0% found this document useful (0 votes)
19 views17 pages

Information Security Audit Overview

Uploaded by

Satish Kumar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLSX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
19 views17 pages

Information Security Audit Overview

Uploaded by

Satish Kumar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLSX, PDF, TXT or read online on Scribd

Grasim Industries Limited

Document Control
Document Details
Document Title: Status:
Draft
Classification: Reviewed & Approved By:
Confidential
Prepared By:

Distribution List
Sr. No. Version Location
1 1.0 IT
Revision History
Sr. No. Version Date Changes Made
1 1.0 10/7/2020 Initial Version Created as per ABG Information Security Policy v8.1

Confidential_x000D_ Sensitivity: General


#
Pulp & Fibre
Current
Sl. No Domains
Score
1 Risk Management 5.00
2 Management direction for information security 4.33
3 Organization of information security 3.00
4 Human resource security 3.00
5 Asset management 3.00
6 Access control 3.00
7 Information Lifecycle Management and Protection 3.00
8 Physical and environmental security 3.00
9 Operations security 3.00
10 Network and Communication Security 3.00
11 System acquisition, development and maintenance 3.00
12 Incident management 3.00
13 Business continuity management / Disaster Recovery 3.00
14 Compliance 3.00
15 Bring Your Own Device (BYOD) Security 3.00
16 Cloud Security 3.00
17 Third Party 3.00
18 Operational Technology Security (SCADA / DCS) 3.00
19 Data Privacy 0.00

Sensitivity: General
#
Pulp & Fibre
Desired
Score
5.00
4.67
4.00
4.00
4.00
4.00
4.00
4.00
4.00
4.00
4.00
4.00
4.00
4.00
4.00
4.00
4.00
4.00
5.00

#Sensitivity: General
Current Current Desired Desired
Control Control Description Evidence / Justification / Remarks
Maturity Level Score Maturity Level Score
Information security policies
Information Security Risk Management 5.00 5.00
Does the Business/ Unit define and apply an information
Risk Assessment security risk assessment process? Yes 5 Yes 5
Does the Business/ Unit retain documented information
Risk Assessment Document about the information security risk assessment process? Yes 5 Yes 5

Does the Business/ Unit define and apply an information


Risk Treatment security risk treatment process? Yes 5 Yes 5
Does the Business/ Unit retain documented information
Risk Treatment Plan about the information security risk treatment process? Yes 5 Yes 5
Management direction for information security 4.33 4.67
A set of policies for information security shall be defined,
Policies for information security approved by management, published and communicated to Yes 5 Yes 5
employees and relevant external parties.

Review of the policies for information The policies for information security shall be reviewed at
security planned intervals or if significant changes occur to ensure Yes 5 Yes 5
their continuing suitability, adequacy and effectiveness.

Has the security policy been published and Is it freely available on a website, handbook, or is shared with
communicated to all relevant parties? employees when they are first hired? Well Defined 3 Quantitatively Controlled 4

Organization of information security 3.00 4.00


Internal organization
Information security roles and All information security responsibilities shall be defined and
responsibilities allocated. Well Defined 3 Quantitatively Controlled 4

Conflicting duties and areas of responsibility shall be


segregated to reduce opportunities for unauthorized or
Segregation of duties
unintentional modification or misuse of the organization’s Well Defined 3 Quantitatively Controlled 4
assets.

Appropriate contacts with relevant authorities shall be


Contact with authorities
maintained. Well Defined 3 Quantitatively Controlled 4

Appropriate contacts with special interest groups or other


Contact with special interest groups specialist security forums and professional associations shall Well Defined 3 Quantitatively Controlled 4
be maintained.

Information security in project management Information security shall be addressed in project Well Defined 3 Quantitatively Controlled 4
management, regardless of the type of the project.
Human resource security 3.00 4.00
Prior to employment

Background verification checks on all candidates for


employment shall be carried out in accordance with relevant
Screening laws, regulations and ethics and shall be proportional to the Well Defined 3 Quantitatively Controlled 4
business requirements, the classification of the information
to be accessed and the perceived risks.

Confidential_x000D_ Sensitivity: General


#
Current Current Desired Desired
Control Control Description Evidence / Justification / Remarks
Maturity Level Score Maturity Level Score
Background verification checks are carried out while
engaging with contractors and third parties. Terms and
Screening (Third Part / Contractor)
conditions for verification check shall be clearly mentioned in Well Defined 3 Quantitatively Controlled 4
the contractual agreements.

