepts and can apply them broadly to situations that were not anticipated. Going beyond what one is told helps define a successful implementation of security policies.
Basic Elements of Motivation
What is motivation? What makes a help desk employee work persistently to fix your problem? It’s being enthusiastic, energized, and engaged to achieve a goal or objective. A lack of motivation can be measured in
poor customer services, and doing the minimum to get by, with mediocre results.
There are three basic elements of motivation: pride, self-interest, and success. When these three elements are combined in the workplace, you often see the following:
• Individual and team motivation
• Individuals going “above and beyond” their job requirements to be successful
• Satisfied customers
• An increase in bottom-line profits
Good leadership can motivate employees. Consider, for example, when information security policies are implemented effectively across all teams but one. A review of differences between the teams would be in order. Suppose that review indicates that all teams across the enterprise use the same technology and received the training, and that all other factors were the same, except that, of course, different teams have different leadership. Then the unsuccessful implementation could be attributed to lack of effective leadership.
Pride
Pride is part of human nature. Individuals are more likely to become motivated when they are working on something that is important. If our work is discarded or trivialized, we’re less likely to put in a high-quality effort the next time. Conversely, if we understand the goal and objectives of our team and see how our individual efforts contribute, we feel a sense of obligation. It also builds team pride and spirit, which is important for future successes.
An important component of pride involves an understanding of the overall goals and objectives. Management is responsible for informing employees of their roles and how their efforts contribute to the larger goal. This is where good leaders can motivate and poor leaders can derail a good security policy. A manager’s comment, “You must do it because the security department says to” is a good indication of poor leadership. In this case, management may not be embracing the policy, and more important, staff might perceive the policy as a burden. That perception could lead to the staff’s doing the bare minimum. Conversely, assume a manger approaches the employees and outlines the problem being solved. A manager might add his personal endorsement of the action taken. Additionally, the manager could position the policy change as an opportunity to expand staff skills and to stress the importance of protecting the customer.
Pride can be a powerful motivator. It can also create competition and a sense of self-worth. Managers must control competition so that the sole measure of success is not simply completing the task first. It must also promote helping each other so the “team” can succeed. Measuring success needs to include all the values important to the organization, including quality of service, customer satisfaction, and teamwork.
Self-Interest
Self-interest, and sometimes self-preservation, is also part of human nature. Humans tend to repeat behavior that is rewarded. Having well-defined goals and objectives for individuals helps them understand what they must achieve. Those who achieve these goals receive rewards. Those who exceed these goals typically receive bigger or better rewards. Those individuals are “high achievers” or high performers. High achievers receive promotions more often and are models for others to emulate. To promote the importance of information and adherence to its policies, you should gain the support of high performers.
In a declining economic market, there’s significant pressure on companies to cut jobs to save money. Self-
preservation is an important part of human nature. Employees who feel their jobs are at risk will not take chances. This could lead to individuals’ doing the minimum to stay out of trouble. Worse yet are individuals who feel they will be next to be let go. They may be angry and try to undermine management efforts. When an organization lays off employees, it’s often called a reduction in force. Generally it’s not a good idea to implement significant policy changes during a force reduction.
Discipline also has an important self-preservation effect on our behavior. When an employee fails to perform, they may require disciplinary action. How management handles disciplinary actions either motivates or de- motivates an employee.
NOTE
Disciplining employees can be risky if you don’t do it right. You need to make sure that you do not discipline different employees differently for the same policy violation. Your inconsistency could lead to a lawsuit or a claim of employment discrimination. Always work through your human resources department and strictly follow company procedures in disciplining employees.
Everyone has strengths and weakness. Most people make mistakes and at some point will do something foolish. One management approach is to look at an employee’s pattern of behavior more than at individual errors in judgment. This approach has its limits, as in a case of sexual harassment or fraud. Except for these extreme cases, though, when management accepts failures as part of individual and team growth, a culture of taking chances emerges. More important, this approach creates the trust that encourages employees to report policy failures and breakdowns. Not only the individual employee but the whole organization can learn from such failures. This experience is often referred to as “lessons learned.” Making it easier to record and track these lessons learned will allow the information security team to improve policies to prevent future problems.
Taking chances and going beyond what’s expected define high achievers and high-performance teams. Because security polices cannot define every event, their success depends on employees taking action by applying core principles to new situations.
For example, you may have a clear policy and related process for setting up administrator accounts. Assume a vendor provides support for your organization. Assume it’s not unusual for the vendor to request to change access to devices they support. Historically, they request access changes once or twice a year. Now let’s assume you receive a request from the vendor representative (in accordance with established processes) to remove all existing administrator accounts and replace them with new accounts. The request follows established processes.
But those employees who understand the risks associated with administrator accounts and those who feel empowered might challenge the request and ask for additional authorization, even though additional approvers are not required by policy. And it might turn out that the vendor representative asking to make those highly unusual changes has just been fired, or has just been victim of some form of identity theft. In this scenario, the high-achieving employees who had the systems knowledge and the confidence to challenge the vendor rep could be what protects the organization.
Success
Wanting to be successful is part of human nature. Anyone who has played on a winning team knows the feeling. Imagine you played on a sports team that just won regional finals. It’s simply a lot more fun being on the winning team than on the team that always comes in last. Even if you are a high performer, it’s hard to get motivated if your team as a whole keeps losing. It is no different in the workplace. Individuals build confidence when frequently recognized for their successes. These individuals quickly become highly motivated. Equally important, they can motivate others and support others to win. This is an essential
element in creating a winning team. They can also afford to take chances and are more likely to build on their success by going beyond what’s required. Success is measured as the perception of how well you perform your work, how you work as part of the team, ethical behavior, and perception of your customers.
