Search in ISMS Guides

Google
 

Wednesday, August 22, 2007

The MIC has compiled the Information Security Management Guidelines for Telecommunications as a contribution to the establishment of information security management in the telecommunications business.

Background

Nowadays, with the increase in information security threats such as viruses, cyber-attacks and information leaks, organizations are being required to put in place information security management. With regard to this point, the Study Group on Next Generation IP-based Infrastructure (chaired by SAITO Tadao, Professor Emeritus, the University of Tokyo) stated in its second report (announced on July 7, 2005) that there was a need to establish and promote the guidelines for information security management for telecommunications business.

The MIC set up the Task Force on ISMS-T* (chaired by NAKAO Koji, General Manager, Information Security Department, KDDI Corporation) in February 2005. The group considered topics that should be taken into account in line with the implementation of information security management for telecommunications organizations. These have now been compiled as the Information Security Management Guidelines for Telecommunications (referred to below as "the guidelines").

* Information Security Management System for Telecommunications

Outline of the guidelines

The guidelines comprise control, implementation guidance, etc, in 11 areas of information security management, to establish information security management within telecommunications organizations.

Future plans

The MIC will work in cooperation with telecommunications carriers and relevant industry organizations to implement the guidelines, and will propose these guidelines to the ITU (International Telecommunication Union) as a contribution to considering the information security management guidelines for telecommunications.


Background of Investigation

Background of Investigation



Comparison of Control in International Standards

Comparison of Control in International Standards



Information Security Management Guideline for Telecommunications

Information Security Management Guideline for Telecommunications



Organization of the Guidelines

Organization of the Guidelines


"FY2005 Competition Review in the Telecommunications Field"
-- Release of "Market Definition of Fixed Telephone Segment"

Upon implementation of the "FY2005 Competition Review in the Telecommunications Field," MIC invited public comments and held the open conference on the "Market Definition of Fixed Telephone Segment" for defining objective markets.

Background

During the period from February 22 through March 15, 2006, MIC invited public comments on the "FY2005 Competition Review in the Telecommunications Field 'Market Definition of Fixed Telephone Segment (draft).'" During said period, MIC received nine comments.

In addition, on March 22, 2006, MIC held the open conference on the "Market Definition of Fixed Telephone Segment" for exchanging opinions with stakeholders, including telecommunications carriers and specialists. Based upon those results, MIC defined the objective markets for review.

Future plans

Based upon the "Basic Approach of Competition Review in the Telecommunications Field" and the "FY2005 Details for Implementation of Competition Review in the Telecommunications Field," MIC will analyze the markets as defined for review. In summer of 2006, MIC will publicize the "FY2005 Competition Review in the Telecommunications Field."

In FY2005, MIC will analyze mainly the fixed telephone segment, in parallel with such segments as the mobile communications and the Internet access.

Main points of "Market Definition of Fixed Telephone Segment"

The FY2005 Competition Review targets the fixed telephone segment carries out a new analysis, the main points governing ideas on the market definition are as follows. Concerning the segments such as "Internet access" and "mobile communications," the results of market definition for FY 2003 and 2004 are adopted.

Settling the market structure of fixed telephones
- "Access" and "Call" will not be differentiated, both being taken together in making up the market.
- "Access" can be selected from (1) NTT East/West telephony service, (2) Direct access telephony service, (3) Cable telephony service or (4) OABJ (geographical number) type IP telephony service.
- "Call" can be selected from (5) PSTN call service, (6) 050 (location free number) type IP telephony service or (7) Internet telephony service. In the case of (1) "Call" is unbundled from "Access" and call service carriers can be selected freely. But in the case of (2) to (4), "Call" is bundled to "Access" and call service carriers are limited.

Market definition of fixed telephone segment (service market)
- The range of the market has been defined as (1) NTT East/West telephony service, (2) Direct access telephony service, (3) Cable telephony service and (4) OABJ type IP telephony service.
[Reason] (1) to (4) options offer a high level of demand-side substitution little difference in functions, and comparable with each other when contracting, etc).

Handling of NTT East/West telephony service
- The (1) NTT East/West telephony service will be handled as a sub-market, and in addition to analyzing the demand structure of the service, we will also analyze the state of competition in (5) PSTN call service and (6) 050 type IP telephony service.
[Reason] NTT East/West telephony service have a high level of independence "Access" and "Call" are structurally separated, and there exists much switching cost when changing the service, etc.)
We did not define the market for (7) Internet telephony service, for the demand for the service has not taken off yet. So analysis will be conducted where data is available.

Definition of geographical market
- The administrative division into prefectures is the smallest unit for analysis.
- Taking the state of competition into account, geographical markets have been set into 2 areas of eastern and western Japan according to the service areas of NTT East/West, or for 10 regional blocks nationwide according to the service areas of the electric power companies.
[Reason] In terms of the possibility of obtaining data, the division is the minimum unit. Since we define the geographical market based on the state of competition, it is necessary to analyze the market divided into 2 areas according to the service areas of NTT East/West or the market divided into 10 areas according to the service areas of the electric power companies.

Handling of 050 type IP telephony service (relationship with Internet access market)
- With regard to 050 type IP telephony service, we analyze from many aspects such as a sub-market of the Internet access market and also as a part of the IP telephony (050 type and 0ABJ type IP telephony) market, in addition to the analysis as a part of the fixed telephone market.
[Reason] 050 type IP telephony service substitute the functions of PSTN call service, but many users consider the service as an additional service to Internet access. In addition, they can hardly distinguish the service from the OABJ type IP telephony service, and see both as the IP telephony service.

Relationship with mobile communications market
- Fixed telephone market and mobile communications market are separate markets (observe the leverage from the other market and the trend in FMC services).
[Reason] Although there is a definite substitution between fixed and mobile, there is also a complementarity as they are used together. So it is unsuitable for them to be considered as the same market.

Preparatory Meeting Held for the Establishment of Hotline Center

The Internet Association Japan held a preparatory meeting to put together standards from experts and related people from industry organizations and the like, in order to make the preparations necessary for the establishment of "Hotline Center" (provisional name).

Aims

Illegal materials on the Internet, such as child pornography and information on covert sale of drugs and the like, as well as sites that are not immediately seen as illegal, such as suicide sites and those showing the manufacturing process for explosive devices, and harmful information regarding contracts murders and other illegal acts have been circulating on the Internet and have become a major societal problem.

Taking these circumstances into consideration, and in order to promote effective measures against illegal activity and harmful information on the Internet, information provided by Internet users concerning illegal and harmful information will be collected and classified according to predetermined standards. The police will be informed concerning illegal information and requests will be made to the administrators of the providers or electronic notice boards asking that measures be taken to block the transmissions.

A preparatory meeting for the establishment of hotline center was held so that providers can fulfill their responsibility in the face of harmful information by taking action and making the preparations necessary to set up "Hotline Center" (provisional name).

Outline

Date and Time: April 4, 2006 (Tuesday) 2-3pm
Place: Shinbashi Internet Association Japan, Shinbashi Frontier Bldg. 6th floor, 3-4-5, Minato-ku, Tokyo
Organizer: Internet Center Japan
Proceedings:
- Preparatory meeting for the establishment of hotline centers
- Invitation to comment on the range of illegal and harmful information handled by the hot lines and procedure for determining this

Outline of "Hotline Center" (provisional name)

Background of establishment

At present, the circulation of child pornography on the Internet, information on restricted drugs and the like, as well as sites that are not immediately seen as illegal, such as suicide sites and those showing the manufacturing process for explosive devices, and harmful information regarding contracts for illegal activities such as murders, have become a major societal problem.

Countermeasures to deal with this illegal and harmful information on the Internet, such as arrests by the police and requests to administrators of providers and electronic notice board operators to voluntarily take measures to stop these transmissions, have been taken. But since vast amounts of new information circulate on the Internet every day, it is clear that there are limits to such countermeasures.

