0% found this document useful (0 votes)
2 views34 pages

Chapter

The document introduces the management of information security, emphasizing its broad scope beyond traditional computer security to include data protection and human resources. It highlights the shared responsibility of all employees, particularly managers, in making information security decisions and outlines key concepts such as confidentiality, integrity, and availability. Additionally, it discusses the principles of information security management, including planning, policy, programs, protection, people, and project management.

Uploaded by

Moto Marct
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views34 pages

Chapter

The document introduces the management of information security, emphasizing its broad scope beyond traditional computer security to include data protection and human resources. It highlights the shared responsibility of all employees, particularly managers, in making information security decisions and outlines key concepts such as confidentiality, integrity, and availability. Additionally, it discusses the principles of information security management, including planning, policy, programs, protection, people, and project management.

Uploaded by

Moto Marct
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

MANAGEMENT of

INFORMATION
SECURITY Third
Edition
CHAPTER 1
INTRODUCTION TO THE
MANAGEMENT OF
INFORMATION SECURITY
If this is the information superhighway, it’s going through
a lot of bad, bad neighborhoods. – Dorian Berger
Introduction
• Information technology
– The vehicle that stores and transports
information from one business unit to another
– The vehicle can break down
• The concept of computer security has been
replaced by the concept of information
security
– Covers a broad range of issues
• From protection of data to protection of human
resources

Management of Information Security, 3rd Edition


Introduction (cont’d.)
• Information security is no longer the sole
responsibility of a discrete group of people
in the company
– It is the responsibility of every employee,
especially managers

Management of Information Security, 3rd Edition


Introduction (cont’d.)
• Information security decisions should
involve three distinct groups of decision
makers (communities of interest)
– Information security managers and
professionals
– Information technology managers and
professionals
– Non-technical business managers and
professionals

Management of Information Security, 3rd Edition


Introduction (cont’d.)
• InfoSec community
– Protects the organization’s information assets
from the threats they face.
• IT community
– Supports the business objectives of the
organization by supplying and supporting
information technology appropriate to the
business needs

Management of Information Security, 3rd Edition


Introduction (cont’d.)
• Non-technical general business community
– Articulates and communicates organizational
policy and objectives and allocates resources
to the other groups

Management of Information Security, 3rd Edition


What Is Security?
• Definitions
– Security is defined as “the quality or state of
being secure—to be free from danger”
– Security is often achieved by means of several
strategies undertaken simultaneously or used
in combination with one another
• Specialized areas of security
– Physical security, operations security,
communications security, and network security

Management of Information Security, 3rd Edition


What Is Security? (cont’d.)
• Information security
– The protection of information and its critical
elements (confidentiality, integrity and
availability), including the systems and
hardware that use, store, and transmit that
information
• Through the application of policy, technology, and
training and awareness programs
• Policy, training and awareness programs
and technology are vital concepts

Management of Information Security, 3rd Edition


CNSS Security Model (cont’d.)
• C.I.A. triangle
– Confidentiality, integrity, and availability
– Has expanded into a more comprehensive list
of critical characteristics of information
• NSTISSC (CNSS) Security Model
– Also known as the McCumber Cube
– Provides a more detailed perspective on
security
– Covers the three dimensions of information
security
Management of Information Security, 3rd Edition
CNSS Security Model (cont’d.)
• NSTISSC Security Model (cont’d.)
– Omits discussion of detailed guidelines and
policies that direct the implementation of
controls
– Weakness of this model emerges if viewed
from a single perspective
• Need to include all three communities of interest

Management of Information Security, 3rd Edition


Key Concepts of
Information Security
• Confidentiality
– The characteristic of information whereby only
those with sufficient privileges may access
certain information
• Measures used to protect confidentiality
– Information classification
– Secure document storage
– Application of general security policies
– Education of information custodians and end
users
Management of Information Security, 3rd Edition
Key Concepts of
Information Security (cont’d.)
• Integrity
– The quality or state of being whole, complete,
and uncorrupted
• Information integrity is threatened
– If exposed to corruption, damage, destruction,
or other disruption of its authentic state
• Corruption can occur while information is
being compiled, stored, or transmitted

Management of Information Security, 3rd Edition


Key Concepts of
Information Security (cont’d.)
• Availability
– The characteristic of information that enables
user access to information in a required format,
without interference or obstruction
– A user in this definition may be either a person
or another computer system
– Availability does not imply that the information
is accessible to any user
• Implies availability to authorized users

Management of Information Security, 3rd Edition


Key Concepts of Information
Security (cont’d.)
• Privacy
– Information collected, used, and stored by an
organization is to be used only for the
purposes stated to the data owner at the time it
was collected
– Privacy as a characteristic of information does
not signify freedom from observation
• Means that information will be used only in ways
known to the person providing it

Management of Information Security, 3rd Edition


Key Concepts of Information
Security (cont’d.)
• Identification
– An information system possesses the
characteristic of identification when it is able to
recognize individual users
– Identification and authentication are essential
to establishing the level of access or
authorization that an individual is granted
• Authentication
– Occurs when a control proves that a user
possesses the identity that he or she claims
Management of Information Security, 3rd Edition
Key Concepts of Information
Security (cont’d.)
• Authorization
– Assures that the user has been specifically and
explicitly authorized by the proper authority to
access, update, or delete the contents of an
information asset
– User may be a person or a computer
– Authorization occurs after authentication

