Need help
ports Organizational Mission, Goals and Objectives • Risk Management • Security Management • Personnel Security
• Professional Ethics
1
2 Chapter 1
The International Information Systems Security Certification Consortium (ISC)2 Common Body of Knowledge (CBK) defines the key areas of knowledge for Information Security and Risk Management in this way:
Information Security and Risk Management entails the identification of an organization’s information assets and the development, documentation, and implementation of policies, stan- dards, procedures and guidelines that ensure confidentiality, integrity, and availability. Man- agement tools such as data classification, risk assessment, and risk analysis are used to identify the threats, classify assets, and to rate their vulnerabilities so that effective security controls can be implemented.
Risk management is the identification, measurement, control, and minimization of loss associ- ated with uncertain events or risks. It includes overall security review, risk analysis; selection and evaluation of safeguards, cost benefit analysis, management decision, safeguard imple- mentation, and effectiveness review.
The candidate will be expected to understand the planning, organization, and roles of indivi- duals in identifying and securing an organization’s information assets; the development and use of policies stating management’s views and position on particular topics and the use of guidelines, standards, and procedures to support the policies; security awareness training to make employees aware of the importance of information security, its significance, and the spe- cific security-related requirements relative to their position; the importance of confidentiality, proprietary and private information; employment agreements; employee hiring and termina- tion practices; and risk management practices and tools to identify, rate, and reduce the risk to specific resources.
Key areas of knowledge:
· Understand and document the goals, mission, and objectives of the organization
· Establish governance
· Understand concepts of availability, integrity, and confidentiality
· Apply the following security concepts in planning: defense in depth, avoid single paths of failure
· Develop and implement security policy
· Define the organization’s security roles and responsibilities
· Secure outsourcing
· Develop and maintain internal service level agreements
· Integrate and support identity management
· Understand and apply risk management concepts
· Evaluate personnel security
· Develop and conduct security education, training, and awareness
· Understand data classification concepts
· Evaluate information system security strategies
· Support certification and accreditation efforts
· Design, conduct, and evaluate security assessments
· Report security issues to management
· Understand professional ethics
1
Organizational Mission, Objectives, and Goals 3
Even though this domain is positioned as number 5 in the Certified Information Systems Secu- rity Professional (CISSP) common body of knowledge, it is placed first in this book because all security activities should take place as a result of security and risk management.
Organizational Mission, Objectives, and Goals
In order to be able to protect an organization’s assets, it is first necessary to understand sev- eral basic characteristics of the organization, including its goals, mission, and objectives. All are statements that define what the organization desires to achieve and how it will proceed to achieve them. These three terms are described in more detail here.
Mission
The mission of an organization is a statement of its ongoing purpose and reason for exis- tence. An organization usually publishes its mission statement, so that its employees, custo- mers, suppliers, and partners are aware of the organization’s stated purpose. Some example mission statements:
“Promote professionalism among information system security practitioners through the provisioning of professional certification and training.”—(ISC)2
“Empower and engage people around the world to collect and develop educa- tional content under a free license or in the public domain, and to disseminate it effectively and globally.”—Wikimedia Foundation
“Help civilize the electronic frontier; to make it truly useful and beneficial not just to a technical elite, but to everyone; and to do this in a way which is in keep- ing with our society’s highest traditions of the free and open flow of information and communication.”—Electronic Frontier Foundation
An organization’s security professionals need to be aware of their organization’s mission, because it will, in part, influence how we will approach the need to protect the organization’s assets.
Objectives
The objectives of an organization are statements of activities or end-states that the organiza- tion wishes to achieve. Objectives support the organization’s mission and describe how the organization will fulfill its mission.
4 Chapter 1
Objectives are observable and measurable. People can determine whether the organization met its objectives or not. Also, objectives do not necessarily specify how they will be com- pleted, or by whom.
Sample organization objectives include:
“Obtain ISO 27001 certification by the end of third quarter.” “Reduce development costs by twenty percent in the next fiscal year.” “Complete the integration of CRM and ERP systems by the end of November.”
Security personnel need to know the organization’s objectives and be involved in their fruition, so that the organization can achieve its objectives with the lowest reasonable level of risk.
Goals
While objectives describe desired end-states for an organization, goals specify specific accom- plishments that will enable the organization to meet its objectives.
Security Support of Mission, Objectives, and Goals
Security professionals in an organization ought to be concerned with the reduction of risk through the proper activities and controls that protect assets and activities. We need to be keenly aware of our organizations’ mission, objectives, and goals, so that we can become involved in the key activities that the organization is undertaking.
Involvement and influence in an organization’s key activities requires the support of senior management. This support comes in the form of priorities and resources that permit security professionals to be closely involved with key activities. This is discussed in greater detail later in this chapter in the section, “Security Management.”
Risk Management
Risk management is the process of determining the maximum acceptable level of overall risk to and from a proposed activity, then using risk assessment techniques to determine the initial level of risk and, if this is excessive, developing a strategy to ameliorate appropriate individual risks until the overall level of risk is reduced to an acceptable level. In the vernacular this means, find the level of risk (associated with a given activity or asset) and do something about it if needed.
Two basic steps are performed in risk management: risk assessment and risk treatment. Risk assessment is used to identify risks, and risk treatment is used to manage the identified risks. These are discussed in the remainder of this section.
NIST 800-30, Risk Management Guide for Information Technology Systems, is an outstand- ing, high quality standard for risk management. This document was developed by the U.S. National Institute of Standards and Technology, which develops all of the security standards for the U.S. federal government.
Risk Assessment
Risk Management 5
1
Risk assessments are activities that are carried out to discover, analyze, and describe risks. Risk assessments may be qualitative, quantitative, or a combination of these.
Internal audit is related to risk assessment; internal audit is discussed in a separate section in this chapter.
Qualitative Risk Assessment A qualitative risk assessment occurs with a pre-defined scope of assets or activities. Assets can, for example, consist of software applications, infor- mation systems, business equipment, or buildings. Activities may consist of activities carried out by an individual, group, or department.
A qualitative risk assessment will typically identify a number of characteristics about an asset or activity, including:
· Vulnerabilities. These are weaknesses in design, configuration, documentation, procedure, or implementation.
· Threats. These are potential activities that would, if they occurred, exploit specific vulnerabilities.
· Threat probability. An expression of the likelihood that a specific threat will be carried out, usually expressed in a Low-Medium-High or simple numeric (1–5 or 1–10) scale.
· Countermeasures. These are actual or proposed measures that reduce the risk associated with vulnerabilities or threats.
Here is an example. A security manager is performing a qualitative risk assessment on the assets in an IT environment. For each asset, the manager builds a chart that lists each threat, along with the probability of realization. The chart might resemble the list in Table 1.1.
