· 9 years ago · May 31, 2017, 06:16 AM
1Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
39
4‡ Remote Computing Security
5Key Terms
6telecommuting A work arrangement in which employees work from an off-site location and
7connect to an organization’s equipment electronically. Also known as telework.
8telework See telecommuting.
9virtual organization A group of people brought together for a specific task, usually from
10different organizations, divisions, or departments.
11Remote site computing, which is becoming increasingly popular, involves a wide variety of
12computing sites outside the organization’s main facility and includes all forms of telecom-
13muting. Telecommuting (or telework) involves off-site computing that uses Internet con-
14nections, dial-up connections, connections over leased point-to-point links between offices,
15and other mechanisms.
16Telecommuting from users’ homes deserves special attention. One of the appeals of telecom-
17muting is that employees can avoid physical commuting and have more time to focus on their
18work. But, as more people become telecommuters, the risk to information traveling via their
19often unsecured connections is substantial. The problem is that not enough organizations
20provide secure connections to their office networks, and even fewer provide secure systems if
21the employee’s home computer is compromised. To secure the entire network, the organiza-
22tion must dedicate security resources to protecting these home connections. Although the
23installation of a virtual private network (VPN) may go a long way toward protecting the
24data in transmission, telecommuters frequently store office data on their home systems, in
25home filing cabinets, and on off-site media. To ensure a secure process, the computers that
26telecommuters use must be made more secure than the organization’s systems, because they
27are outside the security perimeter. An attacker who breaks into someone’s home would prob-
28ably find a much lower level of security than at an office. Most office systems require users to
29log in, but the telecommuter’s home computer is probably a personal machine. Thus, it has a
30much less secure operating system or may not require a password. Telecommuters must use a
31securable device with a client operating system that can be configured to require password
32authentication, such as Windows 7/8, a current-generation Mac, or a properly configured
33Linux distribution. They must store all loose data in locking filing cabinets and loose media
34in locking fire safes. They must handle data at home more carefully than they would at the
35office, because the general level of security for the average home is less than that of a com-
36mercial building.
37The same principles apply to workers using portable computing devices on the road. Employ-
38ees who use tablets, smartphones, and notebook computers in hotel rooms should presume
39that their unencrypted transmissions are being monitored, and that any unsecured notebook
40computer can be stolen. The off-site worker using leased facilities does not know who else is
41attached to the network and who might be listening to his or her data conversations. VPNs
42are a must in all off-site to on-site communications, and the use of associated advanced
43authentication systems is strongly recommended.
44Although it is possible to secure remote sites, organizations cannot assume that employees
45will invest their own funds for security. Many organizations barely tolerate telecommuting
46Securing Mobile and Portable Systems 497
47Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
48Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
49for a number of reasons, foremost among them that such employees generally require two
50sets of computing equipment, one for the office and one for the home. This extra expense is
51difficult to justify, especially when the employee is the only one gaining the benefit from tele-
52commuting. In rare cases in which allowing employees or consultants to telecommute is the
53only way for them to gain extremely valuable skills, the organization is usually willing to do
54what is necessary to secure its systems. Only when additional research into telecommuting
55clearly displays a bottom-line advantage do organizations begin to invest sufficient resources
56into securing telecommuting equipment.
57However, some organizations do support telecommuting, and they typically fall into one
58of three groups. The first is the mature and fiscally sound organization with a sufficient
59budget to support telecommuting and thus enhance its standing with employees and its
60own image. In recent years, the option to telecommute has become more important in
61organizational rankings developed by various magazines. Some organizations seek to
62improve employee work conditions and improve their position in best-workplace rank-
63ings by adding telecommuting as an option for employees. The second group consists of
64new high-technology companies with large numbers of geographically diverse employees
65who telecommute almost exclusively. These companies use technology extensively and
66are determined to make it the cornerstone of their organizations. The third group over-
67laps with the second, and is called a virtual organization. A virtual organization is a
68group of people from different organizations who form a virtual company, either in
69leased facilities or through 100-percent telecommuting arrangements. When the job is
70done, the organization is either redirected or dissolved. These organizations rely almost
71exclusively on remote computing and telecommuting, but they are rare and therefore are
72not well documented or studied.
73For more information on telework, including the Telework Enhancement Act of 2010, visit www
74.telework.gov.
75Special Considerations for Physical Security
76An organization must account for several special considerations when developing a physical
77security program. The first is the question of whether to handle physical security in-house or
78to outsource it. As with any aspect of information security, the make-or-buy decision should
79not be made lightly. Many qualified and professional agencies can provide physical security
80consulting and services. The benefits of outsourcing physical security include gaining the expe-
81rience and knowledge of these agencies, many of which have been in the field for decades.
82Outsourcing unfamiliar operations always frees an organization to focus on its primary objec-
83tives rather than support operations. The disadvantages include the expense, the loss of con-
84trol over individual components of physical security, and the need to trust another company
85to perform an essential business function. An organization must trust the processes used by
86the contracted company and its ability to hire and retain trustworthy employees who respect
87the security of the contracting company, even though they have no allegiance to it. This level
88of trust is often the most difficult aspect of the decision to outsource, because the reality of
89outsourcing physical security is that an outside agency will be providing a safeguard that the
90organization administers only marginally.
91498 Chapter 9
92Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
93Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
949
95Another physical security consideration is social engineering. As you learned in previous chap-
96ters, social engineering involves using people skills to obtain confidential information from
97employees. While most social engineers prefer to use the telephone or computer to solicit infor-
98mation, some attempt to access the information more directly. Technically proficient agents can
99be placed in janitorial positions at a competitor’s office, and an outsider can gain access to an
100organization’s resources in other ways. For example, most organizations do not have thorough
101procedures for authenticating and controlling visitors who access their facility. When no proce-
102dure is in place, no one gives the wandering repairman, service worker, or city official a second
103look. It is not difficult to get a clipboard, dress like a repairman or building inspector, and move
104freely throughout a building. If you look like you have a mission and appear competent, most
105people will leave you alone. Organizations can combat this type of attack by requiring all people
106who enter the facility to display appropriate visitor badges and be escorted in restricted areas.
107Selected Readings
108â—
109Effective Physical Security, Third Edition by Lawrence Fennelly. 2004. Butterworth
110Heinemann.
111â—
112Build the Best Data Center Facility for Your Business by Douglas Alger. 2005. Cisco Press.
113â—
114Guard Force Management, Updated Edition by Lucien Canton. 2003. Butterworth
115Heinemann.
116Chapter Summary
117â– Physical security requires the design, implementation, and maintenance of counter-
118measures that protect the physical resources of an organization.
119â– Many threats to information security can also be classified as threats to physical secu-
120rity. An organization’s policy should guide the planning for physical security through-
121out the development life cycle.
122â– In facilities management, a secure facility is a physical location that has controls to
123minimize the risk of attacks from physical threats. A secure facility can use natural
124terrain, traffic flow, and urban development, and can complement these environmental
125elements with protection mechanisms, such as fences, gates, walls, guards, and alarms.
126■The management of keys and locks is a fundamental part of general management’s
127responsibility for the organization’s physical environment.
128â– A fail-safe lock is typically used on an exit door when human safety in a fire or other
129emergency is the essential consideration. A fail-secure lock is used when human safety
130is not a factor.
131â– Monitoring equipment can record events that guards and dogs might miss, and can be
132used in areas where other types of physical controls are not practical.
133â– As with any phase of the security process, the implementation of physical security
134must be constantly documented, evaluated, and tested. Once the physical security of a
135facility is established, it must be diligently maintained.
136Chapter Summary 499
137Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
138Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
139â– Fire detection systems are devices that detect and respond to a fire or potential fire.
140Fire suppression systems stop the progress of a fire once activated.
141â– The three basic types of fire detection systems are thermal detection, smoke detection,
142and flame detection.
143â– Four environmental variables controlled by HVAC systems can cause damage to
144information systems: temperature, filtration, humidity, and static electricity.
145â– Computer systems depend on stable power supplies to function; when power levels are
146too high, too low, or too erratic, computer circuitry can be damaged or destroyed. The
147power provided to computing and networking equipment should contain no unwanted
148fluctuations and no embedded signaling.
149■Water problems and the weakening and subsequent failure of a building’s physical
150structure represent potential threats to personal safety and to the integrity and avail-
151ability of information assets.
152â– Data can be intercepted electronically and manually. The three routes of data inter-
153ception are direct observation, interception of data transmission, and interception of
154electromagnetic radiation.
155â– TEMPEST is a technology that prevents the possible loss of data from the emission of
156electromagnetic radiation (EMR).
157â– With the increased use of laptops, handhelds, and PDAs, organizations should be
158aware that mobile computing requires even more security than the average in-house
159system.
160■Remote site computing requires a secure extension of the organization’s internal net-
161works and special attention to security for any connected home or off-site computing
162technology.
163â– Like computing equipment, classified information should be inventoried and managed.
164If multiple copies are made of a classified document, they should be numbered and
165tracked.
166Review Questions
1671. What is physical security? What are the primary threats to physical security? How are
168they manifested in attacks against the organization?
1692. What are the roles of an organization’s IT, security, and general management with
170regard to physical security?
1713. How does physical access control differ from logical access control, which is described
172in earlier chapters? How are they similar?
1734. Define a secure facility. What is the primary objective of designing such a facility?
174What are some secondary objectives of designing a secure facility?
1755. Why are guards considered the most effective form of control for situations that
176require decisive action in the face of unfamiliar stimuli? Why are they usually the
177most expensive controls to deploy? When should dogs be used for physical security?
178500 Chapter 9
179Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
180Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1819
1826. List and describe the four categories of locks. In which situation is each type of lock
183preferred?
1847. What are the two possible modes of locks when they fail? What implications do these
185modes have for human safety? In which situation is each preferred?
1868. What is a mantrap? When should it be used?
1879. What is the most common form of alarm? What does it detect? What types of sensors
188are commonly used in this type of alarm system?
18910. Describe a physical firewall that is used in buildings. List reasons that an organization
190might need a firewall for physical security controls.
19111. What is considered the most serious threat within the realm of physical security? Why
192is it valid to consider this threat the most serious?
19312. What three elements must be present for a fire to ignite and continue to burn? How do
194fire suppression systems manipulate the three elements to quell fires?
19513. List and describe the three fire detection technologies covered in the chapter. Which is
196the most commonly used?
19714. List and describe the four classes of fire described in the text. Does the class of the fire
198dictate how to control it?
19915. What is Halon and why is its use restricted?
20016. What is the relationship between HVAC and physical security? What four physical
201characteristics of the indoor environment are controlled by a properly designed
202HVAC system? What are the optimal temperature and humidity ranges for computing
203systems?
20417. List and describe the four primary types of UPS systems. Which is the most effective
205and the most expensive, and why?
20618. What two critical factors are affected when water is not available in a facility?
207Why are they important to the operation of the organization’s information assets?
20819. List and describe the three fundamental ways that data can be intercepted.
209How does a physical security program protect against each of these data interception
210methods?
21120. What can you do to reduce the risk of theft of portable computing devices, such as
212smartphones, tablets, and notebooks?
213Exercises
2141. Assume that your organization is planning to have an automated server room that
215functions without human assistance. Such a room is often called a lights-out server
216room. Describe the fire control system(s) you would install in that room.
217Exercises 501
218Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
219Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2202. Assume you have converted an area of general office space into a server room.
221Describe the factors you would consider for each of the following components:
222a. Walls and doors
223b. Access control
224c. Fire detection
225d. Fire suppression
226e. Heating, ventilating, and air conditioning
227f. Power quality and distribution
2283. Assume you have been asked to review the power needs of a stand-alone computer system
229that processes important but noncritical data. Although the system does not have to be
230online at all times, it stores valuable data that could be corrupted if the power system
231were suddenly interrupted. Which UPS features are most important to such a system?
232Which type of UPS do you recommend for it?
2334. Using a floor plan from a building you are familiar with, design an electronic monitor-
234ing plan that includes closed-circuit television, burglar alarms with appropriate sen-
235sors, fire detectors, and suppression and access controls for key entrances.
2365. Define the required wattage for a UPS to be used with the following systems:
237a. Monitor: 2 amps; CPU: 3 amps; printer: 3 amps
238b. Monitor: 3 amps; CPU: 4 amps; printer: 3 amps
239c. Monitor: 3 amps; CPU: 4 amps; printer: 4 amps
2406. Search the Web for a UPS that provides the wattage necessary to run the systems
241described in Exercise 5 for at least 15 minutes during a power outage.
