Monday, June 9, 2008
How to apply ISO 27002 to PCI DSS compliance
The PCI Data Security Standard (PCI DSS) consists of 12 mandatory high-level requirements for all organizations that store, transmit, or process payment cards. These 12 requirements are further subdivided into sections, describing activities that organizations must engage in while managing their networks, administering their systems, and, in general protecting the payment card data with which they have been entrusted.
While PCI DSS details compliance requirements in most areas, its directives make only passing reference (if at all) to an overall security framework into which the required actions must fit. If organizations simply follow the PCI DSS blindly, they may not achieve the overall security goals.
ISO 27002, also known as ISO 17799, is a security standard of practice. In other words, it is a comprehensive list of security practices that can be applied -- in varying degrees -- to all organizations. The benefit of such a standard to organizations attempting to comply with the PCI-DSS is twofold. First, it provides a framework that allows organizations to achieve their PCI security goals along with those from other sources, like industry or governmental regulations. Second, it provides guidance on how to fit some of PCI's governance and policy requirements into an organization's compliance program.
For example, ISO 27002 discusses the necessity of involving business, management, human resources and technology representatives in the security program. It also provides references for high-level policies for important areas such as data classification, data handling and access control. While PCI DSS describes specific technical practices and organizational activities, it doesn't talk about the overall program in which these activities exist or the specific policies that require these activities.
When a company establishes a program based on a broad standard like ISO 27002, it can treat the PCI-DSS requirements as a subset of those required by the ISO. Further, a program structured according to ISO 27002 will require organizations to employ critical support systems required by many regulations (and PCI DSS in particular). For example, ISO 27002 requires change control in network administration, system configuration, policy management, procedure management and software development. PCI DSS calls out the need for accurate diagrams and documentation for its network and systems as well as change control processes to ensure discipline in administration of the PCI DSS-related components.
ISO 27002's broad requirements for change control associated with all aspects of administration encourage a consistent approach across an enterprise. This kind of approach, when applied to PCI DSS, would help improve both the consistency, effectiveness and efficiency of change control across a company and increase the likelihood that an auditor would find a company's practices acceptable.
Another benefit of combining the structure of ISO 27002 and the specific requirements of PCI DSS is that the PCI DSS helps organizations define three of the most challenging aspects of ISO compliance: scope of compliance, data classification and data handling. Armed with these constraining requirements, organizations can define policies and procedures that are consistent with best practice as specified by ISO and directly address PCI DSS compliance. For example, PCI DSS defines what aspects of credit card data are sensitive. It describes access control requirements for credit card information, encryption requirements for transmission and storage, and even the testing necessary to verify effectiveness of controls. These specific requirements allow organizations to state how systems must be configured, how employees must treat data and how an organization monitors the effectiveness of its controls.
A growing number of organizations are building security programs according to standard frameworks like ISO 27002. These frameworks are allowing organizations to factor compliance with multiple regulations and contracts into their security programs in a consistent and effective manner.
The beauty of using the ISO standard with specific regulations is that the regulations fill in the necessary details that the framework lacks while the framework provides structure to address multiple sets of requirements consistently. The two concepts work hand in hand and provide effectiveness, efficiency and auditability.
About the author:
Richard E. "Dick" Mackey is regarded as one of the industry's foremost authorities on security and compliance. He is a frequent speaker and contributor to magazines and online publications. He has advised leading financial firms on compliance with PCI, GLBA and SOX. He has also provided guidance to a wide range of companies on enterprise security architectures, identity and access management and security policy and governance.
New Risk Assessment Tool for ISO27001 Consultants Simplifies and Accelerates Compliance Process for Clients
Targeted at specialist consultants dealing with ISO27001 compliance, vsRCE is an affordable and intuitive risk assessment management tool for the IT consultant community that allows consultants the ability to directly support their clients' risk assessment activity from an off-site location. vsRCE allows clients to create and export risk assessment files that can be analysed on the consultants' own workstations or laptops, and then re-imported into the client's own software.
vsRCE allows IT consultants to manage up to ten separate risk assessments or risk assessment in up to ten different organisations, each of which must have purchased its own copy of vsRisk. By working in harmony with its sister application vsRisk, vsRCE will dramatically reduce the time and effort it takes for companies to achieve ISO27001 compliance, transferring an important element of the work to the consultant and ensuring that the work of the project team can be monitored more closely.
In addition to supporting ISO/IEC27001, vsRCE supports ISO/IEC27002 (17799); complies with BS7799-3:2006; conforms to ISO/IEC TR 13335-3:1998 and NIST SP 800-30; and complies with the UK's Risk Assessment Standard.
Vigilant Software is a joint venture between IT Governance Limited, the one-stop-shop for books, tools and information on ISO27001 compliance, and Top Solutions (UK) Limited, an award-winning developer of risk management software tools.
Alan Calder, Chief Executive of IT Governance, commented, "vsRCE is the perfect complement to vsRisk and offers a major enhancement to vsRisk users. By employing a consultant who uses vsRCE, companies can simplify and speed the process of achieving ISO27001 compliance. For consultants, it offers a means of providing greater added value and is therefore a powerful competitive advantage."
Source: compliancehome.com
Tuesday, September 25, 2007
Information Security : Design, Implementation, Measurement, and Compliance
Product Details
Hardcover : 222 pages
Publisher : AUERBACH; 1 edition (July 20, 2006)
Language : English
ISBN-10 : 0849370876
ISBN-13 : 978-0849370878
Table of Contents
EVALUATING AND MEASURING AN INFORMATION SECURITY PROGRAM
INFORMATION SECURITY RISK ASSESSMENT MODEL (ISRAM�)
. Background
. Linkage
. Risk Assessment Types
. Relationship to Other Models and Standards
. Terminology
. Risk Assessment Relationship
. Information Security Risk Assessment Model (ISRAM)
. References
GLOBAL INFORMATION SECURITY ASSESSMENT METHODOLOGY (GISAM�)
. GISAM and ISRAM Relationship
. GISAM Design Criteria
. General Assessment Types
. GISAM Components
. References
DEVELOPING AN INFORMATION SECURITY EVALUATION (ISE�) PROCESS
. The Culmination of ISRAM and GISAM
. Business Process
A SECURITY BASELINE
. KRI Security Baseline Controls
. Security Baseline
. Information Security Policy Document
. Management Commitment to Information Security
. Allocation of Information Security Responsibilities
. Independent Review of Information Security
. Identification of Risks Related to External Parties
. Inventory of Assets
. Classification Guidelines
. Screening
. Information Security Awareness, Education, and Training
. Removal of Access Rights
. Physical Security Perimeter
. Protecting Against External and Environmental Threats
. Secure Disposal or Reuse of Equipment
. Documented Operating Procedures
. Change Management
. Segregation of Duties
. System Acceptance
. Controls against Malicious Code
. Management of Removable Media
. Information Handling Procedures
. Physical Media in Transit
. Electronic Commerce
. Access Control Policy
. User Registration
. Segregation in Networks
. Teleworking
. Security Requirements Analysis and Specification
. Policy on the Use of Cryptographic Controls
. Protection of System Test Data
. Control of Technical Vulnerabilities
. Reporting Information Security Events
. Including Information Security in the Business Continuity Process
. Identification of Applicable Legislation
. Data Protection and Privacy of Personal Information
. Technical Compliance Checking
. References
BACKGROUND OF THE ISO/IEC 17799 STANDARD
. History of the Standard
. Internals of the Standard
. Guidance for Use
. High-Level Objectives
. ISO/IEC Defined
. References
ISO/IEC 17799:2005 GAP ANALYSIS
. Overview
. Guidance for Use
. General Changes
. Security Policy
. Organization of Information Security
. Asset Management
. Human Resources Security
. Physical and Environmental Security
. Communications and Operations Management
. Access Control
. Information Systems Acquisition, Development, and Maintenance
. Information Security Incident Management
. Business Continuity Management
. Compliance
. References
ANALYSIS OF ISO/IEC 17799:2005 (27002) CONTROLS
SECURITY POLICY
. Information Security Policy
. Summary
. References
ORGANIZATION OF INFORMATION SECURITY
. Internal Organization
. External Parties
. Summary
. References
ASSET MANAGEMENT
. Responsibility for Assets
. Information Classification
. Summary
. References
HUMAN RESOURCES SECURITY
. Prior to Employment
. During Employment
. Termination or Change of Employment
. Summary
. References
PHYSICAL AND ENVIRONMENTAL SECURITY
. Secure Areas
. Equipment Security
. Summary
. References
COMMUNICATIONS AND OPERATIONS MANAGEMENT
. Operational Procedures and Responsibilities
. Third-Party Service Delivery Management
. System Planning and Acceptance
. Protection against Malicious and Mobile Code
. Backup
. Network Security Management
. Media Handling
. Exchange of Information
. Electronic Commerce Services
. Monitoring
. Summary
. References
ACCESS CONTROL
. Business Requirements for Access Control
. User Access Management
. User Responsibilities
. Network Access Control
. Operating System Access Control
. Application and Information Access Control
. Mobile Computing and Teleworking
. Summary
. References
INFORMATION SYSTEMS ACQUISITION, DEVELOPMENT, AND MAINTENANCE
. Security Requirements of Information Systems
. Correct Processing in Applications
. Cryptographic Controls
. Security of System Files
. Security in Development and Support Processes
. Technical Vulnerability Management
. Summary
. References
INFORMATION SECURITY INCIDENT MANAGEMENT
. Reporting Information Security Events and Weaknesses
. Management of Information Security Incidents and Improvements
. Summary
. References
BUSINESS CONTINUITY MANAGEMENT
. Information Security Aspects of Business Continuity Management
. Summary
. References
COMPLIANCE
. Compliance with Legal Requirements
. Compliance with Security Policies and Standards, and Technical Compliance
. Information Systems Audit Considerations
. Summary
. References
APPENDIX A: ISO STANDARDS CITED IN ISO/IEC 17799:2005 APPENDIX B: GENERAL REFERENCES INDEX
-------------------------------------------------------------
Editorial Reviews
I have had the pleasure of working with Tim on several large risk assessment projects and I have tremendous respect for his knowledge and experience as an information security practitioner. … Risk assessment is the cornerstone of an effective information security program. … striving to achieve compliance in the absence of a risk-based security strategy can only lead to failure. … Implement an effective risk assessment program and take control of the compliance monster. … This book will help you do just that. I know you will benefit from Tim's guidance on how to get the most from your risk assessment efforts. For today's information security leaders, there is not a topic more important.