You need to have some proficiency in soft skills to convince an organization to adopt security policies. The term soft skills refers to certain social personality traits such as the ability to communicate and project optimism. Mastering these soft skills is essential to influencing others. This is particularly important when trying to sell new security policy and control concepts. More and more, business relies on the agility of its workforce to adapt to the unexpected. These skills are just as highly valued as technical knowledge. In other words, the “people” part of the equation is also critical to implementing security policies. Soft skills help turn people into high performers who apply their own knowledge effectively and draw out the best from others. Successful implementation of security policies over time will change individual attitudes. If that success continues throughout the organization, a culture that is more security and risk aware may emerge. This culture shift makes it much easier in the future to identify and mitigate risk.
Pride, self-interest, and success issues overlap and interact. Sustaining motivation comes by creating the right balance between these basic elements. When you achieve balance, you not only motivate individuals but teams, departments, and entire organizations. Figure 5-1 depicts these three basic elements of motivation and their intersection.
Motivated employees are far more likely to embrace the implementation security policies. This leads to more risks being identified and mitigated for the organization.
FIGURE 5-1 Three basic elements of motivation.
Personality Types of Employees
It’s easy to see firsthand that individuals react differently in the workplace. What motivates one person does not always work for another. Understanding different personality types within a team is key to understanding how to motivate people. It’s important to understand and appreciate the differences. This understanding allows you to leverage talents more effectively.
Let’s illustrate this point with a simple example. Assume you’re dealing with two key stakeholders in the Finance and Audit departments. The financial analyst may be very analytical and want to know about the financial impact of implementing the new security policy. The auditor may be more focused on the outcome. What risks will be reduced after the policy is implemented? There may also be a host of individuals with a wide variety of motivations. Being able to recognize these differences will allow you to speak to the points of interest that will be most persuasive. Talking to financial analysts about threats might be good background to
justify a project, but doesn’t address their potential concern about going over budget.
HR Magazine identified eight classic personality types in the workplace. They are commanders, drifters, attackers, pleasers, performers, avoiders, analyticals, and achievers. In many ways their personality names speak to their individual traits.
NOTE
Understanding personalities is particularly important in dealing with stakeholders. Stakeholder is a term referring to individuals who have an interest in the success of security policies. During the early stages of implementing policy, the stakeholders play a critical role. If you understand their personalities and needs, you will be better able to motivate them to support the implementation.
The following is a high-level summary of each of these traits:
• Commanders—Are demanding and not tactful. They might come across at best as impolite, at worst rude and abrupt. They are forceful in an attempt to achieve stated goals. They can be agents for change, breaking from the past and overcoming barriers within the organization.
• Drifters—Are uncomfortable with structure and deadlines. They might be great with people and communications. What they lack in discipline may be offset by their creativity and thinking out of the box.
FYI
Personality assessments have existed for a long time. The Myers-Briggs Type Indicator (MBTI), for example, was first published in 1962. Assessments of personality types have become more widely used recently because computer-based testing makes them easier to deliver and their perceived accuracy has grown. Such an assessment should not, however, be the sole basis for hiring someone. A test can simply help you better understand a job candidate. Personality tests are also helpful when forming teams for long-term or highly important projects. Human resources (HR) books and Web sites are also good sources for personality type models.
• Attackers—May seem angry or even hostile toward ideas and others on the team. They are critical of others’ ideas. They may know why things fail but offer no alternative solutions. They can be helpful in understanding the risks associated with a new policy. But don’t expect them to offer solutions to make the policies better.
• Pleasers—Are very kind and thoughtful to others. They want everyone to “feel good” and will put their own self-interest aside for the good of the whole. They may shy away from enforcing rules that offend others. These individuals would not be effecting enforcing security policies.
• Performers—Like to be on center stage. They like to entertain and be the center of attention. They develop over time a wit and charm to capture people’s attention. They may not be the highest producers and may be in the habit of self-promotion. These individuals are good candidates to promote awareness of and training in security policies. Their wit and humor, when harnessed, are effective in communicating why the security policy is important.
• Avoiders—Like to fly under the radar and be in the background. They tend not to take chances or do anything that brings attention on them. They will do precisely what’s asked of them but not much more. While not good as leaders at looking beyond the letter of the policy, they will execute the security policy and related processes consistently.
• Analyticals—Like structure and deadlines. They measure their success in precise terms of the number of widgets produced in a given time at a given quality level. They tend to be obsessed with precision and attention to detail. They may not be the best at understanding human dynamics, so working with customers and emotions may be a problem. They would be well suited for measuring the effectiveness of the information policy, such as by being part of the quality control function.
• Achievers—Are very result oriented. They may have several traits of the other personality types. For example, they may be self-confident but not at the expense of others. They genuinely want the best result and may seek different ways to achieve it. Achievers are well suited to listening to all stakeholders and crafting security policies that meet both security and business needs.
It’s rare that an individual is just one of these personality types. Typically, personality types blend and mix depending on many factors. Dominant traits over time can become your safe zone. A safe zone refers to the skills you are comfortable with to achieve a predictable outcome.