This is an oversimplified example, but sometimes qualitative risk analysis won’t be much more complicated than this—although a real risk analysis should list many more threats and countermeasures.
|
Threat |
Impact |
Probability |
Countermeasure |
Probability |
|
Flooding |
H |
L |
Water alarms |
L |
|
Theft |
H |
L |
Key card, video surveillance, guards |
L |
|
Earthquake damage |
M |
M |
Lateral rack bracing; attach all assets to racks |
L |
|
Logical intrusion |
H |
M |
Network-based intrusion detection system; host-based intrusion detection system |
L |
Table 1-1 Risk assessment chart
Quantitative Risk Assessment A quantitative risk assessment can be thought of as an extension of a qualitative risk assessment. A quantitative risk assessment will include the elements of a qualitative risk assessment but will include additional items, including:
• Asset value. Usually this is a dollar figure that may represent the replacement cost of an asset, but could also represent income derived through the use of the asset.
6 Chapter 1
· Exposure factor (EF). The proportion of an asset’s value that is likely to be lost through a particular threat, usually expressed as a percentage. Another way to think about exposure factor is to consider the impact of a specific threat on an asset.
· Single loss expectancy (SLE). This is the cost of a single loss through the realization of a particular threat. This is a result of the calculation:
SLE = asset value ($) × exposure factor (%)
· Annualized rate of occurrence (ARO). This is the probability that a loss will occur in a year’s time. This is usually expressed as a percentage, which can be greater than 100% if it is believed that a loss can occur more than once per year.
· Annual loss expectancy (ALE). This is the yearly estimate of loss of an asset, calculated as follows:
ALE = ARO × SLE Let’s look at an example: an organization asset, an executive’s laptop computer, that is
worth $4,000. The asset value is $4,000.
Now we will calculate the exposure factor (EF), which is the proportion of the laptop’s value that is lost through a particular threat. The threat of theft will, of course, result in the entire laptop’s value to be lost. For theft, EF = 100%. For sake of example, let’s add another threat, that of damage, if the executive drops the laptop and breaks the screen. For that threat, the EF = 50% (presuming a $2,000 repair bill to replace the LCD screen).
For theft, the single loss expectancy (SLE) is $4,000 × 100% = $4,000. For damage, the SLE is $4,000 × 50% = $2,000.
Now we need to calculate how often either of these scenarios might occur in a single year. For theft, let us presume that there is a 10% probability that this executive’s laptop will be stolen (he’s a popular individual). Thus, the ARO = 10%. This particular executive is really clumsy and drops his laptop computer a lot, so the ARO for that threat is 25%.
The annual loss expectancy (ALE) for theft is 10% × $4,000 or $400.
The ALE for damage is 25% × $2,000 = $500.
This all means that the organization will lose $900 ($400 for theft and $500 for damage) each year in support of the executive’s laptop computer. Knowing this will help manage- ment make more intelligent spending decisions for any protective measures that they feel will reduce the probability or impact of these and other threats. This is discussed in the next section on countermeasures.
Quantifying Countermeasures Annual loss expectancy (ALE) is the cost that the orga- nization is likely to bear through the loss of the asset. Because ALE is expressed in dollars (or other local currency), the organization can now make decisions regarding specific investments in countermeasures that are designed to reduce the risk. The risk analysis can be extended to include the impact of countermeasures on the overall risk equation:
• Costs of countermeasures. Each countermeasure has a specific cost associated with it. This may be the cost of equipment, software, or labor costs.
Risk Management 7
· Changes in exposure factor. A specific countermeasure may have an impact on a specific threat. For example, the use of an FM-200-based fire extinguishment system will mean that a fire in a business location will cause less damage than a sprinkler- based extinguishment system.
· Changes in single loss expectancy. Specific countermeasures may influence the probability that a loss will occur. For instance, the introduction of an anti-virus network appliance will reduce the frequency of malware attacks.
Geographic Considerations Organizations can take quantitative risk analysis a step or two further by calculating SLE, ALE, and ARO values in specific geographic locations. This is useful in organizations with similar assets located in different locations where the probabil- ity of loss or the replacement cost of these assets varies enough to matter.
Specific Risk Assessment Methodologies The risk assessment steps described in this section are intentionally simplistic, with the intention of illustrating the concepts of identi- fying the value of assets and by using formulas to arrive at a quantitative figure that repre- sents the probable loss of assets in a year’s time. For some organizations, this simple approach may be sufficient. On the other hand, there are several formal approaches to risk assessment that may be suitable for larger or more complex efforts. Among these approaches are:
· OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation). Developed by Carnegie Mellon University’s Software Engineering Institute (SEI), OCTAVE is an approach where analysts identify assets and their criticality, identify vulnerabilities and threats, evaluate risks, and create a protection strategy to reduce risk.
· FRAP (Facilitated Risk Analysis Process). This is a qualitative risk analysis methodology that can be used to pre-screen a subject of analysis as a means to determine whether a full blown quantitative risk analysis is needed.
· Spanning Tree Analysis. This can be thought of as a visual method for identifying categories of risks, as well as specific risks, using the metaphor for a tree and its branches. This approach would be similar to a Mind Map for identifying categories and specific threats and/or vulnerabilities.
· NIST 800-30, Risk Management Guide for Information Technology Systems. This document describes a formal approach to risk assessment that includes threat and vulnerability identification, control analysis, impact analysis, and a matrix depiction of risk determination and control recommendations.
Risk Treatment
When a qualitative or quantitative risk assessment has been performed, an organization’s man- agement can begin the process of determining what steps, if any, need to be taken to manage the risks identified in the risk assessment. The four general approaches to risk treatment are:
· Risk acceptance
· Risk avoidance
· Risk reduction
1
8 Chapter 1 • Risk transfer
It is important to remember that the objective of risk treatment is not to eliminate risk—often risk cannot be eliminated, but only managed.
Risk Avoidance Generally the most extreme form of risk treatment, in risk avoidance the associated activity that introduces the risk is discontinued. For instance, an organization performs a risk analysis of an Internet-based shopping cart application, and then decides to abandon the use of the application altogether. This is risk avoidance.
Risk Reduction Risk reduction—also known as risk mitigation—involves the use of countermeasures to reduce the risks initially identified in the risk analysis. Examples of risk reduction in information systems include firewalls, intrusion detection systems, and DMZ networks.
Risk Acceptance In a typical risk assessment, there will be many identified risks, typi- cally ranked as high, medium, and low risk. Management may choose to forego mitigation of all of the risks ranked low, in other words leaving things as they are and accepting the stated risks. This is known as risk acceptance.
