0% found this document useful (0 votes)
12 views40 pages

Module 3 - Information Security Management

This document outlines the key functions of information security management, including governance, policy development, and planning. It emphasizes the importance of aligning information security strategies with organizational goals and the roles of senior management in overseeing these efforts. Additionally, it discusses the need for effective communication and training within the organization to ensure a robust information security program.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views40 pages

Module 3 - Information Security Management

This document outlines the key functions of information security management, including governance, policy development, and planning. It emphasizes the importance of aligning information security strategies with organizational goals and the roles of senior management in overseeing these efforts. Additionally, it discusses the need for effective communication and training within the organization to ensure a robust information security program.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

MODULE 3

Information Security
Management
Upon completion of this material, you should be able to: Begin with the end in
1 Describe the different management functions with respect to information security mind.
— Stephen Covey, Author of
2 Define information security governance and list the expectations of the organiza-
Seven Habits of Highly
tion’s senior management with respect to it Effective People

3 Describe management’s role in the development, maintenance, and enforcement


of information security policy, standards, practices, procedures, and guidelines
4 List the elements in an effective security education, training, and awareness
program and describe a methodology for effectively implementing security policy
in the organization
5 Explain what an information security blueprint is, identify its major components,
and explain how it supports the information security program

Opening Scenario
Charlie had a problem. Well, to be precise, Janet Kinneck had a problem, and now Charlie had to deal with it.
Janet, the vice president of social media market development in the SLS Marketing unit, had appeared on the monthly
abuse report. Charlie had started having the security operations team prepare this report, based on the network activity for
the prior month. All SLS employees consented to this monitoring whenever they used the company’s network.
SLS had a pretty liberal policy in place that described how and when employees could use company computers and
networks for their own personal reasons. Charlie had convinced CEO Fred Chin and the other senior executives that employees
had lives that filtered over into the workplace and that the minor costs of the company network’s incidental use for personal
matters, within certain boundaries, were well worth the improved productivity that resulted. It was those “certain boundaries”
that they were dealing with now.
Charlie looked at the report and the data it contained once more and picked up his phone to call Gladys Williams, the CIO.
He had considered whether this meeting should involve Fred, but he decided it fit better with Gladys’ role. She could always
decide to bring Fred in if she determined that his presence was needed.
Gladys picked up, saying, “Hi, Charlie, what’s up?”
82 Principles of Information Security

He replied, “Hey, Gladys, we have an issue with that new monthly abuse report we are implementing.” Gladys knew the
report, as she had helped in its creation. She knew what was coming next because she was to be informed when employees
above a specific rank were involved.
Charlie continued, “Well, anyway, it looks like we have an issue with Janet Kinneck in Marketing. Near as I can tell without
a forensic examination of her computer, she’s running a commercial sports gaming league out of her office on the sixth floor.”
Gladys thought for a second and replied, “That doesn’t sound like an acceptable use to me.”

Introduction To The Management Of Information


Security
An organization’s information security effort succeeds only when it operates in conjunction with the organization’s
information security policy. An information security program begins with policy, standards, and practices, which are
the foundation for the information security program and its blueprint. The creation and maintenance of these elements
require coordinated planning. The role of planning in modern organizations is hard to overemphasize. All but the small-
est organizations engage in some planning, from strategic planning to manage the future direction of the organization
to the operational day-to-day planning to control the use and allocation of resources.
As part of the organization’s management team, the InfoSec management team operates like all other management
units. However, the InfoSec management team’s goals and objectives differ from those of the IT and general management
communities in that the InfoSec management team is focused on the secure operation of the organization. In fact, some
of the InfoSec management team’s goals and objectives may be contrary to or require resolution with the goals of the
IT management team, as the primary focus of the IT group is to ensure the effective and efficient processing of information,
whereas the primary focus of the InfoSec group is to ensure the confidentiality, integrity, and availability of information.
Security, by its very nature, will slow down the information flow into, through, and out of an organization as infor-
mation is validated, verified, and assessed against security criteria. Because the chief information security officer
(CISO) in charge of the security management team typically reports directly to the chief information officer (CIO), who
is responsible for the IT function, issues and prioritization conflicts can arise unless upper management intervenes.
Because InfoSec management oversees a specialized program, certain aspects of its managerial responsibility are
unique. These unique functions, which are known as “the six Ps” (planning, policy, programs, protection, people, and
project management), are discussed throughout this book and briefly described in the following sections.

Planning
Planning in InfoSec management is an extension of the basic planning mentioned later in this module. Included in the
InfoSec planning model are activities necessary to support the design, creation, and implementation of InfoSec strat-
egies within the planning environments of all organizational units, including IT. Because the InfoSec strategic plans
must support not only the IT department’s use and protection of information assets but those of the entire organiza-
tion, it is imperative that the CISO work closely with all senior managers in developing InfoSec strategy. The business
strategy is translated into the IT strategy. The strategies of other business units and the IT strategy are then used to
develop the InfoSec strategy. Just as the CIO uses the IT objectives gleaned from the business unit plans to create the
organization’s IT strategy, the CISO develops InfoSec objectives from the IT and other business units to create the
organization’s InfoSec strategy.
The IT strategy and that of the other business units provides critical information used for InfoSec planning as the
CISO gets involved with the CIO and other executives to develop the strategy for the next level down. The CISO then
works with the appropriate security managers to develop operational security plans. These security managers con-
sult with security technicians to develop tactical security plans. Each of these plans is usually coordinated across the
business and IT functions of the enterprise and placed into a master schedule for implementation. The overall goal is
to create plans that support long-term achievement of the overall organizational strategy. If all goes as expected, the
Module 3 Information Security Management 83

entire collection of tactical plans accomplishes the operational goals and the entire collection of operational goals
accomplishes the subordinate strategic goals; this helps to meet the strategic goals and objectives of the organization
as a whole.
Several types of InfoSec plans and planning functions exist to support routine operations as well as activities and
responses that are not part of the normal operating environment. Routine planning includes that for policy, personnel
issues, technology rollouts, risk management, and security programs. Plans and functions that go beyond the routine
include planning for incident response, business continuity, disaster recovery, and crisis management. Each of these
plans has unique goals and objectives, yet each can benefit from the same methodical approach. These planning areas
are discussed in detail in Module 4.
Another basic planning consideration unique to InfoSec is the location of the InfoSec department within the orga-
nization structure. This topic is discussed in Module 7.

Policy
In InfoSec, there are three general policy categories, which are discussed in greater detail later in this module:

• Enterprise information security policy (EISP)—Developed within the context of the strategic IT plan, this sets
the tone for the InfoSec department and the InfoSec climate across the organization. The CISO typically drafts
the program policy, which is usually supported and signed by the CIO or the CEO.
• Issue-specific security policies (ISSPs)—These are sets of rules that define acceptable behavior within a specific
organizational resource, such as e-mail or Internet usage.
• Systems-specific policies (SysSPs)—A merger of technical and managerial intent, SysSPs include both the
managerial guidance for the implementation of a technology as well as the technical specifications for its
configuration.

Programs
InfoSec operations that are specifically managed as separate entities are called “programs.” An example would be a
security education, training, and awareness (SETA) program or a risk management program. SETA programs provide
critical information to employees to maintain or improve their current levels of security knowledge. Risk management
programs include the identification, assessment, and control of risks to information assets. Other programs that may
emerge include a physical security program, complete with fire protection, physical access, gates, and guards. Some
organizations with specific regulations may have additional programs dedicated to client/customer privacy, awareness,
and the like. Each organization will typically have several security programs that must be managed.

Protection
The protection function is executed via a set of risk management activities, as well as protection mechanisms, tech-
nologies, and tools. Each of these mechanisms or safeguards represents some aspect of the management of specific
controls in the overall InfoSec plan.

People
People are the most critical link in the InfoSec program. This area encompasses security personnel (the professional
information security employees), the security of personnel (the protection of employees and their information), and
aspects of the SETA program mentioned earlier.

Projects
Whether an InfoSec manager is asked to roll out a new security training program or select and implement a new firewall,
it is important that the process be managed as a project. The final element for thoroughgoing InfoSec management
is the application of a project management discipline to all elements of the InfoSec program. Project management
involves identifying and controlling the resources applied to the project, as well as measuring progress and adjusting
the process as progress is made toward the goal.
84 Principles of Information Security

strategic planning
The process of defining and specifying
Information Security Planning And
the long-term direction (strategy) to
be taken by an organization, and the
Governance
allocation and acquisition of resources
needed to pursue this effort. Strategic planning sets the long-term direction to be taken by the organization and
each of its component parts. Strategic planning should guide organizational efforts
goals and focus resources toward specific, clearly defined goals. After an organization
A term sometimes used synony- develops a general strategy, it generates an overall strategic plan by extending
mously with objectives; the desired
end of a planning cycle.
that general strategy into plans for major divisions. Each level of each division then
translates those plan objectives into more specific objectives for the level below. To
strategic plan execute this broad strategy, the executive team must first define individual respon-
The documented product of strate- sibilities. (The executive team is sometimes called the organization’s C-level, as in
gic planning; a plan for the organi- CEO, COO, CFO, CIO, and so on.)
zation’s intended strategic efforts
over the next several years.

objectives
Information Security Leadership
A term sometimes used synony- The leadership of the information security function that delivers strategic planning
mously with goals; the intermediate and corporate responsibility is best accomplished using an approach industry refers
states obtained to achieve progress
to as governance, risk management, and compliance (GRC). GRC seeks to inte-
toward a goal or goals.
grate these three previously separate responsibilities into one holistic approach that
governance, risk can provide sound executive-level strategic planning and management of the InfoSec
management, and function. The subjects themselves are neither new nor unique to InfoSec; however,
compliance (GRC) recognition of the need to integrate the three at the board or executive level is becom-
An approach to information security ing increasingly important to practitioners in the field. Note that the management
strategic guidance from a board of
directors’ or senior management
of risk is not limited to an organization’s information security. Although organiza-
perspective that seeks to integrate tions increasingly seem to manage their risk challenges with an integrated InfoSec
the three components of informa- approach focused on GRC, many types of organizations face many types of risk and
tion security governance, risk man-
have developed specific strategies to manage them.
agement, and regulatory compliance.
InfoSec objectives must be addressed at the highest levels of an organization’s
governance management team in order to be effective and offer a sustainable approach. In
The set of responsibilities and prac- organizations with formal boards of directors, the boards should be the basis for
tices exercised by the board and governance review and oversight. For organizations that have a parent organization,
executive management with the the executive management of the parent should be the basis. For organizations that
goal of providing strategic direc-
tion, ensuring that objectives are
don’t have either, this strategic oversight must stem from a formal governance
achieved, ascertaining that risks are board consisting of executive management from across the organization—usually
managed appropriately, and verify- the chief executive officer (CEO) or president and their immediate subordinate
ing that the enterprise’s resources
executives.
are used responsibly.
Just like governments, corporations and other organizations have guiding docu-
corporate governance ments—corporate charters or partnership agreements—as well as appointed or
Executive management’s respon- elected leaders or officers, and planning and operating procedures. These elements
sibility to provide strategic direc- in combination provide corporate governance.
tion, ensure the accomplishment
When security programs are designed and managed as a technical specialty in
of objectives, oversee that risks are
appropriately managed, and vali- the IT department, they are less likely to be effective. A broader view of InfoSec
date responsible resource use. encompasses all of an organization’s information assets, including IT assets. These
valuable commodities must be protected regardless of how the information is pro-
information security cessed, stored, or transmitted, and with a thorough understanding of the risks and
governance
benefits.
The application of the principles and
practices of corporate governance Each operating unit within an organization also has controlling customs, pro-
to the information security function, cesses, committees, and practices. The information security group’s leadership
emphasizing the responsibility of the monitors and manages all organizational structures and processes that safeguard
board of directors and/or senior man-
agement for the oversight of informa-
information. Information security governance then applies these principles and
tion security in the organization. management structures to the information security function.
Module 3 Information Security Management 85

According to the Corporate Governance Task Force (CGTF), the organization should engage in a core set of activi-
ties suited to its needs to guide the development and implementation of the InfoSec governance program:
• Conduct an annual InfoSec evaluation, the results of which the CEO should review with staff and then report
to the board of directors.
• Conduct periodic risk assessments of information assets as part of a risk management program.
• Implement policies and procedures based on risk assessments to secure information assets.
• Establish a security management structure to assign explicit individual roles, responsibilities, authority, and
accountability.
• Develop plans and initiate actions to provide adequate InfoSec for networks, facilities, systems, and information.
• Treat InfoSec as an integral part of the system life cycle.
• Provide InfoSec awareness, training, and education to personnel.
• Conduct periodic testing and evaluation of the effectiveness of InfoSec policies and procedures.
• Create and execute a plan for remedial action to address any InfoSec inefficiencies.
• Develop and implement incident response procedures.
• Establish plans, procedures, and tests to provide continuity of operations.
• Use security best practices guidance, such as the ISO 27000 series, to measure InfoSec performance.1
The CGTF framework defines the responsibilities of the board of directors and trustees, the senior organizational
executive (for example, the CEO), executive team members, senior managers, and all employees and users.
ISO 27014:2013 is the ISO 27000 series standard for Governance of Information Security. This remarkably short
document (11 pages) provides brief recommendations for the assessment of an information security governance pro-
gram. The standard specifies six high-level “action-oriented” information security governance principles:
1. Establish organization-wide information security.
2. Adopt a risk-based approach.
3. Set the direction of investment decisions.
4. Ensure conformance with internal and external requirements.
5. Foster a security-positive environment.
6. Review performance in relation to business outcomes.2
The standard also promotes five governance processes, which should be adopted by the organization’s executive
management and its governing board. These processes are illustrated in Figure 3-1 and described in the following list.
• Evaluate—Review the status of current and projected progress toward organizational information security
objectives and make a determination whether modifications of the program or its strategy are needed to keep
on track with strategic goals.
• Direct—The board of directors provides instruction for developing or implementing changes to the security
program. This could include modification of available resources, structure of priorities of effort, adop-
tion of policy, recommendations for the risk management program, or alteration to the organization’s risk
tolerance.
• Monitor—The review and assessment of organizational information security performance toward goals and
objectives by the governing body. Monitoring is enabled by ongoing performance measurement.
• Communicate—The interaction between the governing body and external stakeholders, where information on
organizational efforts and recommendations for change are exchanged.
• Assure—The assessment of organizational efforts by external entities like certification or accreditation groups,
regulatory agencies, auditors, and other oversight entities, in an effort to validate organizational security
governance, security programs, and strategies.3

According to the Information Technology Governance Institute (ITGI), information security governance includes all
of the accountabilities and methods undertaken by the board of directors and executive management to provide the
following:

• Strategic direction
• Establishment of objectives
86 Principles of Information Security

GOVERNING BODY

Strategy & Policy DIRECT


Stakeholders
Executive Requirements
Management
& Proposals EVALUATE COMMUNICATE
InfoSec Reports
Management

Performance MONITOR Recommendations


ASSURE
Commission

Figure 3-1 ISO/IEC 27014:2013 governance processes4

Source: R. Mahncke, Australian eHealth Informatics and Security Conference, December 2013.