Understanding these personality traits is an advantage in implementing security policies. Often new security policies represent change. You can use the strengths of these personality traits to overcome objection to the change. For example, Analyticals could review detail logs and network designs to identify potential security threats. There is no set rule of how to tap the talent of each of these personality types. Understanding these types allows you to leverage people’s strengths to more quickly implement security policies.
Leadership, Values, and Ethics
Given all the material that has been written on the subject, entire libraries can be built around leadership, business values, and ethics. They are discussed in this section to help you better understand human nature in the workplace. This section focuses on how leadership affects employee behavior, and how good leadership can help ensure that employees adhere to policies.
Leaders must require proper behavior from employees and exhibit the same qualities in their own actions. A leader who demonstrates ethical behavior every day is more likely to see that behavior emulated by employees. Good leaders recognize the need to work within these personality types, guide their energy and passion, and get results. A leader’s job is to work through others to achieve specific goals. Implementing security policies is all about working through others to gain their support and adhere to the policies.
There is no secret formula for motivating individuals. Some widely accepted leadership rules that also apply to security policies include:
• Values—Good leaders have core values. Leaders share their core values with employees. Good leaders will seek to understand and convey the importance of security policies.
• Goals—Good leaders have clear vision and set goals. They communicate these goals both to the team and to individuals. They communicate how contributions lead to success. People want to know they are working on something that matters. Good leaders will be able to communicate the importance of the policy to the organization and to individual team goals.
• Training—Good leaders train their team to focus on goals and support each other’s work. A good leader will make sure the team is ready to take on the additional responsibilities outlined in the policy.
• Support—Good leaders accept failures. Things will go wrong. People will make mistakes. How a leader reacts to these mistakes sets a tone that can be healthy or destructive. The trust a good leader creates is essential in encouraging accurate reporting of whatever is not working. This, in turn, is essential in improving the control environment. When employees trust that they can report noncompliance without repercussions, and can report the reason the mistake was made, it’s more likely that the problem can be corrected and kept
from recurring. In fact, the practice of candid reporting of problems should be the norm and should be rewarded when it occurs.
• Reward—Good leaders reward results, not personalities. A quick way to demoralize a team is to reward individuals based on who is liked versus who produces. What’s commonly referred to as “company politics” can never be eliminated. However, the more a leader can measure real risk reduction because of security policies and controls, the less interference from office politics will be encountered.
Part of understanding human nature in the workplace is recognizing its complexity. You need to understand what motivates individuals and yourself. A leader can’t simply issue commands and expect good results time after time. Nor can an executive simply mandate information security policies and expect staff to follow them. Good leaders demonstrate core values in their own actions, and communicate their expectations. They understand the human personality, ignite passions, and inspire people to achieve common goals. Managers and employees must understand these dynamics to approach implementation of security policies in a realistic and thoughtful manner.
NOTE
Implementing security policy means continuous communication with stakeholders. It means being transparent about what’s working and what’s not working. In this way, the control environment can be continuously improved over time.
Being thoughtful about the implementation of security policies and controls means balancing the need to reduce risk with the impact to the business operations. It could mean phasing security controls in over time, or as simple as aligning security implementation with the business’s training events.
Organizational Structure
The way an organizational structure evolves over time affects the way people behave. Management must determine the behaviors and values it wants to promote. Then it can design an appropriate structure. The organizational structure chosen by management influences how security policies are put in place. It creates complex relationships and personal dynamics between different leaders, layers of approvals, and core values. An organization’s structure reflects the relationship between teams (or departments), their responsibilities, and lines of authority. Table 5-1 highlights some common types of stakeholders. It is not an exhaustive list. The list of stakeholders will vary depending on the policy being implemented. For example, data center security policies will typically include physical security. Consequently, data center security policies will include building managers to ensure all doors are secure and cameras are well placed. But Table 5-1 does illustrate the broad and competing interests that must be addressed when implementing a security policy.
An organizational structure clearly indicates who’s in charge and who reports to whom. Figure 5-2 depicts a typical U.S. company organizational chart. You can learn a lot from an organizational structure. In this example, notice two lines of businesses. Assume that these businesses are distinct enough that they require a separate focus and leadership. This could be because the products are distinctive or the customer base has unique needs. For example, a bank typically separates its retail banking functions (including services such as personal checking accounts and lines of credit) from its commercial banking (business loans and checking accounts, among other services). While both are banking functions, the products, customers, and regulations can be very different.
TABLE 5-1 Common stakeholders
STAKEHOLDERS KEY FOCUS AREAS
Lines of business Timely delivery of high-quality products and services at competitive prices
Information security Protection of the company and the customer
Compliance Compliance with laws and regulations
Operational risk Keeping operations within risk tolerances
IT architects Setting of technical standards
IT developers Building solutions to meet business and technical standards
IT operations Operationalizing
Audit Effective comprehensive assurance policies
Finance Effectively managed budgets
FIGURE 5-2 Typical organizational chart.
FIGURE 5-3 CISO reporting directly to CFO.
The key point is that an organizational structure gives you insight into leadership’s perspective on the business and the type of challenges faced. You also get a sense of priorities. You see in Figure 5-2 that the business has decided to centralize the information technology (IT) function. This is typically called shared services. This term relates to a department or team that provides similar services across an entire organization. By centralizing services, a business can reduce operating costs. For example, rather than building two almost identical data centers to service two business lines, both can share the same data center operated by the IT department. Within the IT department’s structure you find a further breakdown on how services are provided to the two lines of business. Also notice how some departments report directly to the office of the president. This gives them greater influence and perceived authority.