242Case Exercises
243Amy walked into her office cubicle and sat down. The entire episode with the blond man had
244taken well over two hours of her day. Plus, the police officers had told her the district attor-
245ney would also want to speak with her, which meant she would have to spend even more
246time dealing with this incident. She hoped her manager would understand.
247Discussion Questions
2481. Based on this case study, what security awareness measures, training documents, and
249posters had an impact on this event?
2502. Do you think that Amy should have done anything differently? What would you have
251done in her situation?
252Ethical Decision Making
253Suppose that the blond man in the scenario was someone Amy knew socially. Suppose she
254also knew he had no relationship to the company and no business being in the building. If
255Amy chose not to make a report about the event, would she be violating her ethical position?
256502 Chapter 9
257Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
258Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2599
260Endnotes
2611. Parker, Donn B. Fighting Computer Crime. 1998. New York: John Wiley and Sons
262Inc., 250–251.
2632. Army Study Guide. “Guard Duty.†Accessed 27 February 2014 from www.armystudy
264guide.com/content/army_board_study_guide_topics/guard_duty/guard-duty-study-guide
265.shtml.
2663. Ibid.
2674. Swanson, Marianne. National Institute of Standards and Technology. Guide for Devel-
268oping Security Plans for Federal Information Systems. SP 800-18, Rev. 1. February
2692006. Accessed 27 February 2014 from http://csrc.nist.gov/publications/PubsSPs.html.
2705. Artim, Nick. An Introduction to Fire Detection, Alarm, and Automatic Fire Sprinklers.
271Emergency Management, Technical Leaflet 2, Sec. 3. Middlebury: Fire Safety
272Network.
2736. Environmental Protection Agency. “Questions and Answers on Halons and Their
274Substitutes.†Ozone Layer Protection Home. Accessed 27 February 2014 from www
275.epa.gov/ozone/snap/fire/lists/stream.html.
2767. Ibid.
2778. Webopedia. “Static Electricity and Computers.†Webopedia Online. May 2003.
278Accessed 27 February 2014 from www.webopedia.com/DidYouKnow/Computer
279_Science/static.asp.
2809. Rasmussen, N. “The Different Types of UPS Systems.†White Paper 1 Revision 7. 2011.
281Accessed 24 February 2014 from www.apcmedia.com/salestools/SADE-5TNM3Y
282/SADE-5TNM3Y_R7_EN.pdf.
28310. Van Eck, Wim. “Electromagnetic Radiation from Video Display Units: An Eavesdropping
284Risk?†Computers & Security 4 (1985): 269–286.
28511. Loughry, Joe, and Umphress, David A. “Information Leakage from Optical
286Emanations.†ACM Transactions on Information and System Security 7, no. 7 (March
2872002).
28812. PC Privacy. “Is Tempest a Threat or Hoax?†PC Privacy 8, no. 4 (April 2000).
28913. Metropolitan Police of the District of Columbia. “Tips for Preventing Theft of Laptops
290and Personal Electronics.†Government of the District of Columbia Online. Accessed 7
291July 2007 from http://mpdc.dc.gov/page/tips-preventing-theft-laptops-and-personal-
292electronics.
293Endnotes 503
294Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
295Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
296Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
297Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
298chapter 10
299Implementing Information Security
300Change is good. You go first!
301DILBERT (BY SCOTT ADAMS)
302KelvinUrich arrivedearly for the changecontrol meeting.Inthe large,empty conference
303room, he reviewed his notes and then flipped through the handouts one final time. During
304the meeting last week, the technical review committee had approved his ideas, and
305now he was confident that the project plan he’d developed was complete, tight, and
306well-ordered.
307The series of change requests resulting from this project would keep the company’s technical
308analysts busy for months to come, but he hoped that the scope and scale of the project, and
309the vast improvements it was sure to bring to the SLS information security program, would
310inspire his colleagues. To help the project proceed smoothly, he had loaded his handouts
311with columns of tasks, subtasks, and action items, and had assigned dates to every action
312step and personnel to each required task. He checked that the handouts were organized
313properly and that he had plenty of copies. Everything was under control.
314Naomi Jackson, the change control supervisor, also arrived a few minutes early. She nodded
315to Kelvin as she placed a stack of revised agendas in the middle of the conference table.
316Everyone attending had received the detailed report of planned changes the previous day.
317Charlie Moody came in, also nodding to Kelvin, and took his usual seat.
318Once the room filled, Naomi said, “Time to get started.†She picked up her copy of the
319planned change report and announced the first change control item for discussion, Item 742.
320505
321Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
322Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
323One of the members of the UNIX support team responded, “As planned,†meaning that the
324item, a routine maintenance procedure for the corporate servers, would occur as scheduled.
325Naomi continued down the list in numeric order. Most items received the response “As
326planned†from the sponsoring team member. Occasionally, someone answered “Cancelledâ€
327or “Will be rescheduled,†but for the most part, the review of the change items proceeded as
328usual until it came to Kelvin’s information security change requests.
329Naomi said, “Items 761 through 767. Kelvin Urich from the security team is here to discuss
330these items with the change control group.â€
331Kelvin distributed his handouts around the table. He waited, a little nervously, until every-
332one had a copy, and then began speaking: “I’m sure most of you are already aware of the
333information security upgrades we’ve been working on for the past few months. We’ve cre-
334ated an overall strategy based on the revised policies that were published last month and a
335detailed analysis of the threats to our systems. As the project manager, I’ve created what I
336think is a very workable plan. The seven change requests on the list today are all network
337changes and are each a top priority. In the coming weeks, I’ll be sending each department
338head a complete list of all planned changes and the expected dates. Of course, detailed
339change requests will be filed in advance for change control meetings, but each department
340can find out when any item is planned by checking the master list. As I said, there are more
341changes coming, and I hope we can all work together to make this a success.â€
342“Comments or questions?†asked Naomi.
343Instantly six hands shot into the air. All of them belonged to senior technical analysts.
344Kelvin realized belatedly that none of these analysts were on the technical review com-
345mittee that had approved his plan. He also noticed that half the people in the room, like
346Amy Windahl from the user group and training committee, were busy pulling calendars
347and PDAs out of briefcases and bags, and that Davey Martinez from Accounting was
348engaged in a private but heated discussion with Charlie Moody, Kelvin’s boss. Charlie
349did not look pleased.
350Above the noise, Kelvin heard someone say, “I should have been warned if we are going
351to have all this work dumped on us all at once.†Someone else said, “We can’t make this
352happen on this schedule.â€
353Amid the sudden chaos that had broken out during an otherwise orderly meeting, it occurred
354to Kelvin that his plan might not be as simple as he’d thought. He braced himself—it was
355going to be a very long afternoon.
356LEARNING OBJECTIVES:
357Upon completion of this material, you should be able to:
358• Explain how an organization’s information security blueprint becomes a project plan
359• Discuss the many organizational considerations that a project plan must address
360• Explain the significance of the project manager’s role in the success of an information
361security project
362• Describe the need for professional project management for complex projects
363• Discuss technical strategies and models for implementing a project plan
364• List and discuss the nontechnical problems that organizations face in times of rapid change
365506 Chapter 10
366Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
367Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
36810
369Introduction
370Key Term
371project plan The documented instructions for participants and stakeholders of a project that
372provide details on goals, objectives, tasks, scheduling, and resource management.
373First and foremost, an information security project manager must realize that implementing an
374information security project takes time, effort, and a great deal of communication and coordi-
375nation. This chapter and the next discuss the two stages of the security systems development
376life cycle (SecSDLC) implementation phase and describe how to successfully execute the infor-
377mation security blueprint. In general, the implementation phase is accomplished by changing
378the configuration and operation of the organization’s information systems to make them
379more secure. It includes changes to the following:
380â—
381Procedures (for example, through policy)
382â—
383People (for example, through training)
384â—
385Hardware (for example, through firewalls)
386â—
387Software (for example, through encryption)
388â—
389Data (for example, through classification)
390As you may recall from earlier chapters, the SecSDLC involves collecting information about
391an organization’s objectives, its technical architecture, and its information security environ-
392ment. These elements are used to form the information security blueprint, which is the foun-
393dation for protecting the confidentiality, integrity, and availability of the organization’s
394information.
395During the implementation phase, the organization translates its blueprint for information
396security into a project plan. The project plan instructs the people who are executing the imple-
397mentation phase. These instructions focus on the security control changes needed to improve
398the security of the hardware, software, procedures, data, and people that make up the organi-
399zation’s information systems. The project plan as a whole must describe how to acquire and
400implement the needed security controls and create a setting in which those controls achieve
401the desired outcomes.
402Before developing a project plan, however, management should coordinate the organization’s
403information security vision and objectives with the communities of interest involved in the
404plan’s execution. This coordination ensures that only controls of value to the organization’s
405information security program are incorporated into the project plan. If a statement of the
406vision and objectives for the organization’s security program does not exist, one must be
407developed and incorporated into the project plan. The vision statement should be concise. It
408should state the mission of the information security program and its objectives. In other
409words, the project plan is built upon the vision statement, which serves as a compass for guid-
410ing the changes necessary for the implementation phase. The components of the project plan
411should never conflict with the organization’s vision and objectives.
412Introduction 507
413Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
414Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
415Information Security Project Management
416As the opening vignette of this chapter illustrates, organizational change is not easily accom-
417plished. The following sections discuss the issues a project plan must address, including project
418leadership; managerial, technical, and budgetary considerations; and organizational resistance
419to the change.
420The major steps in executing the project plan are as follows:
421â—
422Planning the project
423â—
424Supervising tasks and action steps
425â—
426Wrapping up
427The project plan can be developed in any number of ways. Each organization has to deter-
428mine its own project management methodology for IT and information security projects.
429Whenever possible, information security projects should follow the organization’s project
430management practices. Many organizations now make use of a project office—a centralized
431resource to maximize the benefits of a standardized approach to project management. One
432such benefit is the leveraging of common project management practices across the organiza-
433tion to enable reallocation of resources without confusion or delays.
434‡ Developing the Project Plan
435Key Terms
436deliverable A completed document or program module that can either serve as the beginning
437point for a later task or become an element in the finished project.
438milestone A specific point in the project plan when a task that has a noticeable impact on the
439plan’s progress is complete.
440predecessors Tasks or action steps that come before the specific task at hand.
441projectitis A situation in project planning in which the project manager spends more time
442documenting project tasks, collecting performance measurements, recording project task
443information, and updating project completion forecasts in the project management software
444than accomplishing meaningful project work.
445request for proposal (RFP) A document specifying the requirements of a project, provided to
446solicit bids from internal or external contractors.
447resources Components required for the completion of a project, which could include skills,
448personnel, time, money, and material.
449successors Tasks or action steps that come after the specific task at hand.
450work breakdown structure (WBS) A list of the tasks to be accomplished in the project, the
451skill sets or individual employees needed to perform the tasks, the start and end dates for tasks,
452the estimated resources required, and the dependencies among tasks.
453Planning for the implementation phase requires the creation of a detailed project plan, which
454is often assigned either to a project manager or the project champion. This person manages
455the project and delegates parts of it to other decision makers. Often the project manager is
456from the IT community of interest because most other employees lack the requisite informa-
457tion security background, management authority, and technical knowledge.
458508 Chapter 10
459Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
460Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
46110
462The project plan can be created using a simple planning tool such as the work breakdown
463structure (WBS). An example is shown in Table 10-1. To use the WBS approach, you first
464break down the project plan into its major tasks. The major project tasks are placed into the
465WBS, along with the following attributes for each:
466â—
467Work to be accomplished (activities and deliverables)
468â—
469The people or skill sets assigned to perform the task
470â—
471Start and end dates for the task, when known
472â—
473Amount of effort required for completion, in hours or work days
474â—
475Estimated capital expenses for the task
476â—
477Estimated noncapital expenses for the task
478â—
479Identification of dependencies between and among tasks
480Each major task in the WBS is then further divided into either smaller tasks (subtasks) or spe-
481cific action steps. For the sake of simplicity, the sample project plan outlined in the table and
482described later in this chapter divides each major task into action steps. In an actual project
483plan, major tasks are often much more complex and must be divided into subtasks before
484action steps can be identified and assigned to a specific person or skill set. Given the variety
485of possible projects, there are few formal guidelines for determining the appropriate level of
486detail—that is, the level at which a task or subtask should become an action step. However,
487one hard-and-fast rule can help you make this determination: a task or subtask becomes an
488action step when it can be completed by one person or skill set and has a single deliverable.