Risk Transfer Risk transfer typically involves the use of insurance as a means for miti- gating risk. For instance, a risk analysis on the use of laptop computers may identify theft as one risk. While the organization may mitigate the risk through the use of cable locks, it may transfer part of the risk to an insurance company. Note that risk transfer usually involves a cost (insurance premiums) that should be considered in a quantitative risk analysis.
Residual Risk In any particular risk situation, generally only some of the risk can be avoided, reduced, or transferred. There is always some remaining risk, called residual risk. Typically this risk must be accepted, unless management can enact another round of analysis and a fresh set of countermeasures to avoid, reduce, or transfer the risk. But even then, there will be some “leftover” risk, called residual risk.
Security Management Concepts
Several concepts and terms are used in the security management profession. When security professionals are discussing the measures needed to protect assets in the organization, the fol- lowing terms are commonplace:
· Security controls
· CIA Triad
· Defense in depth
· Single points of failure
· Fail open, fail closed, fail soft
· Privacy
Security Management Concepts 9
The ISO 27001 standard, “Information Technology—Security Techniques—Information Secu- rity Management Systems—Requirements,” is an outstanding standard for information secu- rity management. Originally developed as British Standard 7799, the standard was adopted by the International Standards Organization (ISO) in 2000. ISO 27001 was later updated in 2005. ISO 27001 is a top-down process approach to security management that, when prop- erly implemented, will result in continuous improvement in security management within an organization.
Security Controls
Security controls are the measures that are taken to enforce security policy and reduce risk. The types of controls used are detective, deterrent, preventive, corrective, recovery, and com- pensating. These controls are discussed in detail in Chapter 3, “Application Security.”
The CIA Triad
The core principles of information security are confidentiality, integrity, and availability, often coined as CIA. All other concepts and activities in information security are based on these principles. The CIA Triad is depicted in Figure 1-1.
Confidentiality The principle of confidentiality asserts that information and functions can be accessed only by properly authorized parties.
Private information about citizens has resulted in the proliferation of information systems operated by both government and industry. Typically, a personal “profile” containing many items of basic information is established when an individual begins a relationship with an orga- nization. This relationship is started when a person makes a purchase, registers to vote, renews a driver’s license, pays taxes, or consults a physician. Even if the purpose or the duration of the relationship is brief, often the information will remain on the organization’s information sys- tems for an extended period of time, often for many years.
1
Data & Services
Availability
Figure 1-1 The CIA Triad Source: Course Technology/Cengage Learning
Integrity
Confidentiality
10 Chapter 1
Individuals expect that their confidential information will not be disclosed to unauthorized parties and that it will be properly protected. However, we have come to expect that some organizations will not handle information properly, resulting in an unauthorized disclosure that, in its worst case, could result in an attempted identity theft or financial fraud carried out against the persons whose information was compromised.
Integrity The principle of integrity asserts that information and functions can be added, altered, or removed only by authorized persons and means.
The general expectation of information systems is that information will be properly and accu- rately introduced into a system, and throughout its lifetime the information will remain accu- rate. While the principle of confidentiality states that only authorized parties will be able to view information, the principle of integrity assets that only authorized parties will be able to modify information. Integrity is achieved through role-based access control, which is the generic name for a mechanism that controls the actions performed by individuals. In the con- text of information stored in a database of tables consisting of tables, rows, and fields, the concept of integrity will govern which individuals are able to modify which tables, rows, and fields in a database.
In data security, the need for integrity encompasses software, systems, and the people who design, build, and operate them. Software must operate properly, particularly when a pro- gram is accessing and modifying data. Systems must be properly configured so that the data that resides on them is managed and updated correctly. The people who design, build, and operate software and systems must be properly trained on the technologies that they are using, and they must also adhere to a code of professional ethics that guides their behavior and decision-making.
Availability The principle of availability asserts that systems, functions, and data must be available on-demand according to any agreed-upon parameters regarding levels of ser- vice. In other words, systems should generally be available and running properly when they are supposed to be available.
Availability is multi-faceted and involves many separate safeguards and mechanisms to ensure that systems and data are available when needed. These safeguards range from fire- walls and anti-virus software to resilient architectures to disaster recovery planning. Avail- ability covers nearly all of the aspects of data security that directly or indirectly protect a system from harm.
Defense in Depth
The term defense in depth implies a layered defense consisting of two or more protective methods that protect some asset. Some of the characteristics of defense in depth are:
· Heterogeneity. A good defense in depth mechanism contains different types of protective mechanisms. For example, two layers of firewalls of different brands.
· Entire protection. Each layer of the defense fully protects an asset against the type of threat that the defense is designed to block. For example, anti-virus on an e-mail server and also on end-user workstations.
Security Management Concepts 11
The classic example of a good defense in depth is the medieval castle’s defenses that include a drawbridge, a moat, a moat monster, archers, soldiers to pour boiling oil, and so on. These defenses are all different from one another but are all designed to protect the castle (and its assets) from attack from outsiders.
The objective of a defense in depth is to reduce the probability that a threat can act upon an asset. This occurs in two ways:
· Single vulnerability. If one of the components of a defense in depth had an exploitable vulnerability, chances are that another layer in the defense will not have the same vulnerability.
· Single malfunction. If one of the components of a defense in depth malfunctions, chances are that another layer in the defense will not malfunction.
· Fail open. If one of the components in a defense in depth fails open, the other component(s) will continue to operate and protect the asset.
Single Points of Failure
A single point of failure is the characteristic of a component in a system if the failure of the component will result in the failure of the entire system.
Single points of failure are generally discussed only in a system that is designed for resilience and that contains redundant components. A single point of failure in such a system would be the portion of the system where redundancy does not exist.
For example, the firewall in Figure 1-2 would be a single point of failure. If the firewall fails, the system will be unreachable. The firewall is a single point whose failure will cause the fail- ure of the entire system.
Fail Open, Fail Closed, Fail Soft
The concepts of fail open, fail closed, and fail soft are related to what happens to the protec- tion in the event of a failure of a security control.
When a security control fails, generally one of two things happens: either the control blocks all access, or it permits all access. If the control fails and it blocks all access, it is said to fail closed. Another term for fail closed is fail safe.
If the control fails and permits all access, it fails open.
LB
LB
1
FW Rtr App Internet GW
FW Rtr App Single Point of Failure
Figure 1-2 Single point of failure in an otherwise resilient environment Source: Course Technology/Cengage Learning
12 Chapter 1
A system can take action during an adverse situation such as a hardware failure. Fail soft is the process of shutting down non-essential components on a system, thereby freeing up resources so that critical components can continue operating.