Against such a background, and in order to promote effective and efficient measures against illegal and harmful information on the Internet, the Study Group to Address Illegal and Harmful Information on the Internet also stated in its interim report (announced on January 26, 2006) that an investigation should be carried out on policies to support and promote effective measures by providers and electronic notice board operators to stop such transmissions.

In addition, the National Police Agency, in its fiscal year 2005 General Security Countermeasures Conference, stated that it receives a large number of notices from users concerning illegal and harmful information on the Internet, and proposed that decisions concerning the information received should be made based on predetermined standards, and that there was a need to request of administrators at providers and electronic notice board operators for "hotlines" and a framework for their operation in response to the information.

At present, operation guidelines are being investigated at "Hotline Center" (provisional name) which will be the implementation bodies for these hotlines.

Responsibilities

"Hotline Center" (provisional name) will receive information concerning illegal and harmful information on the Internet from Internet users and will categorize them according to predetermined standards that consider the balance between fundamental human rights such as freedom of expression and public welfare. A decision will be made based on predetermined standards, followed by a notice to the police and a request to administrators at providers and electronic notice board operators to erase the information.

[Reference]
Meeting of the Study Group to Address Illegal and Harmful Information on the Internet
http://www.soumu.go.jp/s-news/2005/050728_5.html
Midterm report of the Study Group to Address Illegal and Harmful Information on the Internet
http://www.soumu.go.jp/s-news/2006/060126_1.html

Operation form

The Center will be operated by a private entity and it is planned that a certain number of experts provide the hotline services, after installing service bases and preparing necessary reference material and equipment.


From : Mic Communications News Vol.17 No.2

ISO/IEC 27000 Information Security Standards Family Adopts a New Member

(July 17, 2007)-- ISO/IEC has formally announced the incorporation of the popular Code of Practice for Information Security Management, formerly known as ISO/IEC 17799:2005 and originally BS 7799, into the ISO/IEC 27000-series. The standard is now known as ISO/IEC 27002:2005.

The announcement is more significant than merely a change of name. The growing family of ISO/IEC 27000 series information security standards is increasingly recognised by information security professionals worldwide as an embodiment of good information security practices. Well over 3,500 large and small organizations have been formally certified compliant with ISO/IEC 27001, with many thousands more using the standards internally to structure their approach to information security management and drive continuous security improvements.

First released in 1995, British Standard BS 7799 comprised three parts. Part 1 became ISO/IEC 27002. Part 2 became ISO/IEC 27001. Part 3 is anticipated to become ISO/IEC 27005 in due course.

ISO (the International Organization for Standardization) and IEC (the International Electrical Committee) released ISO/IEC 17799 in 2000 and revised in 2005. Apart from the name , ISO/IEC 27002:2005 is identical to ISO 17799:2005. Its full English title is: "International Standard ISO/IEC 27002:2005. Information technology - Security techniques - Code of practice for information security management".

The ISO/IEC 27000 family is evolving rapidly but at present comprises the following issued or proposed standards:

* ISO/IEC 27000 - will contain the vocabulary and definitions i.e. the specialist terminology used by all of the ISO27k standards.

* ISO/IEC 27001:2005 - is the Information Security Management System requirements standard (specification) against which organizations are formally certified compliant. Published.

* ISO/IEC 27002:2005 is the code of practice for information security management describing a comprehensive set of information security control objectives and a menu of generally accepted good practice controls. Published.

* ISO/IEC 27003 - will be an implementation guide for these standards.

* ISO/IEC 27004 - will be an information security management measurement (metrics) standard to improve the effectiveness of your ISMS.

* ISO/IEC 27005 - will be an information security risk management standard (replacing BS 7799 Part 3).

* ISO/IEC 27006:2007 - is a guide to the certification or registration process for accredited ISMS certification or registration bodies. Published.


* ISO/IEC 27007 - will be a guideline for auditing Information Security Management Systems.

* ISO/IEC 27031 will be a business continuity standard.

* ISO/IEC 27032 will be guidelines for cybersecurity

* ISO/IEC 27034 will be guidelines for application security.

* ISO/IEC 27799 - will be health sector-specific implementation guidance for ISO/IEC 27002. Other sector-specific implementation guides are planned for industries such as lotteries and (in conjunction with the ITU) telecomms.


From : www.compliancehome.com

ISO/IEC 27031 Information technology

ISO/IEC 27031 Information technology -- Security techniques -- ICT readiness for business continuity (draft, title uncertain)

This new business continuity standard may be based on a Singaporean BC/DR standard SS507 (see below) and may incorporate parts of British Standard BS25999. Published July 18, updated Aug 16 If you are interested, Part 2 of BS25999 is currently freely available in draft for comments prior to its formal publication but hurry - comments were due at the end of July 2007 and final release must be imminent.

SS507 - Singapore Standards for Business Continuity/Disaster Recovery (BC/DR) Service Providers

SS507:2004 “Provides a basis to certify and differentiate the BC/DR service providers, helps the end-user organisations in selecting the best-fit service providers and provides quality assurance. Also establishes industry best practices to mitigate outsourcing risks.”

“Singapore [was] the first country in the world to introduce a Standard and Certification programme for BC/DR service providers. Developed by the Infocomm Development Authority of Singapore and the IT Standards Committee (ITSC), the Standard specifies the stringent requirements for BC/DR service providers. These requirements benchmark against the top practices in the region and stipulate the operating, monitoring and up-keeping of BC/DR services offered. ... By engaging a certified BC/DR service provider, assurance is provided to the end-user and frees the company to focus on its core competencies. This enhances the company’s competitive advantage as it is able to achieve stringent Recovery Time Objective, minimise business and data loss; and enjoy uninterrupted services. The certification also serves as a quality mark to inspire service providers to upgrade themselves to provide better services.”

Read a press release about SS507 and purchase a copy here.

0. Introduction

The ICT DR Services Model or Framework - showing the foundation layer to define supporting infrastructure from which services are derived, such as policies, processes, programme, performance measurement, people and products.

1. Scope

Describes the purpose of this standard, assumptions made when using this standard and what is excluded. Introduces subsequent clauses and explains their interpretation

2. Definitions

Defines terms used within the standard to establish a common understanding by the readers.

3. General Guidelines

Basic guidelines for the ICT DR services provision:

3.1 Environmental stability

3.2 Asset management

3.3 Proximity of services

3.4 Subscription (contention) ratio for shared services

3.5 Third party vendor management

3.6 Outsourcing arrangements

3.7 Privacy and confidentiality

3.8 Activation of subscribed services

4. Disaster Recovery Facilities

Specific guidelines for the ICT DR services provision to provide a secure physical operating environment to facilitate recovery:

4.1 Physical access control

4.2 Physical facilities and security

4.3 Environmental controls

4.4 Telecommunications

4.5 Power supply

4.6 Cable management

4.7 Fire protection

4.8 Location of recovery site

4.9 Emergency operations centre

4.10 Restricted facilities

4.11 Physical facilities and equipment lifecycle

4.12 Non recovery amenities

4.13 Testing

4.14 Training and education

5. Recovery Services Capability

Specific guidelines for the ICT DR services provision to develop service delivery capability supporting recovery. Besides qualified staffing, other minimum capabilities include capacity to support simultaneous invocation of disasters:

5.1 Expertise

5.2 Logical access controls

5.3 Equipment and operation readiness

5.4 Simultaneous recovery support

5.5 Levels of service

5.6 Types of service

5.7 Client testing

5.8 Changes in capability

5.9 Emergency response plan

5.10 Self-assessment

5.11 Disaster recovery training and education

6. Guidelines for Selection of Recovery Sites

Provides guidelines on the factors to consider when selecting recovery sites, such as:

6.1 Infrastructure

6.2 Skilled manpower and support

6.3 Critical mass of vendors and suppliers

6.4 Local service providers’ track records

6.5 Proactive local support

7. Additional Guidelines for the Professional ICT DR Service Provider

Additional guidelines for professional service providers in the provision of ICT DR services.