489The WBS can be prepared with a simple desktop PC spreadsheet program. The use of more
490complex project management software often leads to projectitis, in which the project man-
491ager spends more time working with the project management software than accomplishing
492meaningful project work. Recall Kelvin’s handouts from the opening vignette, which were
493loaded with dates and details. His case of projectitis led him to develop an elegant, detailed
494plan before gaining consensus for the required changes. Because he was new to project man-
495agement, he did not realize that simpler software tools could help him focus on organizing
496and coordinating with the project team.
497Work to Be Accomplished The work to be accomplished encompasses both activi-
498ties and deliverables. Ideally, the project planner provides a label and a thorough description
499for the task. The description should be complete enough to avoid ambiguity during the
500tracking process later, yet should not be so detailed as to make the WBS unwieldy. For
501instance, if the task is to write firewall specifications for the preparation of a request for
502proposal (RFP), the planner should note that the deliverable is a specification document suit-
503able for distribution to vendors.
504Assignees The project planner should describe the skills or personnel, often referred to
505as resources, needed to accomplish the task. The naming of individual employees should be
506avoided in early planning efforts, a rule Kelvin ignored when he named employees for every
507task in the first draft of his project plan. Instead of making individual assignments, the
508project plan should focus on organizational roles or known skill sets. For example, if any
509of the engineers in the networks group can write the specifications for a router, the assigned
510Information Security Project Management 509
511Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
512Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
513resource would be noted as “network engineer†in the WBS. As planning progresses,
514however, specific tasks and action steps should be assigned to individual employees. For
515example, when only the manager of the networks group can evaluate responses to the RFP
516and make an award for a contract, the project planner should assign the network manager
517as the resource for this task.
518Start and End Dates In the early stages of planning, the project planner should
519attempt to specify completion dates only for major project milestones. For example, the
520date for sending the final RFP to vendors is a milestone because it signals that all RFP
521Task or subtask Resources
522Start (S) &
523end (E) dates
524Estimated
525effort in
526hours
527Estimated
528capital
529expense
530Estimated
531noncapital
532expense
533Depend-
534encies
5351 Contact field office
536and confirm network
537assumptions
538Network
539architect
540S: 9/22
541E: 9/22
5422 $0 $200
5432 Purchase standard
544firewall hardware
5452.1 Orderfirewallthrough
546purchasing group
547Network
548architect
549S: 9/23
550E: 9/23
5511 $0 $100 1
5522.2 Order firewall from
553manufacturer
554Purchasing
555group
556S: 9/24
557E: 9/24
5582 $4,500 $100 2.1
5592.3 Firewall delivered Purchasing
560group
561E: 10/3 1 $0 $50 2.2
5623 Configure firewall Network
563architect
564S: 10/3
565E: 10/5
5668 $0 $800 2.3
5674 Package and ship
568firewall to field office
569Student
570intern
571S: 10/6
572E: 10/15
5732 $0 $85 3
5745 Work with local
575technical resource to
576install and test
577Network
578architect
579S: 10/22
580E: 10/31
5816 $0 $600 4
5826 Penetration test
5836.1 Request penetration
584test
585Network
586architect
587S: 11/1
588E: 11/1
5891 $0 $100 5
5906.2 Perform penetration
591test
592Penetration
593test team
594S: 11/2
595E: 11/12
5969 $0 $900 6.1
5976.3 Verify that results of
598penetration test
599were passing
600Network
601architect
602S: 11/13
603E: 11/15
6042 $0 $200 6.2
6057 Get remote office
606sign-off and update
607all network drawings
608and documentation
609Network
610architect
611S: 11/16
612E: 11/30
6138 $0 $800 6.2
614Table 10-1 Example Project Plan Work Breakdown Structure
615© Cengage Learning 2015
616510 Chapter 10
617Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
618Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
61910
620preparation work is complete. Assigning too many dates to too many tasks early in the
621planning process exacerbates projectitis. This is another mistake Kelvin made, and was a sig-
622nificant cause of the resistance he faced from his coworkers. Planners can avoid this pitfall
623by assigning only key or milestone start and end dates early in the process. Later, planners
624may add start and end dates as needed.
625Amount of Effort Planners need to estimate the effort required to complete each task,
626subtask, or action step. Estimating effort hours for technical work is a complex process.
627Even when an organization has formal governance, technical review processes, and change
628control procedures, it is always good practice to ask the people who are most familiar with
629the tasks to make these estimates. After these estimates are made, the people assigned to
630action steps should review the estimated effort hours, understand the tasks, and agree with
631the estimates. Had Kelvin collaborated with his peers more effectively and adopted a more
632flexible planning approach, much of the resistance he encountered in the meeting would
633not have emerged.
634Estimated Capital Expenses Planners need to estimate the capital expenses
635required for the completion of each task, subtask, or action item. While each organization
636budgets and expends capital according to its own established procedures, most differentiate
637between capital outlays for durable assets and expenses for other purposes. For example, a
638firewall device that costs $5,000 may be a capital outlay for an organization, but it might
639not consider a $5,000 software package to be a capital outlay because its accounting rules
640classify all software as expense items, regardless of cost.
641Estimated Noncapital Expenses Planners need to estimate the noncapital
642expenses for the completion of each task, subtask, or action item. In business, capital
643expenses are those for revenue-producing projects that are expected to yield a return on
644investment, usually more than a year in the future. Noncapital expenses do not meet the cri-
645teria for capital expenditures. Some organizations require that current expenses for a project
646include a recovery charge for staff time, while others exclude employee time and consider
647only contract or consulting time used by the project as a noncapital expense. As mentioned
648earlier, it is important to determine the cost accounting practices of the organization for
649which the plan is to be used. For example, at some companies, a project to implement a fire-
650wall may charge only the costs of the firewall hardware as capital and consider all costs for
651labor and software as expense, regarding the hardware element as a durable good that has a
652lifespan of many years. Another organization might use the aggregate of all cash outflows
653associated with the implementation as the capital charge and make no charges to the
654expense category for everything needed to complete the project. The justification behind
655using this aggregate of all costs, which might include charges for items like hardware,
656labor, and freight, is that the newly implemented capability is expected to last for many
657years and is an improvement to the organization’s infrastructure. A third company may
658charge the whole project as expense if the aggregate amount falls below a certain threshold,
659under the theory that small projects are a cost of ongoing operations.
660Task Dependencies Whenever possible, planners should note the dependencies of
661other tasks or action steps on the one at hand, including task predecessors and successors.
662Multiple types of dependencies can exist, but such details are typically covered in courses
663on project management and are beyond the scope of this text.
664Information Security Project Management 511
665Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
666Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
667A process for developing a simple WBS-style project plan is provided in the following steps.
668In this example, a small information security project has been assigned to Jane Smith for
669planning. The project is to design and implement a firewall for a small office. The hardware
670is a standard organizational product and will be installed at a location that already has a
671network connection.
672Jane’s first step is to list the major tasks:
6731. Contact field office and confirm network assumptions.
6742. Purchase standard firewall hardware.
6753. Configure firewall.
6764. Package and ship firewall to field office.
6775. Work with local technical resource to install and test firewall.
6786. Coordinate vulnerability assessment by penetration test team.
6797. Get remote office sign-off and update all network drawings and documentation.
680After all the people involved review and refine Jane’s plan, she revises it to add more dates
681to the tasks listed, as shown in Table 10-1.
682For more information on project management certifications in the federal sector, visit www.fai
683.gov/drupal/certification/program-and-project-managers-fac-ppm.
684‡ Project Planning Considerations
685Key Term
686project scope A description of a project’s features, capabilities, functions, and quality level, used
687as the basis of a project plan.
688As the project plan is developed, adding detail is not always straightforward. The following
689sections discuss factors that project planners must consider as they decide what to include in
690the work plan, how to break tasks into subtasks and action steps, and how to accomplish the
691objectives of the project.
692Financial Considerations Regardless of an organization’s information security
693needs, the amount of effort that can be expended depends on the available funds. A cost-
694benefit analysis (CBA), as described in Chapter 5, is typically prepared in the analysis phase
695of the SecSDLC and must be reviewed and verified prior to the development of the project
696plan. The CBA determines the impact that a specific technology or approach can have on
697the organization’s information assets and what it may cost.
698Each organization has its own approach to the creation and management of budgets and
699expenses. In many organizations, the information security budget is a subsection of the overall
700IT budget. In others, information security is a separate budget category that may have the same
701degree of visibility and priority as the IT budget. Regardless of where information security items
702arelocatedinthe budget,monetaryconstraints determine what can andcannot beaccomplished.
703512 Chapter 10
704Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
705Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
70610
707Public organizations tend to be more predictable in their budget processes than private organi-
708zations because the budgets of public organizations are usually the product of legislation or
709public meetings. This makes it difficult to obtain additional funds once the budget is deter-
710mined. Also, some public organizations rely on temporary or renewable grants for their bud-
711gets and must stipulate their planned expenditures when the grant applications are written. If
712new expenses arise, funds must be requested via new grant applications. Also, grant expendi-
713tures are usually audited and cannot be misspent. However, many public organizations must
714spend all budgeted funds within the fiscal year—otherwise, the subsequent year’s budget is
715reduced by the unspent amount. As a result, these organizations often conduct end-
716of-fiscal-year spend-a-thons. This is often the best time to acquire, for example, that remaining
717piece of technology needed to complete the information security architecture.
718Private (for-profit) organizations have budgetary constraints that are determined by the mar-
719ketplace. When a for-profit organization initiates a project to improve security, the funding
720comes from the company’s capital and expense budgets. Each for-profit organization deter-
721mines its capital budget and the rules for managing capital spending and expenses differ-
722ently. In almost all cases, however, budgetary constraints affect the planning and actual
723expenditures for information security. For example, a preferred technology or solution may
724be sacrificed for a less desirable but more affordable solution. The budget ultimately guides
725the information security implementation.
726To justify the amount budgeted for a security project at either a public or for-profit organiza-
727tion, it may be useful to benchmark expenses of similar organizations. Most for-profit organi-
728zations publish the components of their expense reports. Similarly, public organizations must
729document how funds are spent. A savvy information security project manager might find a
730number of similarly sized organizations with larger expenditures for security to justify planned
731spending. While such tactics may not improve this year’s budget, they could improve future
732budgets. Ironically, attackers can also help information security project planners justify the
733information security budget. If attacks successfully compromise secured information systems,
734management may be more willing to support the information security budget.
735Priority Considerations In general, the most important information security controls
736in the project plan should be scheduled first. Budgetary constraints may have an effect on
737the assignment of a project’s priorities. As you learned in Chapter 5, the implementation of
738controls is guided by the prioritization of threats and the value of the threatened informa-
739tion assets. A less important control may be prioritized if it addresses a group of specific vul-
740nerabilities and improves the organization’s security posture to a greater degree than other
741high-priority controls.
742Time and Scheduling Considerations Time and scheduling can affect a project
743plan at dozens of points, including the time between ordering and receiving a security con-
744trol, which may not be immediately available; the time it takes to install and configure the
745control; the time it takes to train the users; and the time it takes to realize the control’s
746return on investment. For example, if a control must be in place before an organization can
747implement its electronic commerce product, the selection process is likely to be influenced by
748the speed of acquisition and implementation of the various alternatives.
749Staffing Considerations The need for qualified, trained, and available personnel also
750constrains the project plan. An experienced staff is often needed to implement technologies
751Information Security Project Management 513
752Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
753Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
754and to develop and implement policies and training programs. If no staff members are
755trained to configure a new firewall, the appropriate personnel must be trained or hired.
756Procurement Considerations There are often constraints on the selection of equip-
757ment and services—for example, some organizations require the use of particular service ven-
758dors or manufacturers and suppliers. These constraints may limit which technologies can be
759acquired. For example, in a recent budget cycle, the authors’ lab administrator was considering
760selecting an automated risk analysis software package. The leading candidate promised to inte-
761grate everything, including vulnerability scanning, risk weighting, and control selection. Upon
762receipt of the RFP, the vendor issued a bid to meet the desired requirements for a heart-
763stopping $75,000, plus a 10 percent annual maintenance fee. If an organization has an annual
764information security budget of $30,000, it must eliminate a package like this from consider-
765ation. Also, consider the chilling effect on innovation when an organization requires elaborate
766supporting documentation and complex bidding for even small-scale purchases. Such procure-
767ment constraints, which are designed to control losses from occasional abuses, may actually
768increase costs when the lack of operating agility is taken into consideration.