Generally speaking it is more desirable for a control to fail closed than to fail open. This, however, is dependent upon the objective and design of the entire system.
An example of undesirable fail open is a doorway controlled by a key card access system that can be bypassed if the key card system fails. A desirable fail open would be the automatic opening of security doors to facilitate personnel exiting in case of fire.
Most security controls fail closed. For example, if a key card system fails, personnel cannot enter or move about the premises. If an application server is unable to access an LDAP authentication server, then no users can log on to the application.
Privacy
Merriam Webster dictionary defines privacy as “freedom from unauthorized intrusion.” The practice of privacy in business refers to the protection of individuals’ private information so that it is used only for intended and agreed-upon purposes and protected from unauthorized disclosure.
Personally Identifiable Information Personally identifiable information (PII) refers to the items that comprise a person’s identity, usually including:
· Full name
· National identification number (in the U.S., social security number)
· Telephone number
· Driver’s license number
· Passport number
· Residential address
· Bank account numbers
· Credit card numbers
In many locales, organizations are required to protect many of these items, and sometimes others, from unauthorized disclosure. Most often this requirement is in the form of laws and regulations intended to curb the proliferation of this information to others.
Security Management
Security management is primarily concerned with strategic level activities that influence the operation of systems and the behavior of employees. Security management will involve several key activities, including:
· Executive oversight
· Governance
· Policy, guidelines, standards, and procedures
· Roles and responsibilities
· Service level agreements
· Security outsourcing
· Data classification and protection
· Certification and accreditation
· Internal audit Security Executive Oversight
The support and oversight by executives of security-related activities is vital to the viability of a security program in an organization. Several activities are related to this oversight, including:
· Support of policies. Executive support is needed to ensure that security policies and other policies are taken seriously by all members of the organization. Support should come in the form of communication (memos stating that adherence to policy is a required condition of employment) and leadership by example.
· Allocation of resources. Executives control the allocation of resources in an organization, primarily through budgeting and staffing levels. In order for a security program to be effective, executives must allocate sufficient resources to security.
· Support of risk. One of the primary activities in a security management function is the performance of risk assessments, which result in the treatment of identified risks. Executives need to visibly accept the disposition of risks as documented in risk assessments whether risks are accepted, transferred, mitigated, or avoided.
Security Governance
The IT Governance Institute in its Board Briefing on IT Governance, 2nd Edition, defines security governance this way:
“Security governance is the set of responsibilities and practices exercised by the board and executive management with the goal of providing strategic direction, ensuring that objectives are achieved, ascertaining that risks are managed appro- priately and verifying that the enterprise’s resources are used responsibly.”
In other words, strategy, objectives, and risks are developed and executed in a top-down manner. In a governance model, executive management is in control of the activities intended to protect organization assets from known threats. Usually this translates into a series of activities that include:
· Steering committee oversight. A group of executives are regularly briefed on activities related to security and risk management. Discussions about incidents and events take place, changes to policies are made, and decisions and opinions are solicited.
· Resource allocation and prioritization. Executives allocate resources to security-related activities, in order that required activities may be carried out.
· Status reporting. Information about events, trends, issues, and other security related matters are collected and sent upwards through meaningful status reports that provide feedback on decisions, strategic direction, and overall effectiveness of the security program.
Security Management 13
1
14 Chapter 1
• Decisions. Decisions made at the steering committee level (and at lower levels) are sent downwards to appropriate levels to be carried out by managers and staff members.
Security Policy, Guidelines, Standards, and Procedures
An organization that desires to manage security in a formal way needs to make several state- ments about the behavior (human, information system, and so on) that is acceptable and unacceptable and how such behavior should be carried out. This is accomplished through a hierarchy of documents, which are:
• Policies • Requirements • Guidelines • Standards • Procedures
Policies Security policy provides constraints of behavior for an organization’s personnel as well as its information systems and other machinery. Put another way, security policy specifies the activities that are required, limited, or forbidden in an organization.
An example policy is, Information systems should be configured to require good security practices in the selection and use of passwords.
Policy Standards The international standard, ISO 27002:2005, Information technology— Security techniques—Code of practice for information security management, is a well known framework on which an organization can build its security policy. The sections in the stan- dard are:
· Organization of information security
· Asset management
· Human resources security
· Physical and environmental security
· Communications and operations management
· Access control
· Information systems acquisition, development, and maintenance
· Information security incident management
· Business continuity management
· Compliance with legal requirements and policies
The SANS organization has a well known security policy model in the SANS Security Policy Project found at http://www.sans.org/resources/policies/. Here the reader can find articles on policies, standards, and guidelines, example policies, and whitepapers on the development of security policy.
Security Management 15
Policy Effectiveness An organization that enacts policies should take steps to ensure that its policies are effective. Policy effectiveness requires a top-down approach. To be effective, a 1 security policy must be:
· Approved by senior management
· Communicated to employees
· Periodically reviewed
· Assessed for effectiveness
Security policy must reflect and support the mission, objectives and goals of an organization. If the organization is risk-averse (for whatever reason, which doesn’t matter), then its security policy should support this risk aversion appropriately. If the organization has a greater appe- tite for risk, then its security policy should reflect this also.
Requirements The term requirements usually refers to characteristics of an information system or business process. Typically, a set of requirements will be created when a new information system is being developed or purchased. The requirements will help the organi- zation make suitable selection, design, or configuration decisions.
Requirements should reflect security policy; if security policy says, “a system shall not do thus-and-so”, then a corresponding requirement should make the same or similar assertion. The goal of security requirements is to constrain a system or process so that, when imple- mented, it complies with the organization’s security policy.
An example requirement is, Information systems must enforce password quality standards and must be able to reference a central authentication service, either LDAP or Active Directory.
Guidelines Whereas security policy defines what should be done (or not done), guide- lines provide information on how policy can be implemented. An organization can choose to make guidelines binding statements that must be adhered to, or they can be suggestions or ideas on how specific policies may be implemented. Which approach is adopted is up to the organization.
For example, if a security policy states that personnel access to business facilities shall be controlled, guidelines can suggest that keycard systems with PIN pads be used at building entrances and within sensitive areas inside buildings.
An example guideline is, Users should choose a password that is easy for the user to remem- ber, but hard for others to guess. The types of passwords that should be avoided include: employee, spouse or pet names, significant anniversaries, common words such as “password,” words related to work functions, and other easily guessed words. Passwords must not be written down unless they are locked in a desk or file cabinet at all times or carried on the user’s person.
Standards Standards are statements that specify what shall be used to support security policies and guidelines. Typically, standards will comprise the following:
• Product standards. These are specific names of products that shall be used to support a policy.