Prior-to being given access to information assets, all


employees shall sign and agree with the terms and conditions
Terms and conditions of employment
of their employment contract, which shall include acceptable Well Defined 3 Quantitatively Controlled 4
usage of information assets and confidentiality agreements.

Terms and conditions of employment (Third Contractors and third parties having access to ABG’s
Part / Contractor) information assets shall be required to agree and sign the Well Defined 3 Quantitatively Controlled 4
confidentiality agreement
During employment

Management shall require all employees and contractors to


Management responsibilities apply information security in accordance with the established Well Defined 3 Quantitatively Controlled 4
policies and procedures of the organization.

All employees of the organization and, where relevant,


Information security awareness, education contractors shall receive appropriate awareness education
and training and training and regular updates in organizational policies Well Defined 3 Quantitatively Controlled 4
and procedures, as relevant for their job function.

Information security awareness, education All new recruits shall complete the training within 30 days of
and training joining Well Defined 3 Quantitatively Controlled 4

Information security awareness, education Evaluate user’s understanding and awareness level by
and training performing simulative activities such as phishing exercises Well Defined 3 Quantitatively Controlled 4

There shall be a formal and communicated disciplinary


Disciplinary process process in place to take action against employees who have Well Defined 3 Quantitatively Controlled 4
committed an information security breach.
Termination and change of employment
Information security responsibilities and duties that remain
Termination or change of employment valid after termination or change of employment shall be
responsibilities defined, communicated to the employee or contractor and Well Defined 3 Quantitatively Controlled 4
enforced.
Asset management 3.00 4.00
Responsibility for assets

Assets associated with information and information


Inventory of assets processing facilities shall be identified and an inventory of Well Defined 3 Quantitatively Controlled 4
these assets shall be drawn up and maintained.

All information assets are assigned


• an asset owner and an asset custodian
Ownership of assets
• C-I-A (Confidentiality, Integrity and Availability) rating of the Well Defined 3 Quantitatively Controlled 4
asset

Rules for the acceptable use of information and of assets


Acceptable use of assets associated with information and information processing Well Defined 3 Quantitatively Controlled 4
facilities shall be identified, documented and implemented.

All employees and external party users shall return all of the
Return of assets organizational assets in their possession upon termination of Well Defined 3 Quantitatively Controlled 4
their employment, contract or agreement.

Confidential_x000D_ Sensitivity: General


#
Current Current Desired Desired
Control Control Description Evidence / Justification / Remarks
Maturity Level Score Maturity Level Score
Information classification
Information shall be classified in terms of legal requirements,
Classification of information value, criticality and sensitivity to unauthorised disclosure or Well Defined 3 Quantitatively Controlled 4
modification.
An appropriate set of procedures for information labelling
shall be developed and implemented in accordance with the
Labelling of information
information classification scheme adopted by the Well Defined 3 Quantitatively Controlled 4
organization.
Procedures for handling assets shall be developed and
Handling of assets implemented in accordance with the information Well Defined 3 Quantitatively Controlled 4
classification scheme adopted by the organization.
Media handling
Procedures shall be implemented for the management of
Management of removable media removable media in accordance with the classification Well Defined 3 Quantitatively Controlled 4
scheme adopted by the organization.
Media shall be disposed of securely when no longer required,
Disposal of media
using formal procedures. Well Defined 3 Quantitatively Controlled 4

Media containing information shall be protected against


Physical media transfer unauthorized access, misuse or corruption during Well Defined 3 Quantitatively Controlled 4
transportation.
Access control 3.00 4.00
Business requirements of access control
An access control policy shall be established, documented
Access control policy and reviewed based on business and information security Well Defined 3 Quantitatively Controlled 4
requirements.
Users shall only be provided with access to the network and
Access to networks and network services network services that they have been specifically authorized Well Defined 3 Quantitatively Controlled 4
to use.
User access management

A formal user registration and de-registration process shall


User registration and de-registration
be implemented to enable assignment of access rights. Well Defined 3 Quantitatively Controlled 4

A formal user access provisioning process shall be


User access provisioning implemented to assign or revoke access rights for all user Well Defined 3 Quantitatively Controlled 4
types to all systems and services.
All privileged user accounts shall be identified and
Management of privileged access rights
documented Well Defined 3 Quantitatively Controlled 4