Let’s examine how these dynamics influence the implementation of security policies. Assume the chief information security officer (CISO) reports directly to the chief finance officer (CFO), as shown in Figure 5-3. The CFO’s role is traditionally a powerful position. Consequently, it’s more likely that information security is perceived as a business concern rather than solely a technology issue. This allows information security policies to be given a higher priority across the enterprise.
TIP
Consider the regulatory mandates, too, when understanding organizational influences. The higher the reporting of information security issues, the more influence. For example, GLBA requires the board of directors of an organization to be briefed on information security programs. GLBA requires many other things of corporate boards as well. But the point is that regulations requiring senior leadership engagement create visibility and opportunity to advocate for information security.
Conversely, let’s assume the CISO role reports three or four layers deep inside the IT department, as shown in Figure 5-4. The CISO would not have the organizational muscle to implement security policies with the same perceived influence or authority. This does not mean security policies couldn’t be implemented effectively. The difference would be the approach used given the organizational realities. In this case, the CISO would most likely seek greater executive involvement rather than reliance on the CFO’s influence and authority.
Ultimately, an organization has to determine how it wants to manage the division of labor and span of
control. The division of labor means how you group various tasks. It’s sometimes more effective to divide tasks into specialties. This way, the depth and quality is higher. As more tasks are divided into separate jobs, more specialties are created. As more specialties are created, more teams are formed. The result is the organization grows, along with operating costs. Employees are the most valuable resource but they are also expensive. They require salaries, training, supplies, facilities, benefits, and leadership support. An organization needs to divide labor in a way that yields quality and keeps it competitive while controlling operating costs.
FIGURE 5-4 CISO organizational chart—CISO role appears several layers deep.
FYI
The larger the organization, the more diverse a set of relationships will exist within it. This means potentially more stakeholders will need to be engaged. It is important to understand that the stakeholders in this matrix are not just communicating with the security team but also with each other. This is why transparency is a necessary part of the policy implementation process. The interaction of leadership and the different personalities can significantly impact a policy deployment. The more you can create a unified view, the greater the likelihood of success.
Another consideration is span of control, which relates to the number of layers and number of direct reports found in an organization. The span of control widens when a leader has many direct reports. This tends to flatten an organization. This is called a flat organizational structure. When the span of control widens, the leader is less connected to the details of what’s going on. If a leader has to deal with a dozen direct reports, for example, it’s doubtful he or she would have time to address many details. The leader would tend to focus on the big picture and the big risks.
There’s no magic rule on the right number of direct reports. The appropriate span of control depends on the nature of the business, complexity of the issues, and number of problems needing the leader’s attention. As the span narrows, the organization gains layers. This is called a hierarchical organizational structure.
More layers tend to make an organization bureaucratic. Hierarchical organizations are necessary. They allow specialties to thrive and produce high-quality products and services.
Having multiple layers isn’t necessarily bad. There needs to be separation, though, not just for efficiency but also to create segregation of duties. Separation of duties, also referred to as segregation of duties (SOD), refers to a requirement that a task be performed by more than one person. This approach is often used to prevent fraud and reduce errors. The point is to create the minimum number of organizational layers needed to achieve a specific business purpose. An organization can have an overall hierarchical structure with pockets of flat organizational structure for specific teams and departments. An example of SOD would be to separate the ability to set up a new vendor account and ability to authorize payment to a vendor. The ability both to set up and to authorize a vendor creates an opportunity for fraud. The SOD controls reduce the likelihood that a fake vendor is set up and paid.
The difference between a flat and hierarchical organization is relative to its size and business model. Figure 5-2 indicates that an organization can be perceived as either flat or hierarchical. To understand the difference, you need to understand the number of layers between managers controlling the business and workers delivering products and services. For example, assume Figure 5-2 represents a carpet cleaning business with 20 workers. The two lines of business could be commercial and residential customers. The organization could be perceived as hierarchical. This is because the number of layers between the president of the company and workers could be perceived as excessive. Given the size and complexity of the business, one would expect a much smaller and flatter organization. Yet the same figure when applied to a larger business would be relatively flat. For example, assume Figure 5-2 represents a major domestic bank that offers retail banking and credit cards as lines of business. A major bank could have tens of thousands of employees. Yet Figure 5-2 reflects a relatively flat organization.
Flat Organizations
In a flat organization, the leaders are close to the workers that deliver products and services. A flat organization is generally defined as one with a limited number of organizational layers between the top and bottom ranks. As a result, leaders know their customers’ and employees’ needs and problems firsthand. This tends to produce faster decisions and more confidence to innovate. The right leader within this type of structure can be inspiring. This structure gives the leader the ability to connect with the workers and build trust.
In a flat organization, leaders can bring their knowledge about customers and products to the creation and implementation of security policies. Security policies are not abstract concepts in a flat organization. They are seen through the lens of individuals directly accountable for the delivery of product and services. In a hierarchical organization, leaders are also responsible for product and services. The accountability is indirect, though, through several layers of leadership. Having firsthand knowledge of the company’s products and services is always valuable in implementing security policies.
Flat organizations often have decentralized authorities. This can quickly become a negative for flat organizations when the span of control becomes too wide. With wide span of control there is no time to bring every problem to management for resolution. In some ways you need higher caliber teams that feel comfortable making independent decisions. Yet these decisions can lead to problems, especially when dealing with information security. Some problems include conflicting statements to regulators by the subordinate and senior leadership. It’s important when defining security policy in a flat organization to decide clearly how issues are to be identified, catalogued, debated, and escalated. This includes clarity about who has the authority to speak to and present the full risk story to the regulator.
