Search in ISMS Guides

Google
 

Monday, July 30, 2007

SIMPLE PASSWORD RULES

Choosing a secure password is an important element of effective information security within an organization, but good password management is of equal importance... this is another straight forward issue that is too often overlooked.

The following guidelines will enable you to protect your own passwords and maintain its confidentiality.

  • Never give your password to anyone, even if that person claims to have authorization. (In the latter case, report such requests to your Information Security Officer immediately.)
  • If you believe your password may have been compromised, change it immediately
  • Never write down your password
  • When receiving technical assistance, do not divulge or expose your password to the IT specialist, but stay with your computer and enter the password yourself when required. (If this is not possible, your Systems Administrator should have permission to log on your behalf.)
  • Never store it on a computer file
  • Change your password regularly. (Your system should prompt a change on, say, a monthly basis.)

Obvious? Maybe - but is surprising how many security breaches stem from employees and others NOT following these simple steps.

WHEN A VIRUS ATTACKS

Despite employing regularly updated anti-virus software and maintaining a constant awareness of the risks of virus infection, some viruses nevertheless can still enter and infect an organization's computer system. For example, a high profile case was reported earlier this year where a senior businessman was sent a price list infected with a virus by another company known to him, albeit a competitor.... he should of course have known better. But what steps can be taken to help mitigate this sort of situation?

Dealing with a virus in a professional and planned way reduces both its impact and its spread throughout the organization and beyond. A failure to respond appropriately to a virus incident can rapidly result in multiple system failures and continued infection.

We offer the following best practice guidelines on how to respond to virus incidents:

  • If possible, appoint a Virus Control Officer who would be the first point of contact for all virus alerts and who co-ordinates follow-up actions.
  • Consider regularly reviewing software and files used for critical business processes to identify and investigate unauthorized and/or suspicious changes.
  • Ensure that your organization has a Virus Incident Response Plan, drawn up jointly by the Information Security Officer, Virus Control Officer and System Administrator. Where no agreed response plan is in place, the reaction of users, IT and management are likely to be ad-hoc and inadequate, possibly turning a containable incident into a significant problem.
  • When a virus is detected:
    1. immediately locate and scan the relevant file(s) with your anti-virus software to determine if the virus has been immunized.
    2. communicate a virus alert to warn staff of the incident and the appropriate response
    3. establish whether the virus might have infected others and, if so, respond accordingly - if necessary close down workstations and possibly parts of the network.
    4. following the virus attack, review the measures taken to minimize damage and prevent a recurrence, and question whether procedures and safeguards remain adequate. Consider updating your anti-virus file definitions on a more frequent, possibly daily, basis.
  • Ensure that your server anti-virus software is configured to proactively scan all incoming and outgoing files. (Also investigate the source of any virus detected on OUTBOUND e-mail as this may indicate a failure to scan files on a workstation or the use of unscanned floppy disks or CD-Roms.)
  • Update your anti-virus file definition files on a regular basis
  • Promote awareness among users of the risks associated with e-mail, and train them to be aware of this type of cyber crime and their responsibilities for its prevention.

ISO 27001 PDCA Approach

ISO 27001 (formerly BS7799) describes an approach known as PDCA:

'Plan Do Check Act' is a broad stage by stage approach which covers a range of standards.

The Six Stage Process

ISO 27001 (formerly BS7799) desribes a 6 stage process

1) Define an information security policy

2) Define scope of the information security management system

3) Perform a security risk assessment

4) Manage the identified risk

5) Select controls to be implemented and applied

6) Prepare an SoA (a "statement of applicability").

Sunday, July 29, 2007

0.8 Developing your own guidelines

This code of practice may be regarded as a starting point for developing organization specific
guidelines. Not all of the controls and guidance in this code of practice may be applicable.
Furthermore, additional controls and guidelines not included in this standard may be required. When
documents are developed containing additional guidelines or controls, it may be useful to include
cross-references to clauses in this standard where applicable to facilitate compliance checking by
auditors and business partners.

0.7 Critical success factors

Experience has shown that the following factors are often critical to the successful implementation of
information security within an organization:
a) information security policy, objectives, and activities that reflect business objectives;
b) an approach and framework to implementing, maintaining, monitoring, and improving
information security that is consistent with the organizational culture;
c) visible support and commitment from all levels of management;
d) a good understanding of the information security requirements, risk assessment, and risk
management;
e) effective marketing of information security to all managers, employees, and other parties to
achieve awareness;
f) distribution of guidance on information security policy and standards to all managers,
employees and other parties;
g) provision to fund information security management activities;
h) providing appropriate awareness, training, and education;
i) establishing an effective information security incident management process;
j) implementation of a measurement 1 system that is used to evaluate performance in
information security management and feedback suggestions for improvement.

0.6 Information security starting point

A number of controls can be considered as a good starting point for implementing information
security. They are either based on essential legislative requirements or considered to be common
practice for information security.
Controls considered to be essential to an organization from a legislative point of view include,
depending on applicable legislation:
a) data protection and privacy of personal information (see 15.1.4);
b) protection of organizational records (see 15.1.3);
c) intellectual property rights (see 15.1.2).
Controls considered to be common practice for information security include:
a) information security policy document (see 5.1.1);
b) allocation of information security responsibilities (see 6.1.3);
c) information security awareness, education, and training (see 8.2.2);
d) correct processing in applications (see 12.2);
e) technical vulnerability management (see 12.6);
f) business continuity management (see 14);
g) management of information security incidents and improvements (see 13.2).
These controls apply to most organizations and in most environments.
It should be noted that although all controls in this standard are important and should be considered,
the relevance of any control should be determined in the light of the specific risks an organization is
facing. Hence, although the above approach is considered a good starting point, it does not replace
selection of controls based on a risk assessment.