-From the Foreword by Gary Geddes, CISSP, Strategic Security Advisor, Microsoft Corporation
-------------------------------------------------------------
Book Description
Organizations rely on digital information today more than ever before. Unfortunately, that information is equally sought after by criminals. New security standards and regulations are being implemented to deal with these threats, but they are very broad and organizations require focused guidance to adapt the guidelines to their specific needs. Fortunately, Information Security: Design, Implementation, Measurement, and Compliance outlines a complete roadmap to successful adaptation and implementation of a security program based on the ISO/IEC 17799:2005 (27002) Code of Practice for Information Security Management. The book first describes a risk assessment model, a detailed risk assessment methodology, and an information security evaluation process. Upon this foundation, the author presents a proposed security baseline for all organizations, an executive summary of the ISO/IEC 17799 standard, and a gap analysis exposing the differences between the recently rescinded version and the newly released version of the standard. Finally, he devotes individual chapters to each of the 11 control areas defined in the standard, covering systematically the 133 controls within the 39 control objectives. Tim Layton's Information Security is a practical tool to help you understand the ISO/IEC 17799 standard and apply its principles within your organization's unique context.
-------------------------------------------------------------
Sunday, September 23, 2007
Information Security Principles (ISO/IEC 17799)
- An Information Security Policy document will be available to all staff and students
- Senior management shall set a clear direction and demonstrate support for, and commitment to, information security across the University
- Information systems owners will be responsible for ensuring the design, operation and use of IT systems comply with Information Security Policies
Security organization
- Responsibility for governing and managing security of information rests with the executive management of the University
- A management framework will be established to initiate and control the implementation of information security within the University
- Information security governance must fit into and support the IT governance framework
- Responsibilities for the protection of individual assets, and for carrying out specific information security processes, rest with information systems owners
- Third parties will be provided access under formally managed conditions only
- Security requirements must be addressed as part of outsourcing contracts
Asset classification and control
- All information systems should be accounted for and have a nominated information system owner
- Classification labels must be used to indicate the need and priorities for security protection
Personnel security
- Security should be addressed at recruitment, included in relevant job descriptions and contracts, and monitored
- Users of information should be trained in security procedures and the correct use of IT facilities
- Users should be formally authorised in writing of their scope to access information systems
- Incidents affecting security should be reported through approved channels as quickly as possible
- All staff, contractors and students should comply with all prevailing legal and community standards relating to data confidentiality and privacy
Physical and environmental security
- IT facilities supporting critical or sensitive business activities must be physically protected from :
+ unauthorized access, damage and interference
+ the effects of environmental events such as fire, electrical supply failure, natural disasters and terrorism
Computer and network management
- The integrity, accuracy and availability of data is to be maintained in a manner appropriate to the business requirement
- Procedures must be established for the operation and management of all computers and networks
- Controls are to be developed to reduce the risk of negligent or deliberate system misuse
Access control
- Access to computer services and data should be controlled on the basis of business requirements
- IT will provide appropriate access and security control systems
- Users should only be allowed access to the data that is necessary for them to do their job
Systems development and maintenance
- Security requirements must be identified and agreed prior to the development or procurement of IT systems
- Appropriate controls, including audit trails, should be designed into applications
- Access to project, support and development environments and associated test data should be closely controlled
Business continuity planning
- Plans must be available to protect critical business processes from the effects of major failures and disasters
Audit and compliance
- All relevant statutory and contractual requirements of information systems should be explicitly defined and documented
- The security of IT systems should be regularly and independently reviewed
- Adherence to all relevant privacy laws is compulsory
- Data will be protected against loss and unauthorised access commensurate with its value and the requirements of the regulators and legislators
- IT will monitor and report on access and security breaches, including unsuccessful attempts
Source : http://www.auckland.ac.nz/security/InformationSecurityPrinciples.htm
Thursday, September 20, 2007
ISO 17799: Standard for Security
by Myler Ellie, Broadbent George
Organizations can use ISO 17799 as a model for creating information security policies and procedures, assigning roles and responsibilities, documenting operational procedures, preparing for incident and business continuity management, and complying with legal requirements and audit controls.
Pretexting. Zero Day Attacks. SQL Injections. Bots and Botnets. Insider Infractions. Click Fraud. Database Hacking. Identity Theft. Lost Laptops and Handhelds. According to Ted Humphreys, in a recent International Organization for Standardization (ISO) press release, "It is estimated that intentional attacks on information systems are costing businesses worldwide around $15 billion each year and the cost is rising."
Organizations need to address information security from legal, operational, and compliance perspectives. The risk of improper use and inadequate documentation abounds, and the penalties are greater than ever. By combining best practices outlined in the international standard ISO/IEC 17799 Information Technology - Security Techniques - Code of Practice for Information security Management (ISO 17799) with electronic records management processes and principles, organizations can address their legal and compliance objectives. This article explores the opportunity to bridge the gaps and bring together information security, intellectual property rights, protection and classification of organizational records, and audit controls.
ISO 17799 Components, Applications, Implications
ISO 17799 provides a framework to establish risk assessment methods; policies, controls, and countermeasures; and program documentation. The standard is an excellent model for organizations that need to:
* Create information security policies and procedures
* Assign roles and responsibilities
* Provide consistent asset management
* Establish human and physical security mechanisms
* Document communications and operational procedures
* Determine access control and associated systems
* Prepare for incident and business continuity management
* Comply with legal requirements and audit controls
Information security can be defined as a program that allows an organization to protect a continuously interconnected environment from emerging weaknesses, vulnerabilities, attacks, threats, and incidents. The program must address tangibles and intangibles. Information assets are captured in multiple and diverse formats, and policies, processes, and procedures must be created accordingly.
Organizations can use this standard not only to set up an information security program but also to establish distinct guidelines for certification, compliance, and audit purposes. The standard provides various terms and definitions that can be adopted as well as the rationale, the importance, and the reasons for establishing programs to protect an organization's information assets and resources. Figure 1 depicts the suggested steps and tasks associated with establishing and implementing an information security program.