Hierarchical Organizations
For large organizations, hierarchical models are a necessity. The complexity required to keep a large
organization running effectively requires a hierarchy of specialties. This means senior leaders are more detached from day-to-day operations. Can the same tone at the top be sent to all employees in a hierarchical organization? Yes, but it’s more difficult than in a flat organization. The dynamics are different in a hierarchical organization.
Consider a help desk worker in an organization with 10,000 employees. The help desk worker is engaged with management within the team and department. Receiving a message on the importance of information security from the president of the company may have far less impact in a hierarchical organization. The message must still be sent but needs to be reinforced throughout the layers.
FYI
When rolling out information security policies, make communications a priority. Be sure your approach includes these points:
1. Be clear—avoid technical jargon when possible.
2. Set the tone at the top—ask your leaders to help deliver the message.
3. Use many channels—reinforce the message as many times as possible.
4. Be forthcoming—be honest and candid about any impact the policy will have.
5. Say “thank you”—acknowledge the efforts both to create and to implement the security policies.
This list is not exhaustive, but it highlights key points.
To be successful in implementing security policies in a large organization, you must continually sell the message at each layer. You must build support at the top, middle, and bottom ranks. You must choreograph the review, approval, and release process so you continue to be part of the messaging. Remember, the message can change as it moves through the layers of the organization. For example, when dealing with senior leaders, a core part of the message could be cost avoidance and reduction in operating risks. Messages to other layers might have greater emphasis on regulatory compliance or meeting customer expectations of privacy. It’s important to tailor the benefit message to resonate with the audience. If workers can connect with the importance and priority they are more likely to follow the policy.
Advantages of a Hierarchical Model
There are some distinct advantages to a hierarchical model. The importance of specialization has been discussed. In a hierarchical model, communication lines are more clearly defined. When you encounter a problem, there is most likely a group that specializes in that area that can help solve it. The depth of knowledge in a subject area tends to be greater. This allows managers to predict and avoid problems before they occur.
Managers can also create “centers of excellence.” These are small, specialized teams that focus on specific problems within an organization to help provide high-quality products and services. Large organizations often have teams dedicated to identifying the next big threat. These teams examine industry breaches and analyze if the company would be vulnerable to those types of attacks. In a small flat organization, these specialties and skills may not be available.
Disadvantages of a Hierarchical Model
There are also some disadvantages in a hierarchical model. One such disadvantage is accountability. A hierarchical model relies on work passing between a number of teams to ultimately produce a product or service. A communications breakdown between these groups could cause errors or delays.
Accountability could also be a problem. When many component teams are involved, whose fault is it if something doesn’t work? This becomes even more difficult when the teams cross organizational boundaries such as between large departments.
WARNING
The larger the organization, the faster it can grow. For example, the more teams involved in producing a product or service means more teams will be needed to coordinate their activity. It’s important that an organization does not grow for the sake of growth. It’s especially important that security policies keep pace with organization growth, which drives a greater exchange of information sharing.
There’s no one structure that fits all organizations. The right type of structure for an organization depends on multiple factors, such as the organization’s goal and the individual styles of its managers. A mature organization, moreover, may tend to be more hierarchical than flat. And an individual manager may be more comfortable establishing layers of controls, leading to a more hierarchical rather than flat organization.
In the end, it’s people within the organization who will make the implementation of security policies and controls successful. How they are motivated to adopt the security principles within these policies indicates how easily you can introduce change. The inherent disadvantage of a hierarchical model is the number of touch points and personalities that must be engaged to successfully implement a security policy. As the number of touch points increases, the number of complex matrix relationships also increases. Matrix relationships are the complex relationships between stakeholders. For example, a line of business and data center operations may be two stakeholders. The relationships involved in discussing a proposed policy might be between the security team and the line of business, the security team and data center operations, and data center operations and the line of business. Conversations may also get more complex as these discussions occur lower in the organizations. Conversations and relationships between senior leaders would be different from those at a staff level. The point here is that you should expect that a complex set of relationships will influence and drive policy conversations. Successful implementation of security policies will depend on how well you can navigate these people issues.
The Challenge of User Apathy
In its basic form, apathy is indifference and lack of motivation. An employee who is apathetic often “goes through the motions.” This attitude results in poor performance and doing the minimum to get by. In the case of information security, it’s hard to imagine that doing the minimum keeps information safe.
Policies by their nature cannot anticipate every situation. Talented and trained individuals will always be needed to deal with the unexpected. The combination of an apathetic worker with an unexpected security incident can result in disaster. A simple delay in reporting a potential incident, for example, could mean the difference between preventing an incident or having to deal with its aftermath. An apathetic worker can miss the opportunity to prevent sensitive information from getting into the wrong hands, leaving thousands of angry customers whose personal privacy has been breached.
TIP
Assigning a security liaison within a department or group can often be a way to effectively engage a group of workers. Someone who knows the personalities and language of the group can convey the security message in a positive way.
Well-defined security policies assume a certain level of non-compliance and even worker apathy. You build redundancy into security policies to detect and react to security breaches. In this way, you don’t have to rely on any one individual to maintain security. A good example is automated escalation. If an administrator is paged about a potential security breach and fails to respond within a given time limit, an escalation page is sent to a supervisor. Security policies can require such escalation.