16 Chapter 1
· Process standards. These may cite process templates, names, or methodologies.
· Technology standards. This includes the use of technology standards such as TCP/IP or OSPF, computer languages, and so on.
· Reference configurations. These include server build specs, router configurations, software configurations, and so on.
· Reference architectures. These include schematics for building networks, specifications for integrating applications, and so on.
It is expected that standards will change far more frequently than policies and guidelines.
An example standard is: Minimum password length is 8 characters. Passwords must consist of lower case, upper case, and numeric characters. Passwords must expire after no more than 90 days. Accounts must automatically lock if a user has entered an incorrect password more than three times in ten minutes; accounts must be unlocked by an access administrator, or may be automatically unlocked one hour after the last logon attempt. Users may not use any of the previous 10 passwords used.
Procedures Procedures are the instructions that specify how tasks are to be performed. True to the hierarchical form, procedures must support policies, guidelines, and standards.
The purpose of a procedure is to ensure the consistent and methodical completion of repeti- tive tasks. Consistency builds quality and reduces incidents, which allows the organization to operate more efficiently and at greater levels of service.
Security Roles and Responsibilities
Management should define security roles and responsibilities in the organization. This includes not only the roles and responsibilities of dedicated security personnel, but of all employees in the organization. Roles and responsibilities should be formally defined in two places:
· Security policy. General and specific expectations of security staff and other employees should be defined in the organization’s security policy.
· Job descriptions. Individual job descriptions of security staff and other employees should define specific security-related roles and responsibilities.
The roles and responsibilities that need to be defined include:
· Ownership of assets. Individual assets and groups of assets need to have designated owners who are responsible for their operation and protection.
· Access to assets. The owners of assets should be designated as the persons who decide who may access or use those assets. A higher level of management may be responsible for approving non-standard access to assets.
· Use of assets. All employees should be explicitly designated as responsible for their individual use of assets.
· Managers. Managers should be designated as being responsible for the behavior of employees under their control.
Service Level Agreements
Security Management 17
1
A service level agreement (SLA) is a formally defined level of service provided by an organi- zation. Within the context of security management, SLAs may be defined for many activities, including:
· Security incident response. A security team may be required to mobilize within a stated period of time when a security incident has been called.
· Security alert delivery. Security alerts, which may be bulletins of threats or vulnerabilities, may need to be delivered to recipients within a stated period of time.
· Security investigation. A security investigator may be required to respond to a call for assistance within a stated period of time.
· Policy and procedure review. A security team may be required to periodically review policies, procedures, and other documents at regular intervals.
SLAs can be defined for other tactical activities performed by security management and staff.
Secure Outsourcing
Outsourcing is the subcontracting of a business process to a third-party company. Organiza- tions outsource many different functions for a variety of reasons, including:
· Redirecting energy on the organization’s core competencies
· Controlling the efficient use of capital and other resources
There are some risks associated with the outsourcing of business processes to third parties, including:
· Control of confidential information. An organization will need to equip the outsourcer with the information required to perform its functions properly. Because this information is now out of its direct control, protection of that information is now entirely dependent upon the outsourcer’s actions.
· Loss of control. Organizations that outsource functions to third parties give up a measure of control to that organization.
· Accountability. While the organization has outsourced functions to a third party and is at the complete mercy to the third party’s integrity, the organization is still completely accountable for the actions performed by the outsourcer.
Data Classification and Protection
Organizations store, transmit, and manage a wide variety of types of information, ranging from personnel and payroll records to computer source code to content on public facing web sites. Information security professionals who are responsible for protecting this informa- tion need to decide what measures are required to protect the data. Data of widely varying levels of sensitivity exists in many forms; while it is possible to develop criteria for protecting every set of data in the organization, this approach scales poorly.
Data classification is the undertaking of developing levels of sensitivity for information, and assigning those levels for the purpose of establishing appropriate modes of protection for those datasets. This orderly system of assigning classification levels is preferable to a chaotic environment where information is protected in an ad hoc style.
18 Chapter 1
A formal data classification program consists of several parts, which are:
· Sensitivity levels
· Marking procedures
· Access procedures
· Handling procedures
Sensitivity Levels In a data classification program, a set of sensitivity levels is estab- lished, which reflects the nature of data that is used in the organization. Such a set of sensi- tivity levels could be, for example:
· Top Secret
· Secret
· Confidential
· Public
Most organizations don’t have more than four or five levels, since each level generally will
have it own sets of marking and handling procedures. The more levels there are, the more complicated the classification program will be. Pragmatically, establishing too many levels will introduce too much complication, increase the likelihood of errors, while providing only marginally more security than a simpler program.
Because information classification and handling is largely a human- driven and -operated process, it is preferable to use a simpler scheme of classification levels that will reduce ambiguity and errors.
Information Labeling Labeling, or marking, is the process of affixing a word, symbol, or phrase on a set of data. The purpose of labeling is to make other readers aware of the level of classification on a set of data. When others are aware of the classification level of a particular set of data, they are more apt to be aware of the classification level and handle the data properly.
Using the example of the four levels of classification above, here are some sample labels that can be affixed to human-readable documents shown in Table 1.2.
Marking is not as simple as it may first appear. While it can be relatively simple to mark a document or report with a header or footer containing a classification word or phrase, or affix a classification label on a backup tape, effectively labeling stored or transmitted data is not so clear-cut. Other situations include:
· On-screen labeling. Software programs that display classified information can include on-screen labeling.
· Data transmission. Devices that transmit classified information can have labels affixed to them; further, administrative interfaces (used by network or systems engineers) can have a label displayed at login time. Cabling used to transmit classified information can be labeled or color-coded.
Security Management 19
1
|
Level |
Label |
|
Top Secret |
“COMPANY Top Secret” in at least 48 pt type on cover page. “COMPANY Top Secret: for registered personnel only” in at least 24 pt type on every page. |
|
Secret |
“COMPANY Secret: for authorized personnel only with a business need-to-know” in at least 20 pt type on every page. |
|
Confidential |
“COMPANY Confidential: for employees and customers only” in at least 14 pt type on every page. |
|
Public |
“COMPANY Approved for Public Use” on every page. |
Table 1-2 Sample classification labels
Handling Once classified information is introduced into an organization, it needs to be handled properly in every type of situation. Handling guidelines need to be developed for each level of classification, for each possible type of activity, including these listed here and possibly several more:
· Computer storage. Classification guidelines can include which systems (or classes of systems) are permitted to store the data and under what specific conditions.
· Computer access control. Classification guidelines may include business rules about which personnel (individuals, groups, departments, roles, security clearance level, etc.) may access classified information.