The allocation and use of privileged access rights shall be


Management of privileged access rights
restricted and controlled. Well Defined 3 Quantitatively Controlled 4

Management of secret authentication The allocation of secret authentication information shall be


information of users controlled through a formal management process. Well Defined 3 Quantitatively Controlled 4

Asset owners shall review users’ access rights at regular


Review of user access rights
intervals. Well Defined 3 Quantitatively Controlled 4

User role access matrix across Applications, Systems,


Review of user access rights Network Resources, End-points and IT information systems Well Defined 3 Quantitatively Controlled 4
shall be identified and documented
User access reviews shall be performed at least once a
Review of user access rights quarter. Any excessive or unauthorized rights shall be Well Defined 3 Quantitatively Controlled 4
revoked.

Confidential_x000D_ Sensitivity: General


#
Current Current Desired Desired
Control Control Description Evidence / Justification / Remarks
Maturity Level Score Maturity Level Score
At a minimum, user access logs shall be monitored to identify
unauthorized activity such as:
1. Failed logon attempts
Review of user access rights
2. Login to system during non-business hours Well Defined 3 Quantitatively Controlled 4
3. Repeated access attempts to business data not pertaining
to job role

The access rights of all employees and external party users to


information and information processing facilities shall be
Removal or adjustment of access rights
removed upon termination of their employment, contract or Well Defined 3 Quantitatively Controlled 4
agreement, or adjusted upon change.

Any user access that violates the information security policy


Removal or adjustment of access rights
shall be revoked immediately Well Defined 3 Quantitatively Controlled 4
Privileged Access and Remote Access
All privileged user accounts shall be identified and
Privileged Access
documented Well Defined 3 Quantitatively Controlled 4

Activity from all logons with Privileged User Accounts shall be


Privileged Access
securely logged and monitored. Well Defined 3 Quantitatively Controlled 4

Remote access to employees/ vendors/ contractors shall be


provided as per the job role and business requirement and
Remote Access
must be reviewed and revoked as soon as the required action Well Defined 3 Quantitatively Controlled 4
is completed

No third-party user or general ABG user shall be assigned


Remote Access
administrative privileges on the VPN appliance. Well Defined 3 Quantitatively Controlled 4

Remote access solutions must support strong, end-to-end


Remote Access
encryption Well Defined 3 Quantitatively Controlled 4
System and application access control

Access to information and application system functions shall


Information access restriction
be restricted in accordance with the access control policy. Well Defined 3 Quantitatively Controlled 4

Where required by the access control policy, access to


Secure log-on procedures systems and applications shall be controlled by a secure log- Well Defined 3 Quantitatively Controlled 4
on procedure.
Password management systems shall be interactive and shall
Password management system
ensure quality passwords. Well Defined 3 Quantitatively Controlled 4

The use of utility programs that might be capable of


Use of privileged utility programs overriding system and application controls shall be restricted Well Defined 3 Quantitatively Controlled 4
and tightly controlled.

Access control to program source code Access to program source code shall be restricted. Well Defined 3 Quantitatively Controlled 4

Passwords shall be mandatory for all user accounts on all


Information Systems, unless there is an alternative
mechanism such as key authentication or biometric
Password Policy
authentication in place. All computerized systems shall Well Defined 3 Quantitatively Controlled 4
require, at minimum a strong username and password
combination, before granting access to the system

Passwords shall be at least eight characters in length and


Password Policy
consist of alphabets, numerals and special characters Well Defined 3 Quantitatively Controlled 4

Confidential_x000D_ Sensitivity: General


#
Current Current Desired Desired
Control Control Description Evidence / Justification / Remarks
Maturity Level Score Maturity Level Score

Passwords at minimum shall be changed every 90 days.


Applications and systems shall enforce this change. Password
Password Policy
in “never expire” mode shall be documented as an exception Well Defined 3 Quantitatively Controlled 4
with approval from InfoSec team.

