Module 3 - Information Security Management
Module 3 - Information Security Management
Information Security
Management
Upon completion of this material, you should be able to: Begin with the end in
1 Describe the different management functions with respect to information security mind.
— Stephen Covey, Author of
2 Define information security governance and list the expectations of the organiza-
Seven Habits of Highly
tion’s senior management with respect to it Effective People
Opening Scenario
Charlie had a problem. Well, to be precise, Janet Kinneck had a problem, and now Charlie had to deal with it.
Janet, the vice president of social media market development in the SLS Marketing unit, had appeared on the monthly
abuse report. Charlie had started having the security operations team prepare this report, based on the network activity for
the prior month. All SLS employees consented to this monitoring whenever they used the company’s network.
SLS had a pretty liberal policy in place that described how and when employees could use company computers and
networks for their own personal reasons. Charlie had convinced CEO Fred Chin and the other senior executives that employees
had lives that filtered over into the workplace and that the minor costs of the company network’s incidental use for personal
matters, within certain boundaries, were well worth the improved productivity that resulted. It was those “certain boundaries”
that they were dealing with now.
Charlie looked at the report and the data it contained once more and picked up his phone to call Gladys Williams, the CIO.
He had considered whether this meeting should involve Fred, but he decided it fit better with Gladys’ role. She could always
decide to bring Fred in if she determined that his presence was needed.
Gladys picked up, saying, “Hi, Charlie, what’s up?”
82 Principles of Information Security
He replied, “Hey, Gladys, we have an issue with that new monthly abuse report we are implementing.” Gladys knew the
report, as she had helped in its creation. She knew what was coming next because she was to be informed when employees
above a specific rank were involved.
Charlie continued, “Well, anyway, it looks like we have an issue with Janet Kinneck in Marketing. Near as I can tell without
a forensic examination of her computer, she’s running a commercial sports gaming league out of her office on the sixth floor.”
Gladys thought for a second and replied, “That doesn’t sound like an acceptable use to me.”
Planning
Planning in InfoSec management is an extension of the basic planning mentioned later in this module. Included in the
InfoSec planning model are activities necessary to support the design, creation, and implementation of InfoSec strat-
egies within the planning environments of all organizational units, including IT. Because the InfoSec strategic plans
must support not only the IT department’s use and protection of information assets but those of the entire organiza-
tion, it is imperative that the CISO work closely with all senior managers in developing InfoSec strategy. The business
strategy is translated into the IT strategy. The strategies of other business units and the IT strategy are then used to
develop the InfoSec strategy. Just as the CIO uses the IT objectives gleaned from the business unit plans to create the
organization’s IT strategy, the CISO develops InfoSec objectives from the IT and other business units to create the
organization’s InfoSec strategy.
The IT strategy and that of the other business units provides critical information used for InfoSec planning as the
CISO gets involved with the CIO and other executives to develop the strategy for the next level down. The CISO then
works with the appropriate security managers to develop operational security plans. These security managers con-
sult with security technicians to develop tactical security plans. Each of these plans is usually coordinated across the
business and IT functions of the enterprise and placed into a master schedule for implementation. The overall goal is
to create plans that support long-term achievement of the overall organizational strategy. If all goes as expected, the
Module 3 Information Security Management 83
entire collection of tactical plans accomplishes the operational goals and the entire collection of operational goals
accomplishes the subordinate strategic goals; this helps to meet the strategic goals and objectives of the organization
as a whole.
Several types of InfoSec plans and planning functions exist to support routine operations as well as activities and
responses that are not part of the normal operating environment. Routine planning includes that for policy, personnel
issues, technology rollouts, risk management, and security programs. Plans and functions that go beyond the routine
include planning for incident response, business continuity, disaster recovery, and crisis management. Each of these
plans has unique goals and objectives, yet each can benefit from the same methodical approach. These planning areas
are discussed in detail in Module 4.
Another basic planning consideration unique to InfoSec is the location of the InfoSec department within the orga-
nization structure. This topic is discussed in Module 7.
Policy
In InfoSec, there are three general policy categories, which are discussed in greater detail later in this module:
• Enterprise information security policy (EISP)—Developed within the context of the strategic IT plan, this sets
the tone for the InfoSec department and the InfoSec climate across the organization. The CISO typically drafts
the program policy, which is usually supported and signed by the CIO or the CEO.
• Issue-specific security policies (ISSPs)—These are sets of rules that define acceptable behavior within a specific
organizational resource, such as e-mail or Internet usage.
• Systems-specific policies (SysSPs)—A merger of technical and managerial intent, SysSPs include both the
managerial guidance for the implementation of a technology as well as the technical specifications for its
configuration.
Programs
InfoSec operations that are specifically managed as separate entities are called “programs.” An example would be a
security education, training, and awareness (SETA) program or a risk management program. SETA programs provide
critical information to employees to maintain or improve their current levels of security knowledge. Risk management
programs include the identification, assessment, and control of risks to information assets. Other programs that may
emerge include a physical security program, complete with fire protection, physical access, gates, and guards. Some
organizations with specific regulations may have additional programs dedicated to client/customer privacy, awareness,
and the like. Each organization will typically have several security programs that must be managed.
Protection
The protection function is executed via a set of risk management activities, as well as protection mechanisms, tech-
nologies, and tools. Each of these mechanisms or safeguards represents some aspect of the management of specific
controls in the overall InfoSec plan.
People
People are the most critical link in the InfoSec program. This area encompasses security personnel (the professional
information security employees), the security of personnel (the protection of employees and their information), and
aspects of the SETA program mentioned earlier.
Projects
Whether an InfoSec manager is asked to roll out a new security training program or select and implement a new firewall,
it is important that the process be managed as a project. The final element for thoroughgoing InfoSec management
is the application of a project management discipline to all elements of the InfoSec program. Project management
involves identifying and controlling the resources applied to the project, as well as measuring progress and adjusting
the process as progress is made toward the goal.
84 Principles of Information Security
strategic planning
The process of defining and specifying
Information Security Planning And
the long-term direction (strategy) to
be taken by an organization, and the
Governance
allocation and acquisition of resources
needed to pursue this effort. Strategic planning sets the long-term direction to be taken by the organization and
each of its component parts. Strategic planning should guide organizational efforts
goals and focus resources toward specific, clearly defined goals. After an organization
A term sometimes used synony- develops a general strategy, it generates an overall strategic plan by extending
mously with objectives; the desired
end of a planning cycle.
that general strategy into plans for major divisions. Each level of each division then
translates those plan objectives into more specific objectives for the level below. To
strategic plan execute this broad strategy, the executive team must first define individual respon-
The documented product of strate- sibilities. (The executive team is sometimes called the organization’s C-level, as in
gic planning; a plan for the organi- CEO, COO, CFO, CIO, and so on.)
zation’s intended strategic efforts
over the next several years.
objectives
Information Security Leadership
A term sometimes used synony- The leadership of the information security function that delivers strategic planning
mously with goals; the intermediate and corporate responsibility is best accomplished using an approach industry refers
states obtained to achieve progress
to as governance, risk management, and compliance (GRC). GRC seeks to inte-
toward a goal or goals.
grate these three previously separate responsibilities into one holistic approach that
governance, risk can provide sound executive-level strategic planning and management of the InfoSec
management, and function. The subjects themselves are neither new nor unique to InfoSec; however,
compliance (GRC) recognition of the need to integrate the three at the board or executive level is becom-
An approach to information security ing increasingly important to practitioners in the field. Note that the management
strategic guidance from a board of
directors’ or senior management
of risk is not limited to an organization’s information security. Although organiza-
perspective that seeks to integrate tions increasingly seem to manage their risk challenges with an integrated InfoSec
the three components of informa- approach focused on GRC, many types of organizations face many types of risk and
tion security governance, risk man-
have developed specific strategies to manage them.
agement, and regulatory compliance.
InfoSec objectives must be addressed at the highest levels of an organization’s
governance management team in order to be effective and offer a sustainable approach. In
The set of responsibilities and prac- organizations with formal boards of directors, the boards should be the basis for
tices exercised by the board and governance review and oversight. For organizations that have a parent organization,
executive management with the the executive management of the parent should be the basis. For organizations that
goal of providing strategic direc-
tion, ensuring that objectives are
don’t have either, this strategic oversight must stem from a formal governance
achieved, ascertaining that risks are board consisting of executive management from across the organization—usually
managed appropriately, and verify- the chief executive officer (CEO) or president and their immediate subordinate
ing that the enterprise’s resources
executives.
are used responsibly.
Just like governments, corporations and other organizations have guiding docu-
corporate governance ments—corporate charters or partnership agreements—as well as appointed or
Executive management’s respon- elected leaders or officers, and planning and operating procedures. These elements
sibility to provide strategic direc- in combination provide corporate governance.
tion, ensure the accomplishment
When security programs are designed and managed as a technical specialty in
of objectives, oversee that risks are
appropriately managed, and vali- the IT department, they are less likely to be effective. A broader view of InfoSec
date responsible resource use. encompasses all of an organization’s information assets, including IT assets. These
valuable commodities must be protected regardless of how the information is pro-
information security cessed, stored, or transmitted, and with a thorough understanding of the risks and
governance
benefits.