769Organizational Feasibility Considerations Whenever possible, security-related
770technological changes should be transparent to system users, but sometimes such changes
771require new procedures—for example, additional authentication or validation. A successful
772project requires that an organization be able to assimilate the proposed changes. New tech-
773nologies sometimes require new policies, employee training, and education. Scheduling train-
774ing after the new processes are in place—after the users have had to deal with the changes
775without preparation—can create tension and resistance, and might undermine security
776operations. Untrained users may develop ways to work around unfamiliar security proce-
777dures, and their bypassing of controls may create additional vulnerabilities. Conversely,
778users should not be prepared so far in advance that they forget the new training techniques
779and requirements. The optimal time frame for training is usually one to three weeks before
780the new policies and technologies come online.
781Training and Indoctrination Considerations The size of the organization and
782the normal conduct of business may preclude a large training program for new security pro-
783cedures or technologies. If so, the organization should conduct a phased-in or pilot imple-
784mentation, such as roll-out training for one department at a time. See the section titled
785“Conversion Strategies†later in the chapter for details about various implementation
786approaches. When a project involves a change in policies, it may be sufficient to brief super-
787visors on the new policy and assign them the task of updating end users in regularly sched-
788uled meetings. Project planners must ensure that compliance documents are also distributed
789and that all employees are required to read, understand, and agree to the new policies.
790Scope Considerations The project scope of any given project plan should be care-
791fully reviewed and kept as small as possible given the project’s objectives. To control project
792scope, organizations should implement large information security projects in stages, as in the
793bull’s-eye approach discussed later in this chapter.
794For several reasons, the scope of information security projects must be evaluated and
795adjusted with care. First, in addition to the challenge of handling many complex tasks at
796one time, the installation of information security controls can disrupt the ongoing operations
797514 Chapter 10
798Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
799Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
80010
801of an organization, and may also conflict with existing controls in unpredictable ways. For
802example, if you install a new packet filtering router and a new application proxy firewall at
803the same time and users are blocked from accessing the Web as a result, which technology
804caused the conflict? Was it the router, the firewall, or an interaction between the two? Lim-
805iting the project scope to a set of manageable tasks does not mean that the project should
806only allow change to one component at a time, but a good plan carefully considers the num-
807ber of tasks that are planned for the same time in a single department.
808Recall from the opening vignette that all of Kelvin’s change requests are in the area of net-
809working, where the dependencies are particularly complex. If the changes in Kelvin’s project
810plan are not deployed exactly as planned, or if unanticipated complexities arise, there could
811be extensive disruption to Sequential Label and Supply’s daily operations. For instance, an
812error in the deployment of the primary firewall rules could interrupt all Internet connectiv-
813ity, which might make detection and recovery from the error more difficult.
814‡ The Need for Project Management
815Key Terms
816gap analysis The process of comparing measured results against expected results, then using
817the resulting “gap†as a measure of project success and as feedback for project management.
818project wrap-up A process of bringing a project to a conclusion, addressing any pending issues
819and the overall project effort, and identifying ways to improve the process in the future.
820Project management requires a unique set of skills and a thorough understanding of a broad
821body of specialized knowledge. In the opening vignette, Kelvin’s inexperience as a project
822manager makes this all too clear. Realistically, most information security projects require a
823trained project manager—a CISO or a skilled IT manager who is trained in project manage-
824ment techniques. Even experienced project managers are advised to seek expert assistance
825when engaging in a formal bidding process to select advanced or integrated technologies or
826outsourced services.
827Supervised Implementation Although it is not an optimal solution, some organiza-
828tions designate a champion from the general management community of interest to supervise
829the implementation of an information security project plan. In this case, groups of tasks are
830delegated to individuals or teams from the IT and information security communities of inter-
831est. An alternative is to designate a senior IT manager or the CIO of the organization to lead
832the implementation. In this case, the detailed work is delegated to cross-functional teams.
833The best solution is to designate a suitable person from the information security community
834of interest. In the final analysis, each organization must find the project leadership that best
835suits its specific needs and the personalities and politics of the organizational culture.
836Executing the Plan Once a project is under way, it is managed using a process known as
837gap analysis (also known as a negative feedback loop or cybernetic loop), which ensures that
838progress is measured periodically. When significant deviation occurs, corrective action is taken
839to bring the deviating task back into compliance with the project plan; otherwise, the project is
840revised in light of new information. See Figure 10-1 for an overview of this process.
841Information Security Project Management 515
842Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
843Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
844Corrective action is taken in two basic situations: either the estimate is flawed or perfor-
845mance has lagged. When an estimate is flawed, as when the number of effort hours required
846is underestimated, the plan should be corrected and downstream tasks updated to reflect the
847change. When performance has lagged—for example, due to high turnover of skilled
848employees—corrective action may take the form of adding resources, making longer sche-
849dules, or reducing the quality or quantity of the deliverable. Corrective action decisions are
850usually expressed in terms of trade-offs. Often a project manager can adjust one of the three
851following planning parameters for the task being corrected:
852â—
853Effort and money allocated
854â—
855Elapsed time or scheduling impact
856â—
857Quality or quantity of the deliverable
858When too much effort and money are being spent, you may decide to take more time to
859complete the project tasks or to lower the deliverable quality or quantity. If the task is tak-
860ing too long to complete, you should probably add more resources in staff time or money or
861decrease the deliverable quality or quantity. If the quality of the deliverable is inadequate,
862you must usually add more resources in staff time or money or take longer to complete the
863task. Of course, there are complex dynamics among these variables, and these simplistic
864Monitor and
865periodically reassess
866Plan initiated
867Current state assessed
868Current state compared
869to desired state as per
870plan
871Current =
872Desired?
873Yes
874Develop gap analysis
875remediation plan
876Implement gap analysis
877remediation plan and
878reassess
879No
880Figure 10-1 Gap analysis
881© Cengage Learning 2015
882516 Chapter 10
883Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
884Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
88510
886solutions do not serve in all cases, but this simple trade-off model can help the project man-
887ager to analyze available options.
888Project Wrap-up Project wrap-up is usually handled as a procedural task and assigned
889to a mid-level IT or information security manager. These managers collect documentation,
890finalize status reports, and deliver a final report and a presentation at a wrap-up meeting.
891The goal of the wrap-up is to resolve any pending issues, critique the overall project effort,
892and draw conclusions about how to improve the process for the future.
893For more information on project management, visit the Project Management Institute’s Web site
894at www.pmi.org.
895‡ Security Project Management Certifications
896For information security professionals who seek additional credentials and recognition for
897their project management experience, some certifications are available.
898GIAC Certified Project Manager The SANS Institute offers a program that focuses
899on security professionals and managers with project management responsibilities who seek
900to demonstrate their mastery of project management methods and strategies. 1 Candidates
901for the certification may either study on their own or enroll in the SANS IT Project Manage-
902ment course. The program focuses on the following topic areas:
903â—
904Earned value technique (EVT)
905â—
906Leadership and management strategy
907â—
908Project communication management
909â—
910Project cost management
911â—
912Project human resource management
913â—
914Project integration management
915â—
916Project management framework and approach
917â—
918Project procurement management
919â—
920Project quality management
921â—
922Project risk management
923â—
924Project scope management
925â—
926Project stakeholder management
927â—
928Project time management 2
929IT Security Project Management The EC Council offers the Project Management in
930Information Technology Security (PMITS) certification as a milestone in its Certified E-Business
931Professional program. This program focuses on the following topics:
932â—
933Components of project management in IT security
934â—
935Organizing the IT security project
936Information Security Project Management 517
937Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
938Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
939â—
940Developing the IT security project team
941â—
942Planning the IT security project
943â—
944Managing IT project management
945â—
946Building quality into IT security projects
947â—
948Closing out IT project management
949â—
950Defining a corporate IT project plan
951â—
952General IT security plan
953â—
954IT operational security plan 3
955Certified Security Project Manager The Security Industry Association (SIA) is a
956consortium focused predominantly on physical security, but it also incorporates information
957security into its programs. It has a certification program called the Certified Security Project
958Manager, which signifies completion of its project manager course, a body of self-study, and
959the completion of a final examination.
960For more information on the SANS GIAC Certified Project Manager certification, visit www.giac
961.org/certification/certified-project-manager-gcpm. For more information on the EC Council’s
962PMITS certification, visit www.eccouncil.org. For more information on the SIA certification, visit
963www.siaonline.org.
964Technical Aspects of Implementation
965Some aspects of the implementation process are technical and deal with the application of
966technology, while others deal with the human interface to technical systems. The following
967sections discuss conversion strategies, prioritization among multiple components, outsourcing,
968and technology governance.
969‡ Conversion Strategies
970Key Terms
971direct changeover The conversion strategy that involves stopping the old system and starting
972the new one without any overlap.
973parallel operations The conversion strategy that involves running the new system concurrently
974with the old system.
975phased implementation The conversion strategy that involves a measured rollout of the
976planned system; only part of the system is brought out and disseminated across an organization
977before the next piece is implemented.
978pilot implementation The conversion strategy that involves implementing the entire system
979into a single office, department, or division, and dealing with issues that arise before expanding
980to the rest of the organization.
981As the components of the new security system are planned, provisions must be made for the
982changeover from the previous method of performing a task to the new method. Just like IT
983systems, information security projects require careful conversion planning. This section
984518 Chapter 10
985Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
986Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
98710
988discusses the four basic approaches for changing from an old system or process to a new one.
989The approaches are illustrated in Figure 10-2.
990Direct Changeover Also known as going “cold turkey,†a direct changeover involves
991stopping the old method and beginning the new one. This approach could be as simple as hav-
992ing employees follow the existing procedure one week and then use a new procedure the next.
993Some cases of direct changeover are simple, such as requiring employees to begin using a new
994password with a stronger degree of authentication on an announced date. Some may be more
995complex, such as requiring the entire company to change procedures when the network team
996disables an old firewall and activates a new one. The primary drawback to the direct change-
997over approach is that if the new system fails or needs modification, users may be without ser-
998vices while the system’s bugs are worked out. Complete testing of the new system in advance
999of the direct changeover reduces the probability of such problems.
1000Phased Implementation A phased implementation is the most common conversion
1001strategy and involves a measured rollout of the planned system, with only part of the system
1002being brought out and disseminated across an organization before the next piece is imple-
1003mented. This could mean that the security group implements only a small portion of the
1004new security profile, giving users a chance to get used to it and resolving issues as they
1005arise. This is usually the best approach to security project implementation. For example, if
1006an organization seeks to update both its VPN and IDPS systems, it may first introduce the
1007new VPN solution that employees can use to connect to the organization’s network while
1008they’re traveling. Each week another department will be allowed to use the new VPN, with
1009this process continuing until all departments are using the new approach. Once the new
1010VPN has been phased into operation, revisions to the organization’s IDPS can begin.
1011Pilot Implementation In a pilot implementation, the entire security system is put in
1012place in a single office, department, or division before expanding to the rest of the organiza-
1013tion. The pilot implementation works well when an isolated group can serve as the “guinea
1014pig,†which prevents any problems with the new system from dramatically interfering with
1015the performance of the organization as a whole. The operation of a research and develop-
1016ment group, for example, may not affect the real-time operations of the organization and
1017could assist security in resolving issues that emerge.
1018New system Old system
1019New system Old system
1020New system Old system
1021New system
1022Old system
1023Direct
1024Phased
1025Pilot
1026Parallel
1027Figure 10-2 Conversion strategies
1028© Cengage Learning 2015
1029Technical Aspects of Implementation 519
1030Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1031Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1032Parallel Operations The parallel operations strategy involves running two systems
1033concurrently; in terms of information systems, it might involve running two firewalls concur-
1034rently, for example. Although this approach is complex, it can reinforce an organization’s
1035information security by allowing the old system(s) to serve as backup for the new systems if
1036they fail or are compromised. Drawbacks usually include the need to deal with both systems
1037and maintain both sets of procedures.
1038‡ The Bull’s-Eye Model
1039Key Term
1040bull’s-eye model A method for prioritizing a program of complex change; it requires that issues
1041be addressed from the general to the specific and focuses on systematic solutions instead of
1042individual problems.