Systems shall not accept last five passwords or passwords


Password Policy
used during the last 12 months. Well Defined 3 Quantitatively Controlled 4

Accounts shall be locked out after maximum of five


Password Policy
unsuccessful logon attempts Well Defined 3 Quantitatively Controlled 4

Where technically feasible, systems shall prevent easily


guessable passwords from being selected. Additionally, the
Password Policy
complete password must not be directly drawn from a Well Defined 3 Quantitatively Controlled 4
dictionary

Emergency Access Control process for granting access in the event of an emergency Well Defined 3 Quantitatively Controlled 4

Allocation of high privileged access in the event of an


emergency, shall be at the discretion of the Department
Emergency Access Control Head/Function Head and shall be signed off by Information Well Defined 3 Quantitatively Controlled 4
Security Team. High privileged accounts shall be adequately
logged and reviewed on a regular basis.

Emergency access and higher privileges shall be revoked after


Emergency Access Control
completion of the necessary tasks Well Defined 3 Quantitatively Controlled 4

Information and system owners shall retain detailed records


Emergency Access Control of any allocated as well as revoked high privilege accounts Well Defined 3 Quantitatively Controlled 4
during emergency.
Information Lifecycle Management and Protection 3.00 4.00
Information Creation

Information shall be classified at the creation stage based on


the criticality and impact to business. All ABG information
shall be classified into:
Highly Confidential/Restricted: disclosure or loss may cause
Information shall be classified at the severe damage to the ABG brand and reputation
creation stage Confidential: significant damage to the ABG brand and Well Defined 3 Quantitatively Controlled 4
reputation
Internal: Disclosure May cause risk including but not limited
to loss of operational effectiveness
Public: disclosure of that information would result in minimal
or no risk to ABG.

Information at rest/ Information in storage Information shall be stored only on ABG approved Well Defined 3 Quantitatively Controlled 4
information systems and locations.
ABG shall ensure that information transmitted outside of
Information in transit ABG network, including the internet shall be encrypted or Well Defined 3 Quantitatively Controlled 4
sent via secured channels
ABG shall ensure that information shared within ABG
Information in transit network is secured via controls such as information rights Well Defined 3 Quantitatively Controlled 4
management.
ABG shall ensure that information shared via physical format
Information in transit is appropriately labeled, sealed and protected while in Well Defined 3 Quantitatively Controlled 4
transit.

Confidential_x000D_ Sensitivity: General


#
Current Current Desired Desired
Control Control Description Evidence / Justification / Remarks
Maturity Level Score Maturity Level Score
ABG shall ensure that Information is disposed/erased
Information Erasure securely and made unrecoverable at the end of its retention Well Defined 3 Quantitatively Controlled 4
period or when no longer required.

Policy on the use of cryptographic controls A policy on the use of cryptographic controls for protection Well Defined 3 Quantitatively Controlled 4
of information shall be developed and implemented.

A policy on the use, protection and lifetime of cryptographic


Key management keys shall be developed and implemented through their Well Defined 3 Quantitatively Controlled 4
whole lifecycle.
document and implement digital certificate management
Digital Certificate Management procedures, for all applications whether managed in-house Well Defined 3 Quantitatively Controlled 4
or by third party.

shall ensure that digital signature certificate is procured from


Digital Certificate Management
an authorized public certification authority (CA) only. Well Defined 3 Quantitatively Controlled 4

shall ensure that internal applications utilizing self-signed


Digital Certificate Management
certificates are approved by the CISO. Well Defined 3 Quantitatively Controlled 4

Physical and environmental security 3.00 4.00


Secure areas
Security perimeters shall be defined and used to protect
Physical security perimeter areas that contain either sensitive or critical information and Well Defined 3 Quantitatively Controlled 4
information processing facilities.

Secure areas shall be protected by appropriate entry controls


Physical entry controls
to ensure that only authorized personnel are allowed access. Well Defined 3 Quantitatively Controlled 4

Physical security for offices, rooms and facilities shall be


Securing offices, rooms and facilities
designed and applied. Well Defined 3 Quantitatively Controlled 4

Protecting against external and Physical protection against natural disasters, malicious attack
environmental threats or accidents shall be designed and applied. Well Defined 3 Quantitatively Controlled 4

Procedures for working in secure areas shall be designed and


Working in secure areas
applied. Well Defined 3 Quantitatively Controlled 4

Access points such as delivery and loading areas and other


points where unauthorized persons could enter the premises
Delivery and loading areas
shall be controlled and, if possible, isolated from information Well Defined 3 Quantitatively Controlled 4
processing facilities to avoid unauthorized access.