· Backup tape and other portable media. Classification guidelines will determine when and how data at different classification levels may be written to various types of portable media. For instance, data at the highest levels of secrecy might be forbidden from most or all portable media, and at other levels, encryption may be required.
· Network transmission. Classification guidelines should specify if and how data at various classification levels may be transmitted over networks. Of course there are different types of networks (internal, external, and perhaps physically separate high- secrecy networks), so this guideline alone will probably be multidimensional.
· E-mail transmission. Classification guidelines may determine which classification levels permit e-mail to be used to transmit classified information to another person. Like network transmission, e-mail transmission will probably contain conditions such as encryption, internal vs. external recipients, and so on.
· Facsimile. Classification guidelines should address whether information at different classification levels can be faxed and, if so, what conditions should be imposed, such as confirming that the sender’s and recipient’s fax machines will be attended throughout the transmission.
· Printing. Classification guidelines should address the conditions under which information at various classification levels may be printed.
· Mailing/shipping/courier. Classification guidelines need to address whether and how classified information may be mailed or shipped. Possible conditions include lockbox, registered, insured, and double-sealed packages.
· Carrying. Classification guidelines need to include guidance on the safeguards that individuals need to take when carrying classified information.
20 Chapter 1
• Hardcopy storage. Classification guidelines should address how hardcopies of classified information must be stored. Some levels may require double-locking (stored in a locked desk or cabined in a locked office), for instance.
Destruction Classification guidelines need to include information on the proper disposal of classified information. Destruction procedures—steps to ensure that information is dis- carded in a way that renders it non-retrievable—need to include every type of media and likely context.
For example, media destruction procedures should include proper disposal of hardcopy documents. In the workplace there are sure to be shredders or secure document disposal bins, but what about staff members who work primarily in home offices? And how does someone on extended travel safely dispose of a classified document?
Certification and Accreditation
Certification and accreditation are the activities associated with the evaluation of a system against a set of standards or policies. These activities are carried out as part of a formal approval process for initiating or continuing the use of a system.
· Certification is the process of evaluating a system against a set of formal standards, policies, or specifications.
· Accreditation is the formal approval for the use of a certified system, for a defined period of time (and possibly other conditions).
Internal Audit
In the context of information security, internal audit is the activity of self-evaluation of con- trols and policies to measure their effectiveness.
In order to be effective itself, the internal audit function must be objective. This means that the staff members performing internal audit activities should not be a part of the department or division that they are examining. Instead, internal audit should report to a dissociated part of the organization such as Legal.
Internal audit should follow a formal methodology that will further the objectivity and qual- ity of the examination of security controls. One of the most widely recognized methodologies is the Standards and Practices of internal auditing from The Institute of Internal Auditors, available at www.theiia.org.
Security Strategies
Management is responsible for developing the ongoing strategy for security management. The development and changes to the security strategy will be based upon the results of past events, including:
· Incidents. If any security incidents have occurred, the facts uncovered in the handling of the incident, as well as its root cause, may prompt management to make changes.
· Performance of SLAs. If the performance of SLAs is below expectations, management may make changes to improve this.
Personnel Security 21
· Certification and accreditation. The outcomes of recent certifications and
accreditations may provide cause for strategic changes.
· Internal audit. The results of internal audits may prompt management to make changes to audited processes or to the audit process itself.
Strategic changes should be made in consultation with executive management and through the governance function described earlier in this section.
Personnel Security
The “cradle-to-grave” approach to employment is largely a thing of the past. In most organi- zations and industries, people are changing jobs as frequently as every three to five years. This can mean that some organizations are replacing as much as a third of their personnel every year. Consequently, organizations have a lot of staff members that they don’t really know all that well. And because most organizations rely heavily on their information systems for many key business processes, they are entrusting the ongoing integrity and viability of the business on people they don’t really know all that well.
With long-term employees comes a high level of comfort and trust. But in businesses with higher employee turnover, employers need to replace the trust with additional up-front due diligence, in the form of more formal hiring practices and background verifications.
Another area of risk lies in the fact that employers are entrusting their employees with access to a great deal of information. Most information systems lack sufficiently detailed access con- trols, resulting in employees having access to a lot more information than they really need. This increases the risk of damage to the business if an employee makes an error in judgment or is careless. Employers, then, need to provide formal training to its staff on the proper use of organization information systems and handling of information.
These topics are addressed in this section.
Hiring Practices and Procedures
The near-universal practice among organizations is the use of written agreements that employ- ers and employees sign at various stages of the employment relationship.
Non-Disclosure Agreement As soon as an employer and an employment candidate are discussing potential employment, an employer can require the candidate to sign a non- disclosure agreement (NDA). This agreement will require that the candidate not discuss any details about the organization with any other party.
The advantage of the pre-employment NDA is that the employer will have some written assurance that the candidate will not share any secrets shared during interviews. While an employment agreement will certainly have a non-disclosure clause in it, a separate pre- employment NDA provides some protection from disclosure by those individuals who the organization does not hire.
Consent to Background Verification As the pre-employment relationship advances, an employer that is considering making an offer of employment to a candidate will, in most
1
22 Chapter 1
jurisdictions, be required to obtain a signed consent to obtain background information from the candidate. In this simple form, the candidate is providing basic identifying information (e.g., full name, aliases, date of birth, country of citizenship, social/insurance number), together with a written consent for the employer to obtain background information.
The consent form may also contain a clause that states that the employer may refuse employ- ment, terminate employment, and even turn the candidate over to law enforcement authorities if the candidate provides false or misleading information or is found to have an undesirable background.
The employer may also use information obtained from the employment application form to confirm certain aspects of a candidate’s background.
Background Verification In regions of the world with higher rates of crime, an orga- nization runs a real risk of hiring someone with a criminal record. An organization that is considering hiring a candidate should complete a background verification to validate the truthfulness of the candidate’s claims and to investigate the candidate’s potential criminal background. The following checks may be included in a background check:
· Confirmation of citizenship and of the candidate’s legal right to employment
· Confirmation of employment history
· Confirmation of education background
· Confirmation of professional certifications and licenses
· Investigation on potential criminal history
· Investigation of credit history, important for positions involving financial management
responsibility
· Investigation of potential ties with terrorist or criminal organizations
Offer Letter An organization intent upon hiring a candidate will next issue an offer of employment, or offer letter, which usually contains:
· Position title and description
· Start date
· Compensation
· Name of manager
The offer letter should tie together the other elements of the hiring process, including non- disclosure, background check, non-compete, and the requirement that the candidate always abide by security policy and other policies.