The application of the principles and
practices of corporate governance Each operating unit within an organization also has controlling customs, pro-
to the information security function, cesses, committees, and practices. The information security group’s leadership
emphasizing the responsibility of the monitors and manages all organizational structures and processes that safeguard
board of directors and/or senior man-
agement for the oversight of informa-
information. Information security governance then applies these principles and
tion security in the organization. management structures to the information security function.
Module 3 Information Security Management 85
According to the Corporate Governance Task Force (CGTF), the organization should engage in a core set of activi-
ties suited to its needs to guide the development and implementation of the InfoSec governance program:
• Conduct an annual InfoSec evaluation, the results of which the CEO should review with staff and then report
to the board of directors.
• Conduct periodic risk assessments of information assets as part of a risk management program.
• Implement policies and procedures based on risk assessments to secure information assets.
• Establish a security management structure to assign explicit individual roles, responsibilities, authority, and
accountability.
• Develop plans and initiate actions to provide adequate InfoSec for networks, facilities, systems, and information.
• Treat InfoSec as an integral part of the system life cycle.
• Provide InfoSec awareness, training, and education to personnel.
• Conduct periodic testing and evaluation of the effectiveness of InfoSec policies and procedures.
• Create and execute a plan for remedial action to address any InfoSec inefficiencies.
• Develop and implement incident response procedures.
• Establish plans, procedures, and tests to provide continuity of operations.
• Use security best practices guidance, such as the ISO 27000 series, to measure InfoSec performance.1
The CGTF framework defines the responsibilities of the board of directors and trustees, the senior organizational
executive (for example, the CEO), executive team members, senior managers, and all employees and users.
ISO 27014:2013 is the ISO 27000 series standard for Governance of Information Security. This remarkably short
document (11 pages) provides brief recommendations for the assessment of an information security governance pro-
gram. The standard specifies six high-level “action-oriented” information security governance principles:
1. Establish organization-wide information security.
2. Adopt a risk-based approach.
3. Set the direction of investment decisions.
4. Ensure conformance with internal and external requirements.
5. Foster a security-positive environment.
6. Review performance in relation to business outcomes.2
The standard also promotes five governance processes, which should be adopted by the organization’s executive
management and its governing board. These processes are illustrated in Figure 3-1 and described in the following list.
• Evaluate—Review the status of current and projected progress toward organizational information security
objectives and make a determination whether modifications of the program or its strategy are needed to keep
on track with strategic goals.
• Direct—The board of directors provides instruction for developing or implementing changes to the security
program. This could include modification of available resources, structure of priorities of effort, adop-
tion of policy, recommendations for the risk management program, or alteration to the organization’s risk
tolerance.
• Monitor—The review and assessment of organizational information security performance toward goals and
objectives by the governing body. Monitoring is enabled by ongoing performance measurement.
• Communicate—The interaction between the governing body and external stakeholders, where information on
organizational efforts and recommendations for change are exchanged.
• Assure—The assessment of organizational efforts by external entities like certification or accreditation groups,
regulatory agencies, auditors, and other oversight entities, in an effort to validate organizational security
governance, security programs, and strategies.3
According to the Information Technology Governance Institute (ITGI), information security governance includes all
of the accountabilities and methods undertaken by the board of directors and executive management to provide the
following:
• Strategic direction
• Establishment of objectives
86 Principles of Information Security
GOVERNING BODY
Source: R. Mahncke, Australian eHealth Informatics and Security Conference, December 2013.
The five goals of information security governance are as follows: tactical plan
1. Strategic alignment of information security with business strategy to support The documented product of tactical
planning; a plan for the organiza-
organizational objectives
tion’s intended tactical efforts over
2. Risk management by executing appropriate measures to manage and the next few years.
mitigate threats to information resources
3. Resource management by using information security knowledge and operational plan
infrastructure efficiently and effectively The documented product of opera-
4. Performance measurement by measuring, monitoring, and reporting tional planning; a plan for the orga-
information security governance metrics to ensure that organizational nization’s intended operational
efforts on a day-to-day basis for the
objectives are achieved next several months.
5. Value delivery by optimizing information security investments in support of
organizational objectives6
tactical planning
The actions taken by management
broad, general, sweeping statements into more specific and applied objectives.
Strategic plans are used to create tactical plans, which in turn are used to develop operational planning
operational plans. The actions taken by management
to specify the short-term goals
Tactical planning focuses on undertakings that will be completed within one or
and objectives of the organization
two years. The process of tactical planning breaks each strategic goal into a series in order to obtain specified tacti-
of incremental objectives. Each objective in a tactical plan should be specific and cal goals, followed by estimates
should have a delivery date within a year of the plan’s start. Budgeting, resource and schedules for the allocation
of resources necessary to achieve
allocation, and personnel are critical components of the tactical plan. Tactical plans those goals and objectives.
often include project plans and resource acquisition planning documents (such as
product specifications), project budgets, project reviews, and monthly and annual
reports. The CISO and security managers use the tactical plan to organize, prioritize, and acquire resources necessary
for major projects and to provide support for the overall strategic plan.
Managers and employees use operational planning derived from tactical planning to organize the ongoing, day-
to-day performance of tasks. An operational plan includes the necessary tasks for all relevant departments as well
as communication and reporting requirements, which might include weekly meetings, progress reports, and other
associated tasks. These plans must reflect the organizational structure, with each subunit, department, or project
team conducting its own operational planning and reporting. Frequent communication and feedback from the teams
to the project managers and/or team leaders, and then up to the various management levels, will make the planning
process more manageable and successful.
strategic planning by function (such as financial, IT, and operations strategies) is then converted into tactical planning
for supervisory managers and eventually provides direction for the operational plans undertaken by non-management
members of the organization. This multilayered approach encompasses two key objectives: general strategy and over-
all strategic planning. First, general strategy is translated into specific strategy; second, overall strategic planning is
translated into lower-level tactical and operational planning.
Information security, like information technology, must support more than its own functions. All organizational
units will use information, not just IT-based information, so the information security group must understand and
support the strategic plans of all business units. This role may sometimes conflict with that of the IT department, as
IT’s role is the efficient and effective delivery of information and information resources, while the role of information
security is the protection of all information assets.
For more information on information security planning, read NIST Special Publication (SP) 800-18, Rev. 1, which
i is available from the NIST SP Web site at [Link]
Table 3-1 Relationship between Policies, Standards, Practices, Procedures, and Guidelines
Policies
Sanctioned by management
Practices
Industry,
Standards
government, Detailed minimum specifications for compliance
and
regulatory
exemplars
Guidelines
Recommendations for compliance
Influence
organization
documents Procedures
Step-by-step instructions for compliance
Policy: Employees must use strong passwords on their accounts. Passwords must be changed
regularly and protected against disclosure.
The standard provides specifics to help employees comply with the policy.
Standard: Passwords must be at least 10 characters long and incorporate at least one lowercase
letter, one uppercase letter, one numerical digit (0–9), and one special character permitted by our
system (&%$#@!). Passwords must be changed every 90 days and must not be written down or
stored on insecure media.
The practice identifies other reputable organizations and agencies that offer recommendations the organization
may have adopted or adapted.
• Prevent the use of personal information as passwords, such as phone numbers and dates of birth.
• Use a minimum password length of 8 characters for standard users.
• Disable local machine credential caching if not required through the use of a Group Policy Object (GPO).
• Deploy a secure password storage policy that provides password encryption.8
Guidelines provide examples and recommendations to assist users in complying with the new policy.
Guidelines: In order to create strong yet easy-to-remember passwords, consider the following
recommendations from NIST SP 800-118: “Guide to Enterprise Password Management” (draft), April 2009:
• Mnemonic method—A user selects a phrase and extracts a letter of each word in the phrase (such as the first letter or
second letter of each word), adding numbers or special characters or both.
❍ Example: “May the force be with you always, young Jedi” becomes Mtfbwya-yJ
• Altered passphrases—A user selects a phrase and alters it to form a derivation of that phrase. This method supports the
creation of long, complex passwords. Passphrases can be easy to remember due to the structure of the password: It is
usually easier for the human mind to comprehend and remember phrases within a coherent structure than a string of
random letters, numbers, and special characters.
❍ Example: Never Give Up! Never Surrender! becomes [Link]!-[Link]!
• Combining and altering words—A user can combine two or three unrelated words and change some of the letters to
numbers or special characters.
❍ Example: Jedi Tribble becomes J3d13bbl
Finally, procedures are step-by-step instructions for accomplishing the task specified in the policy.
Procedures: To change your login password on our system, perform the following steps:
Do not write your new password down. If you own a smartphone, you may request that your
department purchase an approved password management application like eWallet for storing
passwords.
As stated earlier, many organizations combine their policy and standards in the same document and then provide direc-
tions or a Web link to a page with guidelines and procedures.
The meaning of the term security policy depends on the context in which it is used. Governmental agencies view
security policy in terms of national security and national policies to deal with foreign states. A security policy can also
communicate a credit card agency’s method for processing credit card numbers. In general, a security policy is a set
of rules that protects an organization’s assets. An information security policy provides rules for protection of the
organization’s information assets.
information security Management must define three types of security policy, according to SP 800-14
policy of the National Institute of Standards and Technology (NIST):
Written instructions provided by
management that inform employ- 1. Enterprise information security policies
ees and others in the workplace 2. Issue-specific security policies
about proper behavior regarding 3. Systems-specific security policies
the use of information and infor-
mation assets. NIST SP 800-14 will be discussed in greater detail later in this module.