1043A proven method for prioritizing a program of complex change is the bull’s-eye model. This
1044methodology, which goes by many different names and has been used by many organiza-
1045tions, requires that issues be addressed from the general to the specific and that the focus be
1046on systematic solutions instead of individual problems. The increased capabilities—that is,
1047increased expenditures—are used to improve the information security program in a system-
1048atic and measured way. As presented here and illustrated in Figure 10-3, the approach relies
1049on a process of project plan evaluation in four layers:
10501. Policies: This is the outer, or first, ring in the bull’s-eye diagram. The critical impor-
1051tance of policies has been emphasized throughout this textbook, particularly in
1052Chapter 4. The foundation of all effective information security programs is sound
1053Policies
1054Networks
1055Systems
1056Applications
1057Figure 10-3 The bull’s-eye model
1058© Cengage Learning 2015
1059520 Chapter 10
1060Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1061Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
106210
1063information security policy and information technology policy. Because policy estab-
1064lishes the ground rules for the use of all systems and describes what is appropriate
1065and inappropriate, it enables all other information security components to function
1066correctly. When deciding how to implement complex changes and choose from
1067conflicting options, you can use policy to clarify what the organization is trying to
1068accomplish with its efforts.
10692. Networks: In the past, most information security efforts focused on this layer, so until
1070recently information security was often considered synonymous with network security.
1071In today’s computing environment, implementing information security is more complex
1072because networking infrastructure often comes into contact with threats from the public
1073network. If an organization is new to the Internet and examines its policy environment
1074to define how the new company networks should be defended, it will soon find that
1075designing and implementing an effective DMZ is the primary way to secure those
1076networks. Secondary efforts in this layer include providing the necessary authentication
1077and authorization when allowing users to connect over public networks to the organization’s
1078systems.
10793. Systems: Many organizations find that the problems of configuring and operating infor-
1080mation systems in a secure fashion become more difficult as the number and complexity
1081of these systems grow. This layer includes computers used as servers, desktop computers,
1082and systems used for process control and manufacturing systems.
10834. Applications: The layer that receives attention last deals with the application
1084software systems used by the organization to accomplish its work. This includes
1085packaged applications, such as office automation and e-mail programs, as well as
1086high-end enterprise resource planning (ERP) packages than span the organization.
1087Custom application software developed by the organization for its own needs is
1088also included.
1089By reviewing the information security blueprint and the current state of the organiza-
1090tion’s information security efforts in terms of these four layers, project planners can
1091determine which areas require expanded capabilities. The bull’s-eye model can also be
1092used to evaluate the sequence of steps taken to integrate parts of the information security
1093blueprint into a project plan. As suggested by its bull’s-eye shape, this model dictates the
1094following:
1095â—
1096Until sound and usable IT and information security policies are developed, communi-
1097cated, and enforced, no additional resources should be spent on other controls.
1098â—
1099Until effective network controls are designed and deployed, all resources should go
1100toward achieving that goal, unless resources are needed to revisit the policy needs of
1101the organization.
1102â—
1103After policies and network controls are established, implementation should focus
1104on the information, process, and manufacturing systems of the organization.
1105Until there is well-informed assurance that all critical systems are being config-
1106ured and operated in a secure fashion, all resources should be spent on reaching
1107that goal.
1108â—
1109Once there is assurance that policies are in place, networks are secure, and systems
1110are safe, attention should move to assessing and remediating the security of the
1111Technical Aspects of Implementation 521
1112Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1113Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1114organization’s applications. This is a complicated and vast area of concern for
1115many organizations, and most neglect to analyze the impact of information security
1116on existing systems and their own proprietary systems. As in all planning efforts,
1117attention should be paid to the most critical applications first.
1118‡ To Outsource or Not
1119Not every organization needs to develop an information security department or program of
1120its own. Just as some organizations outsource part or all of their IT operations, so too can
1121organizations outsource their information security programs. The expense and time required
1122to develop an effective information security program may be beyond the means of some
1123organizations, so it may be in their best interest to hire professional services to help their IT
1124departments implement such a program.
1125When an organization outsources most or all of its IT services, information security should
1126be part of the contract arrangement with the supplier. Organizations that handle most of
1127their own IT operations may choose to outsource the more specialized information security
1128functions. Small and medium-sized organizations often hire outside consultants for penetra-
1129tion testing and information security program audits. Organizations of all sizes frequently
1130outsource network monitoring functions to make certain that their systems are adequately
1131secured and to gain assistance in watching for attempted or successful attacks.
1132For an interesting article on outsourcing security, visit renowned security consultant and author
1133Bruce Schneier’s Web page at www.schneier.com/essay-084.html.
1134‡ Technology Governance and Change Control
1135Key Terms
1136change control A method of regulating the modification of systems within the organization by
1137requiring formal review and approval for each change.
1138technology governance A process organizations use to manage the effects and costs of
1139technology implementation, innovation, and obsolescence.
1140Other factors that determine the success of an organization’s IT and information security
1141programs are technology governance and change control. Governance was covered in detail
1142in Chapter 4.
1143Technology governance guides how frequently technical systems are updated and how tech-
1144nical updates are approved and funded. Technology governance also facilitates communica-
1145tion about technical advances and issues across the organization.
1146Medium-sized and large organizations deal with the impact of technical change on their
1147operations through a change control process. By managing the process of change, the organi-
1148zation can do the following:
1149â—
1150Improve communication about change across the organization.
1151â—
1152Enhance coordination between groups within the organization as change is scheduled
1153and completed.
1154522 Chapter 10
1155Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1156Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
115710
1158â—
1159Reduce unintended consequences by having a process to resolve conflict and disruption
1160that change can introduce.
1161â—
1162Improve quality of service as potential failures are eliminated and groups work
1163together.
1164â—
1165Assure management that all groups are complying with the organization’s
1166policies for technology governance, procurement, accounting, and information
1167security.
1168Effective change control is an essential part of the IT operation in all but the smallest organi-
1169zations. The information security group can also use the change control process to ensure
1170that the organization follows essential process steps that assure confidentiality, integrity, and
1171availability when systems are upgraded across the organization.
1172‡ The SANS Top 20 Critical Security Controls
1173To provide guidance for the implementation of security controls in the organization, the
1174SANS Institute serves as a sponsor and host of the list of top 20 critical security controls.
1175The SANS Institute notes that security standards and requirement frameworks have come
1176and gone in recent years, always making an effort to address the risks that organizations
1177face when using enterprise systems. These efforts often seem to devolve into a set of rote
1178compliance reports, resulting in a diversion of resources that may have been better spent
1179making actual improvements in the security posture to meet evolving threats rather than
1180writing reports to address threats from the past. This state of affairs was noted in 2008
1181by the U.S. National Security Agency (NSA), which undertook an “offense must inform
1182defense†approach that sought to enable the selection and implementation of controls
1183based on a prioritization model with an intention to block actual threats instead of gener-
1184ating compliance documentation. The result was the emergence of a global consortium
1185drawn from industry and government that became known as the Critical Security Controls
1186(the Controls). The SANS Institute was charged with a coordinating role in this process.
1187Later, in 2013, accountability for the Controls was passed to the Council on CyberSecur-
1188ity (the Council), a global, independent nonprofit organization that intended to provide
1189for a secure and open Internet.
1190The Controls sought to deliver functionality that focused on emerging advanced targeted
1191threats, placing an emphasis on practical control approaches. The Controls were offered in a
1192framework that emphasized standardization of approach and the use of automated techni-
1193ques where possible, seeking to deliver a high degree of effectiveness and an essential effi-
1194ciency to operations. The Controls are recognized as a subset of the controls enumerated in
1195the National Institute of Standards and Technology (NIST) SP 800-53, and are not intended
1196to supplant the NIST directives, including the Cybersecurity Framework developed in
1197response to Executive Order 13636. Rather, this effort is a means of implementing a smaller
1198number of actionable controls that deliver maximum results from a modest set of resource
1199inputs using a structured list of priorities.
1200Since the Controls were derived from the most common attack patterns and were
1201vetted across a very broad community of government and industry, with very
1202strong consensus on the resulting set of controls, they serve as the basis for
1203immediate high-value action. 4
1204Technical Aspects of Implementation 523
1205Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1206Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1207A partial list of the 2013 critical controls follows:
12081. Inventory of Authorized and Unauthorized Devices—Actively manage (inven-
1209tory, track, and correct) all hardware devices on the network […].
12102. Inventory of Authorized and Unauthorized Software—Actively manage […]
1211all software on the network […].
12123. Secure Configurations for Hardware and Software on Mobile Devices, Lap-
1213tops, Workstations, and Servers—Establish, implement, and actively manage
1214[…] the security configuration of laptops, servers, and workstations […].
12154. Continuous Vulnerability Assessment and Remediation—Continuously
1216acquire, assess, and take action on new information in order to identify vul-
1217nerabilities, remediate, and minimize the window of opportunity for attackers.
12185. Malware Defenses—Control the installation, spread, and execution of mali-
1219cious code […].
12206. Application Software Security—Manage the security life cycle of all […]
1221software […].
12227. Wireless Access Control—Manage the processes and tools used to track, con-
1223trol, prevent, and correct the security use of wireless local area networks […].
12248. Data Recovery Capability—The processes and tools used to properly back
1225up critical information with a proven methodology for timely recovery of it.
12269. Security Skills Assessment and Appropriate Training to Fill Gaps—For all
1227functional roles in the organization […], identify the specific knowledge,
1228skills, and abilities needed to support defense of the enterprise; develop and
1229execute an integrated plan to assess, identify gaps, and remediate through
1230policy, organizational planning, training, and awareness programs.
123110. Secure Configurations for Network Devices such as Firewalls, Routers, and
1232Switches—Establish, implement, and actively manage […] the security con-
1233figuration of network infrastructure […].
123411. Limitation and Control of Network Ports, Protocols, and Services—Manage
1235(track/control/correct) the ongoing operational use of ports, protocols, and
1236services on networked devices […].
123712. Controlled Use of Administrative Privileges—The processes and tools used to
1238track, control, prevent, and correct the use, assignment, and configuration of
1239administrative privileges on computers, networks, and applications.
124013. Boundary Defense—Detect, prevent, and correct the flow of information
1241transferring networks of different trust levels with a focus on security-damag-
1242ing data.
124314. Maintenance, Monitoring, and Analysis of Audit Logs—Collect, manage,
1244and analyze audit logs of events that could help detect, understand, or
1245recover from an attack.
124615. Controlled Access Based on the Need to Know—Control the processes and
1247tools used to track, control, prevent, and correct secure access to critical
1248524 Chapter 10
1249Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1250Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
125110
1252assets (e.g., information, resources, systems) according to the formal determi-
1253nation of which persons, computers, and applications have a need and right
1254to access these critical assets based on an approved classification.
125516. Account Monitoring and Control […].
125617. Data Protection […].
125718. Incident Response and Management […].
125819. Secure Network Engineering […].
125920. Penetration Tests and Red Team Exercises […]. 5
1260Nontechnical Aspects of Implementation
1261Some aspects of information security implementation are not technical in nature, but deal
1262instead with the human interface to technical systems. The sections that follow discuss the
1263topic of creating a culture of change management and considerations for organizations facing
1264change.
1265‡ The Culture of Change Management
1266The prospect of change, the familiar shifting to the unfamiliar, can cause employees to resist
1267the change, either unconsciously or consciously. Regardless of whether the changes are per-
1268ceived as good or bad, employees tend to prefer the old way of doing things. Even when
1269employees embrace changes, the stress of actually making the changes and adjusting to new
1270procedures can increase the probability of mistakes or create vulnerabilities in systems. By
1271understanding and applying some basic tenets of change management, project managers can
1272lower employee resistance to change and can even build resilience for it, thereby making
1273ongoing change more palatable to the entire organization.
1274The basic foundation of change management requires people who are making the changes to
1275understand that organizations typically have cultures that represent their mood and philoso-
1276phy. Disruptions to this culture must be properly addressed and their effects minimized. One
1277of the oldest models of change is the Lewin change model, 6 which consists of three simplistic
1278stages:
1279â—
1280Unfreezing: Thawing hard-and-fast habits and established procedures. Preparing
1281the organization for upcoming changes facilitates the implementation of new
1282processes, systems, and procedures. Training and awareness programs assist in this
1283preparation.
1284â—
1285Moving: Transitioning between the old way and the new. The physical implementation
1286of new methods, using the strategies outlined earlier in this chapter, requires the orga-
1287nization to recognize the cessation of old ways of work and reinforces the need to use
1288the new methods.
