Saturday, April 13, 2013

Information Security Policy Creation

Why information security policy is so important?

"The success of an information resources protection program depends on the policy generated, and on the attitude of management toward securing information on automated systems. You, the policy maker, set the tone and the emphasis on how important a role information security will have within your agency. Your primary responsibility is to set the information resource security policy for the organization with the objectives of reduced risk, compliance with laws and regulations and assurance of operational continuity, information integrity, and confidentiality"  (Special Publication SP 500-169, Executive Guide to the Protection of Information Resources)

What are information security policies and how do they support this goal?

The Information Security Policy Framework


  • Policy - High level approach and definition of the information security approach that will be taken high senior management.
  • Standards - The steps that must be followed to support the policy.
  • Guidelines - Recommended steps to follow to support the standards and policy.
  • Procedures - The step by step, standard work to be used to carry out policy. Incorporating best practice and required controls.

Sunday, April 7, 2013

Contingency Planning

A big part of security planning is being prepared for the inevitable a failure that stops or hinders operations of business. These can come in many ways, shapes and forms including malicious attacks, mother nature and just plain human mistakes.

Contingency planning has four key part that have their own planning and task requirements.

Business Impact Analysis (BIA) includes:

  • Threat Attack Identification and Prioritization
  • Business Unit Analysis
  • Attack Success Scenario Development
  • Potential Damage Assessment 
  • Subordinate Plan Coordination
Incident Response Planning (IRP) includes:
  • Incident Planning
  • Incident Assessment
  • Incident Reaction
  • Incident Recovery
Disaster Planning Recovery (DRP) includes:
  • Plan for Disaster Recovery
  • Crisis Management
  • Recovery Operations
Business Continuity Planning (BCP) includes:
  • Establish Continuity Strategies
  • Plan for Continuity of Operations
  • Continuity Management
A total contingency plan includes all phases and will kick in during various times and sequence during an identified incident or disaster:

Plan:        IRP -------------------> DRP--------------------> BCP-------------------->DRP

Timeline: Attack Begins                  Post-attack (hours)           Post-attack (days)         Normal operations

Sunday, March 31, 2013

Planning and Governance

So we have started a few weeks ago with a discussion of the importance of information security on business and how project management methodologies can improve and increase the success of implementation and monitoring of information security...lets call these the what and how.

How about the why?

Ultimately an IT Governance and strategic planning must incorporate the security needs of a business. Only by aligning the goals of the entire organization with the IT efforts will we realize the full benefits of such resource intensive and costly endeavors.

So lets, first and foremost, make sure we are "doing the right work" and not necessarily focusing on "doing the work right" at this point in time.

Strategic and tactical planning give us a solid framework for governance - both long term goals and short term goals that are measurable.

Sunday, March 24, 2013

Security and Project Management

Took me a while to wrap my brain around the McCumber cube but I now understand how this tool can be used to evaluate information security programs based on the universal attributes of desired goals, information states and safeguards.
McCumber Cube

Much of the conversation and article reviews this week had a recurring theme that people, not technology are a main failure point  for security breeches...I am sure this will be revisited more in the future. In my research I also found an interesting website that I will want to revisit during the course: SANS Institute InfoSec Reading Room http://www.sans.org/reading_room/

The second major learning was how heavy this course will use the methodologies of project management in support of information security management and monitoring. I feel much more comfort with project management material and will enjoy employing what I already know of it to information security. 

We start with the basic building block tools of a good PM to see what a security project would entail and the work need to complete it:
  • Work Breakdown Structure (WBS)
  • Gantt Charts
  • PERT
A good website that will help along the way with its thorough and free templates: http://www.projectmanagementdocs.com/

Tuesday, March 12, 2013

I'm back!

Back on my master's pursuit journey after a brief hiatus and starting up with Information Security class again. Let's dive in the McCumber Cube again...

Wednesday, November 28, 2012

Welcome to my first blog! I am looking forward to blogging about my experience and learning's in my journey to obtain my master's degree in management of information systems with a concentration in healthcare. Let's start with information security management....