Module 3 Information Security Management 91
EISP Elements
Although the specifics of EISPs vary among organizations, most EISP documents should include the following elements:
• An overview of the corporate philosophy on security
• Information on the structure of the information security organization and people who fulfill the information
security role
• Fully articulated responsibilities for security that are shared by all members of the organization (employees,
contractors, consultants, partners, and visitors)
• Fully articulated responsibilities for security that are unique to each role within the organization
The components of a good EISP are shown in Table 3-2. For examples of EISP documents and recommendations
for how to prepare them, we recommend using Information Security Policies Made Easy by Charles Cresson Wood,
published by Information Shield. While the current version is relatively expensive, prior editions are widely available
as used books and in libraries around the world.
Component Description
Statement of Purpose Answers the question “What is this policy for?” Provides a framework that helps
the reader understand the intent of the document. Can include text such as the
following: “This document will:
• Identify the elements of a good security policy
• Explain the need for information security
• Specify the various categories of information security
• Identify the information security responsibilities and roles
• Identify appropriate levels of security through standards and guidelines
This document establishes an overarching security policy and direction for our
company. Individual departments are expected to establish standards, guidelines,
and operating procedures that adhere to and reference this policy while
addressing their specific and individual needs."
Information Security Elements Defines information security. For example:
"Protecting the confidentiality, integrity, and availability of information while in
processing, transmission, and storage, through the use of policy, education and
training, and technology …"
This section can also lay out security definitions or philosophies to clarify the policy.
Need for Information Security Provides information on the importance of information security in the
organization and the legal and ethical obligation to protect critical information
about customers, employees, and markets.
Information Security Defines the organizational structure designed to support information security
Responsibilities and Roles within the organization. Identifies categories of people with responsibility
for information security (IT department, management, users) and those
responsibilities, including maintenance of this document.
Reference to Other Information Lists other standards that influence this policy document and are influenced by it,
Standards and Guidelines perhaps including relevant federal laws, state laws, and other policies.
• Use of portable storage devices such as USB memory sticks, backpack drives, game players, music players,
and any other device capable of storing digital files
• Use of cloud-based storage services that are not self-hosted by the organization or engaged under contract;
such services include Google Drive, Dropbox, and Microsoft OneDrive
• Use of networked infrastructure devices, “intelligent assistants” such as Google Assistant and Amazon Echo,
and accompanying devices usually classified as the Internet of Things (IoT)
• Use of programmable logic controller (PLC) devices and associated control protocols with corporate data
networks and production-focused industrial networks
For examples of ISSP policies and recommendations for how to prepare them, we recommend using Information
Security Policies Made Easy by Charles Cresson Wood, published by Information Shield. The book includes a wide vari-
ety of working policy documents and can assist in defining which are needed and how to create them.
Several approaches are used to create and manage ISSPs within an organization. Three of the most common are
as follows:
• Independent ISSP documents, each tailored to a specific issue
• A single comprehensive ISSP document that covers all issues
• A modular ISSP document that unifies policy creation and administration while maintaining each specific
issue’s requirements
The independent ISSP document typically has a scattershot effect. Each department responsible for an application
of technology creates a policy governing its use, management, and control. This approach may fail to cover all neces-
sary issues and can lead to poor policy distribution, management, and enforcement.
Module 3 Information Security Management 93
The single comprehensive ISSP is centrally managed and controlled. With formal procedures for the management
of ISSPs in place, the comprehensive policy approach establishes guidelines for overall coverage of necessary issues
and clearly identifies processes for the dissemination, enforcement, and review of these guidelines. Usually, these
policies are developed by the people responsible for managing the information technology resources. Unfortunately,
these policies tend to overgeneralize the issues and skip over vulnerabilities.
The optimal balance between the independent and comprehensive ISSP is the modular ISSP. It is also centrally
managed and controlled, but it is tailored to individual technology issues. The modular approach provides a
balance between issue orientation and policy management. The policies created with this approach comprise
individual modules, each created and updated by people responsible for the issues addressed. These people report
to a central policy administration group that incorporates specific issues into an overall comprehensive policy.
Table 3-3 is an outline of a sample ISSP, which can be used as a model. An organization should start with this struc-
ture and add specific details that dictate security procedures not covered by these general guidelines.
Components of an ISSP
1. Statement of policy
a. Scope and applicability
b. Definition of technology addressed
c. Responsibilities
2. Authorized access and usage of equipment
a. User access
b. Fair and responsible use
c. Protection of privacy
3. Prohibited use of equipment
a. Disruptive use or misuse
b. Criminal use
c. Offensive or harassing materials
d. Copyrighted, licensed, or other intellectual property
e. Other restrictions
4. Systems management
a. Management of stored materials
b. Employee monitoring
c. Virus protection
d. Physical security
e. Encryption
5. Violations of policy
a. Procedures for reporting violations
b. Penalties for violations
6. Policy review and modification
a. Scheduled review of policy procedures for modification
b. Legal disclaimers
7. Limitations of liability
a. Statements of liability
b. Other disclaimers as needed
Source: Whitman, Townsend, and Aalberts, Communications of the ACM.
94 Principles of Information Security
The components of each major category of a typical ISSP are discussed in the following sections. Even though
the details may vary from policy to policy and some sections of a modular policy may be combined, it is essential for
management to address and complete each section.
Statement of Policy
The policy should begin with a clear statement of purpose—in other words, what exactly is this policy supposed to
accomplish? Consider a policy that covers the issue of fair and responsible Internet use. The introductory section of
this policy should address the following questions: What is the scope of this policy? Who does this policy apply to?
Who is responsible and accountable for policy implementation? What technologies and issues does it address?
Systems Management
The systems management section of the ISSP policy statement focuses on the users’ relationship to systems manage-
ment. Specific rules from management include regulating the use of e-mail, the storage of materials, the authorized
monitoring of employees, and the physical and electronic scrutiny of e-mail and other electronic documents. It is
important that all such responsibilities are assigned either to the systems administrator or the users; otherwise, both
parties may infer that the responsibility belongs to the other.
Violations of Policy
The people to whom the policy applies must understand the penalties and repercussions of violating it. Violations of
policy should carry penalties that are appropriate—neither draconian nor overly lenient. This section of the policy
statement should contain not only specific penalties for each category of violation, but instructions for how people
in the organization can report observed or suspected violations. Many people think that powerful employees in an
organization can retaliate against someone who reports violations. Allowing anonymous submissions is often the only
way to convince users to report the unauthorized activities of more influential employees.
Limitations of Liability
If an employee is caught conducting illegal activities with the organization’s equipment or assets, management does
not want the organization held liable. The policy should state that if employees violate a company policy or any law
using company technologies, the company will not protect them, and the company is not liable for their actions. In
fact, many organizations assist in the prosecution of employees who violate laws when their actions violate policies.
It is assumed that such violations occur without knowledge or authorization by the organization.
Module 3 Information Security Management 95
As illustrated in Figures 3-4 and 3-5, both Microsoft Windows and Linux systems translate ACLs into sets of con-
figurations that administrators use to control access to their systems.
The level of detail may differ from system to system, but in general, ACLs can restrict access for a specific user,
computer, time, or duration—even a specific file. This specificity provides powerful control to the administrator. In
general, ACLs regulate the following:
The who of ACL access may be determined by a person’s identity or membership in a group. Restricting what
authorized users are permitted to access—whether by type (printers, files, communication devices, or applications),
name, or location—is achieved by adjusting the resource privileges for a person or group to Read, Write, Create,
Modify, Delete, Compare, or Copy. To control when access is allowed, some organizations implement time-of-day and
day-of-week restrictions for certain network or system resources. To control where resources can be accessed, many
network-connected assets block remote usage and have some levels of access that are restricted to locally connected
users, such as restrictions by computer MAC address or network IP address. When these various ACL options are
applied concurrently, the organization can govern how its resources can be used.
Configuration Rule Policies Configuration rules (or policies) govern how a security configuration rules
system reacts to the data it receives. Rule-based policies are more specific to the opera- The instructions a system adminis-
tion of a system than ACLs, and they may or may not deal with users directly. Many secu- trator codes into a server, network-
ing device, or security device to
rity systems—for example, firewalls, intrusion detection and prevention systems (IDPSs), specify how it operates.
and proxy servers, all of which you will learn about in Modules 8 and 9—use specific
configuration scripts that represent the configuration rule policy to determine how the
system handles each data element they process. The examples in Figures 3-6 and 3-7 show how network security policy has
been implemented by a Palo Alto firewall’s rule set and by Ionx Verisys (File Integrity Monitoring) in a host-based IDPS rule set.
Combination SysSPs
Many organizations create a single document that combines the managerial guidance SysSP and the technical speci-
fications SysSP. While this document can be somewhat confusing to casual users, it is practical to have the guidance
from managerial and technical perspectives in a single place. If this approach is used, care should be taken to clearly
articulate the required actions. Some might consider this type of policy document a procedure, but it is actually a
hybrid that combines policy with procedural guidance to assist implementers of the system being managed. This
approach is best used by organizations that have multiple technical control systems of different types and by smaller
organizations that want to document policy and procedure in a compact format.
