0% found this document useful (0 votes)
2 views28 pages

Chapter (2) Modified

Chapter 2 of the Management of Information Security discusses the importance of planning in organizations, emphasizing the need for strategic, tactical, and operational planning to guide information security efforts. It outlines the roles of vision and mission statements, governance, and the responsibilities of executives like the CISO in implementing security strategies. The chapter also introduces the Security Systems Development Life Cycle (SecSDLC) as a methodology for designing and implementing information security systems.

Uploaded by

Moto Marct
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views28 pages

Chapter (2) Modified

Chapter 2 of the Management of Information Security discusses the importance of planning in organizations, emphasizing the need for strategic, tactical, and operational planning to guide information security efforts. It outlines the roles of vision and mission statements, governance, and the responsibilities of executives like the CISO in implementing security strategies. The chapter also introduces the Security Systems Development Life Cycle (SecSDLC) as a methodology for designing and implementing information security systems.

Uploaded by

Moto Marct
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

MANAGEMENT of

INFORMATION SECURITY
Third Edition

CHAPTER 2
PLANNING FOR SECURITY

You got to be careful if you don’t know where you’re going,


because you might not get there. – Yogi Berra
The Role of Planning
• Successful organizations utilize planning
• Planning involves
– Employees
– Management
– Stockholders
– Other outside stakeholders
– The physical and technological environment
– The political and legal environment
– The competitive environment

Management of Information Security, 3rd Edition


The Role of Planning (cont’d.)
• Strategic planning includes:
– Vision statement
– Mission statement
– Strategy
– Coordinated plans for sub units
• Knowing how the general organizational
planning process works helps in the
information security planning process

Management of Information Security, 3rd Edition


The Role of Planning (cont’d.)
• Planning is creating action steps toward
goals, and then controlling them
• Planning provides direction for the
organization’s future
• In the top-down method, an organization’s
leaders choose the direction
– Planning begins with the general and ends with
the specific

Management of Information Security, 3rd Edition


Values Statement
• Establishes organizational principles
– Makes organization’s conduct standards clear
• RWW values commitment, honesty, integrity and
social responsibility among its employees, and is
committed to providing its services in harmony with
its corporate, social, legal and natural environments
• The values, vision, and mission statements
together provide the foundation for planning

Management of Information Security, 3rd Edition


Vision Statement
• The vision statement expresses what the
organization wants to become
• Vision statements should be ambitious
– Random Widget Works will be the preferred
manufacturer of choice for every business’s
widget equipment needs, with an RWW widget
in every machine they use

Management of Information Security, 3rd Edition


Mission Statement
• Mission statement
– Declares the business of the organization and
its intended areas of operations
– Explains what the organization does and for
whom
– Random Widget Works, Inc. designs and
manufactures quality widgets and associated
equipment and supplies for use in modern
business environments

Management of Information Security, 3rd Edition


Strategic Planning
• Strategy is the basis for long-term direction
• Strategic planning guides organizational
efforts
– Focuses resources on clearly defined goals
– “… strategic planning is a disciplined effort to
produce fundamental decisions and actions
that shape and guide what an organization is,
what it does, and why it does it, with a focus on
the future.”

Management of Information Security, 3rd Edition


Creating a Strategic Plan (cont’d.)
• An organization develops a general
strategy
– Then creates specific strategic plans for major
divisions
– Each level or division translates those
objectives into more specific objectives for the
level below
• In order to execute this broad strategy
executives must define individual
managerial responsibilities
Management of Information Security, 3rd Edition
Planning Levels
• Strategic goals are translated into tasks
• Objectives should be specific, measurable,
achievable, reasonably high and time-
bound (SMART)
• Strategic planning then begins a
transformation from general to specific
objectives

Management of Information Security, 3rd Edition


Planning Levels (cont’d.)
• Tactical Planning
– Has a shorter focus than strategic planning
– Usually one to three years
– Breaks applicable strategic goals into a series
of incremental objectives

Management of Information Security, 3rd Edition


Planning Levels (cont’d.)
• Operational Planning
– Used by managers and employees to organize
the ongoing, day-to-day performance of tasks
– Includes clearly identified coordination
activities across department boundaries such
as:
• Communications requirements
• Weekly meetings
• Summaries
• Progress reports

Management of Information Security, 3rd Edition


Planning and the CISO
• Elements of a strategic plan
– Executive summary
– Mission statement and vision statement
– Organizational profile and history
– Strategic issues and core values
– Program goals and objectives
– Management/operations goals and objectives
– Appendices (optional)

