UNIT 3
A structure and framework of compressive security policy
A comprehensive security policy in information security typically includes a
structure and framework that helps manage an organization’s information security
risks. Here are some key components:
1. Security Framework: A security framework is a set of policies, guidelines,
and best practices designed to manage an organization’s information
security risks1. It provides the supporting structure needed to protect internal
data against cyber threats and vulnerabilities1.
2. Types of Cybersecurity Frameworks: IT and cybersecurity frameworks
can be broken down into three different types1:
o Control Frameworks: These are the foundation of all security
programs – the specific controls and processes that help protect
against threats1.
o Program Frameworks: These present a higher-level view of the
organization’s security efforts1.
o Risk Frameworks: Mature security programs will typically include
relevant risk frameworks1.
3. Information Security Policy: An information security policy makes it
possible to coordinate and enforce a security program and communicate
security measures to third parties and external auditors2. It should cover end-
to-end security processes across the organization, be enforceable and
practical, regularly updated in response to business needs and evolving
threats, and focused on the business goals of your organization2.
4. Elements of an Information Security Policy: A security policy can include
various elements, such as purpose, scope, policy, compliance, standards,
procedures, and guidelines2.
Remember, the structure and framework of a comprehensive security policy can
vary depending on the specific industry regulations, compliance goals, or
information security concerns of an organization1. It’s important to tailor the policy
to the organization’s needs and regularly update it to address evolving threats and
business requirements2.
policy infrastructure
The policy infrastructure in information security refers to the set of rules, policies,
and procedures designed to ensure that all end users and networks within an
organization meet minimum IT security and data protection security requirements 1.
Here are some key elements:
1. Information Security Policy (ISP): An ISP is a set of rules that guide
individuals when using IT assets2. Companies create information security
policies to ensure that employees and other users follow security protocols
and procedures2. The goal is to ensure that only authorized users can access
sensitive systems and information2.
2. Coverage: Ideally, your information security policy will cover all programs,
data, facilities, systems, and other technological infrastructure within your
organization3. This broad scope of coverage helps your policy reduce your
company’s data security risks3.
3. Benefits of an Information Security Policy: Information security policies
can facilitate data integrity, availability, and confidentiality 4. They can
protect sensitive data, minimize the risk of security incidents, execute
security programs across the organization, provide a clear security statement
to third parties, and help comply with regulatory requirements4.
4. Elements of an Information Security Policy: A security policy can include
various elements, such as purpose, scope, policy, compliance, standards,
procedures, and guidelines4.
Remember, the policy infrastructure in information security is crucial for
maintaining the security posture of an organization and protecting its valuable
assets from potential threats2431.
policy design life cycle and design processes
The policy design life cycle and design processes in information security are
crucial for creating, implementing, and maintaining effective security policies.
Here’s an overview:
Policy Design Life Cycle123:
1. Development: Suggestions for new policies or revisions to existing ones are
reviewed and assessed according to need1. This stage includes planning,
researching, writing, vetting, approving, and authorizing2.
2. Publication: Once approved, the policy is published and introduced to the
organization. This stage involves communication, dissemination, and
education2.
3. Implementation: The policy is put into action across the organization1.
4. Evaluation: The implementation of the policy is evaluated to assess its
effectiveness1.
5. Maintenance: The policy is regularly updated to address evolving threats
and business requirements1.
6. Retirement: When a policy is no longer needed, it is formally retired1.
Design Processes in Information Security
1. Bottom-Up Approach: The security model is applied by system
administrators or people working in network security or as cyber-engineers4.
2. Top-Down Approach: This approach is initialized and initiated by the
executives of the organization. They formulate policies and outline the
procedures to be followed4.
3. Layered Information Security Approach: Because there are so many
possible vulnerabilities, a layered approach is the best method for
implementing total protection across departments4.
4. Security by Design: This approach involves integrating security measures
into IT systems during their development, rather than applying them
afterward5.
Remember, the design processes and life cycle of a policy in information security
should be tailored to the specific needs of the organization and regularly updated to
address evolving threats and business requirements123.
PDCA model
The PDCA (Plan-Do-Check-Act) model is a continuous improvement cycle widely
used in various fields, including information security management1. Here’s how it
works in the context of information security:
1. Plan: Identify a problem to solve or a goal to achieve. To track the goals
and targets, identify all the relevant Key Performance Indicators (KPIs).