• Measurement of progress toward those objectives


• Verification that risk management practices are appropriate
• Validation that the organization’s assets are used properly5
Figure 3-2 illustrates the responsibilities of various people within an organization for information security governance.

Responsibilities Functional Role Examples

Figure 3-2 Information security governance roles and responsibilities


Source: This information is derived from the Corporate Governance Task Force Report, “Information
Security Governance: A Call to Action,” April 2004, National Cyber Security Task Force.

Information Security Governance Outcomes


Effective communication among stakeholders is critical to the structures and processes used in governance at every
level, and especially in information security governance. It requires the development of constructive relationships, a
common language, and a commitment to the objectives of the organization.
Module 3 Information Security Management 87

The five goals of information security governance are as follows: tactical plan
1. Strategic alignment of information security with business strategy to support The documented product of tactical
planning; a plan for the organiza-
organizational objectives
tion’s intended tactical efforts over
2. Risk management by executing appropriate measures to manage and the next few years.
mitigate threats to information resources
3. Resource management by using information security knowledge and operational plan
infrastructure efficiently and effectively The documented product of opera-
4. Performance measurement by measuring, monitoring, and reporting tional planning; a plan for the orga-
information security governance metrics to ensure that organizational nization’s intended operational
efforts on a day-to-day basis for the
objectives are achieved next several months.
5. Value delivery by optimizing information security investments in support of
organizational objectives6
tactical planning
The actions taken by management

Planning Levels to specify the intermediate goals


and objectives of the organization
in order to obtain specified stra-
Once the organization’s overall strategic plan is translated into strategic plans
tegic goals, followed by estimates
for each major division or operation, the next step is to translate these plans into and schedules for the allocation
tactical objectives that move toward reaching specific, measurable, achievable, and of resources necessary to achieve
time-bound accomplishments. The process of strategic planning seeks to transform those goals and objectives.

broad, general, sweeping statements into more specific and applied objectives.
Strategic plans are used to create tactical plans, which in turn are used to develop operational planning
operational plans. The actions taken by management
to specify the short-term goals
Tactical planning focuses on undertakings that will be completed within one or
and objectives of the organization
two years. The process of tactical planning breaks each strategic goal into a series in order to obtain specified tacti-
of incremental objectives. Each objective in a tactical plan should be specific and cal goals, followed by estimates
should have a delivery date within a year of the plan’s start. Budgeting, resource and schedules for the allocation
of resources necessary to achieve
allocation, and personnel are critical components of the tactical plan. Tactical plans those goals and objectives.
often include project plans and resource acquisition planning documents (such as
product specifications), project budgets, project reviews, and monthly and annual
reports. The CISO and security managers use the tactical plan to organize, prioritize, and acquire resources necessary
for major projects and to provide support for the overall strategic plan.
Managers and employees use operational planning derived from tactical planning to organize the ongoing, day-
to-day performance of tasks. An operational plan includes the necessary tasks for all relevant departments as well
as communication and reporting requirements, which might include weekly meetings, progress reports, and other
associated tasks. These plans must reflect the organizational structure, with each subunit, department, or project
team conducting its own operational planning and reporting. Frequent communication and feedback from the teams
to the project managers and/or team leaders, and then up to the various management levels, will make the planning
process more manageable and successful.

Planning and the CISO


The first priority of the CISO and the information security management team is the creation of a strategic plan to
accomplish the organization’s information security objectives. While each organization may have its own format
for the design and distribution of a strategic plan, the fundamental elements of planning share characteristics
across all types of enterprises. The plan is an evolving statement of how the CISO and various elements of the
organization will implement the objectives of the enterprise information security policy (EISP), as you will learn
later in this module.
As a clearly directed strategy flows from top to bottom, a systematic approach is required to translate it into
a program that can inform and lead all members of the organization. Strategic plans formed at the highest levels of
the organization are used to create an overall corporate strategy. As lower levels of the organizational hierarchy are
involved (moving down the hierarchy), the plans from higher levels are evolved into more detailed, concrete planning.
So, higher-level plans are translated into more specific plans for intermediate layers of management. That layer of
88 Principles of Information Security

strategic planning by function (such as financial, IT, and operations strategies) is then converted into tactical planning
for supervisory managers and eventually provides direction for the operational plans undertaken by non-management
members of the organization. This multilayered approach encompasses two key objectives: general strategy and over-
all strategic planning. First, general strategy is translated into specific strategy; second, overall strategic planning is
translated into lower-level tactical and operational planning.
Information security, like information technology, must support more than its own functions. All organizational
units will use information, not just IT-based information, so the information security group must understand and
support the strategic plans of all business units. This role may sometimes conflict with that of the IT department, as
IT’s role is the efficient and effective delivery of information and information resources, while the role of information
security is the protection of all information assets.

For more information on information security planning, read NIST Special Publication (SP) 800-18, Rev. 1, which
i is available from the NIST SP Web site at [Link]

Information Security Policy, Standards, And Practices


Management from all communities of interest, including general staff, information
technology, and information security, must make policy the basis for all information
policy security planning, design, and deployment. Policies direct how issues should be
Instructions that dictate certain addressed and how technologies should be used. Policies do not specify the proper
behavior within an organization.
operation of equipment or software—this information should be placed in the standards,
procedures, and practices of users’ manuals and systems documentation. In addition,
standard
policy should never contradict law; policy must be able to stand up in court, if challenged;
A detailed statement of what must
be done to comply with policy, and policy must be properly administered through dissemination and documented
sometimes viewed as the rules gov- acceptance. Otherwise, an organization leaves itself exposed to significant liability.
erning policy compliance. Good security programs begin and end with policy. Information security is pri-
marily a management problem, not a technical one, and policy is a management tool
de facto standard that obliges personnel to function in a manner that preserves the security of informa-
A standard that has been widely
tion assets. Security policies are the least expensive control to execute but the most
adopted or accepted by a public
group rather than a formal stan- difficult to implement properly. They have the lowest cost in that their creation and
dards organization. dissemination require only the time and effort of the management team. Even if the
management team hires an outside consultant to help develop policy, the costs are
de jure standard minimal compared to those of technical controls.7
A standard that has been formally
evaluated, approved, and ratified
by a formal standards organization.
Policy as the Foundation for Planning
guidelines Policies function like laws in an organization because they dictate acceptable and
Nonmandatory recommendations unacceptable behavior there, as well as the penalties for failure to comply. Like laws,
the employee may use as a refer- policies define what is right and wrong, the penalties for violating policy, and the
ence in complying with a policy.
appeal process. Standards, on the other hand, are more detailed statements of what
must be done to comply with policy. They have the same requirements for compli-
procedures ance as policies. Standards may be informal or part of an organizational culture, as
Step-by-step instructions designed
in de facto standards. Or, standards may be published, scrutinized, and ratified by
to assist employees in following
policies, standards, and guidelines. a group, as in formal or de jure standards. Practices, procedures, and guidelines
effectively explain how to comply with policy.
practices Table 3-1 and Figure 3-3 show the relationships among policies, standards,
Examples of actions that illustrate guidelines, procedures, and practices. These relationships are further examined
compliance with policies. in the nearby feature.
Module 3 Information Security Management 89

Table 3-1 Relationship between Policies, Standards, Practices, Procedures, and Guidelines

Policy “Use strong passwords, frequently changed.”


Standard “The password must be at least 10 characters with at least one of each of these: uppercase letter,
lowercase letter, number, and special character.”
Practice “According to Passwords Today, most organizations require employees to change passwords at least
every six months.”
Procedure “In order to change your password, first click the Windows Start button; then …”
Guideline “We recommend you don’t use family or pet names, or parts of your Social Security number,
employee number, or phone number in your password.”

Policies
Sanctioned by management
Practices
Industry,
Standards
government, Detailed minimum specifications for compliance
and
regulatory
exemplars
Guidelines
Recommendations for compliance
Influence
organization
documents Procedures
Step-by-step instructions for compliance

Figure 3-3 Policies, standards, guidelines, and procedures

Policies, Practices, Standards, Guidelines, and Procedures


The relationships among these terms, even when carefully defined, sometimes confuse the reader. The following exam-
ples are provided for assistance. Note that many organizations may use the terms differently and publish documents they
identify as policy, which may be a combination of what this text defines as policy, standards, or procedures.
The initial statement of intent is the policy.

Policy: Employees must use strong passwords on their accounts. Passwords must be changed
regularly and protected against disclosure.
The standard provides specifics to help employees comply with the policy.

Standard: Passwords must be at least 10 characters long and incorporate at least one lowercase
letter, one uppercase letter, one numerical digit (0–9), and one special character permitted by our
system (&%$#@!). Passwords must be changed every 90 days and must not be written down or
stored on insecure media.
The practice identifies other reputable organizations and agencies that offer recommendations the organization
may have adopted or adapted.

Practice: US-CERT recommends the following:


• Use a minimum password length of 15 characters for administrator accounts.
• Require the use of alphanumeric passwords and symbols.
• Enable password history limits to prevent the reuse of previous passwords.
90 Principles of Information Security

• Prevent the use of personal information as passwords, such as phone numbers and dates of birth.
• Use a minimum password length of 8 characters for standard users.
• Disable local machine credential caching if not required through the use of a Group Policy Object (GPO).
• Deploy a secure password storage policy that provides password encryption.8

Guidelines provide examples and recommendations to assist users in complying with the new policy.

Guidelines: In order to create strong yet easy-to-remember passwords, consider the following
recommendations from NIST SP 800-118: “Guide to Enterprise Password Management” (draft), April 2009:
• Mnemonic method—A user selects a phrase and extracts a letter of each word in the phrase (such as the first letter or
second letter of each word), adding numbers or special characters or both.
❍ Example: “May the force be with you always, young Jedi” becomes Mtfbwya-yJ

• Altered passphrases—A user selects a phrase and alters it to form a derivation of that phrase. This method supports the
creation of long, complex passwords. Passphrases can be easy to remember due to the structure of the password: It is
usually easier for the human mind to comprehend and remember phrases within a coherent structure than a string of
random letters, numbers, and special characters.
❍ Example: Never Give Up! Never Surrender! becomes [Link]!-[Link]!

• Combining and altering words—A user can combine two or three unrelated words and change some of the letters to
numbers or special characters.
❍ Example: Jedi Tribble becomes J3d13bbl

Finally, procedures are step-by-step instructions for accomplishing the task specified in the policy.

Procedures: To change your login password on our system, perform the following steps:

1. Log in using your current (old) password.


2. On your organizational portal home page, click the [Tools] Menu option.
3. Select [Change Password].
4. Enter your old password in the first field and your new password in the second. The system will ask you to confirm
your new password to prevent you from mistyping it.
5. The system will then report that your password has been updated and ask you to log out and log back in with your
new password.

Do not write your new password down. If you own a smartphone, you may request that your
department purchase an approved password management application like eWallet for storing
passwords.

As stated earlier, many organizations combine their policy and standards in the same document and then provide direc-
tions or a Web link to a page with guidelines and procedures.

The meaning of the term security policy depends on the context in which it is used. Governmental agencies view
security policy in terms of national security and national policies to deal with foreign states. A security policy can also
communicate a credit card agency’s method for processing credit card numbers. In general, a security policy is a set
of rules that protects an organization’s assets. An information security policy provides rules for protection of the
organization’s information assets.
information security Management must define three types of security policy, according to SP 800-14
policy of the National Institute of Standards and Technology (NIST):
Written instructions provided by
management that inform employ- 1. Enterprise information security policies
ees and others in the workplace 2. Issue-specific security policies
about proper behavior regarding 3. Systems-specific security policies
the use of information and infor-
mation assets. NIST SP 800-14 will be discussed in greater detail later in this module.
Module 3 Information Security Management 91

Enterprise Information Security Policy enterprise information


security policy (EISP)
An enterprise information security policy (EISP) is also known as a general security
The high-level information security
policy, organizational security policy, IT security policy, or information security policy that sets the strategic direc-
policy. The EISP is an executive-level document, usually drafted by or in cooperation tion, scope, and tone for all of an
with the organization’s chief information officer. This policy is usually two to 10 pages organization’s security efforts; also
known as a security program policy,
long and shapes the philosophy of security in the IT environment. The EISP usually general security policy, IT security
needs to be modified only when there is a change in the strategic direction of the policy, high-level InfoSec policy, or
organization. simply an InfoSec policy.