Overcoming the effects of apathy on security policies is a combination of the following:
• Engaged communication—Get leaders to listen to reasons for worker apathy. Adjust the implementation strategy to better explain the importance of the policy within the context of the individual role.
• Ongoing awareness—Continually reinforce the message of the value and importance of information security. Good security awareness can be a preventative measure against apathy.
• Setting the right expectations—Ultimately workers are expected to follow policy as part of their jobs. Compliance must be monitored and individuals held accountable.
• Creating some layers of redundancy—Some layers of redundancy are good. Avoid, whenever possible, sole reliance on any individual or single technology.
• Recognize and reward compliance—Seek opportunity to spotlight individuals who model the desired behavior. This can be as simple as public recognition by a senior executive or a small gift card reward.
The Importance of Executive Management Support
Implementing security policies starts with executive management. Without executive support, policies are just words. To have meaning they must be given the right priority and be enforced. That’s when the benefits and value of security policies are realized for an organization. Implementing security policies creates a culture in which risk awareness takes work and resources. Unfortunately, some executives see involvement with security policies and risk awareness as an IT issue, and a distraction given their other priorities. However, executive management support is critical to the success of security policy implementation and acceptance throughout the organization.
Be cautious if the security policy depends on the executive management support to implement large, complex IT systems. Not even large IT projects with large budgets have any guarantee of success. In fact, there are numerous examples to indicate that the larger the IT deployment, the greater the risk of failure. A study by McKinsey in 2012 revealed that 17 percent of IT projects with budgets greater than $15 million fail so badly that the company involved almost goes out of business. Consider the rollout of HealthCare.gov, the government Web site for people needing to sign up for medical insurance under the Affordable Care Act. The site’s early months were a disaster, marked by system crashes and lack of functionality, despite a budget of more than $600 million.
Selling Information Security Policies to an Executive
Understanding executive perception of these successes and failures is important. These perceptions must be overcome when soliciting support from executives. An online business site reported that projects fail due to eight common perceived missteps:1
• Unclear purpose—Unclear purpose refers to the clarity of value the project brings. In the case of security policies, it’s important to demonstrate how these policies will reduce risk. It’s equally important to demonstrate how the policies were derived in a way that kept the business cost and impact low.
• Doubt—Doubt refers to the need for change. You need to explain why what’s in place today is not good enough. Change is perceived as a distraction from the core business. You need to convince the executive that the benefits outweigh disruption. Doubt may also be a factor if an organization has had several false starts. If several attempts have been made to implement a security policy with little success, you must convince them that this time is different. Even when the message and benefits are clear, it is also a matter of credibility with the executive.
• Insufficient support from leadership—Insufficient support from leadership refers to the broad support for the project. In the case of policies, a leader doesn’t like surprises and wants to know he or she is not alone. You need to explain both the depth and breadth of support for the policies. To avoid surprises, be sure to articulate any pushback you are getting from other leaders. This will help avoid surprises and the executive can be an advocate to sway his or her peers. When problems are encountered, be sure to anticipate where your support will emerge or evaporate.
• Organizational baggage—Organizational baggage refers to how the organization executes, as judged on the basis of past unsuccessful efforts. Unlike doubt, which is a personal credibility issue, this category focuses on the organization’s ability to execute. If an organization continues to have problems implementing policies of any kind, how will security policies be any different? This type of organization usually fails to stay on course. Organizations that reorganize twice a year or have frequent leadership changes fall within this category.
• Lack of organizational incentives—Lack of organizational incentives refers to the inability to motivate behavior. Value is only derived from policies when they are enforced. An organization must have the will and process to reward adherence. The organization must have a low or zero tolerance for security policy violations.
• Lack of candor—Lack of candor refers to not having open, candid conversations. In the case of policies, you need to be clear what can and cannot be achieved. You need to listen and explain how the business’s input was considered and adopted or rejected. Executives need a sense that they were part of a process and not just the recipients of the result.
• Low tolerance for bad news—Low tolerance for bad news refers to how executives react to missteps. You can count on an error in judgment at some point in implementing security policies. You need to prepare executives for the inevitable. You also need to gauge how they will react.
• Unmanageable complexity—Unmanageable complexity refers to how complex and realistic the project is. The ability of the organization to support the security polices will be an important topic of conversation.
Before, During, and After Policy Implementation
There’s an art and science to obtaining support from executives for security policies. It’s as much about confidence and credibility as it is about the facts. It’s important to stay engaged and in communication with executives before, during, and after security policy implementation.
One pitfall you want to avoid is trying to turn an executive into a knowledgeable security expert. Executives generally have neither the time nor interest, and need to rely on your expertise. What they do expect is that you have packaged the implementation steps into clearly understood and manageable tasks that minimize costs and effort. Their staff will also report back to them the results of your efforts. Therefore, you must be clear about what you expect and what the business must deliver.
TIP
Establish relationships with key stakeholders well in advance of creating security policies. Building confidence and credibility early makes implementing security policies later that much easier.
The following is a checklist for packaging implementation tasks and to help stay on point when discussing security policies:
• Clarity of objectives—What goals and benefits are to be achieved?
• Things to do—What exact tasks are to be performed and by whom?
• Things to pay attention to—How does the business know if it is successful?
• Things to report—What should be reported and when?
• Roles and responsibilities—Who’s responsible for what?
• Things to be aware of—Why is the security policy in place?
• Things to reinforce with employees—What is the messaging to the staff?