1289â—
1290Refreezing: The integration of the new methods into the organizational culture, which
1291is accomplished by creating an atmosphere in which the changes are accepted as the
1292preferred way of accomplishing the necessary tasks.
1293Nontechnical Aspects of Implementation 525
1294Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1295Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1296‡ Considerations for Organizational Change
1297An organization can take steps to make its employees more amenable to change. These steps
1298reduce resistance to change at the beginning of the planning process and encourage members
1299of the organization to be more flexible as changes occur.
1300Reducing Resistance to Change from the Start The level of resistance to
1301change affects the ease with which an organization can implement procedural and mana-
1302gerial changes. The more ingrained the existing methods and behaviors are, the more diffi-
1303cult it will probably be to make the change. It’s best, therefore, to improve interactions
1304between the affected members of the organization and project planners in the early phases
1305of an information security improvement project. These interactions can be improved
1306through a three-step process in which project managers communicate, educate, and
1307involve.
1308Communication is the first and most critical step. Project managers must communicate with
1309employees so they know a new security process is being considered and that their feedback
1310is essential to making it work. You must also constantly update employees on the progress
1311of the SecSDLC and provide information on the expected completion dates. This ongoing
1312series of updates keeps the process from being a last-minute surprise and primes people to
1313accept the change more readily when it finally arrives.
1314At the same time, you must update and educate employees about exactly how the pro-
1315posed changes will affect them individually and within the organization. While detailed
1316information may not be available in earlier stages of a project plan, details that can be
1317shared with employees may emerge as the SecSDLC progresses. Education also involves
1318teaching employees to use the new systems once they are in place. As discussed earlier,
1319this means delivering high-quality training programs at the appropriate times.
1320Finally, project managers can reduce resistance to change by involving employees in the
1321project plan. This means getting key representatives from user groups to serve as members
1322of the SecSDLC development process. In systems development, this process is referred to as
1323joint application development, or JAD. Identifying a liaison between IT and information security
1324implementers and the organization’s general population can serve the project team well in early
1325planning stages, when unforeseen problems with acceptance of the project may need to be
1326addressed.
1327Developing a Culture That Supports Change An ideal organization fosters
1328resilience to change. This means the organization understands that change is a necessary
1329part of the culture, and that embracing change is more productive than fighting it. To
1330develop such a culture, the organization must successfully accomplish many projects that
1331require change. A resilient culture can be either cultivated or undermined by management’s
1332approach. Strong management support for change, with a clear executive-level champion,
1333enables the organization to recognize the necessity for change and its strategic importance.
1334Weak management support, with overly delegated responsibility and no champion, sen-
1335tences the project to almost certain failure. In such a case, employees sense the low priority
1336assigned to the project and do not communicate with the development team because the
1337effort seems useless.
1338526 Chapter 10
1339Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1340Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
134110
1342For a sample change management and control policy template, visit the ISO27001security.com
1343Web page at www.iso27001security.com/ISO27k_Model_policy_on_change_management
1344_and_control.docx.
1345Information Systems Security Certification
1346and Accreditation
1347Key Terms
1348accreditation The process that authorizes an IT system to process, store, or transmit
1349information.
1350certification In information security, the comprehensive evaluation of an IT system’s technical
1351and nontechnical security controls that establishes the extent to which a particular design and
1352implementation meets a set of predefined security requirements, usually in support of an
1353accreditation process.
1354At first glance, it may seem that only systems for handling secret government data require
1355security certification or accreditation. However, organizations are increasingly finding that
1356their systems need to have formal mechanisms for verification and validation in order to com-
1357ply with recent federal regulations that protect personal privacy.
1358‡ Certification Versus Accreditation
1359In security management, accreditation is what authorizes an IT system to process, store,
1360or transmit information. It is issued by a management official and is a means of assuring
1361that systems are of adequate quality. It also challenges managers and technical staff to
1362find the best methods to assure security, given technical constraints, operational con-
1363straints, and mission requirements. In the same vein, certification is the evaluation of an
1364IT system’s security controls to support the accreditation process. Organizations pursue
1365accreditation or certification to gain a competitive advantage or to provide assurance to
1366their customers. Federal systems require accreditation under OMB Circular A-130 and
1367the Computer Security Act of 1987. Accreditation demonstrates that management has
1368identified an acceptable risk level and provided resources to control unacceptable risk
1369levels.
1370Certification and accreditation (C&A) are not permanent. Just as standards of due diligence
1371and due care require ongoing maintenance, most C&A processes typically require reaccredi-
1372tation or recertification every three to five years.
1373‡ The NIST Security Life Cycle Approach
1374Two documents provide guidance for the certification and accreditation of U.S. information
1375systems: SP 800-37, Rev. 1, Guide for Applying the Risk Management Framework to Federal
1376Information Systems: A Security Life Cycle Approach; and CNSS Instruction-1000: National
1377Information Assurance Certification and Accreditation Process (NIACAP).
1378Information Systems Security Certification and Accreditation 527
1379Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1380Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1381Information processed by the U.S. government is grouped into one of three categories:
1382national security information (NSI), non-NSI, and the intelligence community. National secu-
1383rity information is processed on national security systems (NSSs), which are managed and
1384operated by the Committee on National Security Systems (CNSS). Non-NSSs are managed
1385and operated by the National Institute of Standards and Technology (NIST). Intelligence
1386community information is a separate category and is handled according to guidance from
1387the office of the Director of National Intelligence.
1388An NSS is defined as any information system, including any telecommunications system, used
1389or operated by an agency, a contractor of any agency, or other organization on behalf of an
1390agency, that has the following characteristics:
1391â—
1392Involves intelligence activities
1393â—
1394Involves cryptologic activities related to national security
1395â—
1396Involves command and control of military forces
1397â—
1398Involves equipment that is an integral part of a weapon or weapon system
1399â—
1400Is subject to subparagraph (B) of the Federal Information Security Management Act of
14012002, is critical to the direct fulfillment of military or intelligence missions, or is pro-
1402tected at all times by procedures for information that have been specifically authorized
1403under criteria established by an executive order or an act of Congress to be kept clas-
1404sified in the interest of national defense or foreign policy.
1405Subparagraph (B) states that this criterion “does not include a system that is to be used for
1406routine administration and business applications (including payroll, finance, logistics, and
1407personnel management applications).†7
1408National security information must be processed on NSSs, which have more stringent
1409requirements. NSSs process a mix of NSI and non-NSI and are accredited using CNSS guid-
1410ance. Non-NSS systems follow NIST guidance. More than 20 major government agencies
1411store, process, or transmit NSI, and many of them have both NSSs and systems that are not
1412rated as NSSs. You can learn more about the CNSS community and how NSSs are managed
1413and operated at www.cnss.gov.
1414In recent years, the Joint Task Force Transformation Initiative Working Group of the U.S.
1415government and NIST have worked to overhaul the formal C&A program for non-NSI sys-
1416tems. The program has been modified from a separate C&A process into an integrated Risk
1417Management Framework (RMF), which can be used for normal operations and still provide
1418assurance that the systems are capable of reliably housing confidential information. NIST SP
1419800-37, Rev. 1, provides a detailed description of the new RMF process. The following sec-
1420tion is adapted from this document.
1421The revised process emphasizes: (i) building information security capabilities into
1422federal information systems through the application of state-of-the-practice man-
1423agement, operational, and technical security controls; (ii) maintaining awareness
1424of the security state of information systems on an ongoing basis through
1425enhanced monitoring processes; and (iii) providing essential information to senior
1426leaders to facilitate decisions regarding the acceptance of risk to organizational
1427operations and assets, individuals, other organizations, and the nation arising
1428from the operation and use of information systems.
1429528 Chapter 10
1430Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1431Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
143210
1433… The risk management process described in this publication changes the tradi-
1434tional focus of C&A as a static, procedural activity to a more dynamic approach
1435that provides the capability to more effectively manage information system-
1436related security risks in highly diverse environments of complex and sophisticated
1437cyber threats, ever-increasing system vulnerabilities, and rapidly changing
1438missions.
1439… The guidelines in SP 800-37, Rev. 1 are applicable to all federal information
1440systems other than those systems designated as national security systems as
1441defined in 44 U.S.C., Section 3542. 8
1442Risk management is the subject of Chapter 5, but because the U.S. government is replacing
1443the old C&A process with a formal RMF, that framework is briefly described here. As
1444the reference for its RMF, SP 800-37, Rev. 1 specifically refers to NIST SP 800-39, a new
1445publication titled Integrated Enterprise-Wide Risk Management: Organization, Mission and
1446Information Systems View. The NIST RMF builds on a three-tiered approach to risk
1447management that addresses risk-related concerns at the organization level, the mission and
1448business process level, and the information system level, as illustrated in Figure 10-4.
1449Tier 1 addresses risk from an organizational perspective with the development of
1450a comprehensive governance structure and organization-wide risk management
1451strategy …
1452Tier 2 addresses risk from a mission and business process perspective and is
1453guided by the risk decisions at Tier 1. Tier 2 activities are closely associated
1454with enterprise architecture …
1455Tier 3 addresses risk from an information system perspective and is guided by
1456the risk decisions at Tiers 1 and 2. Risk decisions at Tiers 1 and 2 impact the
1457ultimate selection and deployment of needed safeguards and countermeasures
1458(i.e., security controls) at the information system level. Information security
1459Tier 1
1460Organization
1461(Governance)
1462Strategic Risk
1463Tactical Risk
1464Tier 2
1465Mission/Business Process
1466(Information and Information Flows)
1467Tier 3
1468Information System
1469(Environment of Operation)
1470- Multitier Organization-Wide Risk Management
1471- Implemented by the Risk Executive (Function)
1472- Tightly coupled to Enterprise Architecture
1473and Information Security Architecture
1474- System Development Life Cycle Focus
1475- Disciplined and Structured Process
1476- Flexible and Agile Implementation
1477Figure 10-4 Tiered Risk Management Framework
1478© Cengage Learning 2015
1479Information Systems Security Certification and Accreditation 529
1480Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1481Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1482requirements are satisfied by the selection of appropriate management, opera-
1483tional, and technical security controls from NIST Special Publication 800-53.
1484The Risk Management Framework (RMF), which is illustrated in Figure 10-5,
1485provides a disciplined and structured process that integrates information security
1486and risk management activities into the system development life cycle. The RMF
1487operates primarily at Tier 3 in the risk management hierarchy but can also have
1488interactions at Tiers 1 and 2 (e.g., providing feedback from ongoing authoriza-
1489tion decisions to the risk executive [function], dissemination of updated threat
1490and risk information to authorizing officials and information system owners).
1491The RMF steps include:
1492â—
1493Categorize the information system and the information processed, stored,
1494and transmitted by that system based on an impact analysis.
1495â—
1496Select an initial set of baseline security controls for the information system
1497based on the security categorization; tailoring and supplementing the secu-
1498rity control baseline as needed based on an organizational assessment of
1499risk and local conditions.
1500Categorize
1501Information System
1502Step 1
1503Select
1504Security Controls
1505Step 2
1506Implement
1507Security Controls
1508Step 3
1509Monitor
1510Security Controls
1511Step 6
1512Authorize
1513Information System
1514Step 5
1515Assess
1516Security Controls
1517Step 4
1518Process
1519Overview
1520Starting
1521Point
1522Organizational Inputs
1523Laws, Directives, Policy Guidance
1524Strategic Goals and Objectives
1525Priorities and Resource Availability
1526Supply Chain Considerations
1527Architecture Description
1528Architecture Reference Models
1529Segment and Solution Architectures
1530Mission and Business Processes
1531Information System Boundaries
1532Risk
1533Management
1534Framework
1535Repeat as necessary
1536Figure 10-5 Risk Management Framework
1537© Cengage Learning 2015
1538530 Chapter 10
1539Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1540Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
154110
1542â—
1543Implement the security controls and describe how the controls are
1544employed within the information system and its environment of
1545operation.
1546â—
1547Assess the security controls using appropriate assessment procedures to
1548determine the extent to which the controls are implemented correctly,
1549operating as intended, and producing the desired outcome with respect to
1550meeting the security requirements for the system.
1551â—
1552Authorize information system operation based on a determination of the
1553risk to organizational operations and assets, individuals, other organiza-
1554tions, and the nation resulting from the operation of the information sys-
1555tem and the decision that this risk is acceptable.