Management of Information Security, 3rd Edition


Key Concepts of Information
Security (cont’d.)
• Accountability
– Exists when a control provides assurance that
every activity undertaken can be attributed to a
named person or automated process

Management of Information Security, 3rd Edition


What Is Management?
• The process of achieving objectives using a
given set of resources
• Manager
– Someone who works with and through other
people by coordinating their work activities in
order to accomplish organizational goals

Management of Information Security, 3rd Edition


What is Management? (cont’d.)
• Managerial roles
– Informational role
• Collecting, processing, and using information that
can affect the completion of the objective
– Interpersonal role
• Interacting with superiors, subordinates, outside
stakeholders, and other parties that influence or are
influenced by the completion of the task
– Decisional role
• Selecting from among alternative approaches, and
resolving conflicts, dilemmas, or challenges

Management of Information Security, 3rd Edition


What is Management? (cont’d.)
• Leaders
– Influence employees to accomplish objectives
– Lead by example; demonstrating personal
traits that instill a desire in others to follow
– Provide purpose, direction, and motivation to
those that follow
• Managers
– Administers the resources of the organization
– Creates budgets, authorizes expenditures and
hires employees
Management of Information Security, 3rd Edition
Behavioral Types of Leaders
• Three basic behavioral types of leaders
– Autocratic
– Democratic
– Laissez-faire

Management of Information Security, 3rd Edition


Management Characteristics
• Two basic approaches to management
– Traditional management theory
• Uses the core principles of planning, organizing,
staffing, directing, and controlling (POSDC)
– Popular management theory
• Categorizes the principles of management into
planning, organizing, leading, and controlling
(POLC)

Management of Information Security, 3rd Edition


Management Characteristics
(cont’d.)
• Planning
– The process that develops, creates, and
implements strategies for the accomplishment
of objectives
• Three levels of planning
– Strategic, tactical, and operational
• Planning process begins with the creation
of strategic plans for the entire organization

Management of Information Security, 3rd Edition


Management Characteristics
(cont’d.)
• An organization must thoroughly define its
goals and objectives
– Goals are the end results of the planning
process
– Objectives are intermediate points that allow
you to measure progress toward the goal

Management of Information Security, 3rd Edition


Management Characteristics
(cont’d.)
• Organizing
– The management function dedicated to the
structuring of resources to support the
accomplishment of objectives
– Requires determining what is to be done, in
what order, by whom, by which methods, and
according to what timeline

Management of Information Security, 3rd Edition


Management Characteristics
(cont’d.)
• Leading
– Leadership encourages the implementation of
the planning and organizing functions
• Includes supervising employee behavior,
performance, attendance, and attitude
– Leadership generally addresses the direction
and motivation of the human resource

Management of Information Security, 3rd Edition


Management Characteristics
(cont’d.)
• Controlling
– Monitoring progress toward completion
– Making necessary adjustments to achieve the
desired objectives
• The control function serves to assure the
organization of the validity of the plan
– Determines what must be monitored as well as
applies specific control tools to gather and
evaluate information

Management of Information Security, 3rd Edition


Principles of Information Security
Management
• The extended characteristics of information
security are known as the six P’s
– Planning
– Policy
– Programs
– Protection
– People
– Project Management

Management of Information Security, 3rd Edition


Planning
• Planning as part of InfoSec management
– An extension of the basic planning model
discussed earlier in this chapter
• Included in the InfoSec planning model
– Activities necessary to support the design,
creation, and implementation of information
security strategies

Management of Information Security, 3rd Edition


Planning (cont’d.)
• Types of InfoSec plans
– Incident response planning
– Business continuity planning
– Disaster recovery planning
– Policy planning
– Personnel planning
– Technology rollout planning
– Risk management planning
– Security program planning
• includes education, training and awareness
Management of Information Security, 3rd Edition
Policy
• Policy
– The set of organizational guidelines that
dictates certain behavior within the
organization
• Three general categories of policy
– Enterprise information security policy (EISP)
– Issue-specific security policy (ISSP)
– System-specific policies (SysSPs)

Management of Information Security, 3rd Edition


Programs
• Programs
– InfoSec operations that are specifically
managed as separate entities
– Example: a security education training and
awareness (SETA) program
• Other types of programs
– Physical security program
• complete with fire, physical access, gates, guards,
etc.

Management of Information Security, 3rd Edition


Protection
• Executed through risk management
activities
– Including risk assessment and control,
protection mechanisms, technologies, and
tools
– Each of these mechanisms represents some
aspect of the management of specific controls
in the overall information security plan

Management of Information Security, 3rd Edition


People
• People
– The most critical link in the information security
program
– Managers must recognize the crucial role that
people play in the information security program
– This area of InfoSec includes security
personnel and the security of personnel, as
well as aspects of a SETA program

Management of Information Security, 3rd Edition

You might also like