The EISP guides the development, implementation, and management of the


security program. It sets out the requirements that must be met by the information
security blueprint. It defines the purpose, scope, constraints, and applicability of the security program. It also assigns
responsibilities for the various areas of security, including systems administration, maintenance of the information
security policies, and the practices and responsibilities of users. Finally, it addresses legal compliance. According to
NIST, the EISP typically addresses compliance in two areas:
• General compliance to ensure that an organization meets the requirements for establishing a program and
assigning responsibilities therein to various organizational components
• The use of specified penalties and disciplinary action9
When the EISP has been developed, the CISO begins forming the security team and initiating necessary changes
to the information security program.

EISP Elements
Although the specifics of EISPs vary among organizations, most EISP documents should include the following elements:
• An overview of the corporate philosophy on security
• Information on the structure of the information security organization and people who fulfill the information
security role
• Fully articulated responsibilities for security that are shared by all members of the organization (employees,
contractors, consultants, partners, and visitors)
• Fully articulated responsibilities for security that are unique to each role within the organization

The components of a good EISP are shown in Table 3-2. For examples of EISP documents and recommendations
for how to prepare them, we recommend using Information Security Policies Made Easy by Charles Cresson Wood,
published by Information Shield. While the current version is relatively expensive, prior editions are widely available
as used books and in libraries around the world.

Issue-Specific Security Policy


As an organization supports routine operations by executing various technologies issue-specific security
and processes, it must instruct employees on their proper use. In general, the issue- policy (ISSP)
specific security policy , or ISSP, (1) addresses specific areas of technology as An organizational policy that pro-
vides detailed, targeted guidance
listed here, (2) requires frequent updates, and (3) contains a statement about the
to instruct all members of the orga-
organization’s position on a specific issue.10 An ISSP may cover the following topics, nization in the use of a resource,
among others: such as one of its processes or
technologies.
• E-mail
• Use of the Internet and World Wide Web
• Specific minimum configurations of computers to defend against worms and viruses
• Prohibitions against hacking or testing organization security controls
• Home use of company-owned computer equipment
• Use of personal equipment on company networks (BYOD: bring your own device)
• Use of telecommunications technologies, such as fax and phone
• Use of photocopy equipment
92 Principles of Information Security

Table 3-2 Components of the EISP11

Component Description
Statement of Purpose Answers the question “What is this policy for?” Provides a framework that helps
the reader understand the intent of the document. Can include text such as the
following: “This document will:
• Identify the elements of a good security policy
• Explain the need for information security
• Specify the various categories of information security
• Identify the information security responsibilities and roles
• Identify appropriate levels of security through standards and guidelines
This document establishes an overarching security policy and direction for our
company. Individual departments are expected to establish standards, guidelines,
and operating procedures that adhere to and reference this policy while
addressing their specific and individual needs."
Information Security Elements Defines information security. For example:
"Protecting the confidentiality, integrity, and availability of information while in
processing, transmission, and storage, through the use of policy, education and
training, and technology …"
This section can also lay out security definitions or philosophies to clarify the policy.
Need for Information Security Provides information on the importance of information security in the
organization and the legal and ethical obligation to protect critical information
about customers, employees, and markets.
Information Security Defines the organizational structure designed to support information security
Responsibilities and Roles within the organization. Identifies categories of people with responsibility
for information security (IT department, management, users) and those
responsibilities, including maintenance of this document.
Reference to Other Information Lists other standards that influence this policy document and are influenced by it,
Standards and Guidelines perhaps including relevant federal laws, state laws, and other policies.

• Use of portable storage devices such as USB memory sticks, backpack drives, game players, music players,
and any other device capable of storing digital files
• Use of cloud-based storage services that are not self-hosted by the organization or engaged under contract;
such services include Google Drive, Dropbox, and Microsoft OneDrive
• Use of networked infrastructure devices, “intelligent assistants” such as Google Assistant and Amazon Echo,
and accompanying devices usually classified as the Internet of Things (IoT)
• Use of programmable logic controller (PLC) devices and associated control protocols with corporate data
networks and production-focused industrial networks
For examples of ISSP policies and recommendations for how to prepare them, we recommend using Information
Security Policies Made Easy by Charles Cresson Wood, published by Information Shield. The book includes a wide vari-
ety of working policy documents and can assist in defining which are needed and how to create them.
Several approaches are used to create and manage ISSPs within an organization. Three of the most common are
as follows:
• Independent ISSP documents, each tailored to a specific issue
• A single comprehensive ISSP document that covers all issues
• A modular ISSP document that unifies policy creation and administration while maintaining each specific
issue’s requirements
The independent ISSP document typically has a scattershot effect. Each department responsible for an application
of technology creates a policy governing its use, management, and control. This approach may fail to cover all neces-
sary issues and can lead to poor policy distribution, management, and enforcement.
Module 3 Information Security Management 93

The single comprehensive ISSP is centrally managed and controlled. With formal procedures for the management
of ISSPs in place, the comprehensive policy approach establishes guidelines for overall coverage of necessary issues
and clearly identifies processes for the dissemination, enforcement, and review of these guidelines. Usually, these
policies are developed by the people responsible for managing the information technology resources. Unfortunately,
these policies tend to overgeneralize the issues and skip over vulnerabilities.
The optimal balance between the independent and comprehensive ISSP is the modular ISSP. It is also centrally
managed and controlled, but it is tailored to individual technology issues. The modular approach provides a
balance between issue orientation and policy management. The policies created with this approach comprise
individual modules, each created and updated by people responsible for the issues addressed. These people report
to a central policy administration group that incorporates specific issues into an overall comprehensive policy.
Table 3-3 is an outline of a sample ISSP, which can be used as a model. An organization should start with this struc-
ture and add specific details that dictate security procedures not covered by these general guidelines.

Table 3-3 Components of an ISSP12

Components of an ISSP
1. Statement of policy
a. Scope and applicability
b. Definition of technology addressed
c. Responsibilities
2. Authorized access and usage of equipment
a. User access
b. Fair and responsible use
c. Protection of privacy
3. Prohibited use of equipment
a. Disruptive use or misuse
b. Criminal use
c. Offensive or harassing materials
d. Copyrighted, licensed, or other intellectual property
e. Other restrictions
4. Systems management
a. Management of stored materials
b. Employee monitoring
c. Virus protection
d. Physical security
e. Encryption
5. Violations of policy
a. Procedures for reporting violations
b. Penalties for violations
6. Policy review and modification
a. Scheduled review of policy procedures for modification
b. Legal disclaimers
7. Limitations of liability
a. Statements of liability
b. Other disclaimers as needed
Source: Whitman, Townsend, and Aalberts, Communications of the ACM.
94 Principles of Information Security

The components of each major category of a typical ISSP are discussed in the following sections. Even though
the details may vary from policy to policy and some sections of a modular policy may be combined, it is essential for
management to address and complete each section.

Statement of Policy
The policy should begin with a clear statement of purpose—in other words, what exactly is this policy supposed to
accomplish? Consider a policy that covers the issue of fair and responsible Internet use. The introductory section of
this policy should address the following questions: What is the scope of this policy? Who does this policy apply to?
Who is responsible and accountable for policy implementation? What technologies and issues does it address?

Authorized Access and Usage of Equipment


This section of the policy statement addresses who can use the technology governed by the policy and what it can be
used for. Remember that an organization’s information systems are its exclusive property, and users have no rights of
use. Each technology and process is provided for business operations. Use for any other purpose constitutes misuse
of equipment. This section defines “fair and responsible use” of equipment and other organizational assets and should
address key legal issues, such as protection of personal information and privacy.

Prohibited Use of Equipment


Unless a particular use is clearly prohibited, the organization cannot penalize its employees for misuse. For example,
the following can be prohibited: personal use, disruptive use or misuse, criminal use, offensive or harassing materials,
and infringement of copyrighted, licensed, or other intellectual property. As an alternative approach, sections 2 and 3
of Table 3-3 can be collapsed into a single category called “Appropriate Use.” Many organizations use such an ISSP
section to cover both categories.

Systems Management
The systems management section of the ISSP policy statement focuses on the users’ relationship to systems manage-
ment. Specific rules from management include regulating the use of e-mail, the storage of materials, the authorized
monitoring of employees, and the physical and electronic scrutiny of e-mail and other electronic documents. It is
important that all such responsibilities are assigned either to the systems administrator or the users; otherwise, both
parties may infer that the responsibility belongs to the other.

Violations of Policy
The people to whom the policy applies must understand the penalties and repercussions of violating it. Violations of
policy should carry penalties that are appropriate—neither draconian nor overly lenient. This section of the policy
statement should contain not only specific penalties for each category of violation, but instructions for how people
in the organization can report observed or suspected violations. Many people think that powerful employees in an
organization can retaliate against someone who reports violations. Allowing anonymous submissions is often the only
way to convince users to report the unauthorized activities of more influential employees.

Policy Review and Modification


Because any document is only useful if it is up to date, each policy should contain procedures and a timetable for
periodic review. As the organization’s needs and technologies change, so must the policies that govern their use.
This section should specify a methodology for reviewing and modifying the policy to ensure that users do not begin
circumventing it as it grows obsolete.

Limitations of Liability
If an employee is caught conducting illegal activities with the organization’s equipment or assets, management does
not want the organization held liable. The policy should state that if employees violate a company policy or any law
using company technologies, the company will not protect them, and the company is not liable for their actions. In
fact, many organizations assist in the prosecution of employees who violate laws when their actions violate policies.
It is assumed that such violations occur without knowledge or authorization by the organization.
Module 3 Information Security Management 95

Systems-Specific Security Policy (SysSP) systems-specific


security policies
While issue-specific policies are formalized as written documents readily identifiable (SysSPs)
as policy, systems-specific security policies (SysSPs) sometimes have a different Organizational policies that often
look. SysSPs often function as standards or procedures to be used when configur- function as standards or procedures
ing or maintaining systems. For example, a SysSP might describe the configuration to be used when configuring or
maintaining systems. SysSPs can be
and operation of a network firewall. This document could include a statement of
separated into two general groups—
managerial intent; guidance to network engineers on the selection, configuration, managerial guidance and technical
and operation of firewalls; and an access control list that defines levels of access for specifications—but may be written
as a single unified SysSP document.
each authorized user. SysSPs can be separated into two general groups, managerial
guidance SysSPs and technical specifications SysSPs, or they can be combined into
a single policy document that contains elements of both. managerial guidance
SysSP
Managerial Guidance SysSPs A policy that expresses manage-
ment’s intent for the acquisition,
A managerial guidance SysSP document is created by management to guide the implementation, configuration,
implementation and configuration of technology and to address the behavior of and management of a particular
employees in ways that support information security. For example, while the method technology, written from a business
perspective.
for configuring a firewall belongs in the technical specifications SysSP, the firewall’s
configuration must follow guidelines established by management. An organization
might not want its employees to access the Internet via the organization’s network, technical
for instance; in that case, the firewall should be configured accordingly. specifications SysSP
Firewalls are not the only technology that may require systems-specific policies. A policy that expresses technical
Any system that affects the confidentiality, integrity, or availability of information must details for the acquisition, imple-
mentation, configuration, and man-
be assessed to evaluate the trade-off between improved security and restrictions.
agement of a particular technology,
Systems-specific policies can be developed at the same time as ISSPs, or they can written from a technical perspec-
be prepared in advance of their related ISSPs. Before management can craft a policy tive; usually includes details on
informing users what they can do with certain technology and how to do it, system configuration rules, systems poli-
cies, and access control.
administrators might have to configure and operate the system. Some organizations
may prefer to develop ISSPs and SysSPs in tandem so that operational procedures
and user guidelines are created simultaneously. access control list
(ACL)
Technical Specifications SysSPs Specifications of authorization that
govern the rights and privileges of
While a manager can work with a systems administrator to create managerial policy, users to a particular information
as described in the preceding section, the systems administrator in turn might need to asset; includes user access lists,
create a policy to implement the managerial policy. Each type of equipment requires its matrices, and capabilities tables.
own set of policies, which are used to translate management’s intent for the technical
control into an enforceable technical approach. For example, an ISSP may require that
user passwords be changed quarterly; a systems administrator can implement a technical capabilities table
control within a specific application to enforce this policy. There are two general methods A lattice-based access control with
rows of attributes associated with
of implementing such technical controls: access control lists and configuration rules.
a particular subject (such as a user).
Access Control Lists An access control list (ACL) consists of details about user
access and use permissions and privileges for an organizational asset or resource, access control matrix
such as a file storage system, software component, or network communications An integration of access control
device. ACLs focus on assets and the users who can access and use them. A lists (focusing on assets) and capa-
bility tables (focusing on users) that
capabilities table is similar to an ACL, but it focuses on users, the assets they can
results in a matrix with organiza-
access, and what they can do with those assets. In some systems, capability tables tional assets listed in the column
are called user profiles or user policies. headings and users listed in the row
headings; contains ACLs in columns
These specifications frequently take the form of complex matrices rather than
for a particular device or asset and
simple lists or tables, resulting in an access control matrix that combines the infor- capability tables in rows for a par-
mation in ACLs and capability tables. ticular user.
96 Principles of Information Security

As illustrated in Figures 3-4 and 3-5, both Microsoft Windows and Linux systems translate ACLs into sets of con-
figurations that administrators use to control access to their systems.
The level of detail may differ from system to system, but in general, ACLs can restrict access for a specific user,
computer, time, or duration—even a specific file. This specificity provides powerful control to the administrator. In
general, ACLs regulate the following:

• Who can use the system


• What authorized users can access
• When authorized users can access the system
• Where authorized users can access the system

Figure 3-4 Microsoft Windows use of ACLs


Source: Microsoft.
Module 3 Information Security Management 97

1. This Linux Ubuntu system is logged in as user mouse.


2. The id command shows us which groups mouse is in. You can
see that mouse is a member of the rodents group. This group
mouse@ubuntu:~$ id mouse shares a directory for shared files called rodentfiles.
uid=1000(seccdc)
gid=1000(seccdc)
groups=1000(mouse),
27(sudo),
3. The getfacl
114(sambashare), control list (ACL).
901(rodents)

mouse@ubuntu:~$ getfacl rodentfiles


# file: rodentfiles
# owner: rat
# group: rodents 4. This directory is owned by user rat, who has Read (r), Write (w),
user::rwx and Execute (x) privileges on the directory and all files in it.
group::rwx
other::r-x

mouse@ubuntu:~$ 5. All members of the rodents group have these privileges as


well, but everyone else can only Read and Execute files in the
directory.