1556â—
1557Monitor the security controls in the information system on an ongoing
1558basis, including assessing control effectiveness, documenting changes to the
1559system or its environment of operation, conducting security impact analy-
1560ses of the associated changes, and reporting the security state of the system
1561to designated organizational officials. 9
1562With regard to using the RMF:
1563The organization has significant flexibility in deciding which families of security
1564controls or specific controls from selected families in NIST Special Publication
1565800-53 are appropriate for the different types of allocations. Since the security
1566control allocation process involves the assignment and provision of security
1567capabilities derived from security controls, the organization ensures that there
1568is effective communication among all entities either receiving or providing such
1569capabilities. This communication includes, for example, ensuring that common
1570control authorization results and continuous monitoring information are read-
1571ily available to those organizational entities inheriting common controls, and
1572that any changes to common controls are effectively communicated to those
1573affected by such changes. [Figure 10-6] illustrates security control allocation
1574within an organization and using the RMF to produce information for senior
1575leaders (including authorizing officials) on the ongoing security state of organi-
1576zational information systems and the missions and business processes supported
1577by those systems. 10
1578Chapter 3 of SP 800-37, Rev. 1, provides detailed guidance for implementing the RMF,
1579including information on primary responsibility, supporting roles, the system development
1580life cycle phase, supplemental guidance, and references. An overview of the tasks involved is
1581shown in Table 10-2.
1582Why is it important that you know this information? Your organization may someday want
1583to become a government contractor, if it isn’t already. These guidelines apply to all systems
1584that connect to U.S. government entities not identified as national security systems or as con-
1585taining national security information.
1586For more information on these and related NIST Special Publications, visit the CSRC Web Site at
1587http://csrc.nist.gov/publications/PubsSPs.html.
1588Information Systems Security Certification and Accreditation 531
1589Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1590Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1591‡ NSTISS Certification and Accreditation
1592National security interest systems have their own security C&A standards, which also follow
1593the guidance of OMB Circular A-130. CNSS, formerly known as the National Security Tele-
1594communications and Information Systems Security Committee (NSTISSC), has a C&A docu-
1595ment titled NSTISS Instruction 1000: National Information Assurance Certification and
1596Accreditation Process (NIACAP). The following section contains excerpts from this docu-
1597ment and provides an overview of the purpose and process of this C&A program.
15981. The document establishes the minimum national standards for certifying and accrediting
1599national security systems. This process provides a standard set of activities, general
1600tasks, and a management structure to certify and accredit systems that will maintain
1601the information assurance (IA) and security posture of a system or site. This process
1602Information
1603System
1604System-specific
1605Controls
1606Information
1607System
1608Security
1609Plan
1610Core Missions/Business Processes
1611Security Requirements
1612Policy Guidance
1613Risk Executive Function
1614Organization-Wide Risk Governance and Oversight
1615Common Controls
1616Security Controls Inherited by Organizational Information Systems
1617Authorization Decision
1618Authorization Decision
1619Risk
1620Management
1621Framework
1622(RMF)
1623Security
1624Assessment
1625Report
1626Plan of Action
1627and Milestones
1628Security
1629Plan
1630Security
1631Plan
1632Security
1633Assessment
1634Report
1635Security
1636Assessment
1637Report
1638Authorization Decision
1639Plan of Action
1640and Milestones
1641Plan of Action
1642and Milestones
1643System-specific
1644Controls
1645Hybrid Controls
1646Hybrid Controls
1647Figure 10-6 Security control allocation from NIST SP 800-37, Rev. 1
1648© Cengage Learning 2015
1649532 Chapter 10
1650Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1651Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
165210
1653RMF Step 1—Categorize Information System
16541-1 (Security Categorization): Categorize the information system and document the results of the security
1655categorization in the security plan.
16561-2 (Information System Description): Describe the information system, including the system boundary, and
1657document the description in the security plan.
16581-3 (Information System Registration): Register the information system with appropriate organizational program/
1659management offices.
1660Milestone Checkpoint for RMF Step 1:
1661â—
1662Has the organization completed a security categorization of the information system, including the
1663information to be processed, stored, and transmitted by the system?
1664â—
1665Are the results of the security categorization process for the information system consistent with the organization’s
1666enterprise architecture and commitment to protecting organizational mission/business processes?
1667â—
1668Do the results of the security categorization process reflect the organization’s risk management strategy? Has
1669the organization adequately described the characteristics of the information system?
1670â—
1671Has the organization registered the information system for purposes of management, accountability,
1672coordination, and oversight?
1673RMF Step 2—Select Security Controls
16742-1 (Common Control Identification): Identify the security controls provided by the organization as common controls
1675for organizational information systems and document the controls in a security plan or equivalent document.
16762-2 (Security Control Selection): Select the security controls for the information system and document the controls
1677in the security plan.
16782-3 (Monitoring Strategy): Develop a strategy for the continuous monitoring of security control effectiveness and
1679any proposed or actual changes to the information system and its environment of operation.
16802-4 (Security Plan Approval): Review and approve the security plan.
1681Milestone Checkpoint for RMF Step 2:
1682â—
1683Has the organization allocated all security controls to the information system as system-specific, hybrid, or
1684common controls?
1685â—
1686Has the organization used its formal or informal risk assessment to inform and guide the security control
1687selection process?
1688â—
1689Has the organization identified authorizing officials for the information system and all common controls
1690inherited by the system?
1691â—
1692Has the organization tailored and supplemented the baseline security controls to ensure that the controls, if
1693implemented, adequately mitigate risks to the organization’s operations and assets, individual employees,
1694other organizations, and the nation?
1695â—
1696Has the organization addressed minimum assurance requirements for the security controls employed within
1697the information system and inherited by it?
1698â—
1699Has the organization consulted information system owners when identifying common controls to ensure that
1700the security capability provided by the inherited controls is sufficient to deliver adequate protection?
1701â—
1702Has the organization supplemented the common controls with system-specific or hybrid controls when the
1703security baselines of the common controls are less than those of the information system inheriting the controls?
1704â—
1705Has the organization documented the common controls inherited from external providers?
1706â—
1707Has the organization developed a continuous monitoring strategy for the information system, including monitoring
1708of security control effectiveness for system-specific, hybrid, and common controls, that reflects the organization’s risk
1709management strategy and commitment to protecting critical missions and business functions?
1710â—
1711Have appropriate organizational officials approved security plans containing system-specific, hybrid, and
1712common controls?
1713RMF Step 3—Implement Security Controls
17143-1 (Security Control Implementation): Implement the security controls specified in the security plan.
17153-2 (Security Control Documentation): Document the security control implementation as appropriate in the security
1716plan; provide a functional description of the control implementation, including planned inputs, expected
1717behavior, and expected outputs.
1718Table 10-2 Executing the Risk Management Framework Tasks (continues)
1719Information Systems Security Certification and Accreditation 533
1720Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1721Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1722Milestone Checkpoint for RMF Step 3:
1723â—
1724Has the organization allocated security controls as system-specific, hybrid, or common controls consistent with
1725the enterprise architecture and information security architecture?
1726â—
1727Has the organization demonstrated the use of sound information system and security engineering
1728methodologies in integrating information technology products into the information system and in
1729implementing the security controls contained in the security plan?
1730â—
1731Has the organization documented how common controls inherited by organizational information systems
1732have been implemented?
1733â—
1734Has the organization documented how system-specific and hybrid security controls have been implemented
1735within the information system, taking into account specific technologies and platform dependencies?
1736â—
1737Has the organization taken into account the minimum assurance requirements when implementing security
1738controls?
1739RMF Step 4—Assess Security Controls
17404-1 (Assessment Preparation): Develop, review, and approve a plan to assess the security controls.
17414-2 (Security Control Assessment): Assess the security controls in accordance with the assessment procedures
1742defined in the security assessment plan.
17434-3 (Security Assessment Report): Prepare the security assessment report, which documents the issues, findings,
1744and recommendations from the security control assessment.
17454-4 (Remediation Actions): Conduct initial remediation actions on security controls based on the findings and
1746recommendations of the security assessment report and reassess remediated control(s), as appropriate.
1747Milestone Checkpoint for RMF Step 4:
1748â—
1749Has the organization developed a comprehensive plan to assess the security controls employed within the
1750information system or inherited by it?
1751â—
1752Was the assessment plan reviewed and approved by appropriate organizational officials?
1753â—
1754Has the organization considered the appropriate level of assessor independence for the security control
1755assessment?
1756â—
1757Has the organization provided all of the essential supporting materials needed by the assessor(s) to conduct
1758an effective security control assessment?
1759â—
1760Has the organization examined opportunities for reusing assessment results from previous assessments or
1761from other sources?
1762â—
1763Did the assessor(s) complete the security control assessment in accordance with the stated assessment plan?
1764Did the organization receive the completed security assessment report with appropriate findings and
1765recommendations from the assessor(s)?
1766â—
1767Did the organization take the necessary remediation actions to address the most important weaknesses and
1768deficiencies in the information system and its environment of operation, based on the findings and
1769recommendations in the security assessment report?
1770â—
1771Did the organization update appropriate security plans based on the findings and recommendations in the
1772security assessment report and any subsequent changes to the information system and its environment of
1773operation?
1774RMF Step 5—Authorize Information System
17755-1 (Plan of Action and Milestones): Prepare the plan of action and milestones based on the findings and recom-
1776mendations of the security assessment report, excluding any remediation actions taken.
17775-2 (Security Authorization Package): Assemble the security authorization package and submit it to the
1778authorizing official for adjudication.
17795-3 (Risk Determination): Determine the risk to the organization’s operations (including mission, functions, image,
1780or reputation), organizational assets, individual employees, other organizations, or the nation.
17815-4 (Risk Acceptance): Determine if the risk to the organization’s operations, organizational assets, individual
1782employees, other organizations, or the nation is acceptable.
1783Table 10-2 Executing the Risk Management Framework Tasks
1784Source: NIST SP 800-37, Rev. 1.
1785534 Chapter 10
1786Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1787Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
178810
1789focuses on an enterprise-wide view of the information system (IS) in relation to the orga-
1790nization’s mission and the IS business case.
17912. The NIACAP is designed to certify that the IS meets documented accreditation require-
1792ments and will continue to maintain the accredited security posture throughout the sys-
1793tem life cycle.
1794The key to the NIACAP is the agreement between the IS program manager, designated
1795approving authority (DAA), certification agent (certifier), and user representative. These par-
1796ties resolve critical schedule, budget, security, functionality, and performance issues.
1797The NIACAP agreements are documented in the system security authorization agreement
1798(SSAA), which is used to guide and document the results of the C&A process. The objective
1799is to use the SSAA to establish an evolving yet binding agreement on the level of security
1800required before system development begins or changes are made to a system. After accredita-
1801tion, the SSAA becomes the baseline security configuration document.
1802The minimum NIACAP roles include the program manager, DAA, certifier, and user repre-
1803sentative. Additional roles may be added to increase the integrity and objectivity of C&A
1804decisions. For example, the information systems security officer (ISSO) usually performs a
1805key role in maintaining the security posture after accreditation and may also play a key role
1806in the system C&A.
1807The SSAA:
1808â—
1809Describes the operating environment and threat
1810â—
1811Describes the system security architecture
1812â—
1813Establishes the C&A boundary of the system to be accredited
1814â—
1815Documents the formal agreement among the DAA(s), certifier, program manager, and
1816user representative
1817â—
1818Documents all requirements necessary for accreditation
1819â—
1820Minimizes documentation requirements by consolidating applicable information into
1821the SSAA; this information includes the security policy, concept of operations, archi-
1822tecture description, and test procedures
1823â—
1824Documents the NIACAP plan
1825â—
1826Documents test plans and procedures, certification results, and residual risk
1827â—
1828Forms the baseline security configuration document
1829The NIACAP is composed of four phases, as shown from several perspectives in Figures 10-7
1830to 10-11. These phases are definition, verification, validation, and post accreditation.
1831Phase 1, definition, determines the necessary security measures and effort level to achieve cer-
1832tification and accreditation. The objective of Phase 1 is to agree on the security requirements,
1833C&A boundary, schedule, level of effort, and resources required.
1834Phase 2, verification, verifies the evolving or modified system’s compliance with the informa-
1835tion in the SSAA. The objective of Phase 2 is to ensure that the fully integrated system is
1836ready for certification testing.