From : iso27001security.com

ISO/IEC 27011 Information technology

ISO/IEC 27011 Information technology -- Security techniques -- Information security management guidelines for telecommunications (draft)

This ISO/IEC 27001/ISO/IEC 27002 implementation guide for the telecomms industry is being developed jointly by ITU and ISO/IEC. It may be published jointly as ITU-T X.1051 and ISO/IEC 27011 but probably not until 2010.

ITU-T Recommendation X.1051 Information security management system – Requirements for telecommunications (ISMS-T) was originally published in English in July 2004, followed by Spanish, French and Russian translations in 2005. It is based on the ISMS standards extant at that time i.e.:

*
ITU-T Recommendation X.800 (1991), Security architecture for Open Systems Interconnection for CCITT applications.
*
ITU-T Recommendation X.805 (2003), Security architecture for systems providing end-to-end communications.
*
ISO 9001:2000, Quality management systems – Requirements.
*
ISO 14001:1996, Environmental management systems – Specification with guidance for use.
*
ISO/IEC 17799:2000, Information technology – Code of practice for information security management (now known as ISO/IEC 27002).
*
ISO/IEC Guide 73:2002, Risk management – Vocabulary – Guidelines for use in standards.
*
BS 7799-2:2002, Information Security Management Systems – Specification with Guidance for use.

The summary states:

“For telecommunications organizations, information and the supporting processes, telecommunications facilities, networks and lines are important business assets. In order for telecommunications organizations to appropriately manage these business assets and to correctly and successfully continue their business activities, information security management is extremely necessary. This Recommendation provides the requirements on information security management for telecommunications organizations.

This Recommendation specifies the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving a documented information security management system (ISMS) within the context of the telecommunication's overall business risks. It specifies requirements for the implementation of security controls customized to the needs of individual telecommunications or parts thereof.”

From : iso27001security.com

Tuesday, August 21, 2007

Information security

Security is everyones responsibility. Security awareness poster. U.S. Department of Commerce/Office of Security.

Information security is the go of guilty in sequence from unofficial access, use, disclosure, destruction, modification, or disruption. [1] The provisions information security , recipe dispensation unit self-confidence and in rank cool are habitually used interchangeably. These fields are unified and bit the unrestricted goals of guilty the confidentiality, integrity and availability of information; however, there are some restrained differences between them. These differences story primarily in the verge on to the subject, the methodologies used, and the areas of concentration. Information self-confidence is disturbed with the confidentiality, integrity and availability of in sequence regardless of the bring into being the in sequence may take: electronic, print, or other forms.

Heads of pomp and forces commanders have stretched tacit the consequence and inevitability of guilty in rank about their forces capabilities, digit of troops and troop movements. Such in rank declining into the hands of the opponent could be disastrous. Governments, military, economic institutions, hospitals, and cap underground businesses mass up a wonderful covenant of confidential in rank about their employees, customers, products, research, and economic status. Most of this in rank is now collected, processed and stored on electronic computers and transmitted across networks to other computers. Should confidential in rank about a businesses customers or finances or new outcome stripe descend into the hands of a competitor, such a crack open of self-confidence could direct to missing business, commandment suits or even insolvency of the business. Protecting confidential in rank is a problem requirement, and in many cases, it is also a lawful requirement, and some would say that it is the right event to do . For the individual, in rank self-confidence has a hefty promote to on Privacy, which is viewed very in a different way in different cultures.

The branch of learning of in rank self-confidence has grown-up and evolved much in latest years. As a career diversity there are many behavior of in advance have a crack into the field. The branch of learning offers many areas for hobby together with Information Systems Auditing, Business Continuity Planning and Digital Forensics Science to name a few.

This condition presents a all-purpose overview of in rank self-confidence and its essential concepts.

Contents

  • 1 A brief occasion gone by of Information Security
  • 2 Basic philosophy of Information Security
    • 2.1 Confidentiality, integrity, availability
    • 2.2 Risk management
    • 2.3 Three types of controls
    • 2.4 Security classification for information
    • 2.5 Access control
    • 2.6 Cryptography
    • 2.7 Defense in depth
  • 3 Information self-confidence as a process
    • 3.1 Security planning
    • 3.2 Incident retort plans
    • 3.3 Change management
    • 3.4 Disaster recovery planning
  • 4 Laws and formula governing Information Security
  • 5 Sources of philosophy for Information Security
  • 6 Conclusion
  • 7 Notes and references
  • 8 Bibliography
  • 9 See also
  • 10 External links

A brief occasion gone by of Information Security

This condition will not try to present a widespread occasion gone by of the branch of learning of in rank security, rather it will be enough to communicate the innovative roots and vital developments of what is now known as in rank security.

Since the near the launch being of writing, heads of pomp and forces commanders tacit that it was necessary to present some method to tending for the confidentiality of on paper correspondence and to have some assets of detecting tampering. Persons desiring confident radio have used shine seals and other sealing diplomacy since the near the launch being of marks to mean the faithfulness of documents, avert tampering, and guarantee confidentiality of correspondence.

Julius Caesar is recognized with the opening out and use of the Caesar symbols c50 B.C. to avert his classified letters from being scan should a significance descend into the wicked hands.

World War II brought about many advancements in in rank self-confidence and may smudge the foundation of in rank self-confidence as a proficient field. WWII saw advancements in the rude shield of in rank with barricades and armed guards calculating right of have a crack into in rank centers. It also saw the preface of spokesperson classification of in sequence based upon the sensitivity of the in rank and who could have right of have a crack to the information. [2] During WWII credentials checks were also conducted before surrendering clearance to classified information. WWII also saw the opening out and use of natural ciphering machines, the German Enigma robot for example, to encode and decode classified communications.

The terminate of the 20th century and near the launch being of the 21st century saw fast advancements in telecommunications, computing hardware and software, and in sequence encryption. The availability of smaller, more potent and less posh computing gear prepared electronic in sequence dispensation within the achieve of miniature problem and the cap underground user. These computers fleetingly became unified through a sorority broadly called the Internet or World Wide Web.

The fast occurrence and eclectic achieve use of electronic in sequence dispensation and electronic problem conducted through the Internet, along with several occurrences of intercontinental terrorism, fueled the need for better methods of guilty these computers and the in rank they store, go and transmit. The speculative disciplines of recipe dispensation unit security, in rank self-confidence and in rank cool emerged along with several proficient organizations - all rift the unrestricted goals of insuring the self-confidence and reliability of in rank systems.

Basic philosophy of Information Security

Confidentiality, integrity, availability

For over twenty being in rank self-confidence has under arrest that three vital concepts bring into being the essential philosophy of in rank security: confidentiality, integrity and availability. These are known as the CIA Triad.

Confidentiality

It is in promote to intolerable to get a drivers license, rent an apartment, find medicinal care, or take out a credit without disclosing a wonderful covenant of very own in rank about ourselves, such as our name, address, cause a buzz number, daylight of the week of birth, Social Security Number, marital status, digit of children, mother’s maiden name, income, rank of employment, medicinal history, etc. This is all very own and cap underground information, yet we are often mandatory to present such in rank in congregate to conclude business. We normally take it on trust that the person, business, or foundation to whom we reveal such own in rank have taken trial to cover that our in rank will be sheltered from unofficial discloser, either unintentional or intentional, and that our in rank will only be joint with other people, businesses or institutions who are strict to have right of have a crack to the in rank and who have a legitimate need to know the information.

CIA Triad.