Non-Compete In some locales, an organization can also restrict an employee’s ability to change employers to work for a competitor. Organizations intent on enforcing non-compete are concerned with the protection of their intellectual property and other insider informa- tion. A non-compete agreement is a legal agreement that specifies terms and conditions related to the possibility of an employee accepting employment with a competing organization in the future.
Personnel Security 23
Intellectual Property Agreement An intellectual property agreement guarantees that the organization owns all intellectual property (IP) that may be created by an employee. 1 Often this includes IP that an employee may create while working on his or her own time using his or her own resources.
Employment Agreement Sometimes an organization and a new employee will sign an employment agreement that defines terms and conditions of the employment relationship. Generally, employment agreements are limited to executives, but are also used when hiring licensed professionals like teachers or doctors. Where labor unions are used to manage employer-employee relationships, employment agreements often represent an entire segment of the organization’s workforce.
Employee Handbook Many organizations have an employee handbook, a formal doc- ument that describes the terms and conditions of employment, including but not limited to:
· Working hours and locations
· Expected behavior
· Benefits
· Paid and unpaid leave
· Policies, including security policy
· Acceptable use of organization assets, including workstations and other information
systems
In many situations, employees are required to sign the employee handbook, which provides a written attestation that the employee understands all of the terms and conditions of employment and of the organization’s principal policies.
Formal Job Descriptions Many organizations have developed formal job descriptions, which are formal documents that typically include:
· Job title
· Pay range
· Description of duties
· Description of responsibilities
· Required experience
Often, organizations include adherence to policies in the list of responsibilities. This further strengthens the organization’s message that all policies, including security policies, are taken seriously.
Termination
Various circumstances lead to a separation of employment, which are either employee- initiated or employer-initiated. Regardless of the cause, organizations need to perform certain critical tasks upon termination of an employee, including:
· Terminate access to all information systems and networks
· Change administrative passwords that may be known to the employee
24 Chapter 1
· Recover all organization-owned assets
· Have incoming e-mail for the terminated employee routed to a designated person or group
Some termination situations call for an urgent mobilization of curtailment of access by the terminated employee, to prevent the former employee from accessing information systems for the purpose of causing harm to the organization. At times the organization will need to take additional steps, including:
· A review of all recent activities related to the terminated employee
· Code reviews of software source code that the terminated employee had access to These reviews may be needed, on the chance that the employee sensed the termination was
imminent and had reason to damage information systems.
Work Practices
Several practices, when put into place, will reduce behavioral-based risk in an organization. These practices are:
· Separation of duties
· Job rotation
· Mandatory vacations
Separation of Duties The principle of separation of duties (sometimes known as segregation of duties) states that important tasks should require more than one person to complete. A group of two or more employees are less likely to carry out an unauthorized task. Examples of tasks that should employ separation of duties include:
· Payment requests
· Requests for privileged access
In these examples, no single individual should be able to perform these duties. Instead, strictly controlled processes should be established that require at least two individuals (and not just any two, but two designated persons or roles) should be required to perform these functions.
Job Rotation Personnel in sensitive roles may, after extended intervals, be tempted to col- lusion for personal gain and other unauthorized activities. When employers occasionally rotate personnel through various roles, especially when unannounced, employees are less likely to perform these “extra” activities. This practice is known as job rotation. Enacting this can be difficult in smaller organizations that have only single individuals in various roles.
Mandatory Vacations While it is laudable that some employees are so loyal to their employers that they wish to never leave their posts, mandatory vacations provide something akin to short-term job rotation that can sometimes helps an organization spot irregularities that may be a sign of unauthorized activities. When mandatory vacations are institutional- ized, employees are less likely to carry out prohibited activities that could be detected during their absence.
Security Education, Training, and Awareness
Professional Ethics 25
1
In order to adequately protect its assets, organizations need their employees to exercise good judgment and be keen to irregularities that could be signs of trouble. But because this new “21st century digital common sense” is not yet common, organizations need to take time to teach its employees the “do’s” and “don’ts” of information security. This formal education is known as security awareness training and needs to be strategic, formal, and presented in a variety of ways, including:
· Security content in new-hire paperwork. This includes the employee handbook and documents that a new employee is required to sign upon hire. This is covered earlier in this chapter in the section, “Hiring practices and procedures.”
· Security content in day-one orientation. New employees need to be made aware of key security policies on their first day of hire.
· Security training. Soon after starting employment, new employees should be enrolled in more comprehensive security awareness training, which may take the form of classroom or web-based training.
· Specialized training. Employees in some job categories may be required to attend additional specialized training, including:
· – Secure programming for software developers
· – Fraud prevention for finance department employees
· – Network and system protection for network and system engineers
· Other messaging. In addition to training, messages of other forms need to be periodically made available to employees, including:
· – Posters and flyers
· – Promotions
· – Voice-mails
· – Incentive programs
· Testing. In addition to providing educational material on security and asset protection, many employers also test employees to assess their knowledge. Employees may even be required to attain a minimum test score or be required to repeat security training.
Professional Ethics
The Merriam Webster dictionary defines ethics as “the discipline dealing with what is good and bad and with moral duty and obligation.” It defines professional ethics as “the principles of conduct governing an individual or a group.” From these two definitions, we understand that security professionals’ behavior should reflect a high level of morality, integrity, and responsibility.
26 Chapter 1
Security professionals are expected to lead by example. Security professionals should abide by security policies that they expect other employees to follow. In a real sense, security profes- sionals are like law enforcement and should be held to an even higher standard than the rank-and-file.
Many professional organizations have published a code of ethical standards that members are required to uphold. (ISC)2, the governing body of the CISSP certification, has a comprehensive code of ethics that all security professionals, CISSP or not, should adopt as their own.
Each CISSP certification holder is required to support the (ISC)2 Code of Ethics, which appears in Appendix B.
Chapter Summary
· An organization’s security program should support the organization’s mission, objectives, and goals.
· Risk management is the process of determining the acceptable level of risk and the use of risk assessment and mitigation to reduce risk to an acceptable level.
· The core principles of information security are confidentiality, integrity, and availability.
· Defense in depth is a technique of using a layered defense to protect an asset.
· A single point of failure is the characteristic of a component in a system if the failure of the component will result in the failure of the system.
· Fail open is the characteristic of a control to permit all accesses when the control fails. Fail closed is the characteristic of a control to block all access when the control fails.
· Privacy is related to the protection of private information associated with private citizens.
· Executive oversight is needed for the support of policies, allocation of resources, and support of risk.
· Security governance is the set of responsibilities and practices related to the development of strategic direction and risk management.
· Security policies specify the required characteristics of information systems and the required conduct of employees.
· Security requirements specify required characteristics of information systems and processes, and are usually used during systems development and acquisitions.