This ISO framework is methodically organized into 11 security control clauses. Each clause contains 39 main security categories, each with a control objective and one or more controls to achieve that objective. The control descriptions have the definitions, implementation guidance, and other information to enable an organization to set up its program objectives according to the standard methodology.
Step 1: Conduct Risk Assessments
This component of the standard applies to activities that should be completed before security policies and procedures are formulated.
Risk is defined as anything that causes exposure to possible loss or injury. Risk analysis is defined as a process of identifying the risks to an organization and often involves an evaluation of the probabilities of a particular event or an assessment of potential hazards. Loss potentials should be understood to determine an organization's vulnerability to such loss potentials.
Risk categories are both internal and external and can include:
* Natural: Significant weather events such as hurricanes, flooding, and blizzards
* Human: Fire, chemical spills, vandalism, power outages, and virus/hackers
* Political: Terrorist attacks, bomb threats, strikes, and riots
Conduct risk assessments to understand, analyze, evaluate, and determine what risks organizations feel are likely to occur in their environment. Risk assessment activities involve information technology (IT) and information processing facilities, facilities management and building security, human resources (HR), records management (RM) and vital records protection, and compliance and risk management groups. These groups must collectively determine what the risks are, the level of acceptance or non-acceptance of that risk, and the controls selected to counteract or minimize these risks.
Risk analysis is conducted to isolate specific and typical events that would likely affect an organization; considering its geography and the nature of its business activities will help to identify risks. Loss potential from any of these events can result in prohibited access, disrupted power supplies, fires from gas or electricity interruptions, water damage, mildew or mold to paper collections, smoke damage, chemical damage, and total loss (with the destruction of the entire building).
Regularly monitor emerging threats and evaluate their impacts, as this is a constant, moving target. For example, according to an IMlogic article, "IM [instant messaging] worms are the most prevalent form of IM malware, representing 90 percent of all unique attacks in 2005. These attacks frequently utilized social engineering techniques to lure end users into clicking on suspicious links embedded inside IM messages, enabling the activation of malicious code that compromised the security of host operating systems or applications."
Although threats are increasingly sophisticated in the virtual sphere, the simple occurrence of employees stealing company information on paper is still very real and prevalent in today's work space.
Step 2: Establish a security Policy
These components of the standard provide the content that should be included as well as implementation guidance to set the foundation and authorization of the program.
To set its precedence, an information security policy should be developed, authorized by management, published, and communicated. It should apply to all information assets and must demonstrate management's commitment to the program. Explain implications on work processes and associated responsibilities and outline them in employee job descriptions.
The security policy should be administered, documented, and periodically evaluated and updated to reflect organizational goals and lines of business. This is captured under clause 6.0 for organizing information security. It reflects administrative and management activities to implement the security policy. All activities must identify authorities, responsibilities, agreements, and external security requirements. This has an impact on information processing facilities, external parties, access issues, and problem resolution measures. Keep a record of all policy administration activities to create historical relevance for the information security program.
Step 3: Compile an Asset Inventory
This component of the standard addresses asset management, controls, and the protection thereof. It applies to all assets in tangible and intangible form.
Identify the organization's intellectual property (IP), tools to create and manage IP, and physical assets with a detailed inventory so the organization knows what type of resources it has, where they are located, and who has responsibility for them. Identifying how assets are to be used, classified, labeled, and handled is necesk sary to establish an asset management inventory.
This inventory should also distinguish the types, formats, and ownership control issues. Implement associated rules for the use of assets including e-mail, Internet usage, and mobile devices. Classifying assets and establishing procedures for labeling and handling according to the classification scheme are also important. Documents in electronic form will lend themselves to being identified through metadata and document properties completion. However, these processes must all be completed by resources. Although automation of these processes is a possibility, an organization still faces extensive costs and resource coordination to address this piece.
Step 4: Define Accountability
This component of the standard addresses the human aspect of security; it applies to the level of accountability that employees, contractors, and third-party users have to use to protect an organization's information assets.
An information security program will not be implemented unless roles and responsibilities are clearly articulated and understood by those having ownership in the program. Ideally, these roles and responsibilities should be outlined in job descriptions and documented in terms and conditions of employment.
Employees are part of the overall information security landscape and often they are the closest and best able to prevent certain incidents from occurring. HR is typically in charge of these issues, but they must collaborate with IT and RM to ensure that all information assets are addressed accordingly.
Define roles and responsibilities during pre-employment and screening processes, and perform background checks to support the hiring process. If the job mandates working with highly sensitive information, an organization must be on guard to hire the most qualified person to perform these tasks. These employees must possess a great deal of integrity, pay attention to detail, and take their responsibilities seriously.
Information security awareness, education, and training must be a routine activity to keep employees informed, to communicate expectations, and to provide updates on their responsibilities. Standardize a disciplinary process for security breaches.
When employees leave or change jobs, it is essential that HR, in collaboration with other stakeholders, follows through with a return of assets process and removal of access rights, which can be captured in HR exit processes and procedures. This often is not a coordinated process, which allows employees to walk off with information or leave behind on servers and in physical work spaces masses of orphaned and unidentified information. Redesign the HR exit interview to ensure that information return or transfer is a coordinated process.
Step 5: Address Physical security
This component of the standard outlines all the requirements for physical security perimeters and authorized entry controls; measures for protecting against external and environmental threats; equipment security, utilities, and cabling considerations; and secure disposal or removal of storage equipment media.
An organization's building and premises, equipment, and informationprocessing facilities must be fail proof to prevent unauthorized intrusions and access, and possible theft issues. This applies mostly to facilities management and IT, although risk management should also participate to provide environmental risk protection measures.
Include guidelines for physical security perimeters, entry controls, environmental threats, and access patterns in this section. Also address supporting utilities, power, and telecommunication networks. Finally, secure the disposal and removal of equipment that holds information so that information is truly deleted or "wiped" clean from the slate.
Step 6: Document Operating Procedures
Procedures for system activities, change management controls, and segregation of duties are included in this component.
Any organizational program will be more established when program administration, policies, procedures, and related processes are formally documented. This component sets out to define operating procedures, instructions for the detailed execution thereof, and the management of audit trail and system log information. It applies to all facets of an information security program.
Formally documenting program activities will allow an organization to keep track of the development, implementation, and associated documentation for the program. Keep in mind that documentation does not magically appear through word processing programs. It takes resources, good writing skills, and an ability to change documentation when necessary.
Address the separation of development, test, and operational facilities to reduce the risk of unauthorized actions. Monitor and review thirdparty service delivery requirements to ensure that actions are carried out as mandated. Plan for, monitor, and update system resources, capacity management, and acceptance criteria, as necessary.
Constantly monitor and prepare to protect against malicious and mobile code to guard the integrity of system software and information. This especially pertains to intelligent cybercrime activities such as structured query language injections and application to mobile devices, which are increasingly becoming more sophisticated. This should also focus on incoming e-mails and downloadable attachments, as well as a review of webpages.
Backup and restoration procedures must provide for the replication of information and methods for dispersal and testing, meeting business continuity requirements. This should also address retention periods for archival information or those with long-term retention requirements. Address media preservation issues to ensure the longevity of media that have long-term retention requirements.
Address network infrastructure through network controls and management. This includes:
* Remote equipment and connections
* Public and wireless networks
* Authentication and encryption controls
* Firewalls and intrusion detection systems
* Media handling and transit methods
* Information classification, retention, and distribution policies and proceduresAlthough mobile devices have helped organizations stay better connected, employees must use more discretion when using them. Alert employees to proper etiquette for relaying information so they will not be overheard in elevators, airports, or on other public transportation.
Address electronic data interchange, e-commerce, online transactions, electronic signatures, electronic publishing systems, and electronic communication methods such as e-mail and IM. Their secure use and associated procedures must demonstrate accuracy, integrity, and reliability. For organizations using e-commerce, this is not an option, as current regulations are pushing this into the forefront of IT agendas. Organizations should also monitor their systems and record security events through audit logs. Also address records retention policies for archival or evidence requirements.
Step 7: Determine Access Controls
This component of the standard includes guidelines for establishing policies and rules for information and system access.