Information that is careful to be confidential in temperament must only be accessed, used, copied, or disclosed by personnel who have been strict to access, use, copy, or reveal the information, and then only when there is a legitimate need to access, use, font or reveal the information. A crack open of confidentiality occurs when in rank that is careful to be confidential in temperament has been, or may have been, accessed, used, copied, or disclosed to, or by, someone who was not strict to have right of have a crack to the information.

For example: permitting someone to look over your shoulder at your recipe dispensation unit vet while you have confidential in sequence displayed on it would be a crack open of confidentiality if they were not strict to have the information. If a pc computer, which contains employment and help in rank about 100,000 employees, is stolen from a van (or is sold on eBay) could outcome in a crack open of confidentiality because the in rank is now in the hands of someone who is not strict to have it. Giving out confidential in rank over the cause a buzz is a crack open of confidentiality if the caller is not strict to have the information.

Confidentiality is a requisite for maintaining the privacy of the fill whose own in rank the congregate holds.

Integrity

In in rank security, integrity assets that in sequence can not be created, changed, or deleted without authorization. It also assets that in sequence stored in one module of a row be an enthusiast of is in covenant with other allied in sequence stored in another module of the row be an enthusiast of (or another system). For example: a trouncing of integrity can come to go on when a row be an enthusiast of is not in the usual behavior go wager on dwelling for the compute down before maintenance is performed or the row ma?tre d’h?tel out of the blue loses electrical power. A trouncing of integrity occurs when an associate of staff accidentally, or with malicious intent, deletes crucial in sequence files. A trouncing of integrity can come to go on if a recipe dispensation unit virus is on the loose onto the computer. A trouncing of integrity occurs when an on-line punter is able to adjustment the estimate of the outcome they are purchasing.

Availability

The idea of availability assets that the information, the computing systems used to go the information, and the self-confidence gearshift used to tending for the in rank are all available and functioning in the usual behavior when the in rank is needed. The contrary of availability is rejection of overhaul (DOS). [3]

In 2002, Mr. Donn Parker upcoming an option outcome for the classic CIA musical tones that he called the six atomic essentials of information. His option outcome includes confidentiality, possession or control, integrity, authenticity, availability, and utility. The virtues of the Parkerian hexad are a branch of learning of contest amongst self-confidence professionals.

Risk management

A widespread dealing of the theme of hazard management is beyond the scope of this article. We will however, present a useful classification of hazard management, outline a regularly used go for hazard management, and communicate some essential terminology.

The CISA Review Manual 2006 provides the following classification of hazard management: “Risk management is the go of identifying vulnerabilities and threats to the in rank capital used by an congregate in achieving problem objectives, and deciding what countermeasures, if any, to take in sinking hazard to an sufficient level, based on the value of the in rank source to the organization.” [4]

There are two gear in this classification that may need some clarification. First, the process of hazard management is an ongoing iterative process. It must be repetitive indefinitely. The problem location is constantly varying and new threats and vulnerabilities emerge every day. Second, the diversity of countermeasures (controls) used to go risks must achieve a weighing scale between productivity, cost, effectiveness of the countermeasure, and the value of the informational asset being protected.

Risk is the likelihood that something contrite will materialize that causes damage to an informational asset (or the trouncing of the asset). A vulnerability is a weakness that could be used to put in danger or cause damage to an informational asset. A threat is anything (man prepared or take steps of nature) that has the possibility to cause harm.

The likelihood that a menace will use a defenselessness to cause damage creates a risk. When a menace does use a defenselessness to inflict harm, it has an impact. In the situation of in rank security, the bang is a trouncing of availability, integrity, and confidentiality, and maybe other losses (lost income, trouncing of life, trouncing of sincere property). It should be barbed out that it is not possible to pinpoint all risks, nor is it possible to eliminate all risk. The lasting hazard is called residual risk .

A hazard assessment is agreed out by a players of fill who have culture of explicit areas of the business. Membership of the players may illustrate a discrepancy over stage as different parts of the problem are assessed. The assessment may use a subjective qualitative examination based on educated opinion, or where dependable dough statistics and chronological in rank is available, the examination may use quantitative analysis.

The ISO-17799:2005 Code of be an enthusiast of for in rank self-confidence management recommends the following be examined during a hazard assesment: security policy, congregate of in rank security, asset management, creature capital security, rude and environmental security, radio and operations management, right of have a crack control, in rank systems acquisition, opening out and maintenance, in rank self-confidence event management, problem continuity management, and rigid compliance.

In broad provisions the hazard management go consists of:

  1. Identification of assets and estimating their value. Include: people, buildings, hardware, software, in sequence (electronic, print, other), supplies.
  2. Conduct a menace assessment. Include: Acts of nature, acts of war, accidents, malicious acts originating from in or outside the organization.
  3. Conduct a defenselessness assessment, and for each vulnerability, gauge the probability that it will be exploited. Evaluate policies, procedures, standards, training, rude security, condition control, industrial security.
  4. Calculate the bang that each menace would have on each asset. Use qualitative examination or quantitative analysis.
  5. Identify, cap underground and apply appropriate controls. Provide a proportional response. Consider productivity, asking estimate effectiveness, and value of the asset.
  6. Evaluate the effectiveness of the charge measures. Insure the gearshift present the mandatory asking estimate sincere shield without discernable trouncing of productivity.

For any given risk, Executive Management can take to accept the risk based upon the qualified at a dwindling smooth value of the asset, the qualified at a dwindling smooth frequency of occurrence, and the qualified at a dwindling smooth bang on the business. Or, leadership may take to mitigate the risk by selecting and implementing appropriate charge trial to cut the risk. In some cases, the hazard can be transferred to another problem by selling reassurance or out-sourcing to another business. The veracity of some risks may be disputed. In such bags leadership may take to deny the risk . This is itself a possibility risk. [3]

Three types of controls

When Management chooses to dull a risk, they will do so by implementing one or more of three different types of controls.

Administrative gearshift are comprised of agreed on paper policies, procedures, philosophy and guidelines. Administrative gearshift bring into being the framework for dealing out the problem and in succession people. They update fill on how the problem is to be persist and how compute to compute operations are to be conducted. Laws and formula shaped by management bodies are also a variety of administrative charge because they update the business. Some trade sectors have policies, procedures, philosophy and guidelines that must be followed - the Payment Card Industry (PCI) Data Security Standard mandatory by Visa and Master Card is such an example. Other examples of administrative gearshift embrace the corporate self-confidence policy, password policy, hiring policies, and disciplinary policies.

Administrative gearshift bring into being the root for the range and implementation of sensible and rude controls. Logical and rude gearshift are manifestations of administrative controls. Administrative gearshift are of chief importance.

Logical gearshift (also called industrial controls) use software and in sequence to overseer and charge right of have a crack to in rank and computing systems. For example: passwords, sorority and multitude based firewalls, sorority interruption detection systems, right of have a crack charge lists, and in sequence encryption are sensible controls.

An crucial sensible charge that is habitually overlooked is the principle of least privilege . The belief of least privilege requires that an individual, course or be an enthusiast of go is not usual any more right of have a crack privileges than are necessary to achieve the task. A blatant example of the catastrophe to adhere to the belief of least privilege is sorting into Windows as addict Administrator to scan Email and breakers the Web. Violations of this belief can also come to go on when an own collects further right of have a crack privileges over time. This happens when employees’ commission duties change, or they are promoted to a new position, or they relocate to another department. The right of have a crack privileges mandatory by their new duties are habitually new onto their already obtainable right of have a crack privileges which may no longer be necessary or appropriate.

Physical gearshift overseer and charge the location of the come off rank and computing facilities. They also overseer and charge right of have a crack to and from such facilities. For example: doors, locks, heating and vent conditioning, smoke and throw out alarms, throw out suppression systems, cameras, barricades, fencing, self-confidence guards, cable locks, etc. Separating the sorority and come off rank into functional areas are also rude controls.