Equipment
Equipment shall be sited and protected to reduce the risks
Equipment siting and protection from environmental threats and hazards, and opportunities Well Defined 3 Quantitatively Controlled 4
for unauthorized access.

Equipment shall be protected from power failures and other


Supporting utilities
disruptions caused by failures in supporting utilities. Well Defined 3 Quantitatively Controlled 4

Power and telecommunications cabling carrying data or


Cabling security supporting information services shall be protected from Well Defined 3 Quantitatively Controlled 4
interception, interference or damage.
Equipment shall be correctly maintained to ensure its
Equipment maintenance
continued availability and integrity. Well Defined 3 Quantitatively Controlled 4

Equipment, information or software shall not be taken off-


Removal of assets
site without prior authorization. Well Defined 3 Quantitatively Controlled 4

Confidential_x000D_ Sensitivity: General


#
Current Current Desired Desired
Control Control Description Evidence / Justification / Remarks
Maturity Level Score Maturity Level Score
Security of equipment and assets off- Security shall be applied to off-site assets taking into account
premises the different risks of working outside the organization’s Well Defined 3 Quantitatively Controlled 4
premises.
All items of equipment containing storage media shall be
verified to ensure that any sensitive data and licensed
Secure disposal or reuse of equipment
software has been removed or securely overwritten prior to Well Defined 3 Quantitatively Controlled 4
disposal or re-use.

Users shall ensure that unattended equipment has


Unattended user equipment
appropriate protection. Well Defined 3 Quantitatively Controlled 4

A clear desk policy for papers and removable storage media


Clear desk and clear screen policy and a clear screen policy for information processing facilities Well Defined 3 Quantitatively Controlled 4
shall be adopted.
Operations security 3.00 4.00
Operational procedures and responsibilities
Operating procedures shall be documented and made
Documented operating procedures
available to all users who need them. Well Defined 3 Quantitatively Controlled 4

Changes to the organization, business processes, information


Change management processing facilities and systems that affect information Well Defined 3 Quantitatively Controlled 4
security shall be controlled.
The use of resources shall be monitored, tuned and
Capacity management projections made of future capacity requirements to ensure Well Defined 3 Quantitatively Controlled 4
the required system performance.

Separation of development, testing and Development, testing, and operational environments shall be
operational environments separated to reduce the risks of unauthorized access or Well Defined 3 Quantitatively Controlled 4
changes to the operational environment.
Backup
Backup copies of information, software and system images
Information backup shall be taken and tested regularly in accordance with an Well Defined 3 Quantitatively Controlled 4
agreed backup policy.
Backups shall be performed only on ABG approved sites such
Information backup
as OneDrive. Well Defined 3 Quantitatively Controlled 4

Maintain appropriate backup logs and conduct periodic


Information backup
backup restoration tests Well Defined 3 Quantitatively Controlled 4
Protection from malware
Detection, prevention and recovery controls to protect
Controls against malware against malware shall be implemented, combined with Well Defined 3 Quantitatively Controlled 4
appropriate user awareness.

all malicious file extensions are blocked at the network and


Controls against malware email gateway. Automated scans shall be performed for all Well Defined 3 Quantitatively Controlled 4
email attachments and removable media

Maintain a list of authorized software. Any software


installation outside the list shall be treated as an exception
Controls against malware and required to be approved by the Department head with Well Defined 3 Quantitatively Controlled 4
valid business justification. Admin privileges for installation of
software shall be prohibited for end users.

The anti-virus must be configured to conduct 2 full scans


Controls against malware
every week. Well Defined 3 Quantitatively Controlled 4
Patch Management

Confidential_x000D_ Sensitivity: General


#
Current Current Desired Desired
Control Control Description Evidence / Justification / Remarks
Maturity Level Score Maturity Level Score
define a patch management process and implement a
centralized patch management system to monitor and
implement the patching across all information systems.
Patch Management Process
Centralized patch management solution shall ensure that the Well Defined 3 Quantitatively Controlled 4
patches are deployed across information systems as soon as
they are available.
Emergency patches/hot fixes shall be exempted from
Patch Management Process following the defined patch management process with valid Well Defined 3 Quantitatively Controlled 4
business justification and approval from the CISO.

Logging and monitoring


Event logs recording user activities, exceptions, faults and
Event logging information security events shall be produced, kept and Well Defined 3 Quantitatively Controlled 4
regularly reviewed.