For policies to be effective and legally defensible, the following must be done properly:
1. Development—Policies must be written using industry-accepted practices and formally approved by
management.
2. Dissemination—Policies must be distributed using all appropriate methods.
3. Review—Policies must be readable and read by all employees.
4. Comprehension—Policies must be understood by all employees.
5. Compliance—Policies must be formally agreed to by act or affirmation.
6. Enforcement—Policies must be uniformly applied to all employees.
We will examine each of these stages in the sections that follow. Before we do, however, you should realize that
almost every organization has a set of existing policies, standards, procedures, and/or practices. This installed base
of guidance may not always have been prepared using an approach that delivers consistent or even usable results.
Most of the situations you find yourself in will involve more policy maintenance than policy development. Prior to
implementation, policy should be reviewed by the organization’s legal counsel to ensure it is acceptable within the
limits of the law and that implementation of the policy and its corresponding penalties would, in fact, be defensible in
the event of a legal dispute.
Policy Distribution
While it might seem straightforward, getting the policy document into the hands of employees can require a substantial
investment by the organization to be effective. The most common alternatives are hard copy and electronic distribu-
tion. Hard copy distribution involves either directly handing or mailing a copy to each employee or posting the policy
in a publicly accessible location. Posting a policy on a bulletin board or other public area may be insufficient unless
another policy requires the employees to read the bulletin board on a specified schedule.
Distribution by internal or external mail may still not guarantee that the individual receives the document. Unless
the organization can prove that the policy reached its target audience, it cannot be enforced. Unlike in law, ignorance
of policy, where policy is inadequately distributed, is considered an acceptable excuse. Distribution of classified
policies—those containing confidential information—requires additional levels of controls, in the labeling of the
document, in the dissemination and storage of new policy, and in the collection and destruction of older versions to
ensure the confidentiality of the information contained within the policy documents themselves.
Another common method of dissemination is by electronic means: e-mail, newsletter, intranet, or document man-
agement systems. Perhaps the easiest way is to post policies on a secure intranet in HTML or PDF (Adobe Acrobat)
form. The organization must still enable a mechanism to prove distribution, such as an auditing log for tracking when
users access the documents. As an alternative delivery mechanism, e-mail has advantages and disadvantages. While
it is easy to send a document to an employee and even track when the employee opens the e-mail, e-mail tracking may
not be sufficient as proof that the employee downloaded and actually read any attached policies, and the document
100 Principles of Information Security
can get lost in an avalanche of spam, phishing attacks, or other unwanted e-mail. The best method is through elec-
tronic policy management software, as described in the section on automated tools. Electronic policy management
software not only assists in the distribution of policy documents, it supports the assessment of comprehension and
evaluation of compliance.
Policy Review
Barriers to employees reading policies can arise from literacy or language issues. A surprisingly large percentage of the
workforce is considered functionally illiterate. According to Macrotrends, a full 1 percent of people 15 and older living
in the United States cannot read and write with understanding. Based on statistics from 2020, that means more than
3.28 million adults in the United States are considered illiterate.13 Many jobs do not require literacy skills—for example,
custodial staff, groundskeepers, or production line workers. Because such workers can still pose risks to InfoSec, they
must be made familiar with policy even if it must be read to them. Visually impaired employees also require additional
assistance, either through audio or large-type versions of the document.
A contributing factor to the literacy issue is that the number of non-English-speaking residents in the United States
continues to climb. According to 2018 U.S. Census data, more than 67 million residents speak a language other than
English at home.14 However, language challenges are not restricted to organizations with locations in the United States.
Multinational organizations also must deal with the challenges of gauging reading levels of foreign citizens. Simple
translations of policy documents, while a minimum requirement, necessitate careful monitoring. Translation issues
have long created challenges for organizations.
Policy Comprehension
Simply making certain that a copy of the policy gets to employees in a form they can review may not ensure that they
truly understand what the policy requires of them. Comprehension involves two aspects of policy administration:
(1) the target audience can understand the policy, and (2) the organization has assessed how well they understand it.
To be certain that employees can understand the policy, the document must be written at an appropriate reading
level, with minimal technical jargon or management terminology. The readability statistics supplied by most productiv-
ity suite applications—such as Microsoft Word—can help determine the current reading level of a policy. The Flesch
Reading Ease test evaluates writing on a scale of 1–100. The higher the score, the easier it is to understand the writing.
For most corporate documents, a score of 60 to 70 is preferred. The Flesch–Kincaid Grade Level test evaluates writ-
ing on a U.S. grade-school level. While a 13th-grade level (freshman in college) may be appropriate for a textbook, it
is too high for organizational policy intended for a broad audience. For most corporate documents, a score of 7.0 to
8.0 is preferred.
The next step is to use some form of assessment to gauge how well employees understand the policy’s underlying
issues. Quizzes and other forms of examination can be employed to assess quantitatively which employees understand
the policy by earning a minimum score (e.g., 70 percent) and which employees require additional training and aware-
ness efforts before the policy can be enforced. Quizzes can be conducted in either hard copy or electronic formats.
The electronic policy management systems mentioned earlier can assist in the assessment of employee performance
on policy comprehension.
Policy Compliance
Policy compliance means the employee must agree to the policy. According to Whitman in “Security Policy: From
Design to Maintenance”: Policies must be agreed to by act or affirmation. Agreement by act occurs when the employee
performs an action, which requires them to acknowledge understanding of the policy prior to use of a technology or
organizational resource. Network banners, end-user license agreements (EULAs), and posted warnings can serve to
meet this burden of proof. However, these approaches in and of themselves may not be sufficient. Only through direct
collection of a signature or the equivalent digital alternative can the organization prove that it has obtained an agree-
ment to comply with policy, which also demonstrates that the previous conditions have been met.15
What if an employee refuses explicitly to agree to comply with policy? Can the organization deny access to infor-
mation that the individual needs to do his or her job? While this situation has not yet been adjudicated in the legal
system, it seems clear that failure to agree to a policy is tantamount to refusing to work and thus may be grounds for
termination. Organizations can avoid this dilemma by incorporating policy confirmation statements into employment
contracts, annual evaluations, or other documents necessary for the individual’s continued employment.
Module 3 Information Security Management 101
Policy Enforcement
The final component of the design and implementation of effective policies is uniform and impartial enforcement. As
in law enforcement, policy enforcement must be able to withstand external scrutiny. Because this scrutiny may occur
during legal proceedings—for example, in a civil suit contending wrongful termination— organizations must establish
high standards of due care with regard to policy management. For instance, if policy mandates that all employees wear
identification badges in a clearly visible location and select members of management decide they are not required
to follow this policy, any actions taken against other employees will not withstand legal challenges. If an employee is
punished, censured, or dismissed as a result of a refusal to follow policy and is subsequently able to demonstrate that
the policies are not uniformly applied or enforced, the organization may find itself facing punitive as well as compen-
satory damages.
One forward-thinking organization found a way to enlist employees in the enforcement of policy. After the organiza-
tion had just published a new ID badge policy, the manager responsible for the policy was seen without his ID. One of
his employees chided him in jest, saying, “You must be a visitor here, since you don’t have an ID. Can I help you?” The
manager smiled and promptly produced his ID, along with a $20 bill, which he presented to the employee as a reward
for vigilant policy enforcement. Soon, the entire staff was routinely challenging anyone without a badge.16
Investigation Phase During the investigation phase, the policy development team or committee should attain the
following:
• Support from senior management because any project without it has a reduced chance of success. Only with
the support of top management will a specific policy receive the attention it deserves from the intermediate-
level managers who must implement it and from the users who must comply with it.
• Support and active involvement of IT management, specifically the CIO. Only with the CIO’s active support will
technology-area managers be motivated to participate in policy development and support the implementation
efforts to deploy it once created.
• Clear articulation of goals. Without a detailed and succinct expression of the goals and objectives of the policy,
broken into distinct expectations, the policy will lack the structure it needs to obtain full implementation.
• Participation of the correct individuals from the communities of interest affected by the recommended
policies. Assembling the right team, by ensuring the participation of the proper representatives from the
groups that will be affected by the new policies, is very important. The team must include representatives from
the legal department, the human resources department, and end users of the various IT systems covered by
the policies, as well as a project champion with sufficient stature and prestige to accomplish the goals of the
project and a capable project manager to see the project through to completion.
• A detailed outline of the scope of the policy development project and sound estimates for the cost and sched-
uling of the project.
❍ “That which is not permitted is prohibited.” Also known as the “whitelist” approach, this is the more restric-
tive of the two, and focuses on creating an approach where specific authorization is provided for various
actions and behaviors; all other actions and behaviors (and uses) are prohibited or at least require specific
permissions. This approach can impede normal business operations if appropriate options emerge but can-
not be incorporated into policy until subsequent revisions are made.
❍ “That which is not prohibited is permitted.” Also known as the “blacklist” approach, this alternate approach
specifies what actions, behaviors, and uses are prohibited and then allows all others by default. While eas-
ier to implement, this approach can result in issues as more and more areas that should be prohibited are
discovered by users.
