Tuesday, July 31, 2007
ISO 17799: Scope and implementation – Part 1 Security Policy.
Introduction
As information security become increasingly important to the continue success for businesses,
many are seeking an appropriate security framework. The ISO 17799 standard is widely
becoming the choice for many. While this standard provides only a high-level description for
implementing and maintaining information security, it should be a starting point for any
organization trying to implement a comprehensive information security strategy. This is the first
article in a series of eleven devoted to reviewing this ISO 17799 standard. In part one, the
following information will be addressed. First, an overview of what the standard is and how it
should be used. Second, it will review the structure of the standard; this is vital for any successful
analysis. Last, it will examine the Security policy control clause, as outlined by the standard.
Subsequent articles will continue reviewing the other ten security control clauses mentioned in
the standard.
ISO 17799: What is it?
According to the ISO, the ISO 17779 ‘establishes guidelines and general principles for initiating,
implementing, maintaining and improving information security management in an organization.’
As mentioned, the standard simply offer guidelines, it does not contain indebt information on how
information security should be implemented and maintained.
The security controls, the means of managing risk, mentioned in this standard should not all be
implemented. The appropriate controls should be selected after an in dept risk assessment has
been completed. Only then should controls be selected to meet the specific needs of the
organization. Each organization is unique; therefore each will face different threats and
vulnerabilities. It is also important to understand that the controls mentioned in the standard are
not organized or prioritized according to any specific criteria. Each control should be given equal
importance and considered at the systems and projects requirements specification and design
stage. Failure to do this will result in less cost effective measures or even failure in achieving
adequate security.
The last point that should be highlighted about the standard is the ISO warning that no set of
controls will achieve complete security. The ISO encourages additional intervention from
management to monitor, evaluate and improve the effectiveness of security controls to support
the business objectives of the organization.
Security Policy
The Security Policy control clause is the first of eleven clauses that will be reviewed. As
mentioned earlier, the ISO 17799 is not a catalogue of indebt security procedures. The sole
objective of the security policy control clause, according to the standard, is to provide
management with direction and support for information security implementation. In essence it
demonstrates management commitment to security and provides high-level rules for protecting
assets.
The ‘main security category’ within the Security Policy clause is ‘Information security policy.’
This category has two controls listed, Information security policy document and Review of the
information security document (Figure 1). There are many resources available on how to
formulate security policies. The ISO 17799 offers a strong foundation on which to start.
Information security policy document: Control 1
The security policy document should be approved by management and communicated to all
employees and relevant external parties.
The ISO 17799 offers the following implementation guidelines on what a policy document should
contain:
a) a definition of information security, its scope and objectives
b) a statement of management’s support for security in conjunction with business objectives
c) a framework for setting control objectives and controls
d) an explanation of policies, principles, standards and compliance requirements:
e.g. legislative requirements, security education requirements, consequences of security
policy violations
e) references to documentation supporting the policy
The information security policy may be apart of a general policy document; however if distributed
outside the organization, care should be taken not to disclose sensitive information.
The second main security category within the Security Policy control clause is ‘Review of the
information security policy.
Review of the information security policy: Control 2
This control requires a review of security policy at ‘planned intervals’ or if ‘significant’ changes
occur, to ensure suitability and effectiveness.
According to the implementation guidelines for this control, the following should be implemented:
a) a policy should have an owner
b) the management approved owner is responsible for the development, review, and
evaluation of security policy
c) a review should consider opportunities for improvement
A review of the security policy should consider results from management reviews. Management
reviews should also be scheduled and contain inputs from sources such as:
a) feedback from interested parties
b) feedback from independent reviews
c) trends related to threats and vulnerabilities
d) reported security incidents
e) recommendations provided by relevant authorities
Outputs from management reviews should include:
a) improvement to the organization’s approach to managing information security
b) improving control objectives
c) improving available resources/responsibilities
Any revision to the policy should obtain management approval.
Summary
The ISO 17799 is widely becoming a framework for many organizations seeking to implement a
comprehensive information security framework. This article reviewed one of eleven control
clauses. A Security Policy provides management with direction and support for information
security. They Security Policy clause has one ‘main security category’, followed by two controls.
The security policy document should be approved by management and communicated to all
employees. Lastly, there should be a planned review of the policy.