Practice standard methods for all users and system administrators to control access to and distribution of information. Policies should apply to users, equipment, and network services. Newer technologies, such as those that have passwords connected to fingerprint digital touch pads, come at a cost, but they should be evaluated as a password management tool.
Access control measures should include:
* Setting up user registration and deregistration procedures
* Allocating privileges and passwords
* Implementing a "clear desk and clear screen policy"
* Managing:
- Unattended equipment
- Virtual private network solutions
- Wireless networks and authentications
- Network service issues such as routing and connections
- Telecommuting virtual spaces and intellectual property rights
- Cryptographic keys and procedures
- Software development, testing, and production environments
- Program source code and libraries
- Change control procedures and documentation
- Patches, updates, and service packs
Any information system that an organization procures or develops must also include security requirements for valid data input, internal processing controls, and encryption protection methods. Document the integrity, authenticity, and completeness of transactions through checks and balances. Retain and archive system documentation for configurations, implementations, audits, and older versions. This is further detailed in clause 12 of the standard.
Step 8: Coordinate Business Continuity
This component of the standard includes reporting requirements, response and escalation procedures, and business continuity management.
As organizations increasingly come under attack and suffer security breaches, they must have some formalized manner of responding to these events.
Business continuity management addresses unexpected interruptions in business activities or counters those events that impede an organization's critical business functions. This process should include:
* Identifying risks and possible occurrences
* Conducting business impact analyses
* Prioritizing critical business functions
* Developing countermeasures to mitigate and minimize the impact of occurrences
* Compiling business continuity plans and setting up regular testing methods for plan evaluation and update
A business continuity management framework also includes emergency or crisis management tasks, resumption plans, recovery and restoration procedures, and training programs. Testing the plan is an absolute must to determine its validity. Tests can include a variety of methods to simulate and rehearse real-life situations. Develop calling trees, hot- and cold-site configurations, and third-party contractors, depending on the organization's priority of critical business functions.
Report information security incidents or breaches as soon as possible to ensure that all relevant information can be remembered. This requires having feedback processes in place as well as establishing a list of contacts that are available around the clock to manage this process. Procedures should be consistent and effective to ensure orderly responses to not only manage the immediate process but also to collect evidence for legal proceedings.
Step 9: Demonstrate Compliance
This component of the standard provides standards for intellectual property rights, RM requirements, and compliance measures. These apply to everything from an organization's information processing systems to the granular data and transactional records contained within those systems.
There is an increased scrutiny on organizations to demonstrate compliance with applicable laws, regulations, and legislative requirements for all aspects of their business transactions. Adherence to rules and regulations are an integral part of the information security program and will contribute to demonstrating corporate accountability.
Address identification, categorization, retention, and stability of media for long-term retention requirements according to business and regulatory requirements. Document retention periods and associated storage media as part of managing the organization's records. Address privacy and personal data requirements, which can vary from one country to the next. Address transborder data flow and movement, and associated encryption methods as related to import and export issues depending on federal laws and regulations.
Follow up on and evaluate compliance with established policies and procedures to determine implementation effectiveness and possible shortcomings. Clearly delineate audit controls and tools to determine areas for improvement. Again, it is critical to take time to document all information related to the development and establishment of compliance and audit, including decisions made, resources involved, and other source documentation cited.
Data Breach Reporting Issues
New information security requirements are emerging as a result of organizations' negligence to protect sensitive data and impose adequate controls on employees using mobile technology to house such data. Information security issues are constantly in the media, as with the recent case when the U.S. Department of Veterans Affairs (VA) lost control of the personal information of 28 million veterans when a laptop containing the information was stolen from an employee's home. The VA was criticized for its delay in disclosing the loss and notifying those affected.
California Senate Bill (SB) 1386 is setting the precedent for reporting and disclosing data security breaches and declarations for privacy and financial security. (See Figure 2 "California SB 1386 Excerpts, Source and Language Summary.") Other states are now adopting laws allowing consumers to "freeze" their credit files, even if they have not been a victim of identity theft. If passed, pending bills in the U.S. Congress, including S.1408: Identity Theft Protec-tion Act and H.R. 4127: The Data Accountability and Trust Act, would also force organizations to be more accountable for the vast amount of personal information that they may have.
Organizations should take heed of these legislative efforts and proactively plan for them by updating their information security practices. Any organization that uses e-commerce in its business practices must align its systems and databases for the protection of information content. Organizations that are subject to these laws should structure their reporting measures according to the following components of the ISO 17799 standard:
* Clause 10.9 establishes electronic commerce countermeasures and cryptographic controls to protect sensitive customer information and all associated electronic records databases.
* Clause 13.1 provides a methodology for reporting incidents supported by timely procedures with appropriate behavior mechanisms and disciplinary processes.
Information Security Objectives and Records Management Components
Although information security is now in the limelight and is being brought to the attention of the executive-level audience, RM is still the basic foundation that branches out into all the various new compliance areas. Records managers need to work with IT to ensure that retention and vital records requirements are addressed and are part of the many inventories that the ISO standard suggests. They must also update their programs to be in line with an information security program's objectives as outlined in the controls and implementation guidance of the ISO 17799 standard.
Maintenance, retention, and protection requirements of data, information, and IP are addressed in the ISO clauses in Figure 3.
Vital records are those records that are needed to resume and continue business operations after a disaster and are necessary to recreate an organization's legal and financial position in preserving the rights of an organization's employees, customers, and stockholders. If vital records protection methods exist before an information security program is established, they should be integrated or referred to as part of the larger information security scheme. IP and the management and protection thereof have long been addressed by organizations through a vital records program. When electronic records were not prevalent, vital records protection methods included the same premises, such as:
* Appraisal and identification of those records that are deemed vital
* Duplication and dispersal processes
These methods can apply to any electronic environment but the inventories of such records must include not only the paper versions but also their electronic counterparts captured in other media or systems within the organization.
The objective to protect electronic vital records must focus on:* Newly created records
* Work in progress
* Other information that is not stored on servers and is typically found on users' desktops
Although it can be argued that many electronic records are captured in enterprise resource planning systems, routine backups of this data may be re-circulated so that long-term retention and protection requirements are not addressed.
Initially, allowing employees to transport laptops and other devices with large amounts of data away from the corporate environment was seen as a way to increase productivity. That is still the case, but controls in the form of policies as to what can and cannot be taken must be established and consistently enforced. As technology offers more ways to compact large amounts of data on very small devices, it is crucial to monitor and correct employees to prevent their actions from compromising the organization's responsibilities for keeping information safe. Establish, fund, and monitor training, support, and compliance to ensure that employees receive appropriate training before turning them loose with the tools.
Compliance also applies to information systems and their audit considerations. Administrators running an organization's information systems must be just as closely scrutinized as the employees within the organization and in virtual spaces.
Stay Ahead of the Curve to Stay Secure
While information security is the newest flavor of the month, chances are that many organizations have no program in place and, therefore, no control over how their employees manage information.
Organizations cannot continue to practice their business in an irresponsible manner. Using the ISO standard to structure their programs is the foundation, but they must also stay ahead of the curve, outguessing and outsmarting potential incidents and occurrences. Websites for information security are pervasive and provide both written materials and podcasts to help keep information professionals informed. Records managers and IT professionals can also help each other achieve a best practices program for information security.
However, any program that an organization initiates will need management support and resources to accomplish it. Collaboration by all parties, including senior management, is essential to achieve compliance in the space of information security.
References
ARMA International. "VA IG Slams Top Officials in VA Data Theft Incident." Washington Policy Brief, July 2006. Available at www.arma.org/news/policybrief/index.cfm?BriefID=1335 (accessed 26 September 2006).
Bartholomew, Doug. "Responding to Risk: Invisible Enemies." Industry Week, 1 March 2006. Available at www.industryweek.com/ReadArticle.aspx?ArticleID=11440 (accessed 26 September 2006).
Greenemeier, Larry. "The Next Data Breach Could Mean Your IT Job." Information Week 17 July 2006. Available at www.informationweek.com/security/showArticle.jhtml?artideID= 190400266. (accessed 26 September 2006).
IMlogic. IMlogic Threat Center - 2005 Real-Time Communication Security: The Year in Review. Accessed 12 July, 2006 at www.imlogic.com/pdf/2005ThreatCenter_report.pdg. No longer available.