An crucial rude charge that is habitually overlooked is the separation of duties . Separation of duties insures that an own can not achieve a decisive commission by himself. For example: an associate of staff who submits a ask for for settlement should not also be able to empower payment or font the check. An applications programmer should not also be the ma?tre d’h?tel spokesperson or the row spokesperson - these roles and responsibilities must be separated from one another. [3]

Security classification for information

An crucial condition of in rank self-confidence and hazard management is recognizing the value of in rank and middle appropriate procedures and shield food for the information. Not all in rank is be imitation with and so not all in rank requires the same rate of protection. This requires in rank to be assigned a self-confidence classification.

The first action in in rank classification is to pinpoint a organ of chief management as the title-holder of the particular in rank to be classified. Next, outcome a classification policy. The decide should communicate the different classification labels, communicate the criteria for in rank to be assigned a particular label, and promote to a catalog the mandatory self-confidence gearshift for each classification.

Some factors that sway which classification in rank should be assigned embrace how much value that in rank has to the organization, how old the in rank is and whether or not the in rank has become obsolete. Laws and other rigid food are also crucial considerations when classifying information.

Common in rank self-confidence classification labels used by the problem sector are: public, sensitive, private, confidential . Common in rank self-confidence classification labels used by management are: unclassified, receptive but unclassified, confidential, secret, perk up on secret .

All employees in the organization, as well as problem partners, must be qualified on the classification graph and value the mandatory self-confidence gearshift and in succession procedures for each classification. The classification a particular in rank asset has been assigned should be reviewed periodically to cover the classification is still appropriate for the in rank and to cover the self-confidence gearshift mandatory by the classification are in place. [3]

Access control

Access to sheltered in rank must be constrained to fill who are strict to right of have a crack the information. The recipe dispensation unit programs, and in many bags the computers that go the information, must also be authorized. This requires that mechanisms be in rank to charge the right of have a crack to sheltered information. The urbanity of the right of have a crack charge mechanisms should be in parity with the value of the in rank being sheltered - the more receptive or beneficial the in rank the stronger the charge mechanisms need to be. The foundation on which right of have a crack charge mechanisms are built foundation with identification and authentication.

Identification is an assertion of who someone is or what something is. If a individuality makes the testimony “Hello, my name is John Doe.” they are construction a have a collection of of who they are. However, their have a collection of may or may not be true. Before John Doe can be usual right of have a crack to sheltered in rank it will be necessary to verify that the individuality claiming to be John Doe really is John Doe.

Authentication is the take steps of verifying a have a collection of of identity. When John Doe goes into a save to put up a withdrawal, he tells the save cashier he is John Doe (a have a collection of of identity). The save cashier asks to see a photo ID, so he hands the cashier his drivers license. The save cashier checks the privilege to put up sure it has John Doe in font on it and compares the photograph on the privilege against the individuality claiming to be John Doe. If the photo and name go with the person, then the cashier has honest that John Doe is who he claimed to be.

There are three different types of in rank that can be used for authentication: something you know, something you have, or something you are. Examples of something you know embrace such gear as a PIN number, a password, or your mothers maiden name. Examples of something you have embrace a drivers privilege or a alluring put up off with card. Something you are refers to biometrics. Examples of biometrics embrace palm prints, classify prints, supremacy of speech prints and retina (eye) scans. Strong legalization requires if in rank from two of the three different types of legalization information. For example, something you know plus something you have. This is called two entity authentication.

On recipe dispensation unit systems in use today, the Username is the most unrestricted bring into being of identification and the Password is the most unrestricted bring into being of authentication. Usernames and passwords have served their object but in our highly industrial humankind they are no longer adequate. Usernames and passwords are at a snail’s pace being replaced with more veteran legalization mechanisms.

After a person, course or recipe dispensation unit has effectively been identified and honest then it must be firm what informational capital they are allowable to right of have a crack and what trial they will be permissible to achieve (run, view, create, delete, or change). This is called authorization .

Authorization to right of have a crack in rank and other computing look coerce begins with administrative polices and procedures. The polices prescribe what in rank and computing look coerce can be accessed, by whom, and under what conditions. The right of have a crack charge mechanisms are then configured to enforce these policies.

Different computing systems are equipped with different kinds of right of have a crack charge mechanisms, some may propose a diversity of different right of have a crack charge mechanisms. The right of have a crack charge method a be an enthusiast of offers will be based upon one of three approaches to right of have a crack charge or it may be consequential from a arrangement of the three approaches.

The non-discretionary verge on consolidates all right of have a crack charge under a middle administration. The right of have a crack to in rank and other capital is usually based on the folks lane (role) in the congregate or the errands the own must perform. The unrestricted verge on gives the designer or title-holder of the in rank source the knack to charge right of have a crack to those resources. In the Mandatory right of have a crack charge approach, right of have a crack is usual or denied bases upon the self-confidence classification assigned to the in rank resource.

Examples of unrestricted right of have a crack charge mechanisms in use nowadays embrace Role-based right of have a crack charge available in many highly industrial Database Management Systems, undemanding row permissions provided in the UNIX and Windows in commission systems, Group Policy Objects provided in Windows sorority systems, Kerberos, RADIUS, TACACS, and the undemanding right of have a crack lists used in many firewalls and routers.

To be effective, policies and other self-confidence gearshift must be enforceable and upheld. Effective policies cover that fill are under arrest accountable for their actions. All abortive and lucrative legalization attempts must be logged, and all right of have a crack to in rank must avoid some variety of appraisal trail. [3]

Cryptography

Information self-confidence uses cryptography to transform usable in rank into a bring into being that renders it unusable by anyone other than an strict user; this go is communicate encryption. Information that has been encrypted (rendered unusable) can be transformed toward the ago into its innovative usable bring into being by an strict user, who possesses the cryptographic key, through the go of decryption. Cryptography is used in in rank self-confidence to tending for in rank from unofficial or unintentional discloser while the in rank is in transit (either electronically or physically) and while in rank is in storage.

Cryptography provides in rank self-confidence with other useful applications as well together with superior legalization methods, significance digests, digital signatures, non-repudiation, and encrypted sorority communications. Older less confident object such as telnet and ftp are at a snail’s pace being replaced with more confident applications such as SSH that use encrypted sorority communications. Wireless radio can be encrypted using the WPA protocol. Software applications such as GNUPG or PGP can be used to encrypt in sequence have a collection of and Email.

Cryptography can present self-confidence troubles when it is not implemented correctly. Cryptographic solutions need to be implemented using trade customary solutions that have undergone rigorous peer assess by unconnected experts in cryptography. The chunk and intensity of the encryption vital is also an crucial consideration. A vital that is weak or too passing will engender weak encryption. The keys used for encryption and decryption must be sheltered with the same rate of notice as any other confidential information. They must be sheltered from unofficial admission and destruction and they must be available when needed. PKI solutions lecture to many of the troubles that surround vital management.

Defense in depth

Information self-confidence must tending for in rank through out the sparkle span of the information, from the preliminary fabrication of the in rank on through to the irrevocable disposal of the information. The in rank must be sheltered while in beckon and while at rest. During its sparkle time, in rank may go by through many different in rank dispensation systems and through many different parts of in rank dispensation systems. There are many different behavior the in rank and in rank systems can be threatened. To wholly tending for the in rank during its lifetime, each module of the in rank dispensation be an enthusiast of must have its own shield mechanisms. The shape up, layering on and overlapping of self-confidence trial is called apology in depth. The intensity of any be an enthusiast of is no better than its weakest link. Using a apology in supremacy strategy, should one guilty quantify neglect there are other guilty trial in rank that pick up again to present protection.