Monday, July 30, 2007
Security Policies
| Chapter | Title |
| ONE | INFORMATION SECURITY ORGANIZATION |
Information Security Policy Information Security policy Information Security Organization Independent Review of Information Security Policy
| |
| TWO | CLASSIFYING INFORMATION AND DATA |
Defining Information
| |
| THREE | CONTROLLING ACCESS TO INFORMATION AND SYSTEMS |
Managing Access Control Standards
| |
| FOUR | PROCESSING INFORMATION AND DOCUMENTS |
Configuring Networks System Operations and Administration Appointing System Administrators E-mail and the Worldwide Web Downloading Files and Information from the Internet Telephones & Fax Making Conference Calls Data Management Transferring and Exchanging Data Backup, Recovery and Archiving Restarting or Recovering your System
| |
| FIVE | PURCHASING AND MAINTAINING COMMERCIAL SOFTWARE |
| |
| SIX | SECURING HARDWARE, PERIPHERALS AND OTHER EQUIPMENT |
| |
| SEVEN | COMBATING CYBER CRIME |
| |
| EIGHT | CONTROLLING E-COMMERCE INFORMATION SECURITY |
| |
| NINE | DEVELOPING AND MAINTAINING IN-HOUSE SOFTWARE |
| |
| TEN | DEALING WITH PREMISES RELATED CONSIDERATIONS |
| |
| ELEVEN | ADDRESSING PERSONNEL ISSUES RELATING TO SECURITY |
| |
| TWELVE | DELIVERING TRAINING AND STAFF AWARENESS |
| |
| THIRTEEN | COMPLYING WITH LEGAL AND POLICY REQUIREMENTS |
| |
| FOURTEEN | DETECTING AND RESPONDING TO IS INCIDENTS |
| |
| FIFTEEN | PLANNING FOR BUSINESS CONTINUITY |
|
From : www.27001-online.com
ISO 27001 CERTIFICATION EXPLAINED
Common reasons to seek certification include: Organisational assurance; trading partner assurance; Competitive advantage (market leverage); reduction or elimination of trade barriers; reduced regulation costs; and so on.
To meet the certification requirements, an organization's ISMS must be audited by a 'Certification Body' (or strictly speaking, an assessor who works for a Certification Body). There is a clear segregation of dutues here: the assessor must be independent of consultancy and training.
A Certification Body must have been accredited by the National Accreditation Body for the territory in question (eg: UKAS in the UK). This helps ensure that the Certification Bodies meet national and international standards for their services, and ensure consistency. In respect to ISO 27001, this is typically a document called EA-7/03 (‘Guidelines for Accreditation of Bodies Operating Certification / Registration of Information Security Management Systems’).
The following diagram may clarify this process:
Different certification bodies tend to adopt slightly different approaches to the exercise, with some being more 'hands on' than others. However, the following six step process is a fairly common one:
1 - Questionnaire (the Certification Body obtains details of your requirements)
2 - Application for Assessment (you complete the application form)
3 - Pre-assessment Visit or a ‘Gap Analysis’ (optional).
4 – The Stage 1 Audit (a ‘Document Review’). This is the first part of the audit proper.
5 - The Stage 2 Audit (otherwise called the ‘Compliance Audit’)
6 – Ongoing Audits
From : www.27001-online.com
Risk Assessment
1) Identify the information assets and information handling assets within the scope of the ISMS and identify the asset owner of each of these assets. A good way of identifying the assets is to map the business processes which fall within scope and list the assets required for the input, execution and output of these processes. |
2) Identify the impacts of loss of confidentiality, availability or integrity of these assets. This impact could be financial, loss of reputation or loss of material ability to perform some aspect of business operations. |
3) Identify the threats to those assets which could lead to the loss in confidentiality, availability or integrity of the asset. |
4) For each of the identified threats, identify the vulnerabilities which can be exploited by the threat. It is very important that everyone involved in the risk assessment (which may well be all asset owners) is very clear of the definition of a threat (e.g. malicious code) as opposed to the vulnerability (e.g. lack of regularly updated virus protection software). |
5) Assess the levels of business impact whch could potentially arise from the loss of confidentiality, availability or integrity of the assets as defined in point 2 above. |
6) Assess the likelihood of occurrence of the threat, and the level of vulnerability. This will yield the likelihood of a particular threat exploiting a particular vulnerability and impacting the confidentiality, availability or integrity of a particular asset, known as the Risk of Exposure. |
7) Estimate the level of risk based on the level of business impact and the risk of exposure. |
risk treatment plan
1) Knowingly accept the risk as it falls within the organisation's "risk appetite", in other words management deem the risk acceptable, compared to the cost of improving controls to mitigate it; |
2) Implement a suitable control or combination of controls to reduce (mitigate) the risk to a more acceptable level. Controls may be selected from the best practices defined in ISO 17799 and/or from other sources; |
3) Avoid the risk i.e. do not undertake the associated business activity; |
asset owner
ISO 17799 and information security awareness
by Gary Hinson. |
Security awareness is very much an integral part of an ISO 17799-compliant information security management system. A recurring theme throughout the standard is that people in an organization must be made aware of the security policies, procedures and control requirements that they are expected to uphold. |
ISO 17799:2005 section 8.2.2 (Information security awareness, education and training) is the most directly relevant section, recommending that ?All employees of the organization and, where relevant, contractors and third parties should receive appropriate awareness training and regular updates in organizational policies and procedures, as relevant for their job function? It goes on to recommend ?a formal induction process?and ?ongoing training? It suggests the need to educate employees on known threats and who to contact in the event of a security incident. |
As with many other important topics, ISO 17799?s coverage of security awareness is not limited to this one section but is distributed throughout the text: |