Make sure that everybody on your team can answer the following questions:
What is the main problem we will be solving? What resources are needed?
What will make the plan successful?2
2. Do: Once you have goals, metrics, and before-value, make the change that
you intend to make. This can be installing a new firewall, modifying the
training, or installing devices in a new way3.
3. Check (or Study): Once the change has been made, you should be able to
measure the effect by looking at changes in the metrics. Many improvement
actions will result in no change or even a worsening. For instance, if you
add more material to a training, it is possible that the training becomes too
difficult for people to follow and they actually learn less3.
4. Act: The action will depend on the result of the check step. If the change
was successful, you should make the change permanent by instructing
everyone, updating documentation, or modifying process descriptions. You
should also update the ‘current values’ of your metrics: the new better
values after the change should become the baseline value for future
improvements. If the change was not an improvement, you may need to
revise your plan3.
In the context of ISO 27001, PDCA refers to the process of implementing,
monitoring, and improving an Information Security Management System (ISMS)1.
The PDCA cycle provides a framework for organizations to continually strengthen
their information security2.
Security policy standards and practices - ISO 27001
ISO 27001 is an international standard that provides a framework for Information
Security Management Systems (ISMS) to provide continued confidentiality,
integrity, and availability of information as well as legal compliance12. Here are
some key points:
1. What is ISO 27001?: ISO 27001 is the world’s best-known standard for
information security management systems (ISMS). It defines requirements
an ISMS must meet1. It was developed to help organizations, of any size or
any industry, to protect their information in a systematic and cost-effective
way2.
2. Why is ISO 27001 important?: With cyber-crime on the rise and new
threats constantly emerging, ISO/IEC 27001 helps organizations become
risk-aware and proactively identify and address weaknesses1. It promotes a
holistic approach to information security: vetting people, policies, and
technology1.
3. Three principles of ISO 27001: The basic goal of an ISMS is to protect
three aspects of information2:
o Confidentiality: Only authorized persons have the right to access
information2.
2
o Integrity: Only authorized persons can change the information .
o Availability: The information must be accessible to authorized
persons whenever it is needed2.
4. ISO 27001 Certification: A company can get certified against ISO 27001
and, in this way, prove to its customers and partners that it safeguards their
data2. Individuals can also get ISO 27001 certified by attending a course and
passing the exam2.
5. ISO 27001 Framework: The ISO 27001 framework is a set of requirements
for defining, implementing, operating, and improving an ISMS2. It is the
leading standard recognized by the ISO for information security2.
Remember, the implementation of ISO 27001 can vary depending on the specific
industry regulations, compliance goals, or information security concerns of an
organization12.
SSE-CMM
The Systems Security Engineering Capability Maturity Model (SSE-CMM) is a
process reference model that focuses on the need to implement security in a system
or a sequence of interconnected systems1. Here are some key points:
1. Framework: The SSE-CMM provides a general framework for
implementing security engineering within an organization, preferably in
conjunction with some manufacturing Capability Maturity Models
(CMMs)1.
2. Goals and Activities: The SSE-CMM defines the goals and activities
contained in such processes, and the maturity of the process is achieved
from implementing these activities1.
3. Integration: The utility of SSE-CMM lies in the integration of the existing
processes in the organization with those contained in the model1.
4. Domain and Capability: The SSE-CMM model is divided into two
different but interrelated areas or dimensions: domain and capability1. The
domain-related practices are oriented towards the security domain, while the
capability practices are more general and apply to a broad range of
domains1.
5. Process Improvement: SSE-CMM builds on the work of Deming, focusing
on process definition and improvement as a core value1. It looks at the
occurrence of security defects or incidents and calls for identifying the flaw
in the related process to remediate the flaw, thereby eliminating the overall
fault1.
6. ISO/IEC 21827:2008: The SSE-CMM is specified in the ISO/IEC
21827:2008 standard, which describes the essential characteristics of an
organization’s security engineering process that must exist to ensure good
security engineering2.
Remember, the SSE-CMM is complex and well-tested architecture for
incorporation into an engineering-oriented organization1. However, it may not be
the best match for service organizations that do not perform an engineering
function1.
IA-CMM
The Information Assurance Capability Maturity Model (IA-CMM) is a model that
provides organizations with a structured set of processes to ensure the protection of
information systems. It is designed to help organizations assess their current level
of capability, set target levels of capability, and define and implement
improvements to increase their information assurance maturity1.