International Organization for Standardization. ISO/IEC 17799: 2005, Information Technology - Security Techniques - Code of Practice for Information Security Management, Geneva, Switzerland: International Organization for Standardization, 2005.
_____. ISO/IEC 18043:2006, Information Technology - Security Techniques Selection, Deployment and Operations of Intrusion Detection System, Geneva, Switzerland: International Organization for Standardization, 2006.
_____. "New ISO/IEC Standard to Help Detect IT Intruders." Available at www.iso.org/iso/en/commcentre/pressreleases/2006/Ref1017.html (accessed 26 September 2006).
U.S. House. Data Accountability and Trust Act, 109th Congress, H.R. 4127. Available at www.govtrack.us/congress/bill.xpd?bill=h109-4127 (accessed 26 September 2006).
U.S. Senate. Identity Theft Protection Act, 109th Congress, S.1408. Available at www.govtrack.us/congress/bill.xpd?bill=s109-1408 (accessed 26 September 2006).
Ellie Myler, CRM, and George Broadbent
Elite Myler is a Certified Records Manager and Certified Business Continuity Professional and a 17-year veteran of the records management industry. A Senior Records Management Analyst with Entium Technology Partners LLC, Myler has previously served as a consultant to Fortune 500 companies in a wide spectrum of industries. She designs and customizes corporate governance programs for records management and business continuity program initiatives and writes and lectures frequently on information management and technology topics. She may be reached at emyler@entium.com.
George Broadbent has more than 17 years of diversified system architecture, network design and implementation, and application development experience, including network management of Novell NetWare and Microsoft Windows 2000/2003 networks. He has designed and built local and wide area networks (LANs/WANs) that include the use of high-availability systems, real-time data replication and hierarchical storage solutions for large multi-site organizations. He has performed the architecture, design, implementation, deployment, and/or support of enterprise electronic mail systems with integrated electronic archiving solutions for Microsoft Exchange-based systems. He can be reached at gbroadbent@entium.com.
Copyright ARMA International Nov/Dec 2006
Provided by ProQuest Information and Learning Company. All rights Reserved
Source : http://findarticles.com/p/articles/mi_qa3937/is_200611/ai_n16871475
Tuesday, September 4, 2007
Enhancing HIPAA Security Rule Compliance Efforts
Gary Swindon, CISM, CHS-III
Chief Operating Officer, RiskWatch Inc.
Protecting and securing medical information is a major concern for private, public, and government organizations in the health-care industry. Internal auditors are equally aware of this importance: Ensuring health-care records and other sensitive information do not fall into the wrong hands is of special concern. Auditors must determine whether or not the organization has taken the necessary steps to prevent the inappropriate exposure, damage, or loss of confidential data.
Since 1996, the U.S. Health Insurance Portability and Accountability Act (HIPAA) has provided organizations in the United States with guidance regarding the proper ways to protect personal health information through the act's Privacy and Security rules. While HIPAA's Privacy Rule provides information to help organizations regulate how they use and disclose personal health information, its Security Rule lists 42 standards companies need to implement to ensure the confidentiality, integrity, and availability of digital personally identifiable health information. Although both rules should be used together, the Security Rule is of special importance to IT departments, because it identifies how organizations can protect personal health information from external and internal security threats, such as e-mail attacks and password compromises.
Internal auditors can help organizations prepare for the IT component of the HIPAA security audit by focusing management's attention on key compliance considerations, such as the organization's IT governance structure; helping IT departments identify how the Security Rule's 42 standards will affect the organization's current IT environment; and comparing each of the report's findings to IT guidance provided in the Security Rule. This will enable auditors to help organizations gain the most from their HIPAA security audits.
SECURITY RULE COMPLIANCE CONSIDERATIONS
HIPAA compliance audits should be based on three things:
- An identification of the organization's governance model. Examples of IT governance models organizations might consider using include the IT Infrastructure Library, ISACA's Control Objectives for Information and related Technology (CobiT), and the International Standards Organization's (ISO's) 17799 or 27001 standards.
- A traditional screening, sometimes called a checklist, of all controls, countermeasures, and items of interest as defined in the scope of the audit.
- An identification of the master rules or conditions required by the regulation based on the organization's type (i.e., private, nonprofit, or publicly traded).
In the case of HIPAA's Security Rule, audits should be based on the rule's provisions or standards (i.e., safeguards and outcomes specified in the body of the regulation, as opposed to industry best practices) and be supplemented by the organization's chosen governance model. Understanding the organization's IT governance model is important, because it enables auditors to determine which standards the company views as appropriate and should be used in the conduct of the audit. The IT governance model also helps auditors frame audit findings and recommendations pertaining to IT controls and identify whether these controls are effective based on HIPAA compliance requirements. If the firm has no adopted IT governance model, the use of generally accepted IT industry standards to conduct the audit would be appropriate, such as ISO's 17799 and 27001 standards, CobiT, or the National Institute of Standard and Technology's Security Self-Assessment Guide for Information Technology Systems (PDF, 1.48MB)
The findings of the audit should help to confirm or call into question the governance model chosen. Audit results that indicate a clear pattern of noncompliance with rules and regulations should warn executives that the company's governance model may not be appropriate.
Traditional screenings or checklists identify required compliance elements that will be reviewed during the audit, such as key items to be addressed, personnel to be interviewed, and new or existing policies. These checklists are important, because they enable the auditor to provide a list of the different areas that need to be improved or implemented for compliance to take place.
Finally, an identification of the master rules or conditions required by the regulation based on the organization's type is important, especially in situations where the company chooses to meet other standards as a demonstration of its good intentions. A good example of this is when a private nonprofit organization adopts IT controls outlined in Section 404 of the U.S. Sarbanes-Oxley Act of 2002, even though the company is exempt from Sarbanes-Oxley compliance. HIPAA's Security Rule identifies four minimum requirements or master conditions that all implemented IT measures and controls need to meet (refer to "HIPAA Security Rule Master Conditions" for more information).
THE AUDIT PROCESS
The Security Rule allows auditors to construct their audit plans more effectively by expressing desired outcomes under three safeguard categories — administrative, physical, and technical. Each of these safeguards is divided into a number of standards — 42 total — which are then categorized as required or addressable. These outcomes can be found in a matrix that has been incorporated into the final Security Rule and is available on the Centers for Medicare and Medicaid Services Web site. Although required standards must be implemented as outlined in the Security Rule, addressable standards can be structured by the entity to suit its particular needs as long as the outcome conforms to those found in the Security Rule. This process is outlined in Figure 1.
Figure 1: HIPAA Security Rule audit process
HIPAA security audits require the auditor to pay attention to the prevailing general conditions or stipulations that may impact the audit plan, as well as how existing controls and methods address each of the 42 security standards. In terms of IT, auditors need to review the organization's use of appropriate controls to ensure the protection of personally identifiable health information. The following list provides useful information auditors should keep in mind during Security Rule audits:
- The HIPAA Security Rule is tied directly to the HIPAA Privacy Rule and incorporates elements of the Privacy Rule through cross referencing. For instance, the requirement found in paragraph 164.530 of the Privacy Rule deals with policies and procedures, including IT, and is carried forward in the Security Rule in its requirement for appropriate policies and procedures and in the retention period for them.
- The Security Rule's scope is corporatewide and applies to the implementation of security standards in all relevant business processes, not just IT.
- The Security Rule represents a minimum set of security standards organizations must have in place for compliance. Many businesses have processes and requirements that are unique to the way they do their work. As a result, appropriate additional IT controls and procedures should be in place.
- The Privacy and Security rules incorporate the extension of adopted IT and other standards to business partners through the formal Business Associate Agreement process. This is a formal standard stated in both rules. The standards for privacy and security are found in the Privacy Rule and Security Rule, respectively.
- The standards found in the Security Rule and the company's implementation of corresponding IT and other controls must be based on the results of periodic risk assessments conducted by the company. The results of these risk assessments will help the auditor determine the effectiveness of companywide information security efforts to protect business assets.
HIPPA SECURITY RULE MASTER CONDITIONS
The Security Rule outlines four master conditions or minimum requirements that apply to business controls and processes used to address the rule's 42 standards. These minimum requirements state that all selected controls must be:
- Cost effective. A company should not spend more for the control's implementation than the probable value of the information or process it is designed to safeguard.