These logs shall be captured, retained, monitored and


analyzed using manual or automated mechanisms (SIEM) At
Event logging minimum, critical log sources shall be forwarded to an SIEM Well Defined 3 Quantitatively Controlled 4
solution. . CISOs and CIOs must sign-off on the inventory and
risk of devices not integrated into the SIEM.

Logging facilities and log information shall be protected


Protection of log information
against tampering and unauthorized access. Well Defined 3 Quantitatively Controlled 4

System administrator and system operator activities shall be


Administrator and operator logs
logged and the logs protected and regularly reviewed. Well Defined 3 Quantitatively Controlled 4

The clocks of all relevant information processing systems


Clock synchronization within an organization or security domain shall be Well Defined 3 Quantitatively Controlled 4
synchronized to a single reference time source.
Control of operational software
Installation of software on operational Procedures shall be implemented to control the installation
systems of software on operational systems. Well Defined 3 Quantitatively Controlled 4
Technical vulnerability management

Information about technical vulnerabilities of information


systems being used shall be obtained in a timely fashion, the
Management of technical vulnerabilities
organization’s exposure to such vulnerabilities evaluated and Well Defined 3 Quantitatively Controlled 4
appropriate measures taken to address the associated risk.

Rules governing the installation of software by users shall be


Restrictions on software installation
established and implemented. Well Defined 3 Quantitatively Controlled 4

Businesses must conduct at least one red-teaming exercise


per year to identify security vulnerabilities and test
capabilities of controls related to incident monitoring,
detection and response
VAPT
Businesses shall identify, document and implement the Well Defined 3 Quantitatively Controlled 4
remediation plan for the identified vulnerabilities. All the
identified vulnerabilities shall be remediated within 3 months
of the identification date.

Security tools (including IP scanners) must not be installed


Security Tools
without the approval of the Business CIO. Well Defined 3 Quantitatively Controlled 4

System utilities (RDP, Powershell etc.) must remain blocked


and be enabled for official purposed only subject to approval
System Utilities
from the HOD. Such system utilities must be blocked after Well Defined 3 Quantitatively Controlled 4
use.

Confidential_x000D_ Sensitivity: General


#
Current Current Desired Desired
Control Control Description Evidence / Justification / Remarks
Maturity Level Score Maturity Level Score
Secure Configuration Management

identifying the minimum baseline security standards required


for the following:
Operating systems
Web servers
Secure Configuration Documents
Application servers Well Defined 3 Quantitatively Controlled 4
Database servers
Network security devices
Network devices

validate the configuration on information systems as per the


Secure Configuration Documents
defined SCD on a Annual basis Well Defined 3 Quantitatively Controlled 4

Network and Communications security 3.00 4.00


Network security management facilities.
Maintain an updated network architecture diagram detailing
network architecture
internal and external network connections. Well Defined 3 Quantitatively Controlled 4
Ensure that internal network is segregated and adequately
Segregation in networks protected from the risks of connecting to internet and other Well Defined 3 Quantitatively Controlled 4
untrusted public networks.

Implement a network discovery mechanism to identify all


authorized and unauthorized components
Implement mechanisms to prevent unauthorized devices
Network Discovery
from connecting to the ABG network Well Defined 3 Quantitatively Controlled 4
Ensure that all network devices are time synced with the
Network Time Protocol (NTP) synchronization device/ server

Restricted internet access shall be provided to authorized


users.
External connections shall be restricted through ABG’s
firewall
internal network connections are protected using
deception/decoy mechanisms to detect attacks and prevent
Perimeter Security significant damage to the network Well Defined 3 Quantitatively Controlled 4
all perimeter security solutions (Firewall, Intruder detection
system (IDS)/ Intruder prevention system (IPS), proxy etc.)
are updated with the latest signatures
all network components (network links, routers, switches
etc.) and perimeter security solutions have redundancies to
avoid single-point-of-failure

Information is shared only with authorized recipients over


electronic channels
Prohibit auto forwarding of emails from ABG account to
personal accounts.
E - Mail Security
Establish and maintain a systematic process for recording, Well Defined 3 Quantitatively Controlled 4
retaining, archiving and deleting e-mail messages and the
relevant accompanying logs considering applicable legal and
regulatory requirements