Design Phase The first task in the design phase is the drafting of the actual policy document. While this task can be
done by a committee, it is most commonly done by a single author. This document should incorporate all the specifica-
tions and restrictions from the investigation and analysis phases. This can be a challenging process, but you do not have
to come up with a good policy document from scratch. A number of resources are at your disposal, including the following:
• The Web—You can search for other similar policies. The point here is not to advocate wholesale copying of
these policies but to encourage you to look for ideas for your own policy. For example, dozens of policies avail-
able on the Web describe fair and responsible use of various technologies. What you may not find, however,
are policies that relate to sensitive internal documents or processes.
• Government sites—Sites such as [Link] contain numerous sample policies and policy support docu-
ments, including SP 800-100, “Information Security Handbook: A Guide for Managers.” While these policies are
typically applicable to federal government Web sites, you may be able to adapt some sections to meet your
organization’s needs.
• Professional literature—Several authors have published books on the subject. Of particular note is Charles
Cresson Wood’s Information Security Policies Made Easy series, which not only provides more than 1,000 pages
of policies, it makes those policies available in electronic format, complete with permission to use them in
internal documents. Exercise caution when using such resources, however; it is extremely easy to take large
sections of policy and end up with a massive, unwieldy document that is neither publishable nor enforceable.
• Peer networks—Other InfoSec professionals must write similar policies and implement similar plans. Attend
meetings like those offered by the Information Systems Security Association ([Link]) or the Information
Systems Audit and Control Association ([Link]), and ask your peers.
• Professional consultants—Policy is one area of InfoSec that can certainly be developed in-house. However, if
your organization does not have the requisite expertise, or if your team simply cannot find the time to develop
your own policy, then hiring an outside consultant may be your best option. Keep in mind that no consultant
can know your organization as well as you do; you may decide to have the consultant design generic policies
that you can then adapt to your specific needs.
Next, the development team or committee reviews the work of the primary author and makes recommendations
about its revision. Once the committee approves the document, it goes to the approving manager or executive for
sign-off.
Implementation Phase In the implementation phase, the team must create a plan to distribute and verify the dis-
tribution of the policies. Members of the organization must explicitly acknowledge that they have received and read
the policy (compliance). Otherwise, an employee can claim never to have seen a policy, and unless the manager can
produce strong evidence to the contrary, any enforcement action, such as dismissal for inappropriate use of the Web,
can be overturned and punitive damages might be awarded to the former employee. The simplest way to document
acknowledgment of a written policy is to attach a cover sheet that states “I have received, read, understood, and agreed
to this policy.” The employee’s signature and date provide a paper trail of his or her receipt of the policy.
Some situations preclude a formal documentation process. Take, for instance, student use of campus computer
labs. Most universities have stringent policies on what students can and cannot do in a computer lab. These policies
are usually posted on the Web, in the student handbook, in course catalogs, and in several other locations, including
bulletin boards in the labs. For the policies to be enforceable, however, some mechanism must be established that
records the student’s acknowledgment of the policy. This is frequently accomplished with a banner screen that displays
a brief statement warning the user that the policy is in place and that use of the system constitutes acceptance of
Module 3 Information Security Management 103
the policy. The user must then click an OK button or press a key to get past the screen. However, this method can be
ineffective if the acknowledgment screen does not require any unusual action to move past it. Most acknowledgment
screens require that the user click a specific button, press a function key, or type text to agree to the terms of the EULA.
Some even require the user to scroll down to the bottom of the EULA screen before the “I accept” button is activated.
Similar methods are used on network and computer logins to reinforce acknowledgment of the system use policy.
A stronger mechanism to document and ensure comprehension is a compliance assessment, such as a short quiz,
to make sure that users both read the policy and understand it. A minimum score is commonly established before the
employee is certified to be “in compliance.” Coupled with a short training video, the compliance quiz is the current
industry best practice for policy implementation and compliance.
The design phase should also include specifications for any automated tool used for the creation and management
of policy documents, as well as revisions to feasibility analysis reports based on improved costs and benefits as the
design is clarified. During the implementation phase, the policy development team ensures that the policy is properly
distributed, read, understood, and agreed to by those to whom it applies, and that their understanding and acceptance
of the policy are documented.
Maintenance Phase During the maintenance phase, the policy development team monitors, maintains, and modi-
fies the policy as needed to ensure that it remains effective as a tool to meet changing threats. The policy should have
a built-in mechanism through which users can report problems—preferably on an anonymous basis through a Web
form monitored either by the organization’s legal team or a committee assigned to collect and review such content.
It is in this phase that the last component of effective policy development—uniform enforcement—comes into play.
The organization should make sure that everyone is required to follow the policy equally and that policies are not
implemented differently in different areas or hierarchies of the organization.
When the policy comes up for schedule review, the development committee reassembles, reviews any submitted
recommendations, and begins the process anew, as described in the next section.
Policy Management
Policies are living documents that must be managed. It is unacceptable to create such an important set of documents
and then shelve them. These documents must be properly distributed, read, understood, agreed to, uniformly applied,
and managed. How they are managed should be specified in the policy management section of the issue-specific policy
described earlier. Good management practices for policy development and maintenance make for a more resilient orga-
nization. For example, all policies, including security policies, undergo tremendous stress when corporate mergers and
divestitures occur. In such situations, employees are faced with uncertainty and many distractions. System vulnerabili-
ties can arise, for instance, if incongruent security policies are implemented in different parts of a newly merged organiza-
tion. When two companies merge but retain separate policies, the difficulty of implementing security controls increases.
Likewise, when one company with unified policies splits in two, each new company may require different policies.
To remain viable, security policies must have a responsible manager, a schedule of reviews, a method for making
recommendations for reviews, and a policy issuance and revision date.
Responsible Manager
Just as information systems and information security projects must have champions and managers, so must policies.
The policy manager is often called the policy administrator. Note that the policy
administrator does not necessarily have to be proficient in the relevant technology. policy administrator
While practicing information security professionals require extensive technical An employee responsible for
knowledge, policy management and policy administration require only a moderate the creation, revision, distribu-
technical background. It is good practice, however, for policy administrators to solicit tion, and storage of a policy in an
organization.
input both from technically adept information security experts and from business-
focused managers in each community of interest when revising security policies. The
administrator should also notify all affected members of the organization when the policy is modified.
It is disheartening when a policy that required hundreds of staff hours to develop and document is ignored. Thus,
someone must be responsible for placing the policy and all subsequent revisions into the hands of people who are
accountable for its implementation. The policy administrator must be clearly identified in the policy document as the
primary point of contact for additional information or suggested revisions to the policy.
104 Principles of Information Security
must be retrained. As a matter of good practice, systems development life cycles must include user training during
the implementation phase. Practices used to take control of the security and privacy of online data are sometimes
called cyber hygiene.
The SETA program consists of three distinct elements: security education, security training, and security aware-
ness. An organization may not be able or willing to undertake all three of these elements, and it may outsource elements
to local educational institutions. The purpose of SETA is to enhance security by doing the following:
• Improving awareness of the need to protect system resources
• Developing skills and knowledge so computer users can perform their jobs more securely
• Building in-depth knowledge as needed to design, implement, or operate security programs for organizations
and systems17
Table 3-4 compares the features of security education, training, and awareness within the organization.
Security Education
Everyone in an organization needs to be trained and made aware of information security, but not everyone needs a
formal degree or certificate in information security. When management agrees that formal education is appropriate, an
employee can investigate courses in continuing education from local institutions of higher learning. Several universi-
ties have formal coursework in information security. For people who are interested in researching formal information
security programs, resources are available, such as the DHS/NSA-designated National Centers of Academic Excellence
program (see [Link]/NIETP/[Link]). This program identifies universities that have had their coursework
and practices in information security reviewed and found to meet national standards. Other local resources can also
provide information on security education, such as Kennesaw State University’s Institute for Cybersecurity Workforce
Development ([Link]
106 Principles of Information Security
Security Training
Security training provides employees with detailed information and hands-on instruction to prepare them to perform
their duties securely. Management of information security can develop customized in-house training or outsource the
training program.
Alternatives to formal training programs are industry training conferences and programs offered through profes-
sional agencies such as SANS ([Link]), (ISC)2 ([Link]), and ISSA ([Link]). All of these agencies are
described in other modules. Many of these programs are too technical for the average employee, but they may be ideal
for the continuing education requirements of information security professionals.
A new venue for security training for both security professionals and the average end user is Massive Open Online
Courses (MOOCs), which are available from a number of vendors, including Coursera ([Link]). Many of
these courses are free to enroll in, and a certificate of completion is provided upon payment of a nominal fee. The
list of available topics ranges from the traditional academic introduction to security to technical topics and general
information.
Several resources for conducting SETA programs offer assistance in the form of sample topics and structures for
security classes. For organizations, the Computer Security Resource Center at NIST provides several useful documents
free of charge in its special publications area ([Link]
Security Awareness
A security awareness program is one of the least frequently implemented but most beneficial programs in an
organization. A security awareness program is designed to keep information security at the forefront of users’
minds. These programs don’t have to be complicated or expensive. Good programs can include newsletters, security
posters (see Figure 3-8 for an example), videos, bulletin boards, flyers, and trinkets. Trinkets can include security
slogans printed on mouse pads, coffee cups, T-shirts, pens, or any object frequently used during the workday that
reminds employees of security. In addition, a good security awareness program requires a dedicated person who is
willing to invest time and effort to promoting the program, and a champion willing to provide the needed financial
support.