Figure 3-5 Linux use of ACLs


Source: Linux.

The who of ACL access may be determined by a person’s identity or membership in a group. Restricting what
authorized users are permitted to access—whether by type (printers, files, communication devices, or applications),
name, or location—is achieved by adjusting the resource privileges for a person or group to Read, Write, Create,
Modify, Delete, Compare, or Copy. To control when access is allowed, some organizations implement time-of-day and
day-of-week restrictions for certain network or system resources. To control where resources can be accessed, many
network-connected assets block remote usage and have some levels of access that are restricted to locally connected
users, such as restrictions by computer MAC address or network IP address. When these various ACL options are
applied concurrently, the organization can govern how its resources can be used.
Configuration Rule Policies Configuration rules (or policies) govern how a security configuration rules
system reacts to the data it receives. Rule-based policies are more specific to the opera- The instructions a system adminis-
tion of a system than ACLs, and they may or may not deal with users directly. Many secu- trator codes into a server, network-
ing device, or security device to
rity systems—for example, firewalls, intrusion detection and prevention systems (IDPSs), specify how it operates.
and proxy servers, all of which you will learn about in Modules 8 and 9—use specific
configuration scripts that represent the configuration rule policy to determine how the
system handles each data element they process. The examples in Figures 3-6 and 3-7 show how network security policy has
been implemented by a Palo Alto firewall’s rule set and by Ionx Verisys (File Integrity Monitoring) in a host-based IDPS rule set.

Combination SysSPs
Many organizations create a single document that combines the managerial guidance SysSP and the technical speci-
fications SysSP. While this document can be somewhat confusing to casual users, it is practical to have the guidance
from managerial and technical perspectives in a single place. If this approach is used, care should be taken to clearly
articulate the required actions. Some might consider this type of policy document a procedure, but it is actually a
hybrid that combines policy with procedural guidance to assist implementers of the system being managed. This
approach is best used by organizations that have multiple technical control systems of different types and by smaller
organizations that want to document policy and procedure in a compact format.

Developing and Implementing Effective Security Policy


How policy is developed and implemented can help or hinder its usefulness to the organization. If an organization takes
punitive action on an effective policy, the individual(s) affected may sue the organization, depending on its action in
implementing the penalties or other actions defined in the policy. Employees terminated for violating poorly designed
and implemented policies could sue their organization for wrongful termination. In general, policy is only enforceable and
legally defensible if it is properly designed, developed, and implemented using a process that assures repeatable results.
98 Principles of Information Security

Source: packet “from.” Destination: packet “to.” Action specifies whether


Zone: port of origin or destination of the packet. the packet from Source:
Address: IP address. User: predefined user groups. is allowed or dropped.

Rules 16 and 17 specify any


packet involving use of the
BitTorrent application is
automatically dropped.

Rule 22 ensures any user


in the Internal (Trusted)
network: L3-Trust is able
to access any external
Web site.

Figure 3-6 Sample Palo Alto firewall configuration rules

Source: Palo Alto Software, Inc.

Figure 3-7 Ionx Verisys (File Integrity Monitor) use of rules


Source: Ionx.
Module 3 Information Security Management 99

For policies to be effective and legally defensible, the following must be done properly:
1. Development—Policies must be written using industry-accepted practices and formally approved by
management.
2. Dissemination—Policies must be distributed using all appropriate methods.
3. Review—Policies must be readable and read by all employees.
4. Comprehension—Policies must be understood by all employees.
5. Compliance—Policies must be formally agreed to by act or affirmation.
6. Enforcement—Policies must be uniformly applied to all employees.
We will examine each of these stages in the sections that follow. Before we do, however, you should realize that
almost every organization has a set of existing policies, standards, procedures, and/or practices. This installed base
of guidance may not always have been prepared using an approach that delivers consistent or even usable results.
Most of the situations you find yourself in will involve more policy maintenance than policy development. Prior to
implementation, policy should be reviewed by the organization’s legal counsel to ensure it is acceptable within the
limits of the law and that implementation of the policy and its corresponding penalties would, in fact, be defensible in
the event of a legal dispute.

Developing Information Security Policy


It is often useful to view policy development as a three-part project. In the first part of the project, policy is designed
and written (or, in the case of an outdated policy, redesigned and rewritten). In the second part, a senior manager or
executive at the appropriate level and the organization’s legal counsel review and formally approve the document. In
the third part of the development project, management processes are established to distribute and enforce the policy
within the organization. The first part is an exercise in project management, whereas the latter two parts require adher-
ence to good business practices and legal regulation.
Writing a policy is not always as easy as it seems. However, the prudent security manager always scours available
resources (including the Web) for examples that may be adapted to the organization. Seldom will the manager find
the perfect policy, ready to be implemented. Some online vendors sell blank policies that you can customize to your
organization. In any event, it is important that the organization respect the intellectual property of others when devel-
oping policy. If parts of another organization’s policy are adapted, appropriate attribution must be made. Most policies
contain a reference section where the author may list any policies used in the development of the current document.
Even policies that are purchased from policy vendors or developed from a book on writing policies may require some
level of attribution. It is recommended that any policies adapted from outside sources are thoroughly summarized to
prevent the need for direct quotations, which can detract from the message the policy is attempting to convey—that
“our organization” wants employees to be effective and efficient without undue distractions.

Policy Distribution
While it might seem straightforward, getting the policy document into the hands of employees can require a substantial
investment by the organization to be effective. The most common alternatives are hard copy and electronic distribu-
tion. Hard copy distribution involves either directly handing or mailing a copy to each employee or posting the policy
in a publicly accessible location. Posting a policy on a bulletin board or other public area may be insufficient unless
another policy requires the employees to read the bulletin board on a specified schedule.
Distribution by internal or external mail may still not guarantee that the individual receives the document. Unless
the organization can prove that the policy reached its target audience, it cannot be enforced. Unlike in law, ignorance
of policy, where policy is inadequately distributed, is considered an acceptable excuse. Distribution of classified
policies—those containing confidential information—requires additional levels of controls, in the labeling of the
document, in the dissemination and storage of new policy, and in the collection and destruction of older versions to
ensure the confidentiality of the information contained within the policy documents themselves.
Another common method of dissemination is by electronic means: e-mail, newsletter, intranet, or document man-
agement systems. Perhaps the easiest way is to post policies on a secure intranet in HTML or PDF (Adobe Acrobat)
form. The organization must still enable a mechanism to prove distribution, such as an auditing log for tracking when
users access the documents. As an alternative delivery mechanism, e-mail has advantages and disadvantages. While
it is easy to send a document to an employee and even track when the employee opens the e-mail, e-mail tracking may
not be sufficient as proof that the employee downloaded and actually read any attached policies, and the document
100 Principles of Information Security

can get lost in an avalanche of spam, phishing attacks, or other unwanted e-mail. The best method is through elec-
tronic policy management software, as described in the section on automated tools. Electronic policy management
software not only assists in the distribution of policy documents, it supports the assessment of comprehension and
evaluation of compliance.

Policy Review
Barriers to employees reading policies can arise from literacy or language issues. A surprisingly large percentage of the
workforce is considered functionally illiterate. According to Macrotrends, a full 1 percent of people 15 and older living
in the United States cannot read and write with understanding. Based on statistics from 2020, that means more than
3.28 million adults in the United States are considered illiterate.13 Many jobs do not require literacy skills—for example,
custodial staff, groundskeepers, or production line workers. Because such workers can still pose risks to InfoSec, they
must be made familiar with policy even if it must be read to them. Visually impaired employees also require additional
assistance, either through audio or large-type versions of the document.
A contributing factor to the literacy issue is that the number of non-English-speaking residents in the United States
continues to climb. According to 2018 U.S. Census data, more than 67 million residents speak a language other than
English at home.14 However, language challenges are not restricted to organizations with locations in the United States.
Multinational organizations also must deal with the challenges of gauging reading levels of foreign citizens. Simple
translations of policy documents, while a minimum requirement, necessitate careful monitoring. Translation issues
have long created challenges for organizations.

Policy Comprehension
Simply making certain that a copy of the policy gets to employees in a form they can review may not ensure that they
truly understand what the policy requires of them. Comprehension involves two aspects of policy administration:
(1) the target audience can understand the policy, and (2) the organization has assessed how well they understand it.
To be certain that employees can understand the policy, the document must be written at an appropriate reading
level, with minimal technical jargon or management terminology. The readability statistics supplied by most productiv-
ity suite applications—such as Microsoft Word—can help determine the current reading level of a policy. The Flesch
Reading Ease test evaluates writing on a scale of 1–100. The higher the score, the easier it is to understand the writing.
For most corporate documents, a score of 60 to 70 is preferred. The Flesch–Kincaid Grade Level test evaluates writ-
ing on a U.S. grade-school level. While a 13th-grade level (freshman in college) may be appropriate for a textbook, it
is too high for organizational policy intended for a broad audience. For most corporate documents, a score of 7.0 to
8.0 is preferred.
The next step is to use some form of assessment to gauge how well employees understand the policy’s underlying
issues. Quizzes and other forms of examination can be employed to assess quantitatively which employees understand
the policy by earning a minimum score (e.g., 70 percent) and which employees require additional training and aware-
ness efforts before the policy can be enforced. Quizzes can be conducted in either hard copy or electronic formats.
The electronic policy management systems mentioned earlier can assist in the assessment of employee performance
on policy comprehension.

Policy Compliance
Policy compliance means the employee must agree to the policy. According to Whitman in “Security Policy: From
Design to Maintenance”: Policies must be agreed to by act or affirmation. Agreement by act occurs when the employee
performs an action, which requires them to acknowledge understanding of the policy prior to use of a technology or
organizational resource. Network banners, end-user license agreements (EULAs), and posted warnings can serve to
meet this burden of proof. However, these approaches in and of themselves may not be sufficient. Only through direct
collection of a signature or the equivalent digital alternative can the organization prove that it has obtained an agree-
ment to comply with policy, which also demonstrates that the previous conditions have been met.15
What if an employee refuses explicitly to agree to comply with policy? Can the organization deny access to infor-
mation that the individual needs to do his or her job? While this situation has not yet been adjudicated in the legal
system, it seems clear that failure to agree to a policy is tantamount to refusing to work and thus may be grounds for
termination. Organizations can avoid this dilemma by incorporating policy confirmation statements into employment
contracts, annual evaluations, or other documents necessary for the individual’s continued employment.
Module 3 Information Security Management 101

Policy Enforcement
The final component of the design and implementation of effective policies is uniform and impartial enforcement. As
in law enforcement, policy enforcement must be able to withstand external scrutiny. Because this scrutiny may occur
during legal proceedings—for example, in a civil suit contending wrongful termination— organizations must establish
high standards of due care with regard to policy management. For instance, if policy mandates that all employees wear
identification badges in a clearly visible location and select members of management decide they are not required
to follow this policy, any actions taken against other employees will not withstand legal challenges. If an employee is
punished, censured, or dismissed as a result of a refusal to follow policy and is subsequently able to demonstrate that
the policies are not uniformly applied or enforced, the organization may find itself facing punitive as well as compen-
satory damages.
One forward-thinking organization found a way to enlist employees in the enforcement of policy. After the organiza-
tion had just published a new ID badge policy, the manager responsible for the policy was seen without his ID. One of
his employees chided him in jest, saying, “You must be a visitor here, since you don’t have an ID. Can I help you?” The
manager smiled and promptly produced his ID, along with a $20 bill, which he presented to the employee as a reward
for vigilant policy enforcement. Soon, the entire staff was routinely challenging anyone without a badge.16

Policy Development and Implementation Using the SDLC


Like any major project, a policy development or redevelopment project should be well planned, properly funded, and
aggressively managed to ensure that it is completed on time and within budget. One way to accomplish this goal is to
use a systems development life cycle (SDLC). The following discussion expands the use of a typical SDLC model by
discussing the tasks that could be included in each phase of the SDLC during a policy development project.