Investing in planning prior to implementation will build a strong relationship with executives. It should also build true support. Executives who truly support you will continue their support when things do not go as planned. Messaging to executives needs to include their accountability for information security. Their role is essential to create a genuine effort to protect information. In the end, it’s their organization that is affected when a breach occurs.
The Role of Human Resources Policies
Well-defined HR policies provide the framework that governs employee relations. HR policies state core business values and what is expected. They can also prevent misunderstandings. Managers are more likely to engage a worker on sensitive topics, such as lack of performance, when there’s a clear process they can follow to stay out of trouble. Like any written record, the HR policies can be used against an organization in a lawsuit. Poorly drafted policies become evidence to support an employee’s contention that he or she acted within company expectations.
Although HR policies must demonstrate commitment to secure business practices and clearly state values, they must be flexible and definsible in a court of law while meeting business objectives. They must also establish processes for management to follow. You often find HR policy language intentionally vague. This avoids language that could be interpreted as an employment contract or unintended promise. Although they may be flexible in their language, HR policies must be applied consistently across individuals. For example, disciplining two individuals differently for the same security policy violation could result in a lawsuit. In contrast, security policies must be precise, establishing clear expectations of behavior that can be enforced.
Consequently, automated enforcement of security policies shows consistency and often leads to higher compliance rate than manual controls. It’s also better to stop a security policy violation immediately through automation than to deal with its aftermath. However, how do you enforce security policies when automated controls are not available or ineffective? A classic example is when a worker views inappropriate sexual material on a company computer. Let’s assume it can clearly be shown as willful versus accidentally stumbling onto an inappropriate Web site. This example starts to show reliance that security policies have on HR policies to define acceptable behavior and to enforce adherence through disciplinary actions.
Relationship Between HR and Security Policies
Security policies must be well grounded within HR policies. Don’t look for precision in HR policies. They are better viewed as a foundation on which to build. They establish broad rules of acceptable behavior. These rules cover such topics as expectation of privacy when using company computers to declaring zero tolerance for certain inappropriate behaviors. Security policies can then operationalize these core values and define controls to enforce them. Just as security policies must align to business processes, they must also align to HR policies.
NOTE
The acceptable use policy (AUP) is often based in part on HR policy. It establishes expected behavior such as prohibiting access to social networking sites from company computers.
FIGURE 5-5 Conceptual relationship between HR policies and security policies.
The relationship between HR and security policies can be seen in Figure 5-5. This figure depicts several key touch points. Let’s use the previous example of viewing inappropriate material on a company computer. Figure 5-5 illustrates the relationship between HR and security policies. First, An HR policy would state the core value. This could be as simple as “Computers are for company use only.” Or it could detail the type of material prohibited. The security policies could then align by outlining acceptable uses of the Internet. Preventative security controls can be designed to block unacceptable sites. A worker who finds a way around these controls may be discovered through detective controls that scan company computers for unauthorized software and information. If such material is found, management can determine what disciplinary action, if any, is necessary. Management would look to HR policies for guidance. After working with HR, management might decide a formal warning or even termination is appropriate. This illustrates the close alignment needed between HR and security policies.
Lack of Support
The ability to take disciplinary action to enforce security policies is not the only reason to seek support from HR. A lack of support can also make implementing security policies difficult or impossible. You need to remember that HR is a primary point of contact with workers. It can serve as a point of communication with the employees and a place to resolve conflicts. The following outlines several key areas of support provided by HR regarding security policy implementation:
• HR policy and values—Establishes a baseline of permitted behavior, including the acceptable use of company technology
• Security awareness—Promotes understanding of security policies
• Exit interview—Allows departing employees to express how effective security controls are in enabling or inhibiting employee productivity; this candid expression allows for the continued improvement of security policies
• Event monitoring—Allows a broader understanding of how effective security policies have been implemented
• Disciplinary action—Provides a process to adjust behavior to align with security policy expectations
• Source of authority—Provides authority for establishing security controls
You need HR support to make sure you are interpreting the language correctly. These interpretations become the basis of key security policies such as monitoring employee behavior on company equipment. If you don’t have the right interpretation of HR policies, it’s difficult or impossible to design effective security controls to prohibit certain behavior.
Security policies rely on employees understanding and cooperating with the rules. Security awareness is one of the best ways to achieve this understanding. A good security awareness program starts when a new employee walks in the door. It’s reinforced at least annually and as an employee is promoted into new responsibilities. A lack of HR support makes it impossible to provide security awareness to new employees, when they are first hired or when their jobs change.
Continuous improvement relies on people telling you what is and isn’t working. A good source for this information is an employee departing a company. You ask current employees what they think. But do you know if they are just telling you what you want to hear? They may not want to make waves. Individuals departing a company tend to be more candid with less to lose. Most HR departments conduct what is called an “exit interview.” They ask basic questions about the work environment and why the person is leaving. It’s also a good opportunity to ask a few well-selected questions on security. This could help you understand the strengths and weaknesses of the information security program. A lack of HR support means you never get to ask the question to know where your security weaknesses may lie.
An important part of HR’s job is to field complaints from employees. No matter how good you are at explaining security policies, at some point you will ruffle someone’s feathers. Count on them calling HR to complain. To get HR staff on your side, you need to let them know exactly how and why you are implementing security policies. They are skilled in listening and communicating with employees on sensitive matters. They can support you to help defuse problems. They can explain how the policies align with company values. They can reinforce key security awareness messages. A lack of support has the opposite effect. Complaints can escalate and get out of hand. Worse yet, if HR takes the employee’s side, you may find yourself backing down on security policies or weakening the security awareness message.