Here are some key points about IA-CMM:
1. Structure: The IA-CMM is structured into several key process areas, each
of which is associated with a maturity level. Each key process area identifies
a cluster of related activities that, when performed collectively, achieve a set
of goals considered important for enhancing capability1.
2. Maturity Levels: The maturity levels in IA-CMM provide a recommended
order for approaching process improvement in specified key process areas1.
3. Benefits: Implementing IA-CMM can help organizations to improve their
processes, leading to higher quality products and services, increased
customer satisfaction, and reduced development and maintenance costs1.
4. Integration with Other Models: IA-CMM can be used in conjunction with
other models such as the Systems Security Engineering Capability Maturity
Model (SSE-CMM) and the Capability Maturity Model Integration (CMMI)
to provide a comprehensive approach to process improvement1.
Remember, the implementation of IA-CMM should be tailored to the specific
needs of the organization and regularly updated to address evolving threats and
business requirements1.
ITIL & BS 15000
ITIL in Information Security:
ITIL (Information Technology Infrastructure Library) is a set of best practices for
IT service management. ITIL Information Security Management (ISM) is one of
the main processes under the Service Design process group of the ITIL best
practice framework12. Here are some key points:
1. Goal: The primary goal of ITIL ISM is to align IT security with business
security and ensure that information security is effectively managed in all
service and IT Service Management activities12.
2. Activities: ITIL ISM has four major activities: Plan, Implement, Evaluate,
and Maintain1.
3. Sub-Processes: ITIL ISM includes sub-processes like Design of Security
Controls, Security Validation & Testing, and more1.
4. Relationship with Other Processes: ITIL ISM has a strong relationship
with other ITIL Processes such as availability management, IT service
continuity management, incident management, and change management1.
BS 15000 in Information Security:
BS 15000 is the world’s first standard specifically aimed at service management. It
defines the features of service management processes that are essential for the
delivery of high-quality services3. Here are some key points:
1. Structure: BS 15000 is divided into two parts: BS 15000-1, a formal
specification that defines what is required for service management processes
to reach best practice standards, and BS 15000-2, a supporting code of
practice that describes best practices3.
2. Transition to ISO/IEC 20000: BS 15000 was the basis for the development
of ISO/IEC 20000, the international standard for IT service management45.
3. Benefits: Implementing BS 15000 can lead to better service levels, customer
retention, and lower business risk4.
Remember, both ITIL and BS 15000 (now ISO/IEC 20000) provide valuable
frameworks for implementing and managing information security in an
organization3412.
BS7799
BS 7799 was a British standard “Code of Practice for Information Security
Management”, first published by the British Standards Institution (BSI) in
February 19951. Here are some key points:
1. Structure: The original BS 7799 outlined a structured approach to the
management of information security but was primarily a description of some
127 information security controls in 10 sections or categories1.
2. Evolution: After a lengthy discussion by standards bodies through ISO/IEC,
BS 7799-1 was eventually fast-tracked and adopted as ISO/IEC 17799,
“Information Technology - Code of practice for information security
management” in 20001. ISO/IEC 17799 was revised in June 2005, and
renumbered ISO/IEC 27002 in July 2007 when it was incorporated into the
growing ISO/IEC 27000 family of standards1.
3. BS 7799 Part 2: “Information Security Management Systems -
Specification with guidance for use” was first published by BSI Group in
1999 as a formal specification supporting conformity assessment and
certification1. BS 7799 Part 2 was adopted by ISO/IEC as ISO/IEC 27001 in
November 20051.
4. BS 7799 Part 3: “Information security management systems - Guidelines
for information security risk management” was first published by BSI
Group in 20051. BS 7799-3 focuses on the identification, analysis, treatment,
and monitoring of information risks1. It was adapted and adopted by
ISO/IEC as ISO/IEC 27005 in 20081.
Remember, BS 7799 was conceived as a technology-neutral, vendor-neutral
management system that, properly implemented, would enable an organization’s
management to assure itself that its information security measures and
arrangements were effective2.
Legislative Solution
Legislative solutions in information security refer to the laws and regulations that
govern how entities must protect their information systems and data. These laws
can be at the national, regional, or international level123. Here are some key points:
1. Data Protection Laws: These laws regulate the processing of data that can
be linked to individuals (personal data). Examples include the Data
Protection Act 2018 and UK GDPR2.