Investigation Phase During the investigation phase, the policy development team or committee should attain the
following:
• Support from senior management because any project without it has a reduced chance of success. Only with
the support of top management will a specific policy receive the attention it deserves from the intermediate-
level managers who must implement it and from the users who must comply with it.
• Support and active involvement of IT management, specifically the CIO. Only with the CIO’s active support will
technology-area managers be motivated to participate in policy development and support the implementation
efforts to deploy it once created.
• Clear articulation of goals. Without a detailed and succinct expression of the goals and objectives of the policy,
broken into distinct expectations, the policy will lack the structure it needs to obtain full implementation.
• Participation of the correct individuals from the communities of interest affected by the recommended
policies. Assembling the right team, by ensuring the participation of the proper representatives from the
groups that will be affected by the new policies, is very important. The team must include representatives from
the legal department, the human resources department, and end users of the various IT systems covered by
the policies, as well as a project champion with sufficient stature and prestige to accomplish the goals of the
project and a capable project manager to see the project through to completion.
• A detailed outline of the scope of the policy development project and sound estimates for the cost and sched-
uling of the project.

Analysis Phase The analysis phase should produce the following:


• A new or recent risk assessment or IT audit documenting the current InfoSec needs of the organization. This
risk assessment should include any loss history, as well as past lawsuits, grievances, or other records of nega-
tive outcomes from InfoSec areas.
• The gathering of key reference materials, including any existing policies. Sometimes policy documents that
affect InfoSec will be housed in the human resources department as well as the accounting, finance, legal, or
corporate security departments.
• The policy development committee must determine the fundamental philosophy of the organization when it
comes to policy. This will dictate the general development of all policies, but in particular, the format to be
used in the crafting of all ISSPs. This philosophy typically falls into one of two groups:
102 Principles of Information Security

❍ “That which is not permitted is prohibited.” Also known as the “whitelist” approach, this is the more restric-
tive of the two, and focuses on creating an approach where specific authorization is provided for various
actions and behaviors; all other actions and behaviors (and uses) are prohibited or at least require specific
permissions. This approach can impede normal business operations if appropriate options emerge but can-
not be incorporated into policy until subsequent revisions are made.
❍ “That which is not prohibited is permitted.” Also known as the “blacklist” approach, this alternate approach
specifies what actions, behaviors, and uses are prohibited and then allows all others by default. While eas-
ier to implement, this approach can result in issues as more and more areas that should be prohibited are
discovered by users.
Design Phase The first task in the design phase is the drafting of the actual policy document. While this task can be
done by a committee, it is most commonly done by a single author. This document should incorporate all the specifica-
tions and restrictions from the investigation and analysis phases. This can be a challenging process, but you do not have
to come up with a good policy document from scratch. A number of resources are at your disposal, including the following:
• The Web—You can search for other similar policies. The point here is not to advocate wholesale copying of
these policies but to encourage you to look for ideas for your own policy. For example, dozens of policies avail-
able on the Web describe fair and responsible use of various technologies. What you may not find, however,
are policies that relate to sensitive internal documents or processes.
• Government sites—Sites such as [Link] contain numerous sample policies and policy support docu-
ments, including SP 800-100, “Information Security Handbook: A Guide for Managers.” While these policies are
typically applicable to federal government Web sites, you may be able to adapt some sections to meet your
organization’s needs.
• Professional literature—Several authors have published books on the subject. Of particular note is Charles
Cresson Wood’s Information Security Policies Made Easy series, which not only provides more than 1,000 pages
of policies, it makes those policies available in electronic format, complete with permission to use them in
internal documents. Exercise caution when using such resources, however; it is extremely easy to take large
sections of policy and end up with a massive, unwieldy document that is neither publishable nor enforceable.
• Peer networks—Other InfoSec professionals must write similar policies and implement similar plans. Attend
meetings like those offered by the Information Systems Security Association ([Link]) or the Information
Systems Audit and Control Association ([Link]), and ask your peers.
• Professional consultants—Policy is one area of InfoSec that can certainly be developed in-house. However, if
your organization does not have the requisite expertise, or if your team simply cannot find the time to develop
your own policy, then hiring an outside consultant may be your best option. Keep in mind that no consultant
can know your organization as well as you do; you may decide to have the consultant design generic policies
that you can then adapt to your specific needs.
Next, the development team or committee reviews the work of the primary author and makes recommendations
about its revision. Once the committee approves the document, it goes to the approving manager or executive for
sign-off.
Implementation Phase In the implementation phase, the team must create a plan to distribute and verify the dis-
tribution of the policies. Members of the organization must explicitly acknowledge that they have received and read
the policy (compliance). Otherwise, an employee can claim never to have seen a policy, and unless the manager can
produce strong evidence to the contrary, any enforcement action, such as dismissal for inappropriate use of the Web,
can be overturned and punitive damages might be awarded to the former employee. The simplest way to document
acknowledgment of a written policy is to attach a cover sheet that states “I have received, read, understood, and agreed
to this policy.” The employee’s signature and date provide a paper trail of his or her receipt of the policy.
Some situations preclude a formal documentation process. Take, for instance, student use of campus computer
labs. Most universities have stringent policies on what students can and cannot do in a computer lab. These policies
are usually posted on the Web, in the student handbook, in course catalogs, and in several other locations, including
bulletin boards in the labs. For the policies to be enforceable, however, some mechanism must be established that
records the student’s acknowledgment of the policy. This is frequently accomplished with a banner screen that displays
a brief statement warning the user that the policy is in place and that use of the system constitutes acceptance of
Module 3 Information Security Management 103

the policy. The user must then click an OK button or press a key to get past the screen. However, this method can be
ineffective if the acknowledgment screen does not require any unusual action to move past it. Most acknowledgment
screens require that the user click a specific button, press a function key, or type text to agree to the terms of the EULA.
Some even require the user to scroll down to the bottom of the EULA screen before the “I accept” button is activated.
Similar methods are used on network and computer logins to reinforce acknowledgment of the system use policy.
A stronger mechanism to document and ensure comprehension is a compliance assessment, such as a short quiz,
to make sure that users both read the policy and understand it. A minimum score is commonly established before the
employee is certified to be “in compliance.” Coupled with a short training video, the compliance quiz is the current
industry best practice for policy implementation and compliance.
The design phase should also include specifications for any automated tool used for the creation and management
of policy documents, as well as revisions to feasibility analysis reports based on improved costs and benefits as the
design is clarified. During the implementation phase, the policy development team ensures that the policy is properly
distributed, read, understood, and agreed to by those to whom it applies, and that their understanding and acceptance
of the policy are documented.
Maintenance Phase During the maintenance phase, the policy development team monitors, maintains, and modi-
fies the policy as needed to ensure that it remains effective as a tool to meet changing threats. The policy should have
a built-in mechanism through which users can report problems—preferably on an anonymous basis through a Web
form monitored either by the organization’s legal team or a committee assigned to collect and review such content.
It is in this phase that the last component of effective policy development—uniform enforcement—comes into play.
The organization should make sure that everyone is required to follow the policy equally and that policies are not
implemented differently in different areas or hierarchies of the organization.
When the policy comes up for schedule review, the development committee reassembles, reviews any submitted
recommendations, and begins the process anew, as described in the next section.

Policy Management
Policies are living documents that must be managed. It is unacceptable to create such an important set of documents
and then shelve them. These documents must be properly distributed, read, understood, agreed to, uniformly applied,
and managed. How they are managed should be specified in the policy management section of the issue-specific policy
described earlier. Good management practices for policy development and maintenance make for a more resilient orga-
nization. For example, all policies, including security policies, undergo tremendous stress when corporate mergers and
divestitures occur. In such situations, employees are faced with uncertainty and many distractions. System vulnerabili-
ties can arise, for instance, if incongruent security policies are implemented in different parts of a newly merged organiza-
tion. When two companies merge but retain separate policies, the difficulty of implementing security controls increases.
Likewise, when one company with unified policies splits in two, each new company may require different policies.
To remain viable, security policies must have a responsible manager, a schedule of reviews, a method for making
recommendations for reviews, and a policy issuance and revision date.

Responsible Manager
Just as information systems and information security projects must have champions and managers, so must policies.
The policy manager is often called the policy administrator. Note that the policy
administrator does not necessarily have to be proficient in the relevant technology. policy administrator
While practicing information security professionals require extensive technical An employee responsible for
knowledge, policy management and policy administration require only a moderate the creation, revision, distribu-
technical background. It is good practice, however, for policy administrators to solicit tion, and storage of a policy in an
organization.
input both from technically adept information security experts and from business-
focused managers in each community of interest when revising security policies. The
administrator should also notify all affected members of the organization when the policy is modified.
It is disheartening when a policy that required hundreds of staff hours to develop and document is ignored. Thus,
someone must be responsible for placing the policy and all subsequent revisions into the hands of people who are
accountable for its implementation. The policy administrator must be clearly identified in the policy document as the
primary point of contact for additional information or suggested revisions to the policy.
104 Principles of Information Security

sunset clause Schedule of Reviews


A component of policy or law that Policies can only retain their effectiveness in a changing environment if they are
defines an expected end date for its periodically reviewed for currency and accuracy and then modified accordingly. Poli-
applicability.
cies that are not kept current can become liabilities as outdated rules are enforced
(or not) and new requirements are ignored. To demonstrate due diligence, an orga-
nization must actively seek to meet the requirements of the market in which it operates. This applies to government,
academic, and nonprofit organizations as well as private, for-profit organizations. A properly organized schedule of
reviews should be defined and published as part of the document. Typically, a policy should be reviewed at least annu-
ally to ensure that it is still an effective control.

Review Procedures and Practices


To facilitate policy reviews, the policy manager should implement a mechanism by which people can comfortably make
recommendations for revisions, whether via e-mail, office mail, or an anonymous drop box. If the policy is controversial,
anonymous submission of recommendations may be the best way to encourage staff opinions. Many employees are
intimidated by management and hesitate to voice honest opinions about a policy unless they can do so anonymously.
Once the policy has come up for review, all comments should be examined, and management-approved improvements
should be implemented. In reality, most policies are drafted by a single responsible employee and then reviewed by a
higher-level manager, but even this method does not preclude the collection and review of employee input.

Policy, Review, and Revision Dates


The simple action of dating the policy is often omitted. When policies are drafted and published without dates, confu-
sion can arise. If policies are not reviewed and kept current, or if members of the organization are following undated
versions, disastrous results and legal headaches can ensue. Such problems are particularly common in a high-turnover
environment. Therefore, the policy must contain the date of origin and the date(s) of any reviews and/or revisions. If
the policy is reviewed and considered up to date, a review date is applied to the document. If it is reviewed and deter-
mined to need updating, a revision date is applied once the update is complete. Some policies may also need a sunset
clause that indicates their expiration date, particularly if the policies govern information use in short-term business
associations. Establishing a policy end date prevents a temporary policy from mistakenly becoming permanent, and
it also enables an organization to gain experience with a given policy before adopting it permanently.

Automated Policy Management


In recent years, a new category of software has emerged for the management of information security policies. This type
of software was developed in response to the needs of information security practitioners. While many software products
can meet the need for a specific technical control, software now can automate some of the busywork of policy man-
agement. Automation can streamline the repetitive steps of writing policy, tracking the workflow of policy approvals,
publishing policy once it is written and approved, and tracking when employees have read the policy. Using techniques
from computer-based training and testing, an organization can train staff members and improve its awareness program.

Security Education, Training, And Awareness Program


Once your organization has defined the policies that will guide its security program,
it is time to implement a security education, training, and awareness (SETA)
security education, program. The SETA program is the responsibility of the CISO and is a control mea-
training, and sure designed to reduce incidents of accidental security breaches by employees.
awareness (SETA) Employee errors are among the top threats to information assets, so it is well worth
A managerial program designed to developing programs to combat this threat. SETA programs are designed to supple-
improve the security of informa-
ment the general education and training programs that many organizations use to
tion assets by providing targeted
knowledge, skills, and guidance for educate staff about information security. For example, if an organization detects
an organization’s employees. that many employees are opening questionable e-mail attachments, those employees
Module 3 Information Security Management 105

must be retrained. As a matter of good practice, systems development life cycles must include user training during
the implementation phase. Practices used to take control of the security and privacy of online data are sometimes
called cyber hygiene.
The SETA program consists of three distinct elements: security education, security training, and security aware-
ness. An organization may not be able or willing to undertake all three of these elements, and it may outsource elements
to local educational institutions. The purpose of SETA is to enhance security by doing the following:
• Improving awareness of the need to protect system resources
• Developing skills and knowledge so computer users can perform their jobs more securely
• Building in-depth knowledge as needed to design, implement, or operate security programs for organizations
and systems17
Table 3-4 compares the features of security education, training, and awareness within the organization.

