Introduction to
Information Security
Chapter 1
Infographic Style
Passwords are like
underwear. Don’t
let people see it,
change it very
often, and you
shouldn’t share it
with strangers.
Table of
Contents
1 History and Terminology
2 Basics of Information Security
3 The CIA Triad
4 System Security Life Cycle
Table of
Contents
5 Security Implementation and
Mechanisms
6 Information Assurance Analysis
Model
7 Disaster Recovery
Click to add related headline text
Learning Outcomes:
ADD RELATED TITLE WORDS
LO1: LO2: LO3: LO4:
Describe the history Outline the system Portfolio 4
Prepare a threat Describe a disaster
of the field of life cycle and its Please replace the text content,
analysis
Click to add related headline text,
recovery scenario
Information relationship to
modify the text content, you can
also copy your content di。Please
replace the text content, Click to
Assurance and security. add related headline text, modify
the text content, you can also copy
Security. your content di。
04
Security Sytem
Development
Life Cycle
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Information security must be managed in
the same way that any other key system in
a business is controlled.
• A version of system development life cycle
(SDLC) called the Security Systems
Development Life Cycle (SecSDLC) can be
used to construct an information security
system in an organization.
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Security Systems Development Life Cycle
(SecSDLC) (SSDLC)
– Is a framework used to manage the
development, maintenance, and
retirement of an organization’s
information security systems.
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Methodology and Phases
– A methodology for the design and
execution of an information system is
the systems development life cycle
(SDLC).
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
– Implementing information security entails
recognizing specific dangers and putting in
place precise procedures to counter them.
– This process is unified by the SecSDLC, which
turns it into a coherent program rather than
a sequence of seemingly unrelated action.
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
– The SSDLC is a cyclical process that includes the
following phases:
• Investigation • Physical Design
• Analysis • Implementation
• Logic Design • Maintenance
and Change
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Investigation
– The most crucial part of the SSDLC.
– What is the objective of the system
being developed?
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Investigation
– The SecSDLS’s research phase begins with
a directive from senior management that
specificies the project’s methodology,
outputs and goals as well as its budget
and other constraints.
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Investigation
– Typically, this phase starts with an Enterprise
Security Policy (EISP), which describes how a
security program will be implemented within the
company.
– The scope of the project, as well as specific goals
and objectives and any additional constraints not
covered by the program policy, are defined.
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Investigation
– Teams of responsible managers, employees, and
contractors are organized;
– Finally, an organizational feasibility analysis is
carried out to see if the business has the resources
and commitment required to complete a
successful security analysis and design.
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Analysis
– The documents from the investigation phase are
examined in the analysis step.
– A preliminary study of existing security policies or
programs, as well as documented current threats
and associated controls, is conducted by the
development team.
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Analysis
– Existing security policies, programs, and
software are examined to see whether there
are any weaknesses or vulnerabilities in the
system. Threats that may arise in the future
are also considered. This method is solely
responsible for risk management.
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Logical Design
– The logical design phase produces and
develops information security blueprint, as well
as analyses and implements essential policies
that have an impact on later decisions.
– The team also plans incident response actions in
the case of a partial or catastrophic loss.
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
The following questions are addressed by the planning:
1. Continuity planning: How will your business continue
if you suffer a setback?
2. Incident Response: When an attack occurs, what
measures are taken to respond?
3. Disaster Recovery: What should be done as soon as
possible following a disaster restore information and
essential systems?
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Logical Design
– The next step is to conduct a
feasibility analysis to decide
whether the project should be
continued or outsourced.
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Physical Design
– The physical design step assess the
information security technologies required to
support the logical design blueprint, creates
alternative alternatives, and selects a final
design.
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Physical Design
– When the physical design is finished, the
information security blueprint may be revised to
keep it in line with the changes that are
required.
– During the step, criteria for defining the
definition of successful solutions are also
developed.
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Physical Design
– The ideas for physical security measures to
support the suggested technology solution are
included at this time.
– The feasibility study assesses the organization’s
readiness for the proposed project at the end of
this phase, and the design is then submitted to
the champion and sponsors.