You have learned how HR support relates to disciplinary action. If security policies are not enforced, employees inevitably perceive them as unimportant. Management needs the broad mandates within HR policies to assess employee performance. This includes how well people follow security policies. Without this HR support, security policies become optional and unenforceable.
Security policies, like any policy, must have a mandate. Someone in authority has to say “This is important” and “You have to do it.” Often this comes from executive leadership. On occasion you can point to key values within HR policies as an additional source of authority. Doing so also provides a perceived mandate
that helps gain support among executives. A lack of HR support makes it more difficult to obtain executive approval for security policies and easier to have them challenged.
In summary, it’s difficult or impossible to implement security policies without HR support. Fortunately, HR in most organizations understands its role in helping implement security policies. It’s rare to find an HR department that attempts to hinder implementation of security policies. More likely, you will find different degrees of support. The relationship with HR is an important one for the information security team to develop.
Policy Roles, Responsibilities, and Accountability
It’s important to note that change is inevitable. The implementation of security policies is just one of a vast array of changes employees must absorb. Understanding this is important when creating security policy roles, responsibilities, and accountability. The closer you can align employees’ current roles with their current job responsibilities, the easier it will be to implement. For example, assume a security policy requires a certified security trainer for a specific team. Now assume that team already has a trainer for a nonsecurity purpose such as office safety. Combining these roles and responsibilities could create the opportunity to combine training requirements and make it easier for the business to accept the security policy.
Many players are involved in the process of security policy implementation. The roles and responsibilities are different depending on where you are in the life cycle of a security policy. The term “life cycle” in this chapter refers to the creation, implementation, awareness, and enforcement of security policies. These different tasks require different roles and responsibilities.
There are many theories on how to approach change and an individual’s role in the change process. The key point is to understand everyone’s role from the perspective of a change model. You need to clearly define everyone’s role when developing and changing policies. You also need to recognize different roles when it comes to enforcing policies after they have been implemented.
TIP
When you implement security policies, you are implementing change. This can include implementing business perspectives and organizational values. This means sometimes you are implementing culture change as much as security controls. Be sure to select a change management model that speaks to the need to influence leaders as much as to technical implementation of controls.
Change Model
There are lots of change models to choose from. You may be able to adapt some when implementing security policies. This section focuses on Kotter’s Eight-Step Change Model. John Kotter, a professor at Harvard Business School, developed the model. He introduced the model in 1995 in a book titled Leading Change. The model has been widely adapted for a number of purposes. This model addresses the need to create executive support for implementing change. This is a critical success factor in implementing security policies.
Professor Kotter states that to be successful in implementing change in a company at least 75 percent of management needs to “buy into” it. The early stages of creating vision and urgency around the need for security policies will be critical later to build the coalition of executives needed to make change happen.
Let’s examine the model in relation to implementing security policies. The model divides an effective change process into eight steps:
1. Create urgency—For change to happen there must be an urgent need. Helping people understand information security threats and risk to the business can help build this sense of urgency.
2. Form a powerful coalition—For change to happen leadership must back you. Establish early a tone at the top for the need for the security policy.
3. Create a vision for change—Change needs to be understandable. It must be clear what you are asking of people and what measurable benefit the security policy will bring.
4. Communicate the vision—Once you have support, you need to communicate your intent widely. Communicate the security message through as many channels as possible.
5. Remove obstacles—There will be barriers to your success. Empower individuals to be change agents. A change agent is someone tasked with challenging current thinking.
6. Create short-term wins—Success, no matter how small, breeds more success. Focus on small well- defined goals that collectively build toward larger long-term goals.
7. Build on the change—Real change takes time and continued effort. Build a process of continuous improvement of the security policies.
8. Anchor the changes in corporate culture—To make anything stick, it must become habit and part of the culture. Find opportunities to integrate security controls into day-to-day routines.
Figure 5-6 shows how this model can be adapted to implementing security policies. You would cycle through this model each time you added a new security policy or made a major change to an existing policy. This model ensures that before you start a formal implementation you have the leadership support needed to succeed. This figure also highlights the separation between informal and formal tasks. When we adapted Kotter’s model for the purposes of this chapter, we created a separation between informal and formal implementation tasks. This is to emphasize the importance of preparing for policy implementation through informal discussions versus starting a formal project approach right away. There are two major benefits to having these informal tasks. First, you gain executive support. Having a formal project before you have executive support is presumptuous and will create unnecessary resistance. Second, it establishes a collaborative setup that allows you to change and modify your approach. It also builds ownership into the process for the executive giving you advice.
FIGURE 5-6
Basic policy implementation approach.
Responsibilities During Change
Implementing security policies is easier if you manage it from a change model perspective. It helps you establish a collaborative style that allows business leaders to understand and buy into what you are trying to accomplish. The process starts with an informal set of steps that builds awareness and understanding. With a clear purpose beyond your security policies, you can build the executive support needed to succeed.
Using the steps in Kotter’s Eight-Step Change Model, the following sections explain the roles and responsibilities involved in the change process.
WARNING
Be candid and transparent with leaders. Explain clearly what information security policies can and cannot achieve. Equally important, be upfront about the impact on the business; otherwise you risk losing credibility.
Step 1: Create Urgency
It is the responsibility of the CISO, who may simply be called the information security officer (ISO), to convey urgency to business leaders. This is selling the need for information security. An effective way of doing this is t