2. Cybercrime Laws: These laws deal with offenses committed against
individuals or groups of individuals with a criminal motive to intentionally
harm the reputation of the victim or cause physical or mental harm to the
victim directly or indirectly. They include laws against illegal access, data
interference, system interference, misuse of devices, etc1.
3. Information Security Laws: These laws mandate organizations to protect
their information systems and data from cyber threats. They may require
organizations to implement specific security measures, improve incident
response and preparedness, and increase penalties for computer crimes3.
4. Sector-Specific Regulations: Certain sectors have specific regulations due
to the sensitivity of the data they handle. For example, the healthcare sector
has regulations like the Health Insurance Portability and Accountability Act
(HIPAA) in the U.S1.
5. Standards and Frameworks: While not laws, standards like ISO 27001
and frameworks like the NIST Cybersecurity Framework can be used by
organizations to help ensure they are complying with legal requirements1.
Remember, the exact legislative solutions applicable to an organization will
depend on factors like the jurisdiction the organization operates in, the type of data
it handles, and the sector it operates in123.
Contractual Solutions
Contractual solutions in information security refer to the agreements and contracts
that organizations establish with their partners, suppliers, and customers to ensure
the protection of information systems and data1. Here are some key points:
1. Purpose: Contractual solutions are used to define the responsibilities and
obligations of each party regarding information security1. They can cover
areas such as data protection, confidentiality, incident response, and service
levels1.
2. Drafting Contracts: When drafting and amending information security
procedures and internal policy documents, organizations should keep in
mind their legal, statutory, regulatory, and contractual requirements1.
3. Designing Controls: When designing, amending, or implementing
information security controls, organizations should consider their
contractual requirements1.
4. Supplier Relationships: When establishing the nature of a supplier
relationship, organizations should consider their contractual obligations
throughout the supply of products and services1.
5. ISO 27001 Control A.15.1.2: This control requires an organization to
consider security clauses in contracts2. It doesn’t list any specific legal,
regulatory, or contractual terms that organizations need to enforce or remain
compliant with, nor does it set out a procedure for drafting contracts1.
Remember, contractual solutions are a critical part of an organization’s information
security strategy. They help ensure that all parties involved in handling an
organization’s data understand their responsibilities and are held accountable for
their actions1.
Evidential Issues
Evidential issues in information security refer to the challenges associated with
using digital evidence in legal proceedings1. Here are some key points:
1. Digital Evidence Admissibility: Certain legal and technical requirements
must be met to ensure the admissibility of digital evidence in a court of law1.
This includes examining the legal authorization to conduct searches and
seizures of information and communication technology and related data, and
the relevance, authenticity, integrity, and reliability of digital evidence 1.
2. Digital Forensics Procedures and Tools: The court critically examines the
digital forensics procedures and tools used to extract, preserve, and analyze
digital evidence; the digital laboratories whereby analyses are performed;
the reports of digital forensic analysts; and the technical and academic
qualifications of digital forensics analysts and expert witnesses (if
required)1.
3. Harmonized Model for Digital Evidence Admissibility Assessment
(HM-DEAA): This framework encapsulates the essential technical and legal
requirements that determine evidence admissibility1. It proposes a three-
phase model for assessing evidence admissibility, which includes digital
evidence assessment, consideration, and determination1.
Remember, the use of digital evidence in legal proceedings is a complex issue that
requires careful consideration of various legal and technical factors1.
International Activity
International activity in information security involves various initiatives and
collaborations among countries and international organizations to ensure the
security of information systems and data globally123. Here are some key points:
1. NIST’s International Cybersecurity and Privacy Resources: The
National Institute of Standards and Technology (NIST) encourages
international participation in the development and evolution of its
cybersecurity and privacy programs and resources1. NIST participates in
conversations on cybersecurity and privacy in several international standards
development organizations1.
2. ITU’s Cybersecurity Activities: The International Telecommunication
Union (ITU) plays a fundamental role in building confidence and security in
the use of Information and Communication Technologies (ICTs). ITU
launched the Global Cybersecurity Agenda (GCA) as a framework for
international cooperation in this area2.
3. Convention on International Information Security: This convention was
developed to build confidence and security in the use of ICTs. It
acknowledges the necessity of cooperation between governments and
private businesses in the fight against illegal activity in the information
space3.