Recall the formerly chat about administrative controls, sensible controls, and rude controls. The three types of gearshift can be used to bring into being the bases upon which to foster a apology in supremacy strategy. With this approach, apology in supremacy can be conceptualized as three distinctive layers or planes laid one on perk up on of the other. Additional insight into apology in supremacy can be gained by belief of it as forming the layers of an onion, with in sequence at the essential of the onion, fill as the surface layer of the onion, and sorority security, multitude based self-confidence and applications self-confidence forming the inner layers of the onion. Both perspectives are just as justifiable and each provides beneficial insight into the implementation of a dependable apology in supremacy strategy.

Information self-confidence as a process

The provisions reasonable and sensible person , due care and due diligence have been used in the fields of Finance, Securities, and Law for many, many years. In latest being these provisions have bring into being their way into the fields of computing and in rank security. U.S.A. Federal Sentencing Guidelines now put up it possible to cleave to corporate officers predisposed for worsening to problem looked-for be disturbed and looked-for thoroughness in the management of their in rank systems.

In the problem world, stockholders, customers, problem partners and governments have the expectation that corporate officers will persist the problem in accordance with customary problem practices and in diminishing in contour with laws and other rigid requirements. This is often described as the “reasonable and sensible person” rule. A sensible individuality takes looked-for be disturbed to cover that everything necessary is done to lane the problem by positive problem philosophy and in a lawful ethical manner. A sensible individuality is also conscientious (mindful, attentive, and ongoing) in their looked-for be disturbed of the business.

In the branch of learning of Information Security, Harris [5] offers the following definitions of due care and due diligence :

“Due be disturbed are steps that are taken to parade that a guests has taken blame for the dealings that take rank within the corporation and has taken the necessary steps to help tending for the company, its resources, and employees.” And, [Due thoroughness are the] “continual dealings that put up sure the shield mechanisms are persistently maintained and operational.”

Attention should be prepared to two crucial points in these definitions. First, in looked-for care, steps are taken to show - this assets that the steps can be verified, measured, or even engender perceptible artifacts. Second, in looked-for diligence, there are continual activities - this assets that fill are actually doing gear to overseer and sustain the shield mechanisms, and these dealings are ongoing.

Security planning

1 to 3 paragraphs (non technical) that discuss:

  • The charter
  • Reporting structure
  • Strategic plan
  • Project management
  • Review applicable laws and the rigid environment
  • Risk assessment and hazard diminution plans
  • Budgeting and funding
  • Standards and Policies
  • Training is not elective - preparation is a requirement
  • Monitoring and auditing plans

Incident retort plans

1 to 3 paragraphs (non technical) that discuss:

  • Selecting players members
  • Define roles, responsibilities and outline of authority
  • Define a self-confidence incident
  • Define a reportable incident
  • Training
  • Detection
  • Classification
  • Escalation
  • Containment
  • Eradication
  • Documentation

Change management

Change management is a decorous go for directing and calculating alterations prepared to the in rank dispensation environment. This includes alterations to desktop computers, the network, servers and software. The objectives of adjustment management are to cut the risks posed by changes to the in rank dispensation location and perk up the stability and reliability of the dispensation location as changes are made. It is not the objective of adjustment management to avert or delay necessary changes from being implemented.

Any adjustment to the in rank dispensation location introduces an facet of risk. Even rumor has it that undemanding changes can have unexpected affects. One of Managements many responsibilities is the management of risk. Change management is a tool for in succession the risks introduced by changes to the in rank dispensation environment. Part of the adjustment management go insures that changes are not implemented at mistimed period when they may disrupt decisive problem processes or interfere with other changes being implemented.

Not every adjustment needs to be managed. Some kinds of changes are a module of the everyday custom of in rank dispensation and adhere to a predefined procedure, which reduces the overall next to of hazard to the dispensation environment. Creating a new addict savings explanation or deploying a new desktop recipe dispensation unit are examples of changes that do not normally expect adjustment management. However, relocating addict row shares, or upgrading the Email ma?tre d’h?tel pose a much upper next to of hazard to the dispensation location and are not a regular everyday activity.

Change management is usually overseen by a Change Review Board comprised of regime from vital problem areas, security, networking, systems administrators, Database administration, applications development, desktop foundation and the help desk. The errands of the Change Review Board can be facilitated with the use of automated come off up to daylight of the week application. The blame of the Change Review Board is to cover the organizations recognized adjustment management procedures are followed. The adjustment management go is as follows:

Requested: Anyone can ask for a change. The individuality construction the adjustment ask for may or may not be the same individuality that performs the examination or gear the change. When a ask for for adjustment is received, it may undergo a preliminary assess to govern if the requested adjustment is similar in temperament with the organizations problem outcome and practices, and to govern the sum of capital painstaking necessary to apply the change.

Approved: Management runs the problem and gearshift the allocation of capital therefore, Management must agree needs for changes and assign a priority for every change. Management might take to rebuff a adjustment ask for if the adjustment is not similar in temperament with the problem model, trade philosophy or best practices. Management might also take to rebuff a adjustment ask for if the adjustment requires more capital than can be allocated for the change.

Planned Planning a adjustment involves discovering the scope and bang of the upcoming change; analyzing the difficulty of the change; allocation of capital and, developing, difficult and documenting an implementation plan.

Tested: Every adjustment must be veteran in a anodyne ordeal environment, which directly reflects the definite invention environment, before the adjustment is functional to the invention environment.

Scheduled: Part of the adjustment assess board’s blame is to assist in the scheduling of changes by reviewing the upcoming implementation daylight of the week for possibility conflicts with other scheduled changes or decisive problem activities.

Communicated: Once a adjustment has been scheduled it must be communicated. The contact is to furnish others the opening to take you wager on the adjustment assess plank about other changes or decisive problem dealings that might have been overlooked when scheduling the change. The contact also serves to put up the Help Desk and users perceptive that a adjustment is about to occur. Another blame of the adjustment assess plank is to cover that scheduled changes have been in the usual behavior communicated to those who will be artificial by the adjustment or otherwise have an hobby in the change.

Implemented: At the appointed daylight of the week and time, the changes must be implemented. Part of the preparation go was to outcome an implementation plan, difficult chart and, a toward the ago out plan. If the implementation of the adjustment should neglect or, the column implementation difficult fails or, other “drop dead” criteria have been met, the toward the ago out chart should be implemented.

Documented: All changes must be documented. The minutes includes the preliminary ask for for change, its approval, the priority assigned to it, the implementation, difficult and toward the ago out plans, the outcome of the adjustment assess plank critique, the date/time the adjustment was implemented, who implemented it, and whether the adjustment was implemented successfully, abortive or postponed.

Post adjustment review: The adjustment assess plank should cleave to a column implementation assess of changes. It is particularly crucial to assess abortive and backed out changes. The assess plank should try to value the troubles that were encountered, and look for areas for improvement.

Change management procedures that are undemanding to be a fan of and cool to use can importantly cut the overall risks shaped when changes are prepared to the in rank dispensation environment. Good adjustment management procedures perk up the over all condition and triumph of changes as they are implemented. This is accomplished through planning, peer review, minutes and communication.

The ISO-20000, Visible Ops and Information Technology Infrastructure Library all present beneficial guidance on implementing an cost-effective and sincere adjustment management program.

Disaster recovery planning

2 or 3 paragraphs (non technical) that discuss:

  • What is Disaster Recovery Planning
  • How are DRP and BCP different
  • How are DRP and BCP related
  • Project leader
  • Identify vital stake holders
  • Identify vital assets
  • Prioritize vital problem functions and vital asset
  • Review up to daylight of the week class for adequacy
  • Make a plan

Laws and formula governing Information Security

Below is a partial item of European, United Kingdom, and USA lawmaking laws and formula that have, or will have, a hefty promote to on in sequence dispensation and in rank security. Important trade sector formula have also been integrated when they have a hefty bang on in rank security.