- Within the technical capability of the firm. The company must be able to maintain and enforce the controls they choose without having to rely on an outside party. For instance, although a company can outsource its IT functions, it must be able to create, maintain, and enforce all IT controls if they are brought back in-house, such as access and authorization controls and audit log evaluations.
- Within the resource capability of the enterprise. The business should have the necessary IT resources to monitor and manage each control throughout the year.
- Suitable when weighed against their desired results. General IT, compensating, or alternative controls should correspond directly to the standard in question. For example, the requirement to be able to back up and restore patient data should rely on access controls, data verification and integrity controls, and storage requirements, among others.
During Security Rule compliance reviews, internal auditors need to identify how companywide IT measures and controls meet each of the four requirements.
EXAMINING THE REPORT'S FINDINGS
Prior to releasing audit findings, internal auditors should be able to answer questions regarding the report's IT recommendations. To do this, auditors can compare each of the report's findings to IT guidance provided in the Security Rule. The following questions can help auditors identify how current IT controls compare to IT guidance provided in the Security Rule, as well as determine whether existing controls meet compliance requirements:
- Given the IT governance model adopted by the firm, does the chosen IT control match the company's intention? If so, does it fit logically?
- Does the chosen IT control meet the general and master conditions outlined in the Security Rule? For example, does it meet the cost, capability, resource, and suitability requirement in the rule?
- Given the apparent investment level in the IT control, is the investment appropriate to accomplish the goal?
- As with any audit, are the IT controls documented adequately?
- Do IT controls tie to a stated security standard outlined in the Security Rule or to an identified business need above and beyond the rule's standards?
- Has the firm identified and documented addressable and required IT controls properly, including its rationale for the choice of action?
- For any given IT control, is there an obvious impact regarding the viability of the security system employed?
- Do audit findings represent a material condition or weakness (e.g. not being able to recognize revenue correctly and consistently or ensuring that pharmacy prescriptions are filled in a timely manner)? If so, is the finding material in its potential impact on financial systems, patient care safety standards, etc.?
- Do chosen IT controls support the company's risk posture? Auditors should look to the IT governance model for direction or to accepted industry standards if no governance model has been identified.
- Do the IT standards and controls make sense in the context of the company's choices as opposed to IT best practices?
LEVERAGING AUDIT RECOMMENDATIONS
Although the information above focuses primarily on the IT aspect of Security Rule compliance, these basic recommendations can be used for overall HIPAA compliance audits. These recommendations also can be applied to other regulations, particularly Sarbanes-Oxley and the U.S. Graham-Leach-Bliley Act (GLBA) of 1999. For instance, HIPAA, Sarbanes-Oxley, and GLBA share many common requirements, such as the need for companies to conduct regular risk assessments or the need to achieve cost effectiveness and stay within the company's IT capability. Furthermore, the blending of implemented audit compliance requirements from different regulations and the organization's adopted governance model can highlight the potential need for changes in the way the company views IT risks and uses IT resources.
For more information about HIPAA, visit:
- The U.S. Department of Health and Human Services' Web site: www.hhs.gov/ocr/hipaa/.
- The U.S. National Institute for Standards and Technology's Security Rule Resource Guide: http://csrc .nist.gov/publications/nistpubs/800-66/SP800-66.pdf. (PDF, 1.68KB)
- The HIPAA Security Rule Web page located on the U.S. Centers for Medicare and Medicaid Services Web site: www.cms.hhs.gov/SecurityStandard/Downloads/securityfinalrule.pdf. (PDF, 309KB).
Gary Swindon is the chief operating officer for RiskWatch Inc., a security risk assessment company. Prior to RiskWatch, Swindon held senior positions in both public and private organizations, including Orlando Regional Healthcare, where he was the hospital group's chief information security officer; WebMD, where he served as chief security and privacy officer; and the state of Michigan, where he was responsible for consolidating more than 20 data centers. He also has served as a director for the ISACA CISM certification board.
Source : www.theiia.org/ITAudit/
7 Steps to a Highly Effective IT Compliance Program
By Michael Rasmussen, Vice President of Enterprise Risk & Compliance Management, Forrester Research Inc.
Regulatory compliance pressures are plaguing organizations around the world. Unfortunately, because compliance challenges often affect multiple areas of an organization and can span across different industries, there is no silver-bullet technology package that will bring companies into compliance. In addition, recent corporate disasters and growing government regulatory action have heightened the focus on corporate governance and are driving the centralization of compliance oversight within today's organization. Because most IT functions permeate the organization and its processes, IT compliance is also a process that requires continuous oversight and management.
To meet IT compliance obligations, many companies are looking for a structured approach that allows them to identify and prioritize IT controls and establish a compliance record system. But, implementing an IT compliance program that is effective and responds to the dynamic business environment can be challenging. Nevertheless, having a structured approach is a major step toward compliance with different standards and legislation, such as the U.S. Sarbanes-Oxley Act of 2002, the International Organization for Standardization (ISO) 27001 standard, and the European Union (EU) Directive on Data Protection of 1995. To ensure their IT infrastructure is compliant year-round, organizations can incorporate a series of seven steps to existing operations. When combined with a formal risk assessment process and IT asset management strategy, these seven steps can bring companies one step closer to compliance.
THE 7 STEPS
In 1991, the U.S. Sentencing Commission (USSC) established the Organization Sentencing Guidelines to assist courts in setting fines for organizations and sentences for executives in criminal regulatory cases. The USSC based its model on seven core elements. In 2001, the original USSC guidelines went into revision to include Sarbanes-Oxley compliance and sentencing information.
Using the USSC guidelines as a basis, Forrester Research — a technology and market research company that advises organizations about technology's impact on businesses and consumers — extended the seven elements by integrating compliance best practices in large organizations. When examined in detail, however, these seven practices or steps are equally useful in small and mid-size enterprises. The extended guidelines provide a framework around which organizations can structure their IT compliance management programs, as well as information that could help organizations in their compliance efforts with non-US regulations, such as ISO 27001 and the EU Directive on Data Protection. Below is a description of each step and key points organizations need to keep in mind when implementing each of these recommendations.
Step No. 1: Document the Policy and Control Environment
To demonstrate IT compliance, firms must start by identifying how they document the compliance process and their IT control architecture. The overall compliance documentation architecture should be implemented through a control framework, such as the Information Systems and Audit Control Association's Control Objectives for Information and related Technology (CobiT), and should document all corporate IT policies, controls, standards, and procedures that align with compliance objectives and requirements.
The policy and control architecture establishes the compliance foundation upon which the remaining seven habits are built. Without a proper governance model of policies and controls, organizations may have a hard time overseeing, communicating, monitoring, enforcing, or responding to gaps. It is the policy and control architecture for compliance that provides the framework for everything else to work within the IT environment. This architecture is unique to each organization, reflecting its culture of control and industry requirements.
After drafting the necessary IT policy and control documentation, organizations need to communicate any relevant documentation clearly to those expected to comply with established policies, procedures, standards, and supporting controls. In addition, companies need to update and maintain all documentation, as well as use an operational control and compliance platform that helps them to manage the complexity of corporate IT policies and compliance controls. This documentation also should include a framework to manage operational risks, define policies and supporting controls to meet risks, conduct control self-assessments to validate IT control implementation and efficiency, and track existing control gaps and incidents within the IT environment.
Step No. 2: Assign Appropriate Compliance Management Oversight
The second element necessary for effective IT compliance is the establishment of appropriate oversight for compliance. In many organizations, the compliance role is divided among different parts of the firm. This results in substantial technology and effort duplication, as well as lack of compliance visibility across the organization.
Effective IT compliance oversight in an organization must achieve the mission and charter of the compliance program. To this end, companies should define IT compliance as a corporate function that has proper authority and governance, as well as create appropriate lines of communication to convey important compliance efforts to all operational areas. The board and executive management team must develop this structure with care and review it at least once per fiscal year for effectiveness. To be successful, organizations should develop a compliance oversight model that:
* Makes executives and the board accountable for compliance.
* Assigns IT compliance responsibility to an oversight manager. This individual may have the title of chief information officer or chief compliance officer.
* Delegates specific compliance areas to distribute oversight.
* Assigns adequate resources (e.g., staff and budget).