The security newsletter is the most cost-effective method of disseminating security information and news to
employees. Newsletters can be distributed via hard copy, e-mail, or intranet. Topics can include new threats to the
organization’s information assets, the schedule for upcoming security classes, and the addition of new security
personnel. The goal is to keep the idea of information security in users’ minds and to stimulate users to care about
security. If a security awareness program is not actively implemented, employees may begin to neglect security matters,
and the risk of employee accidents and failures is likely to increase.
ISO/IEC 27002:2013 gives guidelines for organizational information security standards and information security
management practices, including the selection, implementation, and management of controls, taking into
consideration the organization’s information security risk environment(s).
1. Select controls within the process of implementing an information security management system based on
ISO/IEC 27001;
2. Implement commonly accepted information security controls;
3. Develop their own information security management guidelines.19
108 Principles of Information Security
ISO/IEC 27002:2013 is focused on a broad overview of the various areas of security. It provides information
on 14 security control clauses and addresses 35 control objectives and more than 110 individual controls. Its compan-
ion document, ISO/IEC 27001:2018, provides information for how to implement ISO/IEC 27002 and set up an information
security management system (ISMS). ISO/IEC 27001’s primary purpose is to be used as a standard so organizations
can adopt it to obtain certification and build an information security program; ISO 27001 serves better as an assessment
tool than as an implementation framework. ISO 27002 is for organizations that want information about implementing
security controls; it is not a standard used for certification. Figure 3-9 illustrates the ISO 27001 process.
In the United Kingdom, correct implementation of both volumes of these standards had to be determined by a
BS7799-certified evaluator before organizations could obtain ISMS certification and accreditation. When the standard
first came out, several countries, including the United States, Germany, and Japan, refused to adopt it, claiming that
it had fundamental problems:
• The global information security community had not defined any justification for a code of practice identified
in ISO/IEC 17799.
• The standard lacked the measurement precision associated with a technical standard.
• There was no reason to believe that ISO/IEC 17799 was more useful than any other approach.
• It was not as complete as other frameworks.
• The standard was hurriedly prepared given the tremendous impact its adoption could have on industry infor-
mation security controls.21
The ISO/IEC 27000 series is becoming increasingly important in the field, especially among global organizations.
Many certification bodies and corporate organizations are complying with it or will someday be expected to comply
with it.
Module 3 Information Security Management 109
Step Deliverables
Obtain management support
Project plan (optional)
Establish the project (optional)
Budget: Human Resources plan
List of interested parties, legal,
Identify requirements regulatory, and contractual
requirements
Information security policy and
Define scope, management
scope document information
intention responsibilities
Communication with interested parties and records of communication security objectives
Procedures for document
Implement support procedures control, internal audit,
Source: 27001 Academy: ISO 27001 and ISO 22301 Online Consultation Center.
For more details on current and proposed ISO/IEC 27000 series documents, visit the ISO 27001Security Web site.
i Gary Hinson, author/owner of the site, reports that the ISO 27000 suite has more than 70 standards planned,
with approximately 61 published. For a complete list, visit [Link]/html/[Link].
• SP 800-39: “Managing Information Security Risk: Organization, Mission, and Information System View”
• SP 800-50: “Building an Information Technology Security Awareness and Training Program”
• SP 800-55, Rev. 1: “Performance Measurement Guide for Information Security”
• SP 800-100: “Information Security Handbook: A Guide for Managers”
Many of these documents have been referenced elsewhere in this book as sources of information for the manage-
ment of security. The following sections examine select documents in this series as they apply to the blueprint for
information security.
NIST SP 800-12
SP 800-12, Rev. 1, “An Introduction to Information Security,” is an excellent reference and guide for the security manager
or administrator in the routine management of information security. It provides little guidance, however, for the design
and implementation of new security systems, and therefore should be used only as a precursor to understanding an
information security blueprint.
NIST SP 800-14
SP 800-14, “Generally Accepted Principles and Practices for Securing Information Technology Systems,” provides best
practices and security principles that can direct the security team in the development of a security blueprint. Even
though this legacy publication has been “retired,” there is not yet a replacement document in the NIST SP series that
provides a better basic grounding in information security. In addition to detailing security best practices across the
spectrum of security areas, it provides philosophical principles that the security team should integrate into the entire
information security process:
• Security supports the mission of the organization—Failure to develop an information security system based
on the organization’s mission, vision, and culture guarantees the failure of the information security program.
• Security is an integral element of sound management—Effective management includes planning, organizing, lead-
ing, and controlling. Security enhances management functions by providing input during the planning process
for organizational initiatives. Information security controls support sound management via the enforcement
of managerial and security policies.
• Security should be cost-effective—The costs of information security should be considered part of the cost of
doing business, much like the costs of computers, networks, and voice communications systems. Security
is not a profit-generating area of the organization and may not lead to competitive advantages. Information
security should justify its own costs. The use of security measures that do not justify their cost must have a
strong business justification, such as a legal requirement.
• Systems owners have security responsibilities outside their own organizations—Whenever systems store and use
information from customers, patients, clients, partners, or others, the security of this information becomes
the responsibility of the systems’ owners. These owners are expected to diligently work with each other to
assure the confidentiality, integrity, and availability of the entire value chain of their interconnected systems.
• Security responsibilities and accountability should be made explicit—Policy documents should clearly identify
the security responsibilities of users, administrators, and managers. To be legally binding, the policies must
be documented, disseminated, read, understood, and agreed to by all involved members of the organization.
As noted in Module 6, ignorance of the law is no excuse, but ignorance of policy is. Organizations should also
provide information about relevant laws in issue-specific security policies.
• Security requires a comprehensive and integrated approach—Security personnel alone cannot effectively imple-
ment security. As emphasized throughout this textbook, security is everyone’s responsibility. The three commu-
nities of interest—information technology management and professionals; information security management
and professionals; and users, managers, administrators, and other stakeholders—should participate in the
process of developing a comprehensive information security program.
• Security should be periodically reassessed—Information security that is implemented and then ignored is con-
sidered negligent because the organization has not demonstrated due diligence. Security is an ongoing pro-
cess. To be effective against a constantly shifting set of threats and a changing user base, the security process
must be periodically repeated. Continuous analyses of threats, assets, and controls must be conducted and
new blueprints developed. Only thorough preparation, design, implementation, vigilance, and ongoing main-
tenance can secure the organization’s information assets.
Module 3 Information Security Management 111
• Security is constrained by societal factors—Several factors influence the implementation and maintenance of
security controls and safeguards, including legal demands, shareholder requirements, and even business
practices. For example, security professionals generally prefer to isolate information assets from the Internet,
which is the leading avenue of threats to the assets, but the business requirements of the organization may
preclude this control measure.
• Promotes the concept of near real-time risk management and ongoing information system authorization through the
implementation of robust continuous monitoring
• Encourages the use of automation to provide senior leaders with necessary information to make cost-effective, risk-
based decisions about information systems that support an organization’s core missions and business functions
• Integrates information security into the enterprise architecture and system development life cycle
• Emphasizes the selection, implementation, assessment, and monitoring of security controls and the authorization of
information systems
• Links risk management processes at the information system level to risk management processes at the organization
level through a risk executive function
• Establishes responsibility and accountability for security controls deployed within an organization’s information
systems and inherited by those systems (i.e., common controls).23
The NIST Risk Management Framework is discussed in detail in Module 4, “Risk Management.”
The intent of the framework is to allow organizations to: “1) Describe their current cybersecurity posture;
2) Describe their target state for cybersecurity; 3) Identify and prioritize opportunities for improvement within the
context of a continuous and repeatable process; 4) Assess progress toward the target state; and 5) Communicate among
internal and external stakeholders about cybersecurity risk.”25
The NIST framework consists of three fundamental components:
• The framework core—This is a set of information security activities an organization is expected to perform, as
well as their desired results. These core activities are as follows:
❍ “Identify—Develop the organizational understanding to manage cybersecurity risk to systems, assets, data,
and capabilities.
❍ Protect—Develop and implement the appropriate safeguards to ensure delivery of critical infrastructure services.
❍ Detect—Develop and implement the appropriate activities to identify the occurrence of a cybersecurity event.
❍ Respond—Develop and implement the appropriate activities to take action regarding a detected cybersecu-
rity event.
❍ Recover—Develop and implement the appropriate activities to maintain plans for resilience and to restore
agement practices, and have just begun their formal security programs, so security is not fully established
across the organization.
❍ Tier 3: Repeatable—Organizations in this category not only have risk management practices formally
established, they have documented policy implemented. The organization has begun a repeatable security
program to improve its approach to information protection and proactively manage risk to information assets.
❍ Tier 4: Adaptive—The most mature organization falls into this tier. The organization not only has well-estab-
lished risk management and security programs, it can quickly adapt to new environments and threats. The
organization is experienced at managing risk and responding to threats and has integrated security com-
pletely into its culture.
• The framework profile—Organizations are expected to identify which tier their security programs most closely
match and then use corresponding recommendations within the framework to improve their programs. This
framework profile is then used to perform a gap analysis—comparing the current state of information security
and risk management to a desired state, identifying the difference, and developing a plan to move the organi-
zation toward the desired state. This approach is identical to the approaches outlined elsewhere in this text.