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Physical Design
– Before the project is implemented,
all parties involved have the
opportunity to approve it.
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Implementation
– SecSDLC’s implementation phase is likewise
similar to that of standard SDLC. Security
solutions are purchased (created or
purchased), tested, implemented, and then
test again.
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Implementation
– Personnel issues are assessed, and
training and education programs are
implemented.
– Finally, senior management is
presented with full tested package for
final clearance.
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Maintenance and Change
– Given the present ever-changing threat
environment, maintenance and change is
the final, but maybe most critical phase.
– Information security systems must be
constantly monitored, tested, modified,
updated and repaired in today’s world.
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Maintenance and Change
– Repairing damage and restoring data is
frequently a never-ending battle against an
unseen foe.
– To prevent attacks from unsuccessfully infiltrating
sensitive data, an organization’s information
security profile must constantly adjust as new
threats emerge and old threats evolve.
Click to add related
Security Systemheadline text
Development Life Cycle
ADD RELATED TITLE WORDS
• Maintenance and Change
– This constant vigilance and security can be
compared to that of a castle, where threats
from the outside as well as the inside muts be
constantly watched and verified using new
and more sophisticated technologies.
Click to vs
SSDLC add related
SDLCheadline text
ADD RELATED TITLE WORDS
Steps unique to the Security
Steps common to both
PHASES Systems Development Life
SSDLC and SDLC
Cycle
Phase 1: • Outline project • Management
Investigation scope and goals defines project
• Estimate costs processes and goals
• Evaluate existing and documents
resources these in the program
• Analyze feasibility security policy.
Click to vs
SSDLC add related
SDLCheadline text
ADD RELATED TITLE WORDS
Steps unique to the Security
Steps common to both SSDLC
PHASES Systems Development Life
and SDLC
Cycle
Phase 2: • Assess current system • Analyze existing security
Analysis against plan developed in policies and programs
Phase 1 • Analyze current threats
• Developed preliminary and controls
system requirements • Examine legal issues
• Study integration of new • Perform risk analysis
system with existing system
• Document findings and
update feasibility analysis
Click to vs
SSDLC add related
SDLCheadline text
ADD RELATED TITLE WORDS
Steps unique to the Security
Steps common to both SSDLC
PHASES Systems Development Life
and SDLC
Cycle
Phase 3: • Assess current business • Develop security
Logical needs against plan blueprint
Design developed in Phase 2 • Plan incident response
• Select applications, data actions
support, and structures • Plan business response to
• Generate multiple solutions disaster
for consideration • Determine feasibility of
• Document findings and continuing and/or
update feasibility analysis outsourcing the project
Click to vs
SSDLC add related
SDLCheadline text
ADD RELATED TITLE WORDS
Steps unique to the Security
Steps common to both SSDLC
PHASES Systems Development Life
and SDLC
Cycle
Phase 4: • Select technologies to • Select technologies
Physical support solutions needed to support
Design developed in Phase 3 security blueprint
• Select the best solution • Develop definition of
• Decide to make or buy successful solution
components • Design physical security
• Document findings and measures to support
update feasibility analysis techno logical solutions
• Review and approve
project
Click to vs
SSDLC add related
SDLCheadline text
ADD RELATED TITLE WORDS
Steps unique to the Security
Steps common to both
PHASES Systems Development Life
SSDLC and SDLC
Cycle
Phase 5: • Develop or buy software • Buy or develop security
Implementation • Order components solutions
• Document the system • At the end of phase,
• Train users present tested package
• Update feasibility to management for
analysis approval
• Present system to users
• Test system and review
performance
Click to vs
SSDLC add related
SDLCheadline text
ADD RELATED TITLE WORDS
Steps unique to the Security
Steps common to both
PHASES Systems Development Life
SSDLC and SDLC
Cycle
Phase 6: • Support and modify • Constantly monitor, test,
Maintenance system during its useful modify, update and
and change life repair to meet changing
• Test periodically for threats
compliance with
business needs
• Upgrade and patch as
necessary
Thank you
End of Chapter 1 Part 1
Prepared by: Caroline V. Paraiso