* Ensures that the compliance oversight manager has enforcement authority.
* Establishes lines of communication to the business.
* Defines reports and metrics for operational IT control and compliance.
Step No. 3: Require Personnel Screening and Access Control
Ensuring that the organization is not giving access to information and business processes to an individual likely to exhibit unethical behavior is crucial when establishing an effective IT compliance program. One of the greatest risks that organizations face when trying to enforce compliance with regulations is the internal threat from employees, contractors, and business partners. To ensure that appropriate and authorized access is established across the board, organizations should:
* Conduct a background check on employees, contractors, and business partners before allowing them access to sensitive corporate data.
* Use caution when delegating authority.
* Use identity management and provisioning when giving access to IT systems. Provisioning enables administrators to assign system resources and privileges to users, including employees, contractors, and business partners (e.g., many IT managers use provisioning software to enforce security policies).
* Implement access controls based on the person's job function, role, and responsibility.
* Change access rights when internal changes occur (e.g., an employee changes jobs within the organization).
* Revoke access upon termination.
* Conduct routine reviews to check for unethical behavior in personnel and contractors with access to sensitive resources.
* Publicize disciplinary standards. This allows employees to understand the repercussions of noncompliance with access policies and procedures.
Step No. 4: Ensure Compliance Through Training and Communications
Forrester Research's fourth recommendation is the establishment of effective compliance awareness through active training and communication to employees, contractors, and business partners. To avoid corporate wrongdoing and fraud, as well as to reduce liability, organizations must implement effective compliance training programs that help to promote compliance with regulations and rules of corporate conduct. Characteristics of an effective compliance communication and training program include:
* The integration of compliance into the corporate ethics program.
* An active policy communication.
* Required compliance training for all employees, contractors, and consultants who have access to regulated information.
* The acknowledgement of training and policy adherence.
* Up-to-date information regarding relevant changes in regulations and case law.
In essence, companies have to ensure that individuals with access to regulated processes and information understand what they need to do to comply with internal and external regulations.
Step No. 5: Implement Regular Monitoring and Auditing of IT Controls
Monitoring and auditing IT controls for efficiency and effectiveness is the fifth step toward establishing an effective IT compliance program. Where the first recommendation focused on documenting controls, this step focuses on the working operation of those controls. The proper controls to monitor that may affect IT compliance vary in type. Some include:
* Policy, operational, and technical controls.
* Contractual controls.
* Detective, preventive, and corrective controls.
* Compensating controls.
Firms should monitor and audit controls regularly through a manual or automated process, which validates that the control is in place and is operating effectively. When monitoring the management of IT system controls, many organizations prefer automated control monitoring and enforcement to ease the burden of control validation. When controls cannot be automated, organizations should conduct control self-assessments that are facilitated through workflows on compliance management systems. Furthermore, control self-assessments should be augmented by independent verification of audit controls.
Documented controls are meaningless and could become a business liability if they are not implemented or functioning properly. As a result, the role of compliance management is to implement a process of monitoring control implementation and effectiveness. The critical factors in monitoring and auditing IT controls an organization must have are:
* Ongoing validation of controls by management.
* Independent audit verification of controls.
* The establishment of key risk indicators.
* The reporting of control gaps and audit findings in the environment.
* The monitoring of corporate policy compliance.
* The retention and review of audit trails.
In addition, organizations need to establish a process that helps them incorporate any recommendations accepted by management regarding the control monitoring process, and implement an escalation procedure that details how to proceed when agreed-upon recommendations are not implemented.
Step No. 6: Enforce the Control Environment Consistently
The sixth step identifies some of the ways effective compliance programs may promote a consistent enforcement of policies and controls throughout the company. Consistent enforcement of the control environment allows internal controls to be applied appropriately throughout the organization, its business processes, and relationships, as well as make sure specific control violations are not ignored and are enforced according to policy. The organization’s approach to ensure consistent enforcement should drive the success of the overall compliance program. It is through consistent enforcement that the organization’s culture of compliance is achieved and that employees understand there will be zero tolerance for unethical and noncompliant behavior.
If management does not consistently enforce controls and discipline unethical and noncompliant behavior, the compliance program will fail. Penalties for noncompliance increase with regulators and the courts when organizations do not exhibit effective governance and enforcement practices. Vital factors for consistent enforcement of the control environment include:
* Establishing appropriate incentives to endorse strong ethical and compliance behavior.
* Adhering to consistent disciplinary actions.
* Providing open communication and reporting.
* Implementing a systematic approach to incident investigation.
* Establishing a post-incident evaluation process that enables organizations to learn from each incident.
Step No. 7: Prevent and Respond to Incidents and Gaps in IT Controls
An effective IT compliance program prevents and responds to compliance violations and gaps in controls and includes a lessons-learned process to prevent further violations. For instance, identified control deficiencies or incidents should be corrected in an efficient and effective manner. To prevent and respond to IT control incidents, organizations must:
* Develop a control deficiency response plan.
* Maintain an incident response team and procedures.
* Implement active detection and monitoring for gaps and violations.
* Build a lessons-learned process, so the company is not a repeat offender.
* Establish active and cooperative lines of communication with authorities, and communicate with authorities according to response procedures.
* Obtain legal counsel from a knowledgeable source when incidents occur.
Disregarding control gaps and compliance violations amounts to negligence. Therefore, it is essential that an effective compliance program actively identifies and closes all control gaps, as well as contains or eliminates potential damage or loss to the organization incurred by any violations.
BEYOND THE 7 STEPS
Following the seven guidelines above will help organizations build effective IT compliance programs that improve confidence in business performance. In addition, the seven steps help companies manage operational risks and compliance efforts, as well as measure compliance consistently. To implement the steps, organizations need to involve the use of policy, approach compliance as a process as opposed to individual projects, and consider the use of technology to automate compliance management activities.
Furthermore, organizations need to establish a formal risk assessment process so they can take a more comprehensive approach to information security management. This formal risk assessment process will help organizations expand the effectiveness of the seven recommendations above. After conducting an organizationwide information security risk assessment, companies should implement an information asset management strategy, as well as put into practice a business continuity plan that incorporates IT disaster recovery strategies.
ARCHITECTURE FOR SUSTAINABLE COMPLIANCE
Organizations that do not embrace IT compliance management as a defined business process will approach compliance as fragmented projects. Although this mindset may appear to work for a short time, gaps that can push an organization out of compliance may arise quickly. In fact, one of the 11 control areas mentioned in the ISO 27001 standard is compliance with relevant legislation and regulations that affect the organization's activities. Unfortunately, many organizations don't realize what the consequences of noncompliance are until it's too late: When regulators come asking questions, and there is no central person ready to answer them, the organization looks confused and unorganized and receives more scrutiny.
On the other hand, organizations that incorporate the seven steps make effective IT compliance a cost of doing business — not a one-time business event. For these firms, spending money on a compliance program averts far greater expense resulting from losses and penalties. These organizations also establish greater operational control oversight, enabling them to pour more funding into expanding their activities into new areas with confidence. These well-run organizations will contrast sharply with those that remain reactive and tackle compliance problems as isolated and reactionary initiatives. The end game is a culture of IT compliance and controls and a structured approach that demonstrates the business is practicing IT compliance, while managing information security from the most senior level.
Michael Rasmussen is a vice president and analyst in Forrester's IT Management and Services research group. A risk professional with more than 12 years' experience, Rasmussen advises clients around the world on issues pertaining to enterprise risk and compliance management, as well as public policy, legislation, and regulation.
source : www.theiia.org/ITAudit/
Tuesday, August 21, 2007
ISO 17799 — Compliance
Compliance has become one of the most talked about security issues in American business. Banks and financial institutes have had government oversight for decades. New compliance requirements have been imposed upon many organizations.
Recent financial reporting irregularities prompted Congressional action in which public companies must comply to the financial and accounting disclosure of information act known as Sarbannes-Oxley (SOX). Recent trends with identity theft and fraud, any business — small or large — that accepts credit cards, require businesses to abide by the industry’s Payment Card Industry’s Data Security Standard (PCI DSS). For the healthcare industry, organizations must adhere to the Health Insurance Portability and Accountability Act of 1996 (HIPAA).