Table 3-4 Comparative Framework of SETA18

Awareness Training Education


Attribute Seeks to teach members Seeks to train members of the Seeks to educate members of
of the organization what organization how they should the organization as to why it has
security is and what the react and respond when threats prepared in the way it has and
employee should do in some are encountered in specified why the organization reacts in
situations situations the ways it does
Level Offers basic information Offers more detailed knowledge Offers the background and
about threats and responses about detecting threats and depth of knowledge to gain
teaches skills needed for insight into how processes are
effective reaction developed and enables ongoing
improvement
Objective Members of the organization Members of the organization can Members of the organization
can recognize threats and mount effective responses using can engage in active defense
formulate simple responses learned skills and use understanding of the
organization’s objectives to make
continuous improvement
Teaching • Media videos • Formal training • Theoretical instruction
methods
• Newsletters • Workshops • Discussions/seminars
• Posters • Hands-on practice • Background reading
• Informal training
Assessment True/false or multiple choice Problem solving (apply learning) Essay (interpret learning)
(identify learning)
Impact Short-term Intermediate Long-term
timeframe
Source: NIST SP 800-12.

Security Education
Everyone in an organization needs to be trained and made aware of information security, but not everyone needs a
formal degree or certificate in information security. When management agrees that formal education is appropriate, an
employee can investigate courses in continuing education from local institutions of higher learning. Several universi-
ties have formal coursework in information security. For people who are interested in researching formal information
security programs, resources are available, such as the DHS/NSA-designated National Centers of Academic Excellence
program (see [Link]/NIETP/[Link]). This program identifies universities that have had their coursework
and practices in information security reviewed and found to meet national standards. Other local resources can also
provide information on security education, such as Kennesaw State University’s Institute for Cybersecurity Workforce
Development ([Link]
106 Principles of Information Security

Security Training
Security training provides employees with detailed information and hands-on instruction to prepare them to perform
their duties securely. Management of information security can develop customized in-house training or outsource the
training program.
Alternatives to formal training programs are industry training conferences and programs offered through profes-
sional agencies such as SANS ([Link]), (ISC)2 ([Link]), and ISSA ([Link]). All of these agencies are
described in other modules. Many of these programs are too technical for the average employee, but they may be ideal
for the continuing education requirements of information security professionals.
A new venue for security training for both security professionals and the average end user is Massive Open Online
Courses (MOOCs), which are available from a number of vendors, including Coursera ([Link]). Many of
these courses are free to enroll in, and a certificate of completion is provided upon payment of a nominal fee. The
list of available topics ranges from the traditional academic introduction to security to technical topics and general
information.
Several resources for conducting SETA programs offer assistance in the form of sample topics and structures for
security classes. For organizations, the Computer Security Resource Center at NIST provides several useful documents
free of charge in its special publications area ([Link]

Security Awareness
A security awareness program is one of the least frequently implemented but most beneficial programs in an
organization. A security awareness program is designed to keep information security at the forefront of users’
minds. These programs don’t have to be complicated or expensive. Good programs can include newsletters, security
posters (see Figure 3-8 for an example), videos, bulletin boards, flyers, and trinkets. Trinkets can include security
slogans printed on mouse pads, coffee cups, T-shirts, pens, or any object frequently used during the workday that
reminds employees of security. In addition, a good security awareness program requires a dedicated person who is
willing to invest time and effort to promoting the program, and a champion willing to provide the needed financial
support.
The security newsletter is the most cost-effective method of disseminating security information and news to
employees. Newsletters can be distributed via hard copy, e-mail, or intranet. Topics can include new threats to the
organization’s information assets, the schedule for upcoming security classes, and the addition of new security
personnel. The goal is to keep the idea of information security in users’ minds and to stimulate users to care about
security. If a security awareness program is not actively implemented, employees may begin to neglect security matters,
and the risk of employee accidents and failures is likely to increase.

Figure 3-8 SETA awareness posters


Module 3 Information Security Management 107

Information Security Blueprint, Models, And


Frameworks
Once an organization has developed its information security policies and standards,
information security
the information security community can begin developing the blueprint for the blueprint
information security program. The organization’s policy will guide the selection and In information security, a frame-
development of the blueprint, and the organization will use the blueprint to guide work or security model customized
the implementation of the rest of the security program. This information security to an organization, including imple-
mentation details.
blueprint is the plan and basis for the design, selection, and implementation of all
security program elements, including policies, risk management programs, education
and training programs, technological controls, and program maintenance. information security
The blueprint is the organization’s detailed implementation of an information
framework
security framework. The blueprint specifies tasks and the order in which they are In information security, a specifi-
cation of a model to be followed
to be accomplished, just as an architect’s blueprint serves as the design template for during the design, selection, and
the construction of a building. The framework is the philosophical foundation from initial and ongoing implementation
which the blueprint is designed, like the style or methodology in which an architect of all subsequent security controls,
including information security poli-
was trained. cies, security education and train-
In choosing the framework to use for an information security blueprint, the ing programs, and technological
organization should consider adapting or adopting a recognized or widely accepted controls.
information security model backed or promoted by an established security
organization or agency. This exemplar framework can outline steps for designing and information security
implementing information security in the organization. Several published information model
security frameworks from government agencies and other sources are presented A well-recognized information secu-
later in this module. Because each information security environment is unique, rity framework, usually promoted
by a government agency, standards
the security team may need to modify or adapt pieces from several frameworks. organization, or industry group.
Experience teaches that what works well for one organization may not precisely fit
another.

The ISO 27000 Series


One of the most widely referenced security models is Information Technology—Code of Practice for Information
Security Management, which was originally published as British Standard BS7799. In 2000, this code of practice
was adopted as ISO/IEC 17799, an international standard framework for information security by the International
Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). The standard
has been regularly revised and updated, and today it consists of an entire portfolio of standards related to the
design, implementation, and management of an “information security management system.” The version released
in 2000 was revised in 2005 to become ISO 17799:2005, and it was then renamed as ISO 27002 in 2007 to align it
with ISO 27001.
While the details of the ISO/IEC 27000 series are available only to those who purchase the standard, its structure
and general organization are well known and are becoming increasingly significant for all who work in information
security. For a summary description of the structure of the most recent standard, ISO 27002:2013, see Table 3-5.
Here is the stated purpose of ISO/IEC 27002, as derived from its ISO/IEC 17799 origins:

ISO/IEC 27002:2013 gives guidelines for organizational information security standards and information security
management practices, including the selection, implementation, and management of controls, taking into
consideration the organization’s information security risk environment(s).

It is designed to be used by organizations that intend to:

1. Select controls within the process of implementing an information security management system based on
ISO/IEC 27001;
2. Implement commonly accepted information security controls;
3. Develop their own information security management guidelines.19
108 Principles of Information Security

Table 3-5 The Sections of ISO/IEC 27002:201320

ISO 27002:2013 Contents


Foreword
0. Introduction
1. Scope
2. Normative references
3. Terms and definitions
4. Structure of this standard
5. Information security policies
6. Organization of information security
7. Human resource security
8. Asset management
9. Access control
10. Cryptography
11. Physical and environmental security
12. Operations security
13. Communication security
14. System acquisition, development, and maintenance
15. Supplier relationships
16. Information security incident management
17. Information security aspects of business continuity management
18. Compliance
Bibliography
Source: Compiled from various sources.

ISO/IEC 27002:2013 is focused on a broad overview of the various areas of security. It provides information
on 14 security control clauses and addresses 35 control objectives and more than 110 individual controls. Its compan-
ion document, ISO/IEC 27001:2018, provides information for how to implement ISO/IEC 27002 and set up an information
security management system (ISMS). ISO/IEC 27001’s primary purpose is to be used as a standard so organizations
can adopt it to obtain certification and build an information security program; ISO 27001 serves better as an assessment
tool than as an implementation framework. ISO 27002 is for organizations that want information about implementing
security controls; it is not a standard used for certification. Figure 3-9 illustrates the ISO 27001 process.
In the United Kingdom, correct implementation of both volumes of these standards had to be determined by a
BS7799-certified evaluator before organizations could obtain ISMS certification and accreditation. When the standard
first came out, several countries, including the United States, Germany, and Japan, refused to adopt it, claiming that
it had fundamental problems:

• The global information security community had not defined any justification for a code of practice identified
in ISO/IEC 17799.
• The standard lacked the measurement precision associated with a technical standard.
• There was no reason to believe that ISO/IEC 17799 was more useful than any other approach.
• It was not as complete as other frameworks.
• The standard was hurriedly prepared given the tremendous impact its adoption could have on industry infor-
mation security controls.21
The ISO/IEC 27000 series is becoming increasingly important in the field, especially among global organizations.
Many certification bodies and corporate organizations are complying with it or will someday be expected to comply
with it.
Module 3 Information Security Management 109

Step Deliverables
Obtain management support
Project plan (optional)
Establish the project (optional)
Budget: Human Resources plan
List of interested parties, legal,
Identify requirements regulatory, and contractual
requirements
Information security policy and
Define scope, management
scope document information
intention responsibilities
Communication with interested parties and records of communication security objectives
Procedures for document
Implement support procedures control, internal audit,

Monitoring and measurement and records of the results


corrective action (optional)
Design the process of risk Risk assessment methodology;
assessment and treatment risk acceptance criteria
Risk assessment table,
Perform risk assessment and risk treatment table,
treatment risk assessment, and treatment
report
Develop a security profile of the
Statement of applicability
company
Accept residual risks & develop
Risk treatment plan;
a plan for control
acceptance of residual risks
implementation
Implement all required controls Records of implementation
Perform training and awareness
Training records
programs
Various records required by
Operate the ISMS
ISMS documentation
Internal audit report;
Conduct internal audit
corrective actions
Management review Management review minutes
Stage 1 certification audit* Stage 1 audit report;
(Doc review) corrective actions*
Stage 2 certification audit* Stage 2 audit report;
(Main audit) corrective actions*
* Mandatory for organizations undergoing certification

Figure 3-9 ISO/IEC 27001:2013 major process steps22

Source: 27001 Academy: ISO 27001 and ISO 22301 Online Consultation Center.

For more details on current and proposed ISO/IEC 27000 series documents, visit the ISO 27001Security Web site.
i Gary Hinson, author/owner of the site, reports that the ISO 27000 suite has more than 70 standards planned,
with approximately 61 published. For a complete list, visit [Link]/html/[Link].

NIST Security Models


Other approaches to security are described in the many documents available from the NIST Computer Security
Resource Center ([Link] Because the NIST documents are publicly available at no charge and have been
for some time, they have been broadly reviewed by government and industry professionals, and were among the refer-
ences cited by the U.S. government when it decided not to select the ISO/IEC 17799 (now 27000 series) standards. The
following NIST documents can assist in the design of a security framework:

• SP 800-12, Rev. 1: “An Introduction to Information Security”


• SP 800-18, Rev. 1: “Guide for Developing Security Plans for Federal Information Systems”
• SP 800-30, Rev. 1: “Guide for Conducting Risk Assessments”
• SP 800-37, Rev. 2: “Risk Management Framework for Information Systems and Organizations: A System Life
Cycle Approach for Security and Privacy”
110 Principles of Information Security

• SP 800-39: “Managing Information Security Risk: Organization, Mission, and Information System View”
• SP 800-50: “Building an Information Technology Security Awareness and Training Program”
• SP 800-55, Rev. 1: “Performance Measurement Guide for Information Security”
• SP 800-100: “Information Security Handbook: A Guide for Managers”
Many of these documents have been referenced elsewhere in this book as sources of information for the manage-
ment of security. The following sections examine select documents in this series as they apply to the blueprint for
information security.

NIST SP 800-12
SP 800-12, Rev. 1, “An Introduction to Information Security,” is an excellent reference and guide for the security manager
or administrator in the routine management of information security. It provides little guidance, however, for the design
and implementation of new security systems, and therefore should be used only as a precursor to understanding an
information security blueprint.

NIST SP 800-14
SP 800-14, “Generally Accepted Principles and Practices for Securing Information Technology Systems,” provides best
practices and security principles that can direct the security team in the development of a security blueprint. Even
though this legacy publication has been “retired,” there is not yet a replacement document in the NIST SP series that
provides a better basic grounding in information security. In addition to detailing security best practices across the
spectrum of security areas, it provides philosophical principles that the security team should integrate into the entire
information security process:
• Security supports the mission of the organization—Failure to develop an information security system based
on the organization’s mission, vision, and culture guarantees the failure of the information security program.
• Security is an integral element of sound management—Effective management includes planning, organizing, lead-
ing, and controlling. Security enhances management functions by providing input during the planning process
for organizational initiatives. Information security controls support sound management via the enforcement
of managerial and security policies.
• Security should be cost-effective—The costs of information security should be considered part of the cost of
doing business, much like the costs of computers, networks, and voice communications systems. Security
is not a profit-generating area of the organization and may not lead to competitive advantages. Information
security should justify its own costs. The use of security measures that do not justify their cost must have a
strong business justification, such as a legal requirement.
• Systems owners have security responsibilities outside their own organizations—Whenever systems store and use
information from customers, patients, clients, partners, or others, the security of this information becomes
the responsibility of the systems’ owners. These owners are expected to diligently work with each other to
assure the confidentiality, integrity, and availability of the entire value chain of their interconnected systems.
• Security responsibilities and accountability should be made explicit—Policy documents should clearly identify
the security responsibilities of users, administrators, and managers. To be legally binding, the policies must
be documented, disseminated, read, understood, and agreed to by all involved members of the organization.
As noted in Module 6, ignorance of the law is no excuse, but ignorance of policy is. Organizations should also
provide information about relevant laws in issue-specific security policies.
• Security requires a comprehensive and integrated approach—Security personnel alone cannot effectively imple-
ment security. As emphasized throughout this textbook, security is everyone’s responsibility. The three commu-
nities of interest—information technology management and professionals; information security management
and professionals; and users, managers, administrators, and other stakeholders—should participate in the
process of developing a comprehensive information security program.
• Security should be periodically reassessed—Information security that is implemented and then ignored is con-
sidered negligent because the organization has not demonstrated due diligence. Security is an ongoing pro-
cess. To be effective against a constantly shifting set of threats and a changing user base, the security process
must be periodically repeated. Continuous analyses of threats, assets, and controls must be conducted and
new blueprints developed. Only thorough preparation, design, implementation, vigilance, and ongoing main-
tenance can secure the organization’s information assets.
Module 3 Information Security Management 111

• Security is constrained by societal factors—Several factors influence the implementation and maintenance of
security controls and safeguards, including legal demands, shareholder requirements, and even business
practices. For example, security professionals generally prefer to isolate information assets from the Internet,
which is the leading avenue of threats to the assets, but the business requirements of the organization may
preclude this control measure.

