0% found this document useful (0 votes)
22 views17 pages

Coforge Information Security Overview

Uploaded by

dkalavathimscs
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
22 views17 pages

Coforge Information Security Overview

Uploaded by

dkalavathimscs
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter 1

Information Security
Concepts
What is Information Security?

Information security is the protection of information


and aims at minimizing the risk of exposing information
to unauthorized parties

It is more than setting up technological controls,


applying patches

Information Security answers the following questions:


What needs to be protected, How to protect, Why to
protect, from Whom to protect, Where to store, Who
needs to protect ?

© 2022 Coforge 2
What do we need to protect ?
Paper
We have to protect our Information Assets. In
Information takes many forms. It can be stored on
computers, transmitted across networks, printed out or
written down on paper, and spoken in conversations. An
Information

Information asset is something that has value or utility to Digitized Verbal

the organization, its business operations and its continuity.

Confidentiality Protecting sensitive information from unauthorized disclosure


• e.g. Least Privilege, Encryption

Integrity Safeguarding the accuracy and completeness of information


• e.g. Hashing, Digital Signature

Availability Ensuring that information services are available when required.


• e.g. Backup, BCP, Redundant System

• CIA = Confidentiality + Integrity + Availability of Information Asset


3 © 2022 Coforge
Where is Information Located ?

Services e.g. computing and Paper e.g., contracts, guidelines,


communications services company documentation

Software
e.g., application
software, Information Personnel e.g., SMEs
system software,
development
tools and utilities

Data assets
Physical (Hardware) e.g.,computer
e.g., databases and data files, system
and communications equipment
documentation, user manuals

4 © 2022 Coforge
Who handles the Information Assets (IA) ?

Responsible for
e.g., Service Implements
Responsible Creates and implementing
line Heads, security controls and maintains
for security maintains the the security
Delivery asset e.g.,IT Team for IA
Heads, Project of IA controls on
inventory. assets.
Managers

Custodian: Information
Owner : Information Assets Assets

Ensures that Assesses the Basis review Maintains the


Periodically security
reviews the appropriate of Asset Monitors security
security requirement owner, takes requirement
access to from CIA security controls
assets. controls are in corrective on an ongoing basis CIA
place. standpoint action. basis

Owner: Owner is the person responsible / accountable for the security of Custodian: Custodian is the person responsible for the implementation &
maintenance of the appropriate controls required for the security of the
an Information Asset.
information assets.
5 © 2022 Coforge
Enterprise Security Posture

6 © 2022 Coforge
Who is the Owner of the RISK ?

Risk owner is a “person or entity with the


accountability and authority to manage a risk”.

RISK Owner Member of an organization who ends up using their


budget to pay for fixing the problem

This is a person who is both, interested in resolving a


risk, and positioned highly enough in the organization
to do something about it.

Risk: Risk involves uncertainty about the effects/implications of an activity with respect to something.

Here is an example:
So, for instance, an asset owner of a server might be the IT administrator, and a risk owner for risks related to this server
might be The Head of the IT department. The IT administrator will manage the server on a day-to-day basis, while the head of
the IT department will take care of, e.g., investing in better protection, providing training to the IT administrator, etc.

7 © 2022 Coforge
Risk Management

In business, risk management is defined as the process of Risk Management Process


identifying, monitoring and managing potential risks in Risk Identification
order to minimize the negative impact they may have on & Analysis
an organization. Examples of potential risks include
security breaches, data loss, cyber attacks, pandemics,
system failures and natural disasters. An effective risk Risk Evaluation

management process will help identify which risks pose


the biggest threat to an organization and provide
guidelines for handling them. Risk Treatment &
Response

8 © 2022 Coforge
The 3 Steps in Risk Management
The risk management process consists of three parts: risk identification and analysis, risk evaluation and risk
treatment. Below, we delve further into the three components of risk management and explain what you can do
to simplify the process.

 Risk Identification & Analysis


The first step of the risk management process is called the risk identification and analysis stage. Risk
identification assesses an organization's exposure to uncertain events that could impact its day-to-day
operations and estimates the damage those events could have on an organization's revenue and reputation.

 Risk Evaluation
After the risk assessment/analysis has been completed, a risk evaluation should take place. Risk evaluation
compares estimated risks against risk criteria that the organization has already established. Risk criteria can
include associated costs and benefits, socio-economic factors, legal requirements and system malfunctions.

 Risk Treatment & Response


The last step in the risk management process is risk treatment and response. Risk treatment is the
implementation of policies and procedures that will help avoid or minimize risks.

9 © 2022 Coforge
How to Protect IA ?
To protect our information assets, we have to implement countermeasures, or controls. For example, anti-virus agents to
protect against threat of virus, fire fighting system to protect against threat of fire, data backup to protect against
threat of hardware or media failure etc.