Confidential_x000D_ Sensitivity: General


#
Current Current Desired Desired
Control Control Description Evidence / Justification / Remarks
Maturity Level Score Maturity Level Score

All Wi-Fi access points shall be secured using Wireless


Intrusion Prevention System (WIPS)
Shall implement appropriate user authentication
mechanisms such as for accessing ABG’s corporate network
Wireless Network
via the Wireless Local Area Network (WLAN). Well Defined 3 Quantitatively Controlled 4
Guest wireless network shall be segregated from internal
ABG network. Personal wireless networks such as dongles
and peer-to-peer networks shall be disabled

System acquisition, development and maintenance 3.00 4.00


Security requirements of information systems

Information security requirements analysis The information security related requirements shall be
requirements analysis and specification included in the requirements for new information systems or Well Defined 3 Quantitatively Controlled 4
enhancements to existing information systems.

Information involved in application services passing over


Securing application services on public public networks shall be protected from fraudulent activity,
networks contract dispute and unauthorized disclosure and Well Defined 3 Quantitatively Controlled 4
modification.

Information involved in application service transactions shall


Protecting application services transactions be protected to prevent incomplete transmission, mis- Well Defined 3 Quantitatively Controlled 4
routing, unauthorized message alteration, unauthorized
disclosure, unauthorized message duplication or replay.

Security in development and support processes


Rules for the development of software and systems shall be
Secure development policy established and applied to developments within the Well Defined 3 Quantitatively Controlled 4
organization.

Changes to systems within the development lifecycle shall be


System change control procedures
controlled by the use of formal change control procedures. Well Defined 3 Quantitatively Controlled 4

Technical review of applications after When operating platforms are changed, business critical
operating platform changes applications shall be reviewed and tested to ensure there is Well Defined 3 Quantitatively Controlled 4
no adverse impact on organizational operations or security.

Restrictions on changes to software Modifications to software packages shall be discouraged,


packages limited to necessary changes and all changes shall be strictly Well Defined 3 Quantitatively Controlled 4
controlled.
Principles for engineering secure systems shall be
Secure system engineering principles established, documented, maintained and applied to any Well Defined 3 Quantitatively Controlled 4
information system implementation efforts.
Organizations shall establish and appropriately protect
secure development environments for system development
Secure development policy environment
and integration efforts that cover the entire system Well Defined 3 Quantitatively Controlled 4
development lifecycle.

The organization shall supervise and monitor the activity of


Outsourced development
outsourced system development. Well Defined 3 Quantitatively Controlled 4

Testing of security functionality shall be carried out during


System security testing
development. Well Defined 3 Quantitatively Controlled 4

Acceptance testing programs and related criteria shall be


System acceptance testing established for new information systems, upgrades and new Well Defined 3 Quantitatively Controlled 4
versions.
Test data

Confidential_x000D_ Sensitivity: General


#
Current Current Desired Desired
Control Control Description Evidence / Justification / Remarks
Maturity Level Score Maturity Level Score
Test data shall be selected carefully, protected and
Protection of test data
controlled. Well Defined 3 Quantitatively Controlled 4

Incident management 3.00 4.00


Management of information security incidents and improvements
Management responsibilities and procedures shall be
Responsibilities and procedures established to ensure a quick, effective and orderly response Well Defined 3 Quantitatively Controlled 4
to information security incidents.
A dedicated Incident Response Team (IRT) shall be formed to
Incident Response Team (IRT) address the Information Security Incidents in an appropriate Well Defined 3 Quantitatively Controlled 4
and timely manner

Incident response plan shall be established and documented


Incident Response Plan
to ensure effective and timely resolution of the incident Well Defined 3 Quantitatively Controlled 4

Information security events shall be reported through


Reporting information security events
appropriate management channels as quickly as possible. Well Defined 3 Quantitatively Controlled 4

Employees and contractors using the organization’s


Reporting information security weaknesses information systems and services shall be required to note Well Defined 3 Quantitatively Controlled 4
and report any observed or suspected information security
weaknesses in systems or services.

Assessment of and decision on information Information security events shall be assessed and it shall be
security events decided if they are to be classified as information security Well Defined 3 Quantitatively Controlled 4
incidents.

Response to information security incidents Information security incidents shall be responded to in Well Defined 3 Quantitatively Controlled 4
accordance with the documented procedures.