NIST SP 800-18, Rev. 1


SP 800-18, Rev. 1, “Guide for Developing Security Plans for Federal Information Systems,” can be used as the founda-
tion for a comprehensive security blueprint and framework. This publication provides detailed methods for assess-
ing, designing, and implementing controls and plans for applications of varying size. SP 800-18, Rev. 1, can serve as a
useful guide to the activities described in this module and as an aid in the planning process. It also includes templates
for major application security plans. As with any publication of this scope and magnitude, SP 800-18, Rev. 1, must be
customized to fit the particular needs of an organization.

NIST and the Risk Management Framework


NIST’s approach to managing risk in the organization, titled the Risk Management Framework (RMF), emphasizes the
following:
• Building information security capabilities into federal information systems through the application of state-of-the-
practice management, operational, and technical security controls
• Maintaining awareness of the security state of information systems on an ongoing basis through enhanced monitor-
ing processes
• Providing essential information to help senior leaders make decisions about accepting risk to an
organization’s operations and assets, individuals, and other organizations arising from the use of information
systems

The RMF has the following characteristics:

• Promotes the concept of near real-time risk management and ongoing information system authorization through the
implementation of robust continuous monitoring
• Encourages the use of automation to provide senior leaders with necessary information to make cost-effective, risk-
based decisions about information systems that support an organization’s core missions and business functions
• Integrates information security into the enterprise architecture and system development life cycle
• Emphasizes the selection, implementation, assessment, and monitoring of security controls and the authorization of
information systems
• Links risk management processes at the information system level to risk management processes at the organization
level through a risk executive function
• Establishes responsibility and accountability for security controls deployed within an organization’s information
systems and inherited by those systems (i.e., common controls).23

The NIST Risk Management Framework is discussed in detail in Module 4, “Risk Management.”

The NIST Cybersecurity Framework


In early 2014, NIST published a new Cybersecurity Framework in response to Executive Order 13636 from President
Obama. NIST’s mandate was to create a voluntary framework that provides an effective approach to “manage
cybersecurity risk for those processes, information, and systems directly involved in the delivery of critical
infrastructure services.”24 The resulting framework, which is designed specifically to be vendor-neutral, closely
resembles the other approaches described in this textbook, but it provides additional structure to the process, if
not detail. The NIST framework builds on and works closely with the RMF described in the previous section. The
framework document represents the integration of previously discussed special publications from NIST, in a form
that makes the framework easier to understand and enables organizations to implement an information security
improvement program.
112 Principles of Information Security

The intent of the framework is to allow organizations to: “1) Describe their current cybersecurity posture;
2) Describe their target state for cybersecurity; 3) Identify and prioritize opportunities for improvement within the
context of a continuous and repeatable process; 4) Assess progress toward the target state; and 5) Communicate among
internal and external stakeholders about cybersecurity risk.”25
The NIST framework consists of three fundamental components:

• The framework core—This is a set of information security activities an organization is expected to perform, as
well as their desired results. These core activities are as follows:
❍ “Identify—Develop the organizational understanding to manage cybersecurity risk to systems, assets, data,

and capabilities.
❍ Protect—Develop and implement the appropriate safeguards to ensure delivery of critical infrastructure services.

❍ Detect—Develop and implement the appropriate activities to identify the occurrence of a cybersecurity event.

❍ Respond—Develop and implement the appropriate activities to take action regarding a detected cybersecu-

rity event.
❍ Recover—Develop and implement the appropriate activities to maintain plans for resilience and to restore

any capabilities or services that were impaired due to a cybersecurity event.”


• The framework tiers—The framework then provides a self-defined set of tiers so organizations can relate the
maturity of their security programs and implement corresponding measures and functions. The four tiers
include the following:
❍ Tier 1: Partial—In this category, an organization does not have formal risk management practices, and secu-

rity activities are relatively informal and ad hoc.


❍ Tier 2: Risk Informed—Organizations in this category have developed but not fully implemented risk man-

agement practices, and have just begun their formal security programs, so security is not fully established
across the organization.
❍ Tier 3: Repeatable—Organizations in this category not only have risk management practices formally

established, they have documented policy implemented. The organization has begun a repeatable security
program to improve its approach to information protection and proactively manage risk to information assets.
❍ Tier 4: Adaptive—The most mature organization falls into this tier. The organization not only has well-estab-

lished risk management and security programs, it can quickly adapt to new environments and threats. The
organization is experienced at managing risk and responding to threats and has integrated security com-
pletely into its culture.
• The framework profile—Organizations are expected to identify which tier their security programs most closely
match and then use corresponding recommendations within the framework to improve their programs. This
framework profile is then used to perform a gap analysis—comparing the current state of information security
and risk management to a desired state, identifying the difference, and developing a plan to move the organi-
zation toward the desired state. This approach is identical to the approaches outlined elsewhere in this text.
Using the materials provided in the NIST framework, organizations are encouraged to follow a seven-step approach
to implementing or improving their risk management and information security programs:
Step 1: Prioritize and scope—The organization identifies its business/mission objectives and high-level
organizational priorities. With this information, the organization makes strategic decisions regarding
cybersecurity implementations and determines the scope of systems and assets that support the
selected business line or process.
Step 2: Orient—Once the scope of the cybersecurity program has been determined for the business line or
process, the organization identifies related systems and assets, regulatory requirements, and overall risk
approach. The organization then identifies threats to, and vulnerabilities of, those systems and assets.
Step 3: Create a current profile—The organization develops a current profile by indicating which
category and subcategory outcomes from the framework core are currently being achieved.

Step 4: Conduct a risk assessment—This assessment could be guided by the organization’s overall risk
management process or previous risk assessment activities. The organization analyzes the operational
environment in order to discern the likelihood of a cybersecurity event and the impact that the event
could have on the organization.
Module 3 Information Security Management 113

Step 5: Create a target profile—The organization creates a target profile that focuses on the
assessment of the framework categories and subcategories describing the organization’s desired
cybersecurity outcomes.

Step 6: Determine, analyze, and prioritize gaps—The organization compares the current profile and the
target profile to determine gaps. Next it creates a prioritized action plan to address those gaps that draws
upon mission drivers, a cost-benefit analysis, and understanding of risk to achieve the outcomes in the target
profile. The organization then determines resources necessary to address the gaps.

Step 7: Implement action plan—The organization determines which actions to take in regards to the
gaps, if any, identified in the previous step. It then monitors its current cybersecurity practices against
the target profile.26

As you will learn in Module 11 while studying the SDLC waterfall methodology, the preceding steps are designed
to be an iterative process that gradually moves the organization closer to a Tier 4 security level and results in a better
approach to risk management and information protection.
NIST also provides a “Roadmap for Improving Critical Infrastructure Cybersecurity,”27 which provides supplemental
guidance for the framework and insights into its future development and refinement as an evolutionary, living document.

i For more information on the NIST Cybersecurity Framework, visit the NIST Web site at [Link]/cyberframework.

Other Sources of Security Frameworks


Many public and private organizations promote solid best security practices. Professional societies often provide
information on best practices for their members. The Technology Manager’s Forum ([Link]) has
an annual best practice award in several areas, including information security. The Information Security Forum
([Link]) has a free publication titled “Standard of Good Practice for Information Security,” which
outlines information security best practices.
Many organizations hold seminars and classes on best practices for implementing security; in particular, the Infor-
mation Systems Audit and Control Association ([Link]) hosts regular seminars. The International Association
of Professional Security Consultants ([Link]) has a listing of best practices. At a minimum, information security
professionals can peruse Web portals for posted security best practices. Several free portals dedicated to security
have collections of best practices, such as [Link] and NIST’s Computer Resources Center.

Design of the Security Architecture


To inform the discussion of information security program architecture and to illustrate industry best practices, the
following sections outline a few key components of security architecture. Many of these components are examined in
detail in later modules of the book, but this overview can help you assess whether a framework and blueprint are on
target to meet an organization’s needs.

Spheres of Security
The spheres of security, shown in Figure 3-10, are the foundation of the security framework. Generally speaking, the
spheres of security illustrate how information is under attack from a variety of sources. The right side of Figure 3-10
illustrates the ways in which internal users access information. For example, users can access hard copies of docu-
ments and information directly. Information, as the most important asset in this model, is at the center of the sphere.
Information is always at risk from attacks whenever it is accessible by people or computer systems. Networks and
the Internet are indirect threats, as exemplified by the fact that a person attempting to access information from the
Internet must traverse local networks.
The left side of Figure 3-10 illustrates that a layer of protection must exist between each layer of the sphere of use.
For example, “Policy and law” and “Education and training” are protections placed between people and the information.
Controls are also implemented between systems and the information, between networks and the computer systems, and
between the Internet and internal networks. This reinforces the concept of defense in depth. A variety of controls can
114 Principles of Information Security

Patches
and upgrades
Monitoring
systems Education,
Redundancy Firewalls and
Security planning training, and
proxy servers
(IR, DR, BC, CM) awareness

Encryption
Backups

Employees,
Information Information contractors,
and
trusted
partners

Policy and law

IDPS Access controls


External threats Internal threats

Figure 3-10 Spheres of security

be used to protect the information. The items of control shown in the figure are not intended to be comprehensive, but
they illustrate some of the safeguards that can protect the systems closer to the center of the sphere. Because people
can directly access each ring as well as the information at the core of the model, the side of the sphere of protection
that attempts to control access by relying on people requires a different approach to security than the side that uses
technology. The members of the organization must become a safeguard that is effectively trained, implemented, and
maintained, or they too will present a threat to the information.
Information security is designed and implemented in three layers: policies,
managerial controls people (education, training, and awareness programs), and technology. These layers
Information security safeguards are commonly referred to as PPT. Each layer contains controls and safeguards to
that focus on administrative plan- protect the information and information system assets that the organization values.
ning, organizing, leading, and But, before any technical controls or other safeguards can be implemented, the
controlling, and that are designed
by strategic planners and imple- policies that define the management philosophies behind the security process must
mented by the organization’s secu- be in place.
rity administration; they include
governance and risk management. Levels of Controls
Information security safeguards provide three levels of control: managerial,
operational controls operational, and technical. Managerial controls set the direction and scope of the
Information security safeguards security process and provide detailed instructions for its conduct. In addition, these
focusing on lower-level planning controls address the design and implementation of the security planning process and
that deals with the functionality
security program management. They also address risk management and security
of the organization’s security; they
include disaster recovery planning, control reviews (as described in Module 4), describe the necessity and scope of legal
incident response planning, and compliance, and set guidelines for the maintenance of the entire security life cycle.
SETA programs.
Operational controls address personnel security, physical security, and the
protection of production inputs and outputs. In addition, operational controls guide
technical controls the development of education, training, and awareness programs for users, admin-
Information security safeguards istrators, and management. Finally, they address hardware and software systems
that focus on the application of maintenance and the integrity of data.
modern technologies, systems,
Technical controls are the tactical and technical implementations of security in
and processes to protect informa-
tion assets; they include firewalls, the organization. While operational controls address specific operating issues, such
virtual private networks, and IDPSs. as developing and integrating controls into the business functions, technical controls
Module 3 Information Security Management 115

include logical access controls, such as identification, authentication, authorization, defense in depth
accountability (including audit trails), cryptography, and the classification of assets A strategy for the protection of
and users. information assets that uses mul-
tiple layers and different types of
Defense in Depth controls to provide optimal protec-
tion; typically, implementation of
A basic tenet of security architectures is the layered implementation of security. many different types of controls.
To achieve defense in depth, an organization must establish multiple layers of
security controls and safeguards, which can be organized into policy, training and redundancy
education, and technologies, as shown in the CNSS model presented in Module 1. The use of multiple types and
While policy itself may not prevent attacks, it certainly prepares the organization instances of technology that pre-
to handle them; when coupled with other layers, policy can deter attacks. For vent the failure of one system from
compromising the security of infor-
example, the layer of training and education can help defend against attacks enabled mation; typically, multiple instances
by employee ignorance and social engineering. Technology is also implemented of the same type of control.
in layers, with detection equipment working in tandem with reaction technology
behind access control mechanisms. Redundancy can be implemented at several security perimeter
points throughout the security architecture, such as in firewalls, proxy servers, and The boundary in the network within
access controls. Figure 3-11 illustrates the concept of building controls in multiple which an organization attempts
and sometimes redundant layers. The figure shows firewalls and prevention IDPSs to maintain security controls for
securing information from threats
that use both packet-level rules (shown as the packet header in the diagram) and
from untrusted network areas.
content analysis (shown as a database icon with the caption 0100101011). More
information on firewalls and intrusion detection systems is presented in Modules 8
and 9, respectively.