Using the materials provided in the NIST framework, organizations are encouraged to follow a seven-step approach
to implementing or improving their risk management and information security programs:
Step 1: Prioritize and scope—The organization identifies its business/mission objectives and high-level
organizational priorities. With this information, the organization makes strategic decisions regarding
cybersecurity implementations and determines the scope of systems and assets that support the
selected business line or process.
Step 2: Orient—Once the scope of the cybersecurity program has been determined for the business line or
process, the organization identifies related systems and assets, regulatory requirements, and overall risk
approach. The organization then identifies threats to, and vulnerabilities of, those systems and assets.
Step 3: Create a current profile—The organization develops a current profile by indicating which
category and subcategory outcomes from the framework core are currently being achieved.
Step 4: Conduct a risk assessment—This assessment could be guided by the organization’s overall risk
management process or previous risk assessment activities. The organization analyzes the operational
environment in order to discern the likelihood of a cybersecurity event and the impact that the event
could have on the organization.
Module 3 Information Security Management 113
Step 5: Create a target profile—The organization creates a target profile that focuses on the
assessment of the framework categories and subcategories describing the organization’s desired
cybersecurity outcomes.
Step 6: Determine, analyze, and prioritize gaps—The organization compares the current profile and the
target profile to determine gaps. Next it creates a prioritized action plan to address those gaps that draws
upon mission drivers, a cost-benefit analysis, and understanding of risk to achieve the outcomes in the target
profile. The organization then determines resources necessary to address the gaps.
Step 7: Implement action plan—The organization determines which actions to take in regards to the
gaps, if any, identified in the previous step. It then monitors its current cybersecurity practices against
the target profile.26
As you will learn in Module 11 while studying the SDLC waterfall methodology, the preceding steps are designed
to be an iterative process that gradually moves the organization closer to a Tier 4 security level and results in a better
approach to risk management and information protection.
NIST also provides a “Roadmap for Improving Critical Infrastructure Cybersecurity,”27 which provides supplemental
guidance for the framework and insights into its future development and refinement as an evolutionary, living document.
i For more information on the NIST Cybersecurity Framework, visit the NIST Web site at [Link]/cyberframework.
Spheres of Security
The spheres of security, shown in Figure 3-10, are the foundation of the security framework. Generally speaking, the
spheres of security illustrate how information is under attack from a variety of sources. The right side of Figure 3-10
illustrates the ways in which internal users access information. For example, users can access hard copies of docu-
ments and information directly. Information, as the most important asset in this model, is at the center of the sphere.
Information is always at risk from attacks whenever it is accessible by people or computer systems. Networks and
the Internet are indirect threats, as exemplified by the fact that a person attempting to access information from the
Internet must traverse local networks.
The left side of Figure 3-10 illustrates that a layer of protection must exist between each layer of the sphere of use.
For example, “Policy and law” and “Education and training” are protections placed between people and the information.
Controls are also implemented between systems and the information, between networks and the computer systems, and
between the Internet and internal networks. This reinforces the concept of defense in depth. A variety of controls can
114 Principles of Information Security
Patches
and upgrades
Monitoring
systems Education,
Redundancy Firewalls and
Security planning training, and
proxy servers
(IR, DR, BC, CM) awareness
Encryption
Backups
Employees,
Information Information contractors,
and
trusted
partners
be used to protect the information. The items of control shown in the figure are not intended to be comprehensive, but
they illustrate some of the safeguards that can protect the systems closer to the center of the sphere. Because people
can directly access each ring as well as the information at the core of the model, the side of the sphere of protection
that attempts to control access by relying on people requires a different approach to security than the side that uses
technology. The members of the organization must become a safeguard that is effectively trained, implemented, and
maintained, or they too will present a threat to the information.
Information security is designed and implemented in three layers: policies,
managerial controls people (education, training, and awareness programs), and technology. These layers
Information security safeguards are commonly referred to as PPT. Each layer contains controls and safeguards to
that focus on administrative plan- protect the information and information system assets that the organization values.
ning, organizing, leading, and But, before any technical controls or other safeguards can be implemented, the
controlling, and that are designed
by strategic planners and imple- policies that define the management philosophies behind the security process must
mented by the organization’s secu- be in place.
rity administration; they include
governance and risk management. Levels of Controls
Information security safeguards provide three levels of control: managerial,
operational controls operational, and technical. Managerial controls set the direction and scope of the
Information security safeguards security process and provide detailed instructions for its conduct. In addition, these
focusing on lower-level planning controls address the design and implementation of the security planning process and
that deals with the functionality
security program management. They also address risk management and security
of the organization’s security; they
include disaster recovery planning, control reviews (as described in Module 4), describe the necessity and scope of legal
incident response planning, and compliance, and set guidelines for the maintenance of the entire security life cycle.
SETA programs.
Operational controls address personnel security, physical security, and the
protection of production inputs and outputs. In addition, operational controls guide
technical controls the development of education, training, and awareness programs for users, admin-
Information security safeguards istrators, and management. Finally, they address hardware and software systems
that focus on the application of maintenance and the integrity of data.
modern technologies, systems,
Technical controls are the tactical and technical implementations of security in
and processes to protect informa-
tion assets; they include firewalls, the organization. While operational controls address specific operating issues, such
virtual private networks, and IDPSs. as developing and integrating controls into the business functions, technical controls
Module 3 Information Security Management 115
include logical access controls, such as identification, authentication, authorization, defense in depth
accountability (including audit trails), cryptography, and the classification of assets A strategy for the protection of
and users. information assets that uses mul-
tiple layers and different types of
Defense in Depth controls to provide optimal protec-
tion; typically, implementation of
A basic tenet of security architectures is the layered implementation of security. many different types of controls.
To achieve defense in depth, an organization must establish multiple layers of
security controls and safeguards, which can be organized into policy, training and redundancy
education, and technologies, as shown in the CNSS model presented in Module 1. The use of multiple types and
While policy itself may not prevent attacks, it certainly prepares the organization instances of technology that pre-
to handle them; when coupled with other layers, policy can deter attacks. For vent the failure of one system from
compromising the security of infor-
example, the layer of training and education can help defend against attacks enabled mation; typically, multiple instances
by employee ignorance and social engineering. Technology is also implemented of the same type of control.
in layers, with detection equipment working in tandem with reaction technology
behind access control mechanisms. Redundancy can be implemented at several security perimeter
points throughout the security architecture, such as in firewalls, proxy servers, and The boundary in the network within
access controls. Figure 3-11 illustrates the concept of building controls in multiple which an organization attempts
and sometimes redundant layers. The figure shows firewalls and prevention IDPSs to maintain security controls for
securing information from threats
that use both packet-level rules (shown as the packet header in the diagram) and
from untrusted network areas.
content analysis (shown as a database icon with the caption 0100101011). More
information on firewalls and intrusion detection systems is presented in Modules 8
and 9, respectively.
Effective
information
security policy
Trusted network
Internal
External filtering router and
filtering router VPN concentrator
Untrusted
network
Packet header
0100101011
Security Perimeter
A perimeter is a boundary of an area. A security perimeter is the border of security that protects all internal systems
from outside threats, as pictured in Figure 3-12. Unfortunately, the perimeter does not protect against internal
attacks from employee threats or on-site physical threats. In addition, the emergence of mobile computing devices,
telecommuting, and cloud-based functionality has made the definition and defense of the perimeter increasingly
more difficult. This has led some security experts to declare the security perimeter extinct and call for an increased
focus on improved system-level security and active policing of networked assets. An organization can have both an
116 Principles of Information Security
Firewall
Demilitarized zone
Various firewalls and (DMZ)
proxy servers
Se
cur
ity
pe Trusted network
rim
ete
r
Untrusted High-level
network security domain
External Internal
filtering router filtering router
security domain electronic security perimeter, usually at the exterior network or Internet connection,
An area of trust within which infor-
and a physical security perimeter, usually at the entrance to the organization’s
mation assets share the same level offices. Both require perimeter security. Security perimeters can effectively be
of protection; communication implemented as multiple technologies that segregate the protected information
between these trust areas requires
from potential attackers. Within security perimeters, the organization can establish
evaluation of communications
traffic. security domains, each with differing levels of security, between which traffic must
be screened. The assumption is that if people have access to one system within a
security domain, they have authorized access to all systems within that domain. The
security perimeter is an essential element of the overall security framework, and its implementation details are the core
of the completed security blueprint. The key components of the security perimeter are firewalls, DMZs (demilitarized
zones), proxy servers, and IDPSs. You will learn more about information security technologies in Modules 8, 9, and 10.
Many security experts argue that the security perimeter is dead. With the dramatic growth in popularity of cloud-
based computing and data storage, and the continued use of mobile computing devices, they argue that there is no
“inside” or “outside” to organizations’ networks anymore. Whether this is true is the subject of much debate. With the
extensive use of cloud-based services to deliver key systems capability, including security-related functions, there is
a growing movement toward realizing that a security perimeter is the entirety of an organization’s network presence,
anywhere and everywhere the company’s data is, and that the use of defense in depth is still a valid approach to pro-
tecting it. Whether you subscribe to the “perimeter is dead” philosophy or not, the responsibility for protecting the
organization’s data using every available resource is still alive and well.