Management of Information Security, 3rd Edition


Information Security Governance
• Governance of information security is a
strategic planning responsibility
– Importance has grown in recent years
• Information security objectives must be
addressed at the highest levels of an
organization's management team
– To be effective and offer a sustainable
approach

Management of Information Security, 3rd Edition


Information Security Governance
(cont.)
• Information security governance includes
– Providing strategic direction
– Establishing objectives
– Measuring progress toward those objectives
– Verifying that risk management practices are
appropriate
– Validating that the organization’s assets are
used properly

Management of Information Security, 3rd Edition


Desired Outcomes
• Outcomes of information security
governance
– Strategic alignment of information security with
business strategy to support organizational
objectives
– Risk management to reduce potential impacts
on information resources
– Resource management with efficient use of
information security knowledge and
infrastructure

Management of Information Security, 3rd Edition


Desired Outcomes (cont’d.)
• Outcomes of information security
governance (cont’d.)
– Performance measurement to ensure that
organizational objectives are achieved
– Value delivery by optimizing information
security investments in support of
organizational objectives

Management of Information Security, 3rd Edition


Planning For Information Security
Implementation (cont’d.)
• Roles of the CIO and CISO
– Translating overall strategic plan into tactical
and operational information security plans
– The CISO plays a more active role in the
development of the planning details than does
the CIO

Management of Information Security, 3rd Edition


Planning For Information Security
Implementation (cont’d.)
• CISO Job Description
– Creates a strategic information security plan
with a vision for the future of information
security
– Understands the fundamental business
activities and suggests appropriate information
security solutions to protect these activities
– Develops action plans, schedules, budgets,
and status reports

Management of Information Security, 3rd Edition


Planning For Information Security
Implementation (cont’d.)
• Implementation can begin
– After plan has been translated into IT and
information security objectives and tactical and
operational plans
• Methods of implementation
– Bottom-up
– Top-down

Management of Information Security, 3rd Edition


Introduction to the Security
Systems Development Life Cycle
• An SDLC is a methodology for the design
and implementation of an information
system
• SDLC-based projects may be initiated by
events or planned
• At the end of each phase, a review occurs
to determine if the project should be
continued, discontinued, outsourced, or
postponed

Management of Information Security, 3rd Edition


Introduction to the Security Systems
Development Life Cycle (cont’d.)
• SecSDLC methodology is similar to SDLC
– Identification of specific threats and the risks
they represent
– Design and implementation of specific controls
to counter those threats and manage risks
posed to the organization

Management of Information Security, 3rd Edition


Introduction to the Security Systems
Development Life Cycle (cont’d.)

Figure 2-10 Phases of the SecSDLC

Management of Information Security, 3rd Edition Source: Course Technology/Cengage learning


Introduction to the Security Systems
Development Life Cycle (cont’d.)
• Investigation in the SecSDLC
– Phase begins with directive from management
specifying the process, outcomes, and goals of
the project and its budget
– Frequently begins with the affirmation or
creation of security policies
– Teams assembled to analyze problems, define
scope, specify goals and identify constraints

Management of Information Security, 3rd Edition


Introduction to the Security Systems
Development Life Cycle (cont’d.)
• Investigation in the SecSDLC (cont’d.)
– Feasibility analysis
• Determines whether the organization has the
resources and commitment to conduct a successful
security analysis and design
• Analysis in the SecSDLC
– Prepare analysis of existing security policies
and programs, along with known threats and
current controls

Management of Information Security, 3rd Edition


Introduction to the Security Systems
Development Life Cycle (cont’d.)
• Analysis in the SecSDLC (cont’d.)
– Analyze relevant legal issues that could affect
the design of the security solution
– Risk management begins in this stage
• The process of identifying, assessing, and
evaluating the levels of risk facing the organization,
specifically the threats to the information stored and
processed by the organization
• A threat is an object, person, or other entity that
represents a constant danger to an asset

Management of Information Security, 3rd Edition


Introduction to the Security Systems
Development Life Cycle (cont’d.)
• An attack
– A deliberate act that exploits a vulnerability to
achieve the compromise of a controlled system
– Accomplished by a threat agent that damages
or steals an organization’s information or
physical assets
• An exploit
– A technique or mechanism used to
compromise a system

Management of Information Security, 3rd Edition


Introduction to the Security Systems
Development Life Cycle (cont’d.)
• A vulnerability
– An identified weakness of a controlled system
in which necessary controls that are not
present or are no longer effective

Management of Information Security, 3rd Edition

You might also like