UK Data Protection Act 1998 makes new provisions for the directive of the dispensation of in rank linking to individuals, together with the obtaining, holding, use or admission of such information. The European Union Data Protection Directive (EUDPD) requires that all EU organ must take up pomp formula to regiment the shield of in sequence privacy for citizens throughout the EU.

EU Data Retention laws requires Internet overhaul providers and handset companies to keep in sequence on every electronic significance sent and handset communicate prepared for between six months and two years.

The Family Educational Rights and Privacy Act (FERPA) (20 U.S.C. 1232 g; 34 CFR Part 99) is a USA Federal commandment that protects the privacy of apprentice culture records. The commandment applies to all schools that meet proceeds under an applicable course of the U.S. Department of Education. Generally, schools must have on paper consent from the worry for or eligible apprentice in congregate to discharge any in rank from a student’s culture record.

Health Insurance Portability and Accountability Act (HIPAA) requires the adoption of pomp philosophy for electronic unrefined condition be disturbed transactions and pomp identifiers for providers, unrefined condition reassurance plans, and employers. And, it requires unrefined condition be disturbed providers, reassurance providers and employers to safeguard the self-confidence and privacy of unrefined condition data.

Gramm-Leach-Bliley Act of 1999(GLBA), also know as the Financial Services Modernization Act of 1999, protects the privacy and self-confidence of cap underground economic in rank that economic institutions collect, hold, and process.

Sarbanes-Oxley Act of 2002 (SOX). Section 404 of the take steps requires visibly traded companies to assess the effectiveness of their interior gearshift for economic healing in yearly news they hand in at the terminate of each economic year. Chief in rank officers are to blame for the security, truth and the reliability of the systems that go and story the economic data. The take steps also requires visibly traded companies to engage unconnected auditors who must testify to, and story on, the weight of their assessments.

Payment Card Industry Data Security Standard (PCI DSS) establishes widespread food for enhancing payment savings explanation in sequence security. It was residential by the founding payment brands of the PCI Security Standards Council, together with American Express, Discover Financial Services, JCB, MasterCard Worldwide and Visa International, to help facilitate the broad adoption of in harmony in sequence self-confidence trial on a broad basis. The PCI DSS is a intricate self-confidence banner that includes food for self-confidence management, policies, procedures, sorority architecture, software conceive and other decisive defending measures.

State Security Breach Notification Laws (California and many others) expect businesses, nonprofits, and pomp institutions to acquaint trade when unencrypted “personal information” may have been compromised, lost, or stolen.

Sources of philosophy for Information Security

International Organization for Standardization (ISO) is a conglomerate of pomp philosophy institutes from 157 countries with a Central Secretariat in Geneva Switzerland that coordinates the system. The ISO is the world’s prevalent developer of standards. The ISO-15443: “Information expertise - Security techniques - A framework for IT self-confidence assurance”, ISO-17799: “Information expertise - Security techniques - Code of be an enthusiast of for in rank self-confidence management”, ISO-20000: “Information expertise - Service management”, and ISO-27001: “Information expertise - Security techniques - Information self-confidence management systems” are of particular hobby to in rank self-confidence professionals.

The USA National Institute of Standards and Technology (NIST) is a non-regulatory middle bureau within the U.S. Commerce Department’s Technology Administration. The NIST Computer Security Division develops standards, metrics, tests and confirmation programs as well as publishes philosophy and guidelines to proliferation confident IT planning, implementation, management and operation. NIST is also the curator of the USA Federal Information Processing Standards Publications (FIPS).

The Internet Society (ISOC) is a proficient memory the all-purpose unrestricted with more than 100 congregate and over 20,000 own members in over 180 countries. It provides leadership in addressing issues that confront the upcoming of the Internet, and is the congregate cap underground for the groups to blame for Internet infrastructure standards, together with the Internet Engineering Task Force (IETF) and the Internet Architecture Board (IAB). The ISOC hosts the Requests for Comments (RFCs) which includes the Official Internet Protocol Standards and the RFC-2196 Site Security Handbook.

Conclusion

Information self-confidence is the ongoing go of exercising looked-for be disturbed and looked-for thoroughness to tending for information, and in rank systems, from unofficial access, use, disclosure, destruction, modification, or disruption. The never finish go of in rank self-confidence involves ongoing training, assessment, protection, monitoring & detection, event retort & repair, documentation, and review.

The speculative disciplines of recipe dispensation unit security, in rank self-confidence and in rank cool emerged along with several proficient organizations during the later being of the 20th century and near the launch being of the 21st century. Entry into the branch of learning can be accomplished through self-study, academe or academe teaching in the field, or through week stretched all ears preparation camps. Many colleges, universities and preparation companies propose many of their programs on- line. The GIAC-GSEC and Security+ certifications are both respected have a crack next to self-confidence certifications. The Certified Information Systems Security Professional (CISSP) is a well respected mid- to senior-level in rank self-confidence certification.

The profession of in rank self-confidence has seen an augmented inquire for self-confidence professionals who are skilled in sorority self-confidence auditing, dispersion testing, and digital forensics investigation.

Notes and references

  1. ^ 44 U.S.C 3542 (b)(1) (2006)
  2. ^ Quist, Arvin S. (2002). ” Security Classification of Information ” (HTML). Volume 1. Introduction, History, and Adverse Impacts. Oak Ridge Classification Associates, LLC. Retrieved on 2007-01-11.
  3. ^ a b c d e See Bibliography.
  4. ^ ISACA (2006). CISA Review Manual 2006 . Information Systems Audit and Control Association, p. 85. ISBN 1-933284-15-3.
  5. ^ Harris, Shon (2003). All-in-one CISSP Certification Exam Guide , 2nd Ed., Emeryville, CA: McGraw-Hill/Osborne. 0-07-222966-7.

Bibliography

Allen, Julia H. (2001). The CERT Guide to System and Network Security Practices . Boston, MA: Addison-Wesley. 0-201-73723-X.

Krutz, Ronald L.; Russell Dean Vines (2003). The CISSP Prep Guide , Gold Edition, Indianapolis, IN: Wiley. 0-471-26802-X.

Layton, Timothy P. (2007). Information Security: Design, Implementation, Measurement, and Compliance . Boca Raton, FL: Auerbach publications. 978-0-8493-7087-8.

McNab, Chris (2004). Network Security Assessment . Sebastopol, CA: O’Reilly. 0-596-00611-X.

Peltier, Thomas R. (2001). Information Security Risk Analysis . Boca Raton, FL: Auerbach publications. 0-8493-0880-1.

Peltier, Thomas R. (2002). Information Security Policies, Procedures, and Standards: guidelines for sincere in rank self-confidence management . Boca Raton, FL: Auerbach publications. 0-8493-1137-3.

White, Gregory (2003). All-in-one Security+ Certification Exam Guide . Emeryville, CA: McGraw-Hill/Osborne. 0-07-222633-1.