The ISO 17799 section on compliance has as its objective to help organizations avoid breaches of any criminal and civil law, statutory, regulatory or contractual obligations and of any security requirements. This section marries IT, legal, accounting and security.
Intellectual Property Rights
This is all about patents, trademarks, copyrights including software, and trade secrets. Some recommendations on what an organization can do to help safeguard their IP include: know what you’ve got, prioritize it, label it, lock it, educate employees, know your tools, think holistically, and apply a counter-intelligence mindset. IP protection responsibilities spans the entire organization from the IT systems and facilities to the users, owners and management.
Safeguarding of Organizational Records
Organizational records — hard or soft copies — should be protected from loss, destruction and falsification. Whether these records are accounting, database, transaction and audit logs or operational procedures, all are stored on various paper, microfiche, magnetic, optical media and must adhere to some retention period. Records are useful for business (financial status with respect to shareholders, partners and auditors) as well as precaution required by statutory or regulatory rules, and defense against potential civil or criminal action.
Data Protection and Privacy of Personal Information
Identity theft is only going to get worse. Penalties for organizations that fail to use due diligence at collecting,
processing, disseminating and storing personal information will become more frequent and sever. Large companies will appoint a data protection officer. Smaller organizations need to assign someone to oversee this protection requrieemnt — defining it, creating policies for it, and enforcing it.
Prevention of Misuse of Information Processing Facilities
Management must ensure that business, network and computer equipment and facilities re only used for authorized business purposes. Too many people use their employer’s resources for their personal use. The policies must clearly state was is permitted — everything else is denied — and properly enforced.
Regulation of Cryptographic Controls
Over the past few years, restrictions on commercially available cryptographic technologies have been minimizes. But do not assume that all countries you require secure communications with will allow your chosen cryptographic solutions.
Collection of Evidence
In the unlikely event you need to support an action; i.e., legal, against a person or organization, it is essential your methods of collecting and safeguarding materials follow proper processes and procedures. There are rules for evidence; i.e., the chain of evidence, related documentation and media. Making sure that the evidence is admissibility will be a huge factor in the outcome of your case.
Like most ISO 17799 areas, compliance belongs under the organization’s security policy. Regular reviews and audits of compliance policies will help enforce the policies and provide a means for an active closed-loop corrective action program.
Author : Jeff Hayes
Regulatory Compliance and ISO 27001
Today's regulatory environment is increasingly complex, the penalties for failure unattractive and the route to effective compliance not clear. ISO 27001 provides a best-practice solution to a range of regulatory issues faced by directors.
The Regulatory conundrum
Organizations have traditionally responded to regulatory compliance requirements on a law-by-law, or department-by-department basis. That was, last century, a perfectly adequate response. There were relatively few laws, compliance requirements were generally firmly established and well-understood, and the jurisdictions within which businesses operated were well-defined.
Over the last decade, all that has changed. Rapid globalisation, increasingly pervasive information technology, the evolving business risk and threat environment, and today's governance expectations have, between them, created a fast-growing and complex body of laws and regulations – such as Data Protection and privacy legislation (e HIPAA, GLBA, DPA) and governance requirements (eg SOX and Turnbull) - that all impact the organization's IT systems. While global companies are in the forefront of finding effective compliance solutions, every organization, however small, and in whatever industry, is faced with the same broad range of regulatory requirements.
These regulatory requirements focus on the confidentiality, integrity and availability of electronically-held information, and primarily – but not exclusively – on personal data. Many of the new laws appear to overlap and, not only is there very little established legal guidance as to what constitutes compliance, new laws and regulatory requirements continue to emerge. Increasingly, these laws have a geographic reach that extends to organizations based and operating outside the apparent jurisdiction of the legislative or regulatory body that originated them.
Regulatory requirements in all these areas concentrate on preserving the confidentiality, integrity and availability of electronic data held by organizations operating within the sector. Regulations, which are technology-neutral, describe what must be done, but not how. Organizations are left to establish, for themselves, how to meet these requirements.
In most instances, there is not yet a body of tested case law and proven compliance methodologies to which organizations can turn in order to calibrate their efforts. There are no technology products which, of themselves, can render an organization compliant with any of the data security regulations, because all data security controls consist of a combination of technology, procedure and human behaviour. In other words, installing a firewall will not protect an organization if there are no procedures for correctly configuring and maintaining it, and if users habitually bypass it (through, for instance, Instant Messaging, Internet browsing or the deployment of rogue wireless access points).
In the face of new, blended, complex and evolving threats to their data, organizations have business and regulatory obligations to protect, maintain and make that data available when it is required. They have to do this in an uncertain compliance environment where the rewards for success don't grab headlines, but the penalties for failure do. Fines, reputation and brand damage and, in some circumstances, jail time for directors are outcomes that every business wants to avoid, and wants to avoid as systematically and cost-effectively as possible.
The adoption of an externally-validated, best-practice approach to information security – one that provides a single, coherent framework that enables simultaneous compliance with multiple regulatory requirements - is, therefore, a solution to which organizations are increasingly turning.
ISO 27001
ISO 27001 provides just such a solution. It focuses on the confidentiality, availability and integrity of data and its key precepts and requirements all occur in the regulatory requirements. Implementation of an ISO 27001 framework enables an organization to comply, at one step (and subject to specific documentation and working practices tailored for each individual regulation), with all the core requirements of information related regulation anywhere in the world.
From : searchsecurity.techtarget.com
Thursday, August 16, 2007
Competing regulations clog road to compliance
20 Oct 2005 | SearchSecurity.com
NEW YORK -- Dennis Murray may be in the world's busiest city, but traffic in the Big Apple is nothing like the dangerous intersection of compliance demands he deals with each day as a security analyst for Blue Cross and Blue Shield Association.
And his plight isn't unlike other security managers attending this week's Information Security Decisions conference, namely managing the multitude of regulations enterprises are commanded to comply with.
"The harmonization of it all is difficult," Murray said Wednesday, noting that guidelines provided by the Health Insurance Portability and Accountability Act, the Sabarnes-Oxley Act (SOX) and the National Institute of Standards and Technology often seem to pull companies in different directions. "All this plethora of compliance makes it hard to set a level to it and match the standards and regulations and meet their requirements."
Competing regulations make it difficult for companies to set priorities, make purchasing decisions and execute policy. One strategy to combat this is to build upon one of the popular security frameworks, creating a living document that evolves along with regulations.
Diana Kelley, an analyst for Midvale, Utah-based Burton Group, said these internal frameworks often use established baselines like CoBIT, COSO or ISO 17799, which are then customized according to a particular business unit's needs. Kelly said that set of policies, processes and tools normalizes an enterprise's tactics toward compliance.
"This helps prepare your organization for the next regulation coming down the line," Kelley said. Enterprises that create these internal frameworks can benefit from the consistency of a policy-based approach to compliance, centralized control and better reporting capabilities.
Standards like ISO 17799, however, are not prescriptive. Instead, they're open-ended documents that explain what your organization should be doing, Murray said, but not how.
"What we're trying to do is make sense of this rash of standards," Murray said. "We're constantly being audited from all sides. We do our best to set priorities. The message, though, is that ROI has nothing to do with perceived value of assets. It's about protecting assets and maintaining consumer confidence."
Once an organization establishes an internal framework, the next challenge is the tools that help solidify internal controls and meet regulatory requirements. Despite what many vendors would have you believe, compliance does not come in a box. There are no silver bullets for compliance. In fact, the inherent complexity of enterprise systems is in a constant tug-of-war with compliance efforts.
"The compliance products you bring in may touch a lot of moving parts in the enterprise, including devices you may not own," Kelley cautioned. "You may have to negotiate politically about why you need to implement this in a particular business unit." Normalization and correlation tools are likely the first step down the compliance road, and oftentimes, these tools may already be present in your organization.
Some financial applications, such as those from Oracle Corp. or SAP AG, are being enhanced with features that help organizations comply with certain aspects of SOX 404. Document management systems, present in most financial departments, could help with demonstrating to an auditor a company has established a flow chart of internal controls and has written policies around these controls.
Additinally, network management systems, like Hewlett-Packard Co.'s OpenView or IBM's Tivoli, manage network components, Kelley said, and could be used to demonstrate continuity of service and service levels established in regulatory control objectives.
Information Security Decisions is produced by TechTarget, publisher of SearchSecurity.com.