Coforge shall strive to secure information by:

 Maintaining an effective Information Security Management System (ISMS).


 Deploying most appropriate technology and infrastructure based on risk assessment.
 Creating and maintaining a security conscious culture within Coforge.
 Continually monitoring and improving the effectiveness of ISMS.

Whose responsibility is this?

• Responsibility of ensuring adherence to this policy lies with all Coforge employees.

• The CISO (Chief Information Security Officer) is responsible for coordinating the implementation, monitoring, control,
review and improvement of the ISMS under the direction of the Management Information Security Forum.

10 © 2022 Coforge
Coforge Information Security Policy

The purpose of Information Security policy is to


manage
security within Coforge Limited and maintain
appropriate
security controls to protect its information assets
and processing facilities.

Coforge is committed to :

 Protect the Confidentiality, Integrity and


Availability (CIA) of its Information Assets.

 Provide the same commitment to the


information assets entrusted to it by its
customers.

11 © 2022 Coforge
Scope of ISMS

ISMS scope covers all users of the Information Assets of


Coforge including
 Employees of Coforge
 Employees of
 Temporary Employment Agencies
 Vendors
 Customers
 Business Partners
 Contractor Personnel / Retainers
 All Information Systems (IS) environments operated by
Coforge.

12 © 2022 Coforge
Overview of ISMS
• ISMS (Information Security Management System) is the name given to a comprehensive framework by which business
enterprises and other organizations can appropriately manage information. It is an ISO Standard, referred to as ISO 27001:2013.

Our Information Security Management System (ISMS) conforms to the ISO 27001:2013 standard. ISO 27001 is the globally
recognized standard for "Information Security" with a focus on Confidentiality, Integrity and Availability of information assets.
ISMS is classified into the following 14 domains:

2. 7.
1. 3. 4. 5. 8.
Organization of 6. Physical &
Security Policy Human resource Asset Access environment Operations
information Cryptography
security management control al Security security
security

10. 12. 13.


9. 11.
Information Business 14.
Communication Systems acquisition, Supplier
development & security incident continuity Compliance
s security relationships management
maintenance management

ISMS documentation is available at: [Link] Privacy & IS –> Information Security Management System

13 © 2022 Coforge
ISMS Domains
ISMS is classified into the following 14 domains as per ISO 27001:2013 annexure “A”

A.5 Security policy - Provides management direction and support for information security

A.6 Organization of information security- To help manage Information Security within the organization

A.7 Human resources security - To reduce the risks of human error, theft, fraud or misuse of facilities

A.8 Asset management - To help identify information assets, classify and appropriately protect them

A.9 Access control - To limit access to information and information processing facilities

A.10 Cryptography - To ensure proper and effective use of cryptography to protect the confidentiality, authenticity
and/or integrity of information

A.11 Physical and environmental security - To prevent unauthorized access, damage and interference to business
premises and information

14 © 2022 Coforge
ISMS Domains (Contd.)
A.12 Operations Security - To ensure correct and secure operations of information processing facilities

A.13 Communications Security - To ensure the protection of information in networks and its supporting
information processing systems

A.14 Systems acquisition, development & maintenance - To ensure that security is built into information
systems

A.15 Supplier Relationship - To ensure protection of the organization’s assets that is accessible by suppliers

A.16 Information security incident management - To ensure information security events and weaknesses
associated with information systems are communicated in a manner allowing timely corrective action to be
taken

A.17 Business continuity management - To counteract interruptions to business activities and to protect
critical business processes from the effects of major failures or disasters

A.18 Compliance - To avoid breaches of any criminal and civil law, statutory, regulatory or contractual
obligations, and any security requirement

15 © 2022 Coforge
Summary of Chapter 1
• Information security is determining what needs to be protected and why, what it needs to be protected from, and how to
protect it for as long as it exists.

• For security of the information assets, there are three basic security requirements: Confidentiality, Integrity, and
Availability.

• For protecting our information assets, we need to apply controls/ countermeasures which stem from Information Security
Policy.

• Risk management is defined as the process of identifying, monitoring and managing potential risks in order to minimize
the negative impact they may have on an organization.

• which business enterprises and other organizations can appropriately manage information.

• ISMS (Information Security Management System) is the name given to a comprehensive framework by ISMS is compliant
to the standard requirements of ISO 27001:2013.

• ISMS is divided into 14 domains.

For more detail information about the Chapter, Please go through- iEngage->Privacy & IS ->Information Security
Management System -> ISMS mandatory requirements.

16 © 2022 Coforge
Let’s engage!
End of Chapter - 1

17

You might also like