Running head: INFORMATION SECURITY 1
INFORMATION SECURITY 10
Introduction
Given the current environment of high-threats to information stored within business enterprise systems, it is important to maintain systems aggressively with frequent monitoring and experts who are knowledgeable in the area of information security management. Bank Solutions must hire and train personnel who will adhere to regulations mandated by law and find balance with evolving technologies which sometimes evolve before acts are enacted to for public safeguard.
Step One: Issues Related To Security, Interoperability, and Operations
Bank Solutions faces many challenges related to security, interoperability, and operations. First, there is no regular information security testing (Camara et al. 2011). In this regard, the organization rarely tests its information security control systems and resources to determine if they are working properly. Secondly, Bank Solutions’ employees are poorly-equipped with the necessary knowledge and skills needed to deal with the information security issues that may arise in the pursuit of their duties. This poses a major security problem. Also, when it comes to authorization and security assessments, the organization has poorly handled this area. This is because there lacks a well-defined method for determining who is authorized to access its information security and those who are unauthorized. This makes unwanted parties to information security have accesses to classified information (Camara et al. 2011). The organization rarely audits its information system for security purposes. Auditing helps in identifying whether there are emerging security problems and whether the security control mechanisms are working as desired. It also helps noting NIST standards that are not being observed.
Apart from the above five major areas, Bank Solutions face the following issues: poor risk assessment; lack of contingency planning; poor incidence response mechanisms; insufficient system maintenance; insufficient access control systems; as well as inadequate physical and environmental protection mechanisms (Camara et al. 2011). Because of the above problems, the organization faces many information security risks. Some of the risks posed by failure to observe these standards and guidelines include: risks of hacking; possibility of attacks from malicious software and viruses; and likelihood of loss of valuable data and information as a result of natural calamities such as earthquakes and floods (NIST, 2013). Furthermore, since employees are not properly trained to handle various classified information in the required standards, the organization faces the risk of employees unknowingly or deliberately deleting, modifying exposing important information to unauthorized parties.
Step Two: Prioritization of the Selected Requirements
Awareness and Training
As soon as the information security and risk control mechanisms have been developed, it is important to establish a training program for employees so that workers that handle such resources may familiarize themselves with the responsibilities that they have been given (NIST, 2013). Awareness and training starts with initial training and ends with refresher training. Initial training begins when a person assumes a role of disaster and information risk recovery and mitigation. This training offers a wide overview of the disaster recovery program and responsibility. Refresher training should be done regularly throughout the worker’s tenure since new information security risks may surface (NIST, 2013).
Access Controls
Access controls are mechanisms that are designed to deter unauthorized parties from accessing an organization’s valuable information resources such as classified content. Normally, access control takes three major dimensions -- physical controls, technical controls, and administrative controls (NIST, 2013). Examples of technical control mechanisms include encryption and firewalls, while administrative control may take the form of using policies, procedures and guidelines. Physical control, can be implemented by introducing video surveillance and hiring competent security personnel to protect the organization’s information systems.
Assessment and Authorization
The process of conducting assessments and authorization ensures users get approval or consent for accessing or using the organization’s information systems (NIST, 2013). Assessment is used to evaluate the users’ profiles and determine if they have the approvals to be granted access. After logging into an information system, the users may decide to issue commands, some of which they are not approved to execute. Authorization, therefore, defines if the user has the authorities to execute such commands. For that reason, assessment and authorization can be defined as the process of introducing policies and rules, and identifying the kinds of qualities of activities that a particular user is allowed (NIST, 2013)
Auditing and accountability
Information security auditing is carried out to determine if the security control mechanisms and procedures are effective. Auditing helps an organization to keep track of major changes, alongside authorized and unauthorized accesses, to ensure that the information security policies are adhered to (NIST, 2013). To ease the arduous task of auditing, there needs to be properly-defined roles within the information security policy. Accountability goes hand in hand with auditing. Usually, accountability is applied to suggest responsibility in an individual or for a group of activities. Within the security situation, accountability implies that the security systems need to be capable of telling which person did what, when, and how. This helps in keeping track of the identities of individuals who access or make changes to a given system, as well as the possible threats that the system may be facing (NIST, 2013).
These requirements will cost in the millions and will require a phased approach for implementation. Training for employees would require developing a comprehensive training program which would train employees on information security and management. Bank Solutions will utilize resources such as consultants who are skilled in developing training programs for financial information management. In addition to training, Bank Solution must ensure that confidential, integrity and availability is protected by access controls. To ensure compliance with government regulations, Bank Solutions will conduct frequent audits to ensure regulatory standards are maintained.
Step Three: Government Regulations or Standards Governing How These Requirements
HIPAA
The Health Information Portability and Accountability Act of 1999, is a regulation that was developed by the government to ensure that the security, accountability, and privacy of patients are guaranteed when handling electronic information infrastructures (Nemati, 2007). This regulation was mandated in 2001, and has been widely observed as a compliance standard in the health sector and other industries. The main element that is emphasized in HIPAA regulation is privacy. HIPAA’s privacy rule is meant to ensure patients’ health information is safeguarded while enabling the flow of data required for fostering high-standards healthcare (Nemati, 2007).