-Information security awareness, training and education is one of seven common practice controls listed in section 0.6 (Information security starting point); |
-In section 0.7 (Critical success factors), ?Effective marketing of information security to all managers, employees, and other parties to achieve awareness?and ?providing appropriate awareness, training, and education?are two of the ten critical success factors; |
-Section 5.1.1 (Information security policy document) acknowledges that raising security awareness and informing employees about management requirements is an important function of policies; |
-Section 6.1.1 (Management commitment to information security) tells management to ?initiate plans and programs to maintain information security awareness? |
-Section 6.1.2 (Information security co-ordination) says one of the duties of the information security management/co-ordination function is to ?effectively promote information security education, training and awareness throughout the organization? |
-Section 6.2.1 (Identification of risks related to external parties) notes ?It should be ensured that the external party is aware of their obligations, and accepts the responsibilities and liabilities involved in accessing, processing, communicating, or managing the organization?s information and information processing facilities? |
-Section 6.2.3 (Addressing security in third party agreements) recommends ?ensuring user awareness for information security responsibilities and issues? It further recommends ?user and administrator training in methods, procedures, and security? |
-The control objective stated in section 8.2 ([Human resources security] during employment) is ?To ensure that employees, contractors and third party users are aware of information security threats and concerns, their responsibilities and liabilities, and are equipped to support organizational security policy in the course of their normal work, and to reduce the risk of human error? It continues ?An adequate level of awareness, education, and training in security procedures and the correct use of information processing facilities should be provided to all employees, contractors and third party users to minimize possible security risks.? |
-Section 8.2.1 (Management responsibilities) advises management to ensure that employees, contractors and third party users ?achieve a level of awareness on security relevant to their roles and responsibilities within the organization?[because] ?If employees, contractors and third party users are not made aware of their security responsibilities, they can cause considerable damage to an organization. Motivated personnel are likely to be more reliable and cause less information security incidents? |
-Section 9.2.7 (Removal of property) says ?Individuals should be made aware if spot checks are carried out? |
-Section 10.4 (Protection against malicious and mobile code) says very directly that ?Users should be made aware of the dangers of malicious code. Detection, prevention, and recovery controls to protect against malicious code and appropriate user awareness procedures should be implemented? |
-Section 10.8.1 (Information exchange policies and procedures) warns ?Information could be compromised due to lack of awareness, policy or procedures on the use of information exchange facilities? |
-Section 11.3 (User responsibilities) states that ?The co-operation of authorized users is essential for effective security. Users should be made aware of their responsibilities for maintaining effective access controls, particularly regarding the use of passwords and the security of user equipment? |
-Section 11.3.2 (Unattended user equipment) recommends ?All users should be made aware of the security requirements and procedures for protecting unattended equipment, as well as their responsibilities for implementing such protection? |
-Section 11.7.1 (Mobile computing and communications) says ?Training should be arranged for personnel using mobile computing to raise their awareness on the additional risks resulting from this way of working and the controls that should be implemented? |
-Section 12.6.1 (Control of technical vulnerabilities) states ?if no patch is available, other controls should be considered, such as ... raising awareness of the vulnerability? |
-The control objective in section 13.1 (Reporting information security events and weaknesses) mentions that ?All employees, contractors and third party users should be made aware of the procedures for reporting the different types of event and weakness that might have an impact on the security of organizational assets? |
-Section 13.1.1 (Reporting information security events) continues ?All employees, contractors and third party users should be made aware of their responsibility to report any information security events as quickly as possible. They should also be aware of the procedure for reporting information security events and the point of contact? It also notes that ?information security incidents can be used in user awareness training? |
-?Appropriate education of staff in the agreed procedures and processes, including crisis management?is one of the purposes of continuity plans listed in section 14.1.3 (Developing and implementing continuity plans including information security); |
-Section 14.1.4 (Business continuity planning framework) advises that a BCP framework should include, amongst other things, ?awareness, education, and training activities which are designed to create understanding of the business continuity processes and ensure that the processes continue to be effective? |
-Section 15.1.2 (Intellectual property rights) includes the guideline ?maintaining awareness of policies to protect intellectual property rights? |
-Section 15.1.4 (Data protection and privacy of personal information) notes ?Responsibility for handling personal information and ensuring awareness of the data protection principles should be dealt with in accordance with relevant legislation and regulations? |
-Section 15.1.5 (Prevention of misuse of information processing facilities) advises that ?All users should be aware of the precise scope of their permitted access and of the monitoring in place to detect unauthorized use? |
Conclusions |