Tuesday, July 31, 2007
Hints and Tips
— Aim to reach compliance with ISO 17799 and let the processes bed-down before considering certification against ISO 27001 (ex BS7799-2).
— Stick to the plan (eg: as outlined in the Guide To Certification)
— If you can undertake an implementation, compliance or certification task yourself, do so. In the long run you will obtain greater benefit by learning the ropes and performing activities such writing information security policies yourself. However, advice and guidance from knowledgeable and experienced consultants can help cut corners, save time and avoid pitfalls.
— Be sure that you have explicit backing from the top, the very top, of your organization for your compliance and/or certification efforts, and indeed for information security as a whole. Be sure that senior management understands the objectives, benefits and likely costs of the implementation and certification project at the outset. This implies the need to achieve management awareness of information security at an early stage. Without this, the rest is more-or-less doomed to failure.
— The benefits of compliance with ISO 17799 are not necessarily limited purely to better information security. Rigorous analysis and documentation of key information processing activities may identify opportunities to improve process efficiencies, for instance. The structured information security management framework incorporates elements of ISO 9000 quality assurance practices. Legal and regulatory compliance supports management's governance obligations and reduces liabilities.
— Note that information security is not the same as computer security. All information assets need to be secured appropriately, including hardcopy documents, CCTV/videoconference data, telephone systems etc. as well as computer data, systems and networks.
— Once information security is brought under management control, continuous improvement is possible. Over time, information security and related processes will mature and things you can only dream of today will eventually become a reality. Have faith!
— Don't forget security awareness. See ISO 17799 and information security awareness
— Getting the RiskAssessment right is crucial to the success of implementation. The structure of the risk assessment is clearly outlined in ISO27001 and should be followed very closely. The fourth point above indicates how important the management commitment element is. Part of that commitment is to give approval the risk assessment process and define the levels of risk which are to be accepted, mitigated, transferred or avoided. They must also approve the residual risks following impementation of the selected controls.
From : iso-17799.safemode.org
ISO 17799 and ISO 27001 FAQ
1) Which ISO17799 controls are most important?
That largely depends upon the individual organization. However, ISO17799 does give some guidance, in the form of 'legislative essentials' and 'common best practice' under the IS "starting point" section. These are:
- intellectual property rights (12.1.2)
- safeguarding of organizational records (12.1.3)
- data protection and privacy of personal information (12.1.4)
- information security policy document (3.1.1)
- allocation of information security responsibilities (4.1.3)
- information security education and training (6.2.1)
- reporting security incidents (6.3.1)
- business continuity management (11.1)
2) What is a Certification body?
An accredited certification body is a third party organization that assesses/certifies the IS management system against the standard (BS7799-2 / ISO 27001).
3) Who are the Accredited Certification bodies for the standard?
There are a growing number of organizations accredited to grant certification against ISO27001. The following are amongst them: BSI, Certification Europe, DNV, JACO IS, KEMA, KPMG, SFS-Sertifiointi Oy, SGS, STQC, SAI Global Limited, UIMCert GmbH
4) How do I become a certified auditor?
The International Register for Certified Auditors operates a certification scheme for ISMS auditors.
5) How does this standard fit with ISO 9000?
BS7799 is actually being "harmonized" with other management standards, including ISO 9000 and ISO 14000. Watch this space!
6) Who originally wrote the security standard?
Originally a BSI/DISC committee, which included representatives from a wide section of industry/commerce. It was reviewed subsequently by an ISO (International Standards Organization)committee and ultimately emerged through the ISO publication process.
7) What is the ISO 17799 Toolkit?
This is the main support resource for the standard, including the standard itself, ISO 17799 policy, etc. See top right panel for a more complete description.
8) What is ISO/IEC Guide 62?
This is largely for those bodies operating certification schemes and contains general requirements applicable to them.
9) What is ISO 27001?
BS7799-2, the original specification for an information security management system, was 'fast tracked' by ISO to become ISO 27001 in 2005. It is also suggested that ISO17799 may be renamed to ISO 27002 at some point in the future, thus creating an ISO 27000 series of standards.
From : www.17799.com
INTRODUCING AN EFFECTIVE EMAIL SECURITY POLICY
Email security breach is becoming an increasingly significant threat to organizations around the world. To counter this, most organizations will already have a firewall and anti-virus software in place. Hopefully, as new viruses are found daily, they have made sure that their virus protection is also updated on a daily basis.
Viruses, of course, can sometimes penetrate the firewall by hiding within emails. Once opened, the virus can spread and cause significant damage to internal systems. The virus may not always be serious enough to cause permanent damage but, even with moribund viruses, the disruption may well take time and money to rectify.
Despite these risks, there is no escaping the fact that e-mail is rapidly becoming the principal means of business communication. Draconian restrictions on use are therefore not tenable. However, rigid application of stringent security policy certainly is.
The following high level best practice statements should be adhered to as a basic minimum
• Personnel should understand the rights granted to them by the organization in respect of privacy in personal e-mail transmitted across the organization’s systems and networks. Human Resources Department should incorporate a suitable wording into employee contracts to ensure that this privacy issue is fully understood.
• Confidential and sensitive information should not be transmitted by e-mail - unless it is secured through encryption or other secure means.
• Personnel should not open emails or attached files without ensuring that the content appears to be genuine. If you are not expecting to receive the message or are not absolutely certain about its source, do not open it.
• Personnel should be familiar with general e-mail good practice e.g. the need to save, store and file e-mail with business content in a similar manner to the storage of letters and other traditional mail. E-mails of little or no organizational value should on the other hand be regularly purged or deleted from your system.
From : http://www.17799central.com/news.htm
IT COULDN'T HAPPEN HERE....OR COULD IT ?