Learning from information security Knowledge gained from analyzing and resolving information
incidents security incidents shall be used to reduce the likelihood or Well Defined 3 Quantitatively Controlled 4
impact of future incidents.

The organization shall define and apply procedures for the


Collection of evidence identification, collection, acquisition and preservation of Well Defined 3 Quantitatively Controlled 4
information, which can serve as evidence.

Business continuity management 3.00 4.00


Information security continuity

Business Impact analysis (BIA) shall be carried out to identify


critical business processes. Recovery Time Objective (RTO),
Business Impact analysis Recovery Point Objective (RPO) and Maximum Tolerable Well Defined 3 Quantitatively Controlled 4
Period of Downtime (MTPD) shall be determined for the
identified critical business processes.

Develop an IT DR plan to ensure minimal data loss during


IT DR Plan disruptions and enable efficient recovery and continuity of Well Defined 3 Quantitatively Controlled 4
critical business processes.
IT DR plan shall be tested and reviewed annually, and
Testing & Review whenever there’s a major change in the operating Well Defined 3 Quantitatively Controlled 4
environment.
Ensure that all stakeholders (recovery team, emergency
response team, restoration team, etc.) are made aware of
Awareness & Training
business continuity plan and their responsibilities through Well Defined 3 Quantitatively Controlled 4
periodic awareness and training sessions.
Compliance 3.00 4.00
Compliance with legal and contractual requirements

Confidential_x000D_ Sensitivity: General


#
Current Current Desired Desired
Control Control Description Evidence / Justification / Remarks
Maturity Level Score Maturity Level Score
All relevant legislative statutory, regulatory, contractual
requirements and the organization’s approach to meet these
Identification of applicable legislation and
contractual requirements
requirements shall be explicitly identified, documented and Well Defined 3 Quantitatively Controlled 4
kept up to date for each information system and the
organization.

Appropriate procedures shall be implemented to ensure


compliance with legislative, regulatory and contractual
Intellectual property rights
requirements related to intellectual property rights and use Well Defined 3 Quantitatively Controlled 4
of proprietary software products.

Records shall be protected from loss, destruction,


falsification, unauthorized access and unauthorized release,
Protection of records
in accordance with legislations, regulatory, contractual and Well Defined 3 Quantitatively Controlled 4
business requirements.

Privacy and protection of personally Privacy and protection of personally identifiable information
identifiable information shall be ensured as required in relevant legislation and Well Defined 3 Quantitatively Controlled 4
regulation where applicable.

Cryptographic controls shall be used in compliance with all


Regulation of cryptographic controls
relevant agreements, legislation and regulations. Well Defined 3 Quantitatively Controlled 4

Information security reviews


The organization’s approach to managing information
security and its implementation (i.e. control objectives,
Independent review of information security controls, policies, processes and procedures for information Well Defined 3 Quantitatively Controlled 4
security) shall be reviewed independently at planned
intervals or when significant changes occur.

Managers shall regularly review the compliance of


Compliance with security policies and information processing and procedures within their area of
standards responsibility with the appropriate security policies, Well Defined 3 Quantitatively Controlled 4
standards and any other security requirements.

Information systems shall be regularly reviewed for


Technical compliance review compliance with the organization’s information security Well Defined 3 Quantitatively Controlled 4
policies and standards.

Confidential_x000D_ Sensitivity: General


#
Description Value
Not Performed 0

Performed Informally 1

Planned 2

Well Defined 3

Quantitatively Controlled 4

Continuously Improving 5
Not Applicable

Ref: Systems Security Engineering – Capability Maturity Model

Sensitivity: General
#
There are no security controls or plans in place. The controls are nonexistent.
Base practices of the control area are generally performed on an ad hoc basis.
There is general agreement within the organization that identified actions should
be performed, and they are performed when required. The practices are not
formally adopted, tracked, and reported on.

The base requirements for the control area are planned, implemented, and
repeatable.
The primary distinction from Level 2, Planned and Tracked, is that in addition to
being repeatable the processes used are more mature: documented, approved,
and implemented organization-wide.
The primary distinction from Level 3, Well Defined, is that the process is measured
and verified (e.g., auditable).
The primary distinction from Level 4, Quantitatively Controlled, is that the defined,
standard processes are regularly reviewed and updated. Improvements reflect an
understanding of, and response to, a vulnerability's impact.

neering – Capability Maturity Model

Sensitivity: General
#

You might also like