See also

  • Computer security
  • Computer insecurity

External links

  • Security Management: Guide to CISSP, Information Security Certification
  • OlympoS Information Security Portal (Turkish)



Information Assurance For The Enterprise: A Roadmap To (Paperback) (ShoppersChoice.com)

McGraw-Hill College
Author: Schou, Corey/ Shoemaker, Dan. Number of Pages: 480. Published On: 2006/09/15. Language: ENGLISH

The Information Systems Security Officer S Guide: Establishing And Managing An Information Protection Program (Paperback) (ShoppersChoice.com)

Butterworth-Heinemann
Author: Kovacich, Gerald L. Number of Pages: 361. Published On: 2003/08/01. Language: ENGLISH


Related searches: , , , ,
Tags: , , , ,
related posts:
  • Microsoft Encyclopedia
  • Microsoft Encarta 98 Encyclopedia NR US $0.99 (0 Bid) End Date: Monday Apr-23-2007 15:26:15 PDT Bid now | Add to watch list Microsoft Encarta 2006 Encyclopedia US $4.99
  • Chapin Information Services
  • Related Articles about chapin information services General Information Services Inc. Opens New Network Operations Center; Security and Communications Upgrades Will Enhance Data Protection...... From Business Wire on 05/11/2006 CHAPIN, S.C. -- General Information Services Inc. (GIS) has moved its HP EVA 5000 (Enterpriseregulatory
  • Voting Information
  • Related Articles about voting information Information asymmetries and simultaneous versus sequential voting . From American Political Science Review on 03/01/1999 minutes of instruction. Information Assumptions, Simultaneous Voting, and Sequential VotingAnalysis of Sequential Voting under Incomplete Information Information Revelationthat is, can group A voting reveal
  • Online Translation
  • Is Online Arabic Translation Really Accurate? There are many online dictionaries and rendition tools that are able to take a utterance in English and decipher it into Arabic. But are these online rendition navy always accurate? How are labyrinth companies that manipulate these websites ensuring quality? It is a
  • Information Management
  • Information management This appraisal may oblige attack to touch Wikipedia's class standards. Please thrash out this give out on the rumor side or supplant this tag with a more exact message. This appraisal has been tagged since

    This entry was posted on at and is filed under Encyclopedias. You can follow any responses to this entry through the RSS 2.0 feed. Both comments and pings are currently closed.

    Comments are closed.

    ISO 17799 — Compliance

    Compliance has become one of the most talked about security issues in American business. Banks and financial institutes have had government oversight for decades. New compliance requirements have been imposed upon many organizations.

    Recent financial reporting irregularities prompted Congressional action in which public companies must comply to the financial and accounting disclosure of information act known as Sarbannes-Oxley (SOX). Recent trends with identity theft and fraud, any business — small or large — that accepts credit cards, require businesses to abide by the industry’s Payment Card Industry’s Data Security Standard (PCI DSS). For the healthcare industry, organizations must adhere to the Health Insurance Portability and Accountability Act of 1996 (HIPAA).

    The ISO 17799 section on compliance has as its objective to help organizations avoid breaches of any criminal and civil law, statutory, regulatory or contractual obligations and of any security requirements. This section marries IT, legal, accounting and security.

    Intellectual Property Rights

    This is all about patents, trademarks, copyrights including software, and trade secrets. Some recommendations on what an organization can do to help safeguard their IP include: know what you’ve got, prioritize it, label it, lock it, educate employees, know your tools, think holistically, and apply a counter-intelligence mindset. IP protection responsibilities spans the entire organization from the IT systems and facilities to the users, owners and management.

    Safeguarding of Organizational Records

    Organizational records — hard or soft copies — should be protected from loss, destruction and falsification. Whether these records are accounting, database, transaction and audit logs or operational procedures, all are stored on various paper, microfiche, magnetic, optical media and must adhere to some retention period. Records are useful for business (financial status with respect to shareholders, partners and auditors) as well as precaution required by statutory or regulatory rules, and defense against potential civil or criminal action.

    Data Protection and Privacy of Personal Information

    Identity theft is only going to get worse. Penalties for organizations that fail to use due diligence at collecting,
    processing, disseminating and storing personal information will become more frequent and sever. Large companies will appoint a data protection officer. Smaller organizations need to assign someone to oversee this protection requrieemnt — defining it, creating policies for it, and enforcing it.

    Prevention of Misuse of Information Processing Facilities

    Management must ensure that business, network and computer equipment and facilities re only used for authorized business purposes. Too many people use their employer’s resources for their personal use. The policies must clearly state was is permitted — everything else is denied — and properly enforced.

    Regulation of Cryptographic Controls

    Over the past few years, restrictions on commercially available cryptographic technologies have been minimizes. But do not assume that all countries you require secure communications with will allow your chosen cryptographic solutions.

    Collection of Evidence

    In the unlikely event you need to support an action; i.e., legal, against a person or organization, it is essential your methods of collecting and safeguarding materials follow proper processes and procedures. There are rules for evidence; i.e., the chain of evidence, related documentation and media. Making sure that the evidence is admissibility will be a huge factor in the outcome of your case.

    Like most ISO 17799 areas, compliance belongs under the organization’s security policy. Regular reviews and audits of compliance policies will help enforce the policies and provide a means for an active closed-loop corrective action program.




    Author : Jeff Hayes

    Regulatory Compliance and ISO 27001

    n this excerpt from Chapter 10 of The Case for ISO 27001, author Alan Calder explains how using ISO 27001 can help information security professionals deal with the challenges of complying with complex and overlapping regulatory requirements.

    Today's regulatory environment is increasingly complex, the penalties for failure unattractive and the route to effective compliance not clear. ISO 27001 provides a best-practice solution to a range of regulatory issues faced by directors.

    The Regulatory conundrum
    Organizations have traditionally responded to regulatory compliance requirements on a law-by-law, or department-by-department basis. That was, last century, a perfectly adequate response. There were relatively few laws, compliance requirements were generally firmly established and well-understood, and the jurisdictions within which businesses operated were well-defined.

    Over the last decade, all that has changed. Rapid globalisation, increasingly pervasive information technology, the evolving business risk and threat environment, and today's governance expectations have, between them, created a fast-growing and complex body of laws and regulations – such as Data Protection and privacy legislation (e HIPAA, GLBA, DPA) and governance requirements (eg SOX and Turnbull) - that all impact the organization's IT systems. While global companies are in the forefront of finding effective compliance solutions, every organization, however small, and in whatever industry, is faced with the same broad range of regulatory requirements.

    These regulatory requirements focus on the confidentiality, integrity and availability of electronically-held information, and primarily – but not exclusively – on personal data. Many of the new laws appear to overlap and, not only is there very little established legal guidance as to what constitutes compliance, new laws and regulatory requirements continue to emerge. Increasingly, these laws have a geographic reach that extends to organizations based and operating outside the apparent jurisdiction of the legislative or regulatory body that originated them.

    Regulatory requirements in all these areas concentrate on preserving the confidentiality, integrity and availability of electronic data held by organizations operating within the sector. Regulations, which are technology-neutral, describe what must be done, but not how. Organizations are left to establish, for themselves, how to meet these requirements.

    In most instances, there is not yet a body of tested case law and proven compliance methodologies to which organizations can turn in order to calibrate their efforts. There are no technology products which, of themselves, can render an organization compliant with any of the data security regulations, because all data security controls consist of a combination of technology, procedure and human behaviour. In other words, installing a firewall will not protect an organization if there are no procedures for correctly configuring and maintaining it, and if users habitually bypass it (through, for instance, Instant Messaging, Internet browsing or the deployment of rogue wireless access points).

    In the face of new, blended, complex and evolving threats to their data, organizations have business and regulatory obligations to protect, maintain and make that data available when it is required. They have to do this in an uncertain compliance environment where the rewards for success don't grab headlines, but the penalties for failure do. Fines, reputation and brand damage and, in some circumstances, jail time for directors are outcomes that every business wants to avoid, and wants to avoid as systematically and cost-effectively as possible.

    The adoption of an externally-validated, best-practice approach to information security – one that provides a single, coherent framework that enables simultaneous compliance with multiple regulatory requirements - is, therefore, a solution to which organizations are increasingly turning.

    ISO 27001
    ISO 27001 provides just such a solution. It focuses on the confidentiality, availability and integrity of data and its key precepts and requirements all occur in the regulatory requirements. Implementation of an ISO 27001 framework enables an organization to comply, at one step (and subject to specific documentation and working practices tailored for each individual regulation), with all the core requirements of information related regulation anywhere in the world.

    Download this excerpt


    From : searchsecurity.techtarget.com