Firewall demilitarized zone

Users involved in effective security training


Dual homed proxy server and awareness programs

Effective
information
security policy

Trusted network

Internal
External filtering router and
filtering router VPN concentrator
Untrusted
network
Packet header
0100101011

Network intrusion detection and prevention system

Host intrusion detection and prevention system

Figure 3-11 Defense in depth

Security Perimeter
A perimeter is a boundary of an area. A security perimeter is the border of security that protects all internal systems
from outside threats, as pictured in Figure 3-12. Unfortunately, the perimeter does not protect against internal
attacks from employee threats or on-site physical threats. In addition, the emergence of mobile computing devices,
telecommuting, and cloud-based functionality has made the definition and defense of the perimeter increasingly
more difficult. This has led some security experts to declare the security perimeter extinct and call for an increased
focus on improved system-level security and active policing of networked assets. An organization can have both an
116 Principles of Information Security

Firewall
Demilitarized zone
Various firewalls and (DMZ)
proxy servers

Se
cur
ity
pe Trusted network
rim
ete
r

Untrusted High-level
network security domain

External Internal
filtering router filtering router

Figure 3-12 Security perimeters and domains

security domain electronic security perimeter, usually at the exterior network or Internet connection,
An area of trust within which infor-
and a physical security perimeter, usually at the entrance to the organization’s
mation assets share the same level offices. Both require perimeter security. Security perimeters can effectively be
of protection; communication implemented as multiple technologies that segregate the protected information
between these trust areas requires
from potential attackers. Within security perimeters, the organization can establish
evaluation of communications
traffic. security domains, each with differing levels of security, between which traffic must
be screened. The assumption is that if people have access to one system within a
security domain, they have authorized access to all systems within that domain. The
security perimeter is an essential element of the overall security framework, and its implementation details are the core
of the completed security blueprint. The key components of the security perimeter are firewalls, DMZs (demilitarized
zones), proxy servers, and IDPSs. You will learn more about information security technologies in Modules 8, 9, and 10.
Many security experts argue that the security perimeter is dead. With the dramatic growth in popularity of cloud-
based computing and data storage, and the continued use of mobile computing devices, they argue that there is no
“inside” or “outside” to organizations’ networks anymore. Whether this is true is the subject of much debate. With the
extensive use of cloud-based services to deliver key systems capability, including security-related functions, there is
a growing movement toward realizing that a security perimeter is the entirety of an organization’s network presence,
anywhere and everywhere the company’s data is, and that the use of defense in depth is still a valid approach to pro-
tecting it. Whether you subscribe to the “perimeter is dead” philosophy or not, the responsibility for protecting the
organization’s data using every available resource is still alive and well.

Closing Scenario
Janet stood up from the conference table and left the room.
The meeting had not lasted long, considering how significant its impact would be on Janet’s life. Two officers from the cor-
porate security team waited in the hallway to walk her to her office and collect her personal possessions, which were already
in a box at her administrative assistant’s desk. Her access card, phone, tablet, and laptop were already turned in, and every
password she had ever used at SLS had been deactivated.
She was not looking forward to explaining this to her family.
Module 3 Information Security Management 117

The meeting in the room continued.


Fred asked, “Are we sure this was our only course? This seems harsh to me.”
Janet’s superior, the senior vice president of marketing, nodded and said, “I have to say that I agree. Janet was a solid
performer and will be difficult, and expensive, to replace.”
Charlie added, “I know what you mean. Jamie Hyack, the network engineer, is the same, except he chose to enable
Janet’s network access for her rotisserie league server without approval, without change control, and putting the company’s
entire network at risk. He had to go.”
Gladys took a breath and said, “Sadly, this was needed. We cannot have two tiers of enforcement in our application
of policy. If we do not enforce this policy requirement on executives, how can we be expected to have compliance from
other employees?”
She continued, “As Charlie pointed out when we decided on this course of action, we have to enforce the policy we
have in place. We can make changes to it that we feel better about and enforce those changes in the future.”

Discussion Questions
1. Does this application of policy seem harsh to you? What alternatives might be implemented in policy to make
it enforceable and perhaps less stringent than in this example?
2. Are there other punishments that might be enacted for situations like this? How might you propose structur-
ing the policy to clarify what levels of punishment are appropriate?

Ethical Decision Making


The policies that organizations put in place are similar to laws, in that they are directives for how to act properly. Like
laws, policies should be impartial and fair, and are often founded on ethical and moral belief systems of the people who
create them.
In some cases, especially when organizations expand into foreign countries, they experience a form of culture shock
when the laws of their new host country conflict with their internal policies. For example, suppose that SLS has expanded
its operations into France. Setting aside any legal requirements that SLS make its policies conform to French law, does
SLS have an ethical imperative to modify its policies across the company in all of its locations to better meet the needs of
its stakeholders in the new country?
Suppose SLS has altered its policies for all operations in France and that the changes are much more favorable to
employees—such as a requirement to provide childcare and eldercare services at no cost to employees. Is SLS under any
ethical burden to offer the same benefit to employees in its home country?

Selected Readings
Many excellent sources of additional information are available in the area of information security. The following can add to
your understanding of this module’s content:

• “Information Security Governance: Guidance for Boards of Directors and Executive Management,” available by search-
ing at [Link].
• “Information Security Governance: A Call to Action,” available from [Link]/Documents/Governance/InfoSec-
Gov4_04.pdf.
• Information Security Policies Made Easy, Version 12, by Charles Cresson Wood and Dave Lineman. 2012. Information
Shield.
• Management of Information Security, by Michael E. Whitman and Herbert J. Mattord. 2019. Cengage Learning.
• Principles of Incident Response and Disaster Recovery, by Michael E. Whitman and Herbert J. Mattord. 2020. Cengage
Learning.
118 Principles of Information Security

Module Summary
• Information security governance is the application of the principles of corporate governance to the informa-
tion security function. These principles include executive management’s responsibility to provide strategic
direction, ensure the accomplishment of objectives, oversee that risks are appropriately managed, and validate
responsible resource use.
• Management must use policies as the basis for all information security planning, design, and deployment.
Policies direct how issues should be addressed and technologies should be used.
• Standards are more detailed than policies and describe the steps that must be taken to conform to policies.
• Management must define three types of security policies: general or security program policies, issue-specific
security policies, and systems-specific security policies.
• The enterprise information security policy (EISP) should be a driving force in the planning and governance
activities of the organization as a whole.
• Information security policy is best disseminated in a comprehensive security education, training, and aware-
ness (SETA) program. A security awareness program is one of the least frequently implemented but most
beneficial programs in an organization. A security awareness program is designed to keep information security
at the forefront of users’ minds.
• Several published information security frameworks by government organizations, private organizations, and
professional societies supply information on best practices for their members.
• One of the foundations of security architectures is the layered implementation of security. This layered
approach is referred to as defense in depth.

Review Questions
1. How do the InfoSec management team’s goals and What is information security governance? Who in
objectives differ from those of the IT and general the organization should plan for it?
management communities? 12. Where can a security administrator find informa-
2. What is included in the InfoSec planning model? tion on established security frameworks?
3. List and briefly describe the general categories of 13. What is the ISO 27000 series of standards? Which
information security policy. individual standards make up the series?
4. Briefly describe strategic planning. 14. What documents are available from the NIST
5. List and briefly describe the levels of planning. Computer Security Resource Center (CSRC),
6. What is governance in the context of information and how can they support the development of a
security management? security framework?
7. What are the differences between a policy, a 15. What Web resources can aid an organization in
standard, and a practice? Where would each be developing best practices as part of a security
used? framework?
8. What is an EISP, and what purpose does it serve? 16. Briefly describe management, operational, and
9. Who is ultimately responsible for managing technical controls, and explain when each would be
a technology? Who is responsible for applied as part of a security framework.
enforcing policy that affects the use of a 17. What is defense in depth?
technology? 18. Define and briefly explain the SETA program and
10. What is needed for an information security policy what it is used for.
to remain viable? 19. What is the purpose of the SETA program?
11. How can a security framework assist in the design 20. What is security training?
and implementation of a security infrastructure? 21. What is a security awareness program?
Module 3 Information Security Management 119

Exercises
1. Search the Web for examples of issue-specific security policies. What types of policies can you find? Using
the format provided in this module, draft a simple issue-specific policy that outlines fair and responsible use
of computers at your college, based on the rules and regulations of your institution. Does your school have
a similar policy? Does it contain all the elements listed in the text?
2. Using a graphics program, design several security awareness posters on the following themes: updating
antivirus signatures, protecting sensitive information, watching out for e-mail viruses, prohibiting the per-
sonal use of company equipment, changing and protecting passwords, avoiding social engineering, and pro-
tecting software copyrights. What other themes can you imagine?
3. Search the Web for security education and training programs in your area. Keep a list and see which pro-
gram category has the most examples. See if you can determine the costs associated with each example.
Which do you think would be more cost-effective in terms of both time and money?

References
1. Corporate Governance Task Force. “Information Security Governance: A Call to Action.” National Cyber
Security Partnership, 2004.
2. Mahncke, R. “The Applicability of ISO/IEC 27014:2013 for Use Within General Medical Practice.” Australian
eHealth Informatics and Security Conference. December 2–4, 2013, Edith Cowan University, Perth, Western
Australia. Accessed August 25, 2020, from [Link]
3. International Organization for Standardization. ISO/IEC 27014, “Information Technology—Security
Techniques—Governance of Information Security.” Accessed August 25, 2020, from [Link]/obp/
ui/#iso:std:iso-iec:27014:ed-1:v1:en.
4. Mahncke, R. “The Applicability of ISO/IEC 27014:2013 for Use Within General Medical Practice.” Australian
eHealth Informatics and Security Conference. December 2–4, 2013, Edith Cowan University, Perth, Western
Australia. Accessed August 25, 2020, from [Link]
5. “Information Security Governance: A Call to Action,” 2nd ed. 2006. Rolling Meadows, IL: IT Governance
Institute.
6. Information Technology Governance Institute (ITGI). “Information Security Governance: Guidance for
Information Security Managers.” Accessed October 11, 2016, from [Link].
7. Wood, Charles Cresson. “Integrated Approach Includes Information Security.” Security 37, no. 2 (February
2000): 43–44.
8. US-CERT. “Security Recommendations to Prevent Cyber Intrusions.” Accessed August 24, 2020, from
[Link]
9. Nieles, M., Dempsey, K., and Pillitteri, V. SP 800-12, Rev. 1, “An Introduction to Information Security”
(Draft). National Institute of Standards and Technology. Accessed August 25, 2020, from [Link]
gov/CSRC/media/Publications/sp/800-12/rev-1/draft/documents/sp800_12_r1_draft.pdf.
10. Derived from several sources, the most notable being The Washington University in St. Louis, Office of
Information Security. Accessed August 24, 2020, from [Link]
11. Whitman, Michael E., Townsend, Anthony M., and Aalberts, Robert J. “Considerations for an Effective
Telecommunications Use Policy.” Communications of the ACM 42, no. 6 (June 1999): 101–109.
12. Ibid.
120 Principles of Information Security

13. Macrotrends. “U.S. Literacy Rate 1990-2020.” Accessed August 25, 2020, from [Link]/
countries/USA/united-states/literacy-rate.
14. Zeigler, K., and Camarota, S. “67.3 Million in the United States Spoke a Foreign Language at
Home in 2018.” Center for Immigration Studies. Accessed August 25, 2020, from [Link]
Report/673-Million-United-States-Spoke-Foreign-Language-Home-2018.
15. Whitman, Michael E. “Security Policy: From Design to Maintenance.” Information Security Policies and
Strategies—An Advances in MIS Monograph. Goodman, S., Straub, D., and Zwass, V. (eds). 2008. Armonk
NY: M. E. Sharp, Inc.
16. Ibid.
17. Nieles, M., Dempsey, K., and Pillitteri, V. SP 800-12, Rev. 1, “An Introduction to Information Security.”
National Institute of Standards and Technology. Accessed August 25, 2020, from [Link]
publications/detail/sp/800-12/rev-1/final.
18. Ibid.
19. ISO. “Abstract.” Accessed August 25, 2020, from [Link]/standard/[Link].
20. Compiled from a number of sources, including “ISO/IEC 27002:2013 Information Technology—Security
Techniques—Code of Practice for Information Security Controls.” Accessed August 25, 2020, from
[Link]/html/[Link]. Also, “Introduction to ISO 27002.” Accessed August 25, 2020,
from [Link]/[Link].
21. National Institute of Standards and Technology. “Information Security Management, Code of Practice for
Information Security Management.” ISO/IEC 17799. December 6, 2001. Geneva, Switzerland.
22. Adapted from diagram of ISO 27001:2013 implementation process. Accessed August 25, 2020, from
[Link]
23. National Institute of Standards and Technology. SP 800-37, Rev. 2, “Risk Management Framework for
Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy.” Accessed
August 26, 2020, from [Link]
24. National Institute of Standards and Technology. “Framework for Improving Critical Infrastructure
Cybersecurity,” version 1.0. February 12, 2014. Accessed August 26, 2020, from [Link]/
cyberframework.
25. Ibid.
26. Ibid.
27. National Institute of Standards and Technology. “Roadmap for Improving Critical Infrastructure
Cybersecurity,” version 1.1. April 25, 2019. Accessed August 26, 2020, from [Link]/system/files/
documents/2019/04/25/[Link].

You might also like