1 / 7100%
Running head: Information Security Planning
1
Information Security Planning
CSIS 341 – Final Research Paper
Joshua Caggiano
Information Security Planning
2
Intro
Withing the security field many individuals neglect the importance of security policy and
planning. While it might be exciting to test systems for vulnerabilities it is important to
remember that without the proper implementation and execution of security policies many
systems might remain vulnerable. Even after vulnerabilities are discovered within a system,
many companies next step of action is security planning and implementation of fixes and new
standards within a security policy [ CITATION Wan16 \l 1033 ]. It is important to plan out
polices that have well described and concise actions steps and compliance steps for oversite. This
gives the organization the ability to implement them within and standardize it’s polices.
Implementing and auditing are an important part of the security team job function, so that
systems are complying with established polices. In an enterprise environment polices might
include government regulations and standards, and if not implement could result in fines for the
company. One common example of such policy is the SOX government regulations also known
as the Sarbanes-Oxley Act of 2002 [ CITATION Bas15 \l 1033 ], this policy that must be
implement within certain companies. When creating company security polices it must remember
to think of the CIA triad when creating polices, so that they are not overbearing and provide
availability to resources for its users. While many polices include protection from viruses,
internet usage, server build standards. One often forgot is storage security and backup recover
security policy. This paper will be focusing on the creation and common requirements of a
storage and backup security policy, within a median size company.
Information Security Planning
3
Storage and Backup Security Policy
1. Overview
Backup Recover and Storage is an extremely important part of a security policy in case of
a security event. Protecting where information is stored and backing up systems and storage is
the just as important. This policy is one of the crucial parts of security disasters for reason that
will be described within the purpose section.
2. Purpose
The purpose for the backup recover and storage policy is to have all systems and storage
configured for backup and recover. As well as have a secure place for systems and applications
to store data of sizable amounts. Auditing of this policy will make sure that systems and storage
are compliment will take place. This policy will also consider the CIA triad within its
implementation.
3. Scope
The scope of this of this policy includes all company owned servers and storage devices
outside or within company property.
4. Policy
This companies Solution Architect, Storage/Backup Engineers, and Security/Networking
Engineers. Will support the creation of new backups systems and storage systems, within the
companies. It also will review the successful and failures of these systems. It is important to
review backups are successful incase of security event that causes damage.
Information Security Planning
4
Important Notes Company infrastructure
Since this is a medium size company its infrastructure has been moved to the AWS Cloud
environment.
Guidelines
Storage
•
All storage will be mounted by using AWS S3 buckets as SMB or NFS share.
•
IAM roles will be given to these S3 bucket share based on a group policy structure
implemented by our security team[ CITATION Yan15 \l 1033 ].
•
All S3 buckets for systems owned by this company will be duplicated across at least one
other availability zone within a different region for disaster recovery. This is in the case
of a security event that causes destruction of systems or data[ CITATION Yan15 \l 1033 ].
•
S3 Bucket Storage of critical systems will not be made public under any circumstance
within AWS.
•
There is mandatory encryption of all S3 Buckets on critical systems.
Backups and Recover
•
All EC2 server will use lifecycle policy for automated volume-based backup snapshots
daily.
•
The standard retention policy of backups snapshots is 30 days. All backups that need to
be saved older than 30 days will need to be archived within S3 Glacier
Bucket[ CITATION JBa16 \l 1033 ].
•
Automation of backups S3, RDS Databases, EBS volumes, or EFS will be done by AWS
Backup.
Information Security Planning
5
•
Retention policy of backups within AWS Backups will be 30 days
•
Backups within AWS Backup will happen daily
•
All backups of critical systems will be encrypted
•
Backup success will be monitored and audited for successful, three or more failures will
be cause for investigation.
5. Policy Compliance
Auditing of polices and correct engineering of system will be down after a system has
been created. Reports will be created to Auditing and Security Engineers to make sure all
system are complying annually. Monthly backup auditing will happen to confirm that all
systems within the environment are being backup and getting successful backups.
Exceptions
Any exception to this policy will be reviewed for approval be departs list Backup and
Storage Engineers, AWS Solution Architects, and Security/Network Engineer.
Non-Compliance
Any system or storage that is built and does not comply with this policy will be subject
corrective action to be taken, depending frequency of non-compliance and criticality of
system terminal could result.
Information Security Planning
6
Overview
This policy was created to protect systems and storage in event of a system or storage
going down because of corruption, patching issues, security events, and environmental or
security disasters [ CITATION Kyu18 \l 1033 ]. In overview it is important to protect storage
through encryption to keep unauthorized user out, keep storage S3 buckets from being public
to unauthorized people. It is also important to have storage devices protected and backup so
that availability is there for the employees that use it.
Implementing backup and retentions standards are an important security policy so
that systems can be recovered, but also so that a company is not holding on to too much
backup data, which could cost the company unneeded expense. The S3 archival system is
implemented as a cheap way to store data that needs longer retention[ CITATION Yan15 \l
1033 ]. This can give the security engineer and system engineer confidence and ability to
restore critical data and bring backup the companies systems. All these security guidelines
are implemented for the protection of data and system. As a security engineer is it their
number one adjective to protect its system from issues and provide availability to its clients.
Information Security Planning
7
References
Basile, A., Handy, S., & Fret, F. N. (2015). A Retrospective Look at the Sarbanes-Oxley Act of 2002- Has it
accomplished its original purpose? Journal of Applied Business Research, 1-9.
Han, Y. (2015). Cloud storage for digital preservation: optimal uses of Amazon S3 and Glacier. Library Hi
Tech, 1-3.
J Baron, S. K. (2016). Storage Options in the AWS cloud. Retrieved from aws.amazon.com: myrtec.com.au
Kyungroul Lee, S.-Y. L. (2018). Machine Learning Based File Entropy Analysis for Ransomware Detection in
Backup Systems. IEEE, 1-10.
Wang Shao-Long, W. J.-P. (2016). Wireless Network Penetration Testing and Security Auditing. ITM Web
of Conferences, 5.
Students also viewed