Closing Scenario
Janet stood up from the conference table and left the room.
The meeting had not lasted long, considering how significant its impact would be on Janet’s life. Two officers from the cor-
porate security team waited in the hallway to walk her to her office and collect her personal possessions, which were already
in a box at her administrative assistant’s desk. Her access card, phone, tablet, and laptop were already turned in, and every
password she had ever used at SLS had been deactivated.
She was not looking forward to explaining this to her family.
Module 3 Information Security Management 117
Discussion Questions
1. Does this application of policy seem harsh to you? What alternatives might be implemented in policy to make
it enforceable and perhaps less stringent than in this example?
2. Are there other punishments that might be enacted for situations like this? How might you propose structur-
ing the policy to clarify what levels of punishment are appropriate?
Selected Readings
Many excellent sources of additional information are available in the area of information security. The following can add to
your understanding of this module’s content:
• “Information Security Governance: Guidance for Boards of Directors and Executive Management,” available by search-
ing at [Link].
• “Information Security Governance: A Call to Action,” available from [Link]/Documents/Governance/InfoSec-
Gov4_04.pdf.
• Information Security Policies Made Easy, Version 12, by Charles Cresson Wood and Dave Lineman. 2012. Information
Shield.
• Management of Information Security, by Michael E. Whitman and Herbert J. Mattord. 2019. Cengage Learning.
• Principles of Incident Response and Disaster Recovery, by Michael E. Whitman and Herbert J. Mattord. 2020. Cengage
Learning.
118 Principles of Information Security
Module Summary
• Information security governance is the application of the principles of corporate governance to the informa-
tion security function. These principles include executive management’s responsibility to provide strategic
direction, ensure the accomplishment of objectives, oversee that risks are appropriately managed, and validate
responsible resource use.
• Management must use policies as the basis for all information security planning, design, and deployment.
Policies direct how issues should be addressed and technologies should be used.
• Standards are more detailed than policies and describe the steps that must be taken to conform to policies.
• Management must define three types of security policies: general or security program policies, issue-specific
security policies, and systems-specific security policies.
• The enterprise information security policy (EISP) should be a driving force in the planning and governance
activities of the organization as a whole.
• Information security policy is best disseminated in a comprehensive security education, training, and aware-
ness (SETA) program. A security awareness program is one of the least frequently implemented but most
beneficial programs in an organization. A security awareness program is designed to keep information security
at the forefront of users’ minds.
• Several published information security frameworks by government organizations, private organizations, and
professional societies supply information on best practices for their members.
• One of the foundations of security architectures is the layered implementation of security. This layered
approach is referred to as defense in depth.
Review Questions
1. How do the InfoSec management team’s goals and What is information security governance? Who in
objectives differ from those of the IT and general the organization should plan for it?
management communities? 12. Where can a security administrator find informa-
2. What is included in the InfoSec planning model? tion on established security frameworks?
3. List and briefly describe the general categories of 13. What is the ISO 27000 series of standards? Which
information security policy. individual standards make up the series?
4. Briefly describe strategic planning. 14. What documents are available from the NIST
5. List and briefly describe the levels of planning. Computer Security Resource Center (CSRC),
6. What is governance in the context of information and how can they support the development of a
security management? security framework?
7. What are the differences between a policy, a 15. What Web resources can aid an organization in
standard, and a practice? Where would each be developing best practices as part of a security
used? framework?
8. What is an EISP, and what purpose does it serve? 16. Briefly describe management, operational, and
9. Who is ultimately responsible for managing technical controls, and explain when each would be
a technology? Who is responsible for applied as part of a security framework.
enforcing policy that affects the use of a 17. What is defense in depth?
technology? 18. Define and briefly explain the SETA program and
10. What is needed for an information security policy what it is used for.
to remain viable? 19. What is the purpose of the SETA program?
11. How can a security framework assist in the design 20. What is security training?
and implementation of a security infrastructure? 21. What is a security awareness program?
Module 3 Information Security Management 119
Exercises
1. Search the Web for examples of issue-specific security policies. What types of policies can you find? Using
the format provided in this module, draft a simple issue-specific policy that outlines fair and responsible use
of computers at your college, based on the rules and regulations of your institution. Does your school have
a similar policy? Does it contain all the elements listed in the text?
2. Using a graphics program, design several security awareness posters on the following themes: updating
antivirus signatures, protecting sensitive information, watching out for e-mail viruses, prohibiting the per-
sonal use of company equipment, changing and protecting passwords, avoiding social engineering, and pro-
tecting software copyrights. What other themes can you imagine?
3. Search the Web for security education and training programs in your area. Keep a list and see which pro-
gram category has the most examples. See if you can determine the costs associated with each example.
Which do you think would be more cost-effective in terms of both time and money?
References
1. Corporate Governance Task Force. “Information Security Governance: A Call to Action.” National Cyber
Security Partnership, 2004.
2. Mahncke, R. “The Applicability of ISO/IEC 27014:2013 for Use Within General Medical Practice.” Australian
eHealth Informatics and Security Conference. December 2–4, 2013, Edith Cowan University, Perth, Western
Australia. Accessed August 25, 2020, from [Link]
3. International Organization for Standardization. ISO/IEC 27014, “Information Technology—Security
Techniques—Governance of Information Security.” Accessed August 25, 2020, from [Link]/obp/
ui/#iso:std:iso-iec:27014:ed-1:v1:en.
4. Mahncke, R. “The Applicability of ISO/IEC 27014:2013 for Use Within General Medical Practice.” Australian
eHealth Informatics and Security Conference. December 2–4, 2013, Edith Cowan University, Perth, Western
Australia. Accessed August 25, 2020, from [Link]
5. “Information Security Governance: A Call to Action,” 2nd ed. 2006. Rolling Meadows, IL: IT Governance
Institute.
6. Information Technology Governance Institute (ITGI). “Information Security Governance: Guidance for
Information Security Managers.” Accessed October 11, 2016, from [Link].
7. Wood, Charles Cresson. “Integrated Approach Includes Information Security.” Security 37, no. 2 (February
2000): 43–44.
8. US-CERT. “Security Recommendations to Prevent Cyber Intrusions.” Accessed August 24, 2020, from
[Link]
9. Nieles, M., Dempsey, K., and Pillitteri, V. SP 800-12, Rev. 1, “An Introduction to Information Security”
(Draft). National Institute of Standards and Technology. Accessed August 25, 2020, from [Link]
gov/CSRC/media/Publications/sp/800-12/rev-1/draft/documents/sp800_12_r1_draft.pdf.
10. Derived from several sources, the most notable being The Washington University in St. Louis, Office of
Information Security. Accessed August 24, 2020, from [Link]
11. Whitman, Michael E., Townsend, Anthony M., and Aalberts, Robert J. “Considerations for an Effective
Telecommunications Use Policy.” Communications of the ACM 42, no. 6 (June 1999): 101–109.
12. Ibid.
120 Principles of Information Security
13. Macrotrends. “U.S. Literacy Rate 1990-2020.” Accessed August 25, 2020, from [Link]/
countries/USA/united-states/literacy-rate.
14. Zeigler, K., and Camarota, S. “67.3 Million in the United States Spoke a Foreign Language at
Home in 2018.” Center for Immigration Studies. Accessed August 25, 2020, from [Link]
Report/673-Million-United-States-Spoke-Foreign-Language-Home-2018.
15. Whitman, Michael E. “Security Policy: From Design to Maintenance.” Information Security Policies and
Strategies—An Advances in MIS Monograph. Goodman, S., Straub, D., and Zwass, V. (eds). 2008. Armonk
NY: M. E. Sharp, Inc.
16. Ibid.
17. Nieles, M., Dempsey, K., and Pillitteri, V. SP 800-12, Rev. 1, “An Introduction to Information Security.”
National Institute of Standards and Technology. Accessed August 25, 2020, from [Link]
publications/detail/sp/800-12/rev-1/final.
18. Ibid.
19. ISO. “Abstract.” Accessed August 25, 2020, from [Link]/standard/[Link].
20. Compiled from a number of sources, including “ISO/IEC 27002:2013 Information Technology—Security
Techniques—Code of Practice for Information Security Controls.” Accessed August 25, 2020, from
[Link]/html/[Link]. Also, “Introduction to ISO 27002.” Accessed August 25, 2020,
from [Link]/[Link].
21. National Institute of Standards and Technology. “Information Security Management, Code of Practice for
Information Security Management.” ISO/IEC 17799. December 6, 2001. Geneva, Switzerland.
22. Adapted from diagram of ISO 27001:2013 implementation process. Accessed August 25, 2020, from
[Link]
23. National Institute of Standards and Technology. SP 800-37, Rev. 2, “Risk Management Framework for
Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy.” Accessed
August 26, 2020, from [Link]
24. National Institute of Standards and Technology. “Framework for Improving Critical Infrastructure
Cybersecurity,” version 1.0. February 12, 2014. Accessed August 26, 2020, from [Link]/
cyberframework.
25. Ibid.
26. Ibid.
27. National Institute of Standards and Technology. “Roadmap for Improving Critical Infrastructure
Cybersecurity,” version 1.1. April 25, 2019. Accessed August 26, 2020, from [Link]/system/files/
documents/2019/04/25/[Link].