Gramm-Leach-Bliley Act (GLB)
This regulation was passed with the primary purpose of controlling the privacy and protection of consumers’ records that are kept by financial institutions. The GLB compliance standards for financial organizations, was enacted and mandated in 2001, and included the implementation of various requirements (Nemati, 2007). These standards included: introduction of access controls on consumers’ information resources; application of cryptography on the digital consumer information; Monitoring technologies that perform attacks, intrusions, and alterations of consumers’ information systems; and specification of activities that need to be carried out when unauthorized parties access has taken place (Nemati, 2007).
Sarbanes-Oxley Act
This regulation was passed by Congress in 2002, and brought major transformations in corporate governance, including reporting accuracies of financial reporting systems, financial statements disclosing, organizational top management compensations as well as independence of information security and finance auditors (Nemati, 2007). The impacts of the Sarbanes-Oxley Act on information security are still felt today. Its outcomes have broadly been positive relative to cyber security. Observance of the legislation’s standards has increased the level of awareness and interests in the area of information technology. The Act demands that organizations should have specific internal controls to safeguard their data from such susceptibilities (Nemati, 2007). The Act also requires business organizations to introduce controls that relate to operations to guarantee the integrity of financial audit records within the organization with actual focus on computer systems and network security. Some of the controls recommended are: internal operational controls, employees and business partners’ controls, as well as applications controls (Nemati, 2007).
Food and Drug Administration (FDA) or Code of Federal Regulations (CFR)
The regulations specified by the FDA took effect in 1997. The second section of CFR put in place the United States Food and Drug Administration specifications for electronic records and signatures. These regulations included: introduction of secure audit trails that have to be maintained regularly; ensuring that only authorized parties can utilize the systems and undertake specific operations; ensuring that records are kept within a safeguarded database system; as well as identifying every user and verifying their identities prior to granting them any credentials (Nemati, 2007). The second section of this regulation is high-level in characteristics and does not offer stringent suggestions. Nonetheless, such a regulation offers the essential principles for the utilization of computers within the pharmaceutical sector of the economy. To ensure compliance, all firms are required to define, actualize, and strictly enforce the guidelines and controls so as to guarantee authenticity, integrity, privacy and confidentiality of electronic data (Nemati, 2007).
Step Four: Four NIST Security Controls That Relate To the Issues Specified Above
Access Control
In this security control mechanism, the organization is expected to safeguard its information resources by applying methods such as: physical controls, administrative controls and technical controls (NIST, 2013). Technical control ensures that an organization’s information system is safeguarded by putting in place firewalls and antivirus programs and encryption. In physical control, an organization ensures the security of its information systems are safeguarded through measures such as installation of video surveillance, hiring of security personnel to protect the perimeter, and fencing (NIST, 2013). In administrative control, the company puts in place policies, guidelines and procedures that guide employees and other users on ways of using its information systems.
Awareness and Training
In this information security control, employees undergo regular training so that they can better handle sensitive organizational information (NIST, 2013). Training needs to be done on a regular basis throughout the employee’s tenure. Some of the areas that employees are trained include ways of identifying sensitive information, understanding the identities of individuals privileged with certain information, as well as ways of installing and using antivirus programs (NIST, 2013).
Auditing and Accountability
To ensure accountability, the organization introduces reporting systems and logs. This makes the systems secure and ensure that there is logging of all attempts to access corporate resources. This makes sure that only authorized individuals are accessing the system (Umar, 2003). Auditing, on the other hand, entails keeping an accurate track of all the changes that have been made to an information system, which may be related to security (Umar, 2003). This may entail identification of threats, as well as possible weaknesses that malicious individuals and programs may use to attack the information system.
Assessments and Authorization
Authorization, assessment and authentication are measures that are taken to ensure the validity of a particular transmission, content, or originators. It is a means of evaluating and confirming a user’s qualification to be granted certain categories of information (Nemati, 2010). For a system to be secured, it needs to have a method where users identify themselves before they can undertake any other system operation.
Conclusion
The requirements identified within this document will be key elements in the success of maintaining a robust information security program. Ensuring client data is protected; Bank Solutions much invest in necessary changes to maintain system effectiveness (Confidentiality, Integrity and Availability). The regulations’ mandated by law(s) must be understood by personnel who will maintain compliance and protect data. Information security professionals on staff must ensure the personnel with need-to-know is accessing the compartment data that may not need to be in the hands of all Bank Solutions employees. To enact change within the organization, the requirements identified must be given prompt considerations.
References
Camara, S., Crossler, R., Midha, V., & Wallace, L. (2011). Bank solutions disaster recovery and
business continuity: a case study for business students. Journal Of Information Systems
Education, (2), 117.
NIST. (2013). Security and privacy controls for federal information systems and organizations.
NIST Special Publication, 800, 53.
Nemati, H. (Ed.). (2007). Information Security and Ethics: Concepts, Methodologies, Tools, and
Applications: Concepts, Methodologies, Tools, and Applications. IGI Global.
Nemati, H. (Ed.). (2010). Pervasive Information security and privacy developments: trends and
advancements: trends and advancements. IGI Global.
Umar, A. (2003). Information Security and Auditing in the Digital Age. nge solutions, inc.