· Guidelines are statements that specify how security requirements may be carried out.
· Standards specify the types of systems, tools, technologies, configurations, and
architectures used in an organization.
· Procedures are the step-by-step instructions used to perform tasks.
· Security-related roles and responsibilities are defined in security policies and job descriptions.
· Security roles and responsibilities define the ownership, access, and use of assets, and the general responsibilities of managers and employees.
Key Terms 27 ■ Service level agreements (SLAs) are formal statements that specify levels of service
provided by a service organization.
1
· An organization that outsources business processes needs to ensure that its intellectual property is adequately protected.
· A data classification and protection policy defines levels of sensitivity for business information, as well as handling procedures for each level of sensitivity.
· Certification is the process of evaluating a system against a set of evaluation criteria. Accreditation is the act of permitting the use of a certified system.
· Internal audit is the activity of evaluating security controls and policies to measure their effectiveness.
· Management is responsible for the development of security strategies, in order to maintain and improve security-related activities in the organization.
· An organization’s hiring process should include the use of non-disclosure, employment, non-compete, intellectual property, and acceptable use agreements, as well as background checks.
· An employee handbook should highlight all terms and conditions of employment.
· Job descriptions should explain all responsibilities and requirements for each position
in the organization.
· Upon termination of employment, the organization should retrieve all assets issued to the terminated employee and immediately rescind the employee’s access to all information systems.
· Sound work practices include separation of duties, job rotation, and mandatory vacations.
· A security education, training, and awareness program should keep employees regularly informed of their expectations.
· Security professionals should adhere to a strict code of professional conduct and ethics.
Key Terms
Accreditation The process of formally approving the use of a system. Annual loss expectancy (ALE) The yearly estimate of loss of an asset, calculated as: ALE =
ARO × SLE. Annualized rate of occurrence (ARO) The probability that a loss will occur in a year’s time.
Asset An object of value to the organization. An asset may be a physical object such as a computer, or it can be information.
Availability The concept that asserts that information systems can be accessed and used when needed.
Background verification The process of verifying an employment candidate’s employment, education, criminal, and credit history.
28 Chapter 1
Certification The process of evaluating a system against a specific criteria or specification.
CIA Confidentiality, Integrity, and Availability.
Classification See Data classification.
Confidentiality The concept of information and functions being protected from unauthorized access and disclosure.
Countermeasure A control or means to reduce the impact of a threat or the probability of its occurrence.
Data classification The process of assigning sensitivity levels to documents and data files in order to assure their safekeeping and proper handling.
Defense in depth A strategy for protecting assets that relies upon several layers of protection. If one layer fails, other layers will still provide some protection.
Destruction The process of discarding information in a way that renders it non-retrievable. Employee handbook A formal document that defines terms and conditions of employment.
Employment agreement A legal agreement that specifies terms and conditions of employment for an individual employee or group of employees.
Ethics The discipline of dealing with a code of professional behavior. Exposure factor (EF) The proportion of an asset’s value that is likely to be lost through the
realization of a particular threat.
Fail closed The characteristic of a security control—upon failure, it will deny all access.
Fail open The characteristic of a security control—upon failure, it will permit all access.
Fail safe See Fail closed.
Fail soft The process of shutting down non-essential components on a system, thereby freeing up resources so that critical components can continue operating.
Governance The entire scope of activities related to the management of policies, procedures, and standards.
Guideline Information that describes how a policy may be implemented. Integrity The concept of asserting that information may be changed only by authorized
persons and means.
Intellectual property agreement A legal agreement between an employee and an organization that defines ownership of intellectual property (IP) that the employee may develop during employment.
Internal audit The activity of self evaluation of controls and policies to measure their effectiveness.
Job description A formal document that defines a particular job title, responsibilities, duties, and required experience.
Job rotation The practice of rotating personnel through a variety of roles in order to reduce the risk of unauthorized activities.
Labeling The process of affixing a sensitivity identifiers to a document or data file. Marking See Labeling.
Non-compete agreement A legal agreement that stipulates terms and conditions regarding whether the employee may accept employment with a competing organization in the future.
Key Terms 29
1 Non-disclosure agreement (NDA) A legal agreement that requires one or both parties to
maintain confidentiality.
Offer letter A formal letter from an organization to an employment candidate that offers employment under a basic set of terms.
Personally identifiable information (PII) Items associated with an individual such as name, passport number, driver’s license number, and social insurance number.
Policy An official statement that establishes plans, boundaries, and constraints on the behavior of information systems and employees.
Privacy The protection of sensitive information associated with individuals. Procedure Step-by-step instructions for performing a task. Requirements Statements of necessary characteristics of an information system. Residual risk The risk that remains after countermeasures are applied.
Risk acceptance A form of risk treatment where an identified risk is accepted as-is. Risk assessment The process of examining a system or process to identify potential risks.
Risk avoidance A form of risk treatment where the activity associated with an identified risk is discontinued, thereby avoiding the risk.
Risk management The strategic activities related to the identification of risks through risk assessment and the subsequent treatment of identified risks.
Risk mitigation See Risk reduction Risk reduction A form of risk treatment where an identified risk is reduced through
countermeasures.
Risk transfer A form of risk treatment where an identified risk is transferred to another party, typically through an insurance policy.
Security awareness training A formal education program that teaches security principles and expected behavior to employees.
Security management Activities related to the development and implementation of security policies and controls.
Security policy A branch of organizational policy that defines security-related controls and behaviors.
Sensitivity level A category of information sensitivity in an information classification scheme.
Separation of duties The work practice where high risk tasks are structured to be carried out by two or more persons.
Service Level Agreement (SLA) Formal statements that specify levels of service provided by a service organization.
Single Loss Expectancy (SLE) The cost of a single loss through the realization of a particular threat. This is a result of the calculation, SLE = asset value × exposure factor (EF).
30 Chapter 1 Single point of failure A component in a system that lacks a redundant or backup
counterpart; the failure of the component will cause the failure of the entire system.
Standard A statement that specifies the brand, model, protocol, technology, or configuration of a system.
Termination The cessation of employment for an employee. Threat A potential activity that would, if it occurred, exploit a vulnerability in a system. Vulnerability A weakness in a system that may permit the realization of a threat.
Review Questions
1. An organization that needs to understand vulnerabilities and threats needs to perform a:
a. Penetration test b. Threat analysis c. Qualitative risk assessment d. Quantitative risk assessment
2. A risk manager has performed a risk analysis on a server that is worth $120,000. The risk manager has determined that the Single Loss Expectancy is $100,000. The Exposure Factor is:
a. 83% b. 1.2 c. 80% d. 120%