4. Standards and Frameworks: International standards like ISO 27001 and
frameworks like the NIST Cybersecurity Framework provide valuable
guidelines for implementing and managing information security on a global
scale14.
Remember, international activity in information security is crucial for maintaining
global cybersecurity and protecting valuable assets from potential threats123.
Indian IT Act
The Information Technology Act, 2000, also known as the IT Act, is the primary
law in India dealing with cybercrime and electronic commerce1234. Here are some
key points:
1. Enactment: The IT Act was enacted by the Indian Parliament on October
17, 20001234. It is based on the United Nations Model Law on Electronic
Commerce 1996 (UNCITRAL Model)1.
2. Objective: The main objective of the IT Act is to facilitate lawful,
trustworthy electronic, digital, and online transactions, and to reduce or
alleviate cybercrimes1.
3. Structure: The IT Act has 13 chapters and 94 sections1. The last four
sections, from section 91 to section 94, deal with revisions to the Indian
Penal Code 18601.
4. Schedules: The IT Act has two schedules1:
o First Schedule: Deals with documents to which the Act shall not
apply1.
o Second Schedule: Deals with electronic signature or electronic
authentication method1.
5. Offences and Punishments: The IT Act outlines various offences and their
corresponding punishments1. These include tampering with computer source
documents, publishing obscene information in electronic form, breach of
confidentiality and privacy, hacking for malicious purposes, and more1.
6. Amendments: A major amendment was made in 2008, introducing sections
like 66A, which penalized sending “offensive messages”, and 69, which
gave authorities the power of "interception or monitoring or decryption of
any information through any computer resource"2.
Remember, the IT Act is a crucial piece of legislation that provides a legal
framework for electronic governance, giving recognition to electronic records and
digital signatures234.
Laws of IPR
Intellectual Property Rights (IPR) are legal rights that cover the benefits given to
individuals who are the owners and inventors of a work, and have created
something unique with their intellectual creativity or capability1. Here are some
key points about IPR:
Types of Intellectual Property Rights1:
o Copyright: Ownership or control of the rights to the use and
distribution of certain works of creative expression.
o Patent: Gives its owner the right to exclude others from making,
using, selling, and importing an invention for a limited period of time.
o Trademark: A graphical representation used to distinguish the goods
and services of one party from those of others.
o Trade Secrets: Describes the general formula of any product and the
key behind any organization’s progress.
Advantages of Intellectual Property Rights1:
o IPR yields exclusive rights to the creators or inventors.
o It encourages individuals to distribute and share information and data
instead of keeping it confidential.
o It provides legal defense and offers the creators the incentive of their
work.
o It helps in social and financial development.
o It inspires people to create new things without fear of intellectual
theft.
In the context of information security, there are no specific provisions related to
national security in the laws on copyright, trademark, and geographical indication2.
However, international conventions and treaties have provided various laws to
protect infringement of IPRs online which are helping e-commerce and e-
businesses to grow3. The Information Technology Act does not provide any
provisions in respect of cybercrimes related to IPR, cyberstalking, cyber
defamation, etc3.
Indian Copyright Act
The Indian Copyright Act, established in 1957 and amended several times since,
plays a significant role in information security12. Here are some key points:
Copyright in Software: In India, copyright exists in the source code of a
computer program. Computer software is secured as literary work and so are
computer databases according to Section 2 (o) of the Copyright Act, 19573.
Digital Rights Management (DRM): DRM technologies, which control the
use of digital devices and contents, pose a privacy threat because they can
collect personal information and send it back to a host without the user’s
knowledge1. The Copyright Act, 1957 currently has no provisions against
DRM circumvention1.
Proposed Legislation: The proposed Copyright Bill 2010 includes
provisions to prevent anti-circumvention of DRM technologies and one
provision that clarifies what is a DRM technology1. It also defines Rights
Management Information, excluding any device or procedure intended to
identify the user from the definition1.
Privacy Concerns: There are concerns about the privacy of an individual
because there are no safeguards against the commercialization of
information, and no formal process of redress if an individual discovers that
his information is being used without his consent/prior knowledge1.
Please note that while the Copyright Act provides a framework for protecting
intellectual property in the digital environment, it does not specifically address all
aspects of information security. Other laws and regulations, including the
Information Technology Act, also play a role in this area.