Every issue of The ISO17799 Newsletter features at least one TRUE story of an information security breach and its consequences. This issue considers genuine cases illustrating different threats from WITHIN the organization:
1) The Disgruntled Employee
An organization in the
Shortly after the employee was dismissed, major customers started receiving offensive material purportedly being sent by the organization itself. The ex-employee used a simple open SMTP server to simulate the organization's email addresses. Customers immediately started to move away from the organization and even when they were informed that this material had been maliciously sent to them by a previous employee, they remained unimpressed with a company that had so little security in place.
The organization quickly went out of business, paying a heavy price for not having sufficient control over employee access to sensitive information.
2) Intellectual Property Rights
A firm in
Unfortunately, the firm had not considered protecting the intellectual property rights of work undertaken during the employee’s time with them and it was subsequently successfully sued by the employee who had authored the products, and who then claimed ownership over the intellectual property rights contained within them.
The lesson to be learned here is that employees' contracts should clearly state the ownership of any work developed for the company during his/her employment. This agreement should be signed by the employee to signify acceptance of these terms and conditions prior to undertaking this type of work.
3) Who Audits the Auditor?
A large financial company thought they had security in the bag. Their security department was active, and involved in most activities of the Group. It had a reputation for being on top of new technology, and had an aggressive audit schedule, with all sensitive applications and projects being regularly audited.
What a pity they got a fundamental principle so badly wrong! As the Group's security area they had full access to security settings, and administered access control for key applications. As auditors they audited the same. That was the crunch.
The same individuals who set security levels and granted access to information resources, also audited them. A classic case of insufficient segregation of duties.
In one sense they were lucky. The incident which brought this to light was petty. The individual in question could not resist the temptation to adjust his overtime figures on the payment database. He inflated the figures by several hundred dollars, each month, for several months. He was caught because someone else on his team spotted his payslip (which he had left inside his briefcase, which he left open!) and knew instinctively that he had not been working long hours in recent weeks and therefore that the salary figure was far too high.
It could, however, just as easily been an accounting database he adjusted, or a number of financial databases, and the company could have been facing a substantial and embarrassing loss.
From : http://www.17799central.com/news.htm
PREPARING FOR AN INFORMATION SECURITY AUDIT
For an Information Security audit to be effective it must be planned and have adequate preparation. A common purpose of conducting the audit is to enable the Information Security Officer (or the person who is responsible for the security of information) to measure the level of compliance with the organization’s Information Security Policies and associated procedures.
At the highest level, the Information Security Officer should initially prepare an audit program which ensures that all key risk areas are audited and reviewed on a regular basis. The greater the threats, and the higher the risk or probability of an Information Security incident, the more often the audit should be conducted.
Once the risk area to be audited has been selected, the Information Security Officer should prepare a list of the INFORMATION that needs to be collected to carry out the audit.
As an example, if the audit chosen is regarding the Portable Computing Facilities, the documents to be considered for review are:
• Insurance documents.
• Hardware register.
• Software register.
• User Profile.
• Network Profile.
• Issue form.
• General terms of use.
• Removal of equipment authorization.
The Information Security Officer will also decide on which PERSONNEL need to be audited and arrange an interview schedule. In the same example, the following personnel would be audited:
• The issuers of portable computers.
• A sample of the user population who use portable computers.
• Ancillary staff.
As with many tasks, pre-planning is sometimes seen as a necessary evil, and there is temptation to shortcut. However, in most cases, there is little doubt that the quality of the planning is likely to go a long way in determining the quality of the audit.
From : http://www.17799central.com/news.htm
ISO17799: THE WORLD WIDE PHENOMINON
Our source list for recent purchases of the ISO17799 standard always proves to be a popular talking point. The up to date version of the most recent thousand or so is as follows:
Brasil 11
M้xico 22
From : www.17799central.com/news.htm
A Strategy and Approach for ISO 17799 / BS7799 / ISO 27001
There are actually a variety of way to approach the standard. The correct one for a specific organization will obviously depend upon the nature the organization itself. However, the following 'cycle' has been documented as one possible approach, and may be of use.
- Firstly, obtain a copy of the stand itself. Whilst this may seem rather obvious, it is surprising how often people attempt to judge suitability without actually every having studied the documents themselves. The documents can be obtained stand alone, or as part of the starter kit (The ISO 17799 Toolkit) from the sources given on the right hand panel.
- The merits of the standard itself are considered. Factors can include impact on confidence of new/existing customers/partners, enhancing the organization's security, etc.
- The decision is made to move forward with the standard. All options are available of course: from loose alignment with it, to compliance with it, to certification.
- The project is planned in terms of resourcing (ie: people and time). This could include external resources such as consultants.
- With the previous step the scope of the exercise is decided. In other words, the part(s) of the organization to be included are determined.
- A review of existing documentation is conducted. This will help establish extent and quality of th emeasures already in place (eg: security policies).
- An inventory is drawn up of all significant information assets.
- A 'gap analysis' is performed to identify the gaps between the existing situation, and those controls, processes and procedures documented in the standard.
- A risk analysis exercise is performed in order to determine the extent of risk to the organization through security breach. A Risk Assessment document is produced.
- The organization must determine how the identified risks are to be managed. Responsibilities for managing them assigned and documented.
- Controls to address the identified risks are slected, both from the standard and elsewhere. A "Statement of Applicability" is developed following selection.
- Security policies are created/adapted using the Statement of Applicability and other inputs. This is often based upon the template included in The ISO 17799 Toolkit.
- Appropriate policy based procedures are created.
- An awareness program is initiated to ensure employees and agents are familiar with the IS requirements of the organization.
- A method of compliance monitoring is introduced.
- At this point, the organization reviews its position. Commonly, certification is considered (which of course requires external audit by an accredited body).