1837Information Systems Security Certification and Accreditation 535
1838Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1839Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1840Maintain
1841SSAA
1842SSAA
1843Change
1844Management
1845(CM) and Change
1846Control
1847Security
1848Operations
1849Operate the
1850System
1851Phase 4
1852Post Accreditation
1853Phase 1
1854Definition
1855Phase 2
1856Verification
1857Phase 3
1858Validation
1859Determine
1860Requirements
1861Define Boundaries
1862Tailor the Process
1863& Scope the Effort
1864Draft the SSAA
1865Document
1866Results
1867Evaluate Procedural,
1868Physical, Personnel, CM,
1869etc. Procedures
1870Test Installed
1871System
1872Document
1873Results
1874Initial
1875Certification
1876Analysis
1877System
1878Development
1879Activities
1880Figure 10-7 Overview of the NIACAP process
1881Source: NSTISSI-1000.
1882Preparation
1883Inputs Activities
18841. Review
1885Documentation
1886Registration
1887A
1888Negotiation
18892. Prepare Mission Description
1890and System Identification
18913. Register System
18924. Describe Environment
1893and Threat
18945. Describe System
1895Architecture
18966. Determine Security
1897Requirements
18987. Identify Organization
1899and Resources
19008. Tailor NIACAP and
1901Plan Work
19029. Draft SSAA
190310. Certifications
1904Requirements Review
190511. Agree on Level of
1906Effort and Schedule
190712. Approve Phase 1
1908SSAA
1909Task
1910Agreement? SSAA
1911Phase 2,
1912Verification
1913Yes No
1914Business Case or
1915Mission Need,
1916Threat, Systems Docs.,
1917Requirements, etc.
1918Figure 10-8 NIACAP Phase 1, Definition
1919Source: NSTISSI-1000.
1920536 Chapter 10
1921Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1922Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
192310
1924SSAA from Phase 1,
1925Systems Documents,
1926Configuration Control
1927Plans, etc.
1928Systems Activities—
1929Integration or
1930Development
1931Inputs Activities
1932Initial
1933Certification
1934Analysis
19351. System Architecture
19362. Software Design
19373. Network Connection(s)
19384. Integrity of Integrated products
19395. Life Cycle Management
19406. Prepare Security Requirements
1941Validation Procedures
19427. Vulnerability Evaluation
1943Task
1944Pass?
1945Updated
1946SSAA
1947Phase 3,
1948Validation
1949Yes
1950No
1951Ready for
1952Phase 3?
1953A
1954Reanalyze Revise
1955Yes
1956No
1957Life Cycle Activity (1 to n)
1958Figure 10-9 NIACAP Phase 2, Verification
1959Source: NSTISSI-1000.
1960SSAA from Phase 2,
1961Test Procedures
1962and Site Information
1963Certification
1964Evaluation of
1965Integrated System
1966Inputs Activities
19671. Security Test and Evaluation
19682. Penetration Testing
19693. TEMPEST Evaluation
19704. COMSEC Evaluation
19715. System Management Analysis
19726. Site Evaluation
19737. Contingency Plan Evaluation
19748. Risk Management Review
1975Task
1976Updated
1977SSAA
1978Phase 4, Post
1979Accreditation
1980Yes
1981Accreditation
1982Granted?
1983A
1984Yes
1985No
1986Certify
1987System?
1988Develop
1989Recommendation
1990A
1991No
1992Figure 10-10 NIACAP Phase 3, Validation
1993Source: NSTISSI-1000.
1994Information Systems Security Certification and Accreditation 537
1995Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
1996Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
1997Phase 3, validation, validates compliance of the fully integrated system with the security
1998policy and requirements stated in the SSAA. The objective of Phase 3 is to produce the
1999required evidence to support the DAA in making an informed decision to grant approval
2000to operate the system. This approval is either accreditation or an interim approval to
2001operate (IATO).
2002For more information on the NIACAP process, visit the FISMA Web site at www.fismacenter.com
2003/nstissi_1000.pdf.
2004Phase 4, post accreditation, starts after the system has been certified and accredited for opera-
2005tions. Phase 4 includes activities necessary for the continuing operation of the accredited IS
2006and manages the changing threats and small-scale changes a system faces through its life
2007cycle. The objective of Phase 4 is to ensure that secure system management, operation, and
2008maintenance sustain an acceptable level of residual risk.
2009The accreditation process itself is so complex that professional certifiers must be trained.
2010The CNSS has a set of training standards for federal information technology workers
2011who deal with information security. One of these documents, NSTISSI-4015, provides a
2012SSAA from Phase 3,
2013Test Procedures, and
2014Site Information
2015Inputs Activities
20161. SSAA Maintenance
20172. Physical, Personnel, and
2018Management Control Review
20193. TEMPEST Evaluation
20204. COMSEC Evaluation
20215. Contingency Plan Maintenance
20226. Change Management
20237. System Security Management
20248. Risk Management Review
2025Task
2026Phase 1,
2027Definition
2028No
2029Change
2030Requested or
2031Required?
2032Yes
2033Validation
2034Required?
2035A
2036Yes
2037Compliance
2038Validation
2039No
2040Security Operations
2041System Operations
20429. Site and Physical Security Validation
204310. Security Procedures Validation
204411. System Changes and Related
2045Impact Validation
204612. System Architecture and System
2047Interfaces Validation
204813. Management Procedures Validation
204914. Risk Decisions Validation
2050Figure 10-11 NIACAP Phase 4, Post Accreditation
2051Source: NSTISSI-1000.
2052538 Chapter 10
2053Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2054Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
205510
2056national training standard for systems certifiers (see www.ecs.csus.edu/csc/iac/
2057nstissi_4015.pdf).
2058A qualified systems certifier must be formally trained in the fundamentals of information
2059security and have field experience. Systems certifiers should have system administrator and/
2060or basic ISSO experience, and be familiar with the knowledge, skills, and abilities required
2061of the DAA, as illustrated in NSTISSI-4015. Once professionals complete training based on
2062NSTISSI-4015, which includes material from NSTISSI-1000, they are eligible to be a federal
2063agency systems certifier. Note that NSTISSI-1000 is currently under revision; an updated ver-
2064sion could be available within the next few years.
2065‡ ISO 27001/27002 Systems Certification and Accreditation
2066Many larger organizations outside the United States apply the standards provided under the
2067International Standards Organization, standards ISO 27001 and 27002, as discussed in
2068Chapter 4. Recall that the standards were originally created to provide a foundation for Brit-
2069ish certification of information security management systems (ISMSs). Organizations that
2070want to demonstrate their systems have met this international standard must follow the certi-
2071fication process, which includes the following phases:
2072The first phase of the process involves your company preparing and getting
2073ready for the certification of your ISMS: developing and implementing your
2074ISMS, using and integrating your ISMS into your day-to-day business pro-
2075cesses, training your staff, and establishing an ongoing program of ISMS
2076maintenance.
2077The second phase involves employing one of the accredited certification bodies to
2078carry out an audit of your ISMS.
2079The certificate that is awarded will last for three years, after which the ISMS
2080needs to be recertified. Therefore, there is a third phase of the process (assuming
2081the certification has been successful and a certificate has been issued), which
2082involves the certification body visiting your ISMS site on a regular basis (e.g.,
2083every 6–9 months) to carry out a surveillance audit. 11
2084Figure 10-12 shows the process flow of ISMS certification and accreditation.
2085Information Systems Security Certification and Accreditation 539
2086Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2087Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2088Pass ?
2089Yes
2090No
2091Controls and guidance
2092from ISO 17799 plus
2093controls not in ISO 17799
2094Company
2095approach to risk
2096management
2097Identify main threats,
2098risks, impacts, and
2099vulnerabilities
2100Company decides
2101to implement ISO
210227001
2103Management
2104commitment, assign
2105project responsibilities
2106Define information
2107security policy
2108Boundary of ISMS
2109Framework
2110Processes Inputs Deliverables
2111Define scope of
2112ISMS
2113Perform RA for
2114scope of ISMS
2115Decide how to
2116manage risks
2117identified
2118Select objectives
2119and controls to be
2120implemented
2121Implement
2122controls
2123Get ready for and
2124undergo
2125certification
2126Take corrective
2127action
2128Certificate granted
2129Deliver policy
2130document
2131Deliver ISMS
2132scope document
2133Produce RA
2134document
2135Agree to and document
2136accountabilities and
2137responsibilities
2138Prepare SOA
2139Figure 10-12 ISMS certification and accreditation 12
2140© Cengage Learning 2015
2141Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2142Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2143Selected Readings
2144â—
2145Information Technology Project Management, Fifth Edition, by Kathy Schwalbe.
2146Course Technology. 2007. Boston.
2147â—
2148The PMI Project Management Fact Book, Second Edition, by the Project Management
2149Institute. 2001. Newtown Square, PA.
2150â—
2151NIST SP 800-37, Rev. 1, Guide for Applying the Risk Management Framework to
2152Federal Information Systems: A Security Life Cycle Approach.
2153â—
2154NIST DRAFT SP 800-39, Managing Risk from Information Systems: An Organizational
2155Perspective.
2156Chapter Summary
2157â– The implementation phase of the security systems development life cycle involves
2158modifying the configuration and operation of the organization’s information systems
2159to make them more secure. Such changes include those to procedures, people, hard-
2160ware, software, and data.
2161â– During the implementation phase, the organization translates its blueprint for infor-
2162mation security into a concrete project plan.
2163â– Before developing a project plan, management should articulate and coordinate the
2164organization’s information security vision and objectives with the involved communi-
2165ties of interest.
2166â– The major steps in executing the project plan are planning the project, supervising
2167tasks and action steps within the plan, and wrapping up the plan.
2168â– Each organization determines its own project management methodology for IT and
2169information security projects. Whenever possible, an organization’s information
2170security projects should be in line with its project management practices.
2171â– Planning for the implementation phase involves the creation of a detailed project plan.
2172The project plan can be created by using a simple planning tool such as the work
2173breakdown structure (WBS). The plan can be prepared with a simple desktop PC
2174spreadsheet program or with more complex project management software. The WBS
2175involves addressing major project tasks and their related attributes, including the
2176following:
2177â– Work to be accomplished (activities and deliverables)
2178â– Individual employees or skill sets assigned to perform the task
2179â– Start and end dates for the task, when known
2180â– Amount of effort required for completion, in hours or days
2181â– Estimated capital expenses for the task
2182â– Estimated noncapital expenses for the task
2183â– Identification of task interdependencies
218410
2185Chapter Summary 541
2186Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2187Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2188â– Constraints and considerations should be addressed when developing the project plan,
2189including financial, procurement, priority, time and scheduling, staffing, scope, organi-
2190zational feasibility, training and indoctrination, change control, and technology gover-
2191nance considerations.
2192â– Organizations usually designate a professional project manager to lead a security
2193information project. Alternatively, some organizations designate a champion from a
2194senior level of general management or a senior IT manager, such as the CIO.
2195â– Once a project is under way, it can be managed to completion using a process known
2196as a negative feedback loop or cybernetic loop. This process involves measuring var-
2197iances from the project plan and then taking corrective action when needed.
2198â– As the components of the new security system are planned, provisions must be
2199made for the changeover from the previous method of performing a task to the new
2200method(s). The four common conversion strategies for performing this changeover are:
2201â– Direct changeover
2202â– Phased implementation
2203â– Pilot implementation
2204â– Parallel operations
2205■The bull’s-eye model is a proven method for prioritizing a program of complex
2206change. Using this method, the project manager can address issues from the general to
2207the specific and focus on systematic solutions instead of individual problems.
2208â– When the expense and time required to develop an effective information security pro-
2209gram is beyond the reach of an organization, it should outsource the program to com-
2210petent professional services.
2211â– Technology governance is a complex process that an organizationuses to manage the
2212impacts and costs of technology implementation, innovation, and obsolescence.
2213â– The change control process is a method that medium-sized and large organizations use
2214to deal with the impact of technical change on their operations.
2215â– As with any project, certain aspects of change must be addressed. In any major proj-
2216ect, the prospect of moving from the familiar to the unfamiliar can cause employees to
2217resist change, consciously or unconsciously.
2218â– Implementing and securing information systems often requires external certification or
2219accreditation.
2220â– Accreditation is the authorization of an IT system to process, store, or transmit infor-
2221mation. This authorization is issued by a management official to assure that systems
2222are of adequate quality.
2223■Certification is a comprehensive evaluation of an IT system’s technical and nontechni-
2224cal security controls to validate an accreditation process.
2225â– A variety of accreditation and certification processes are used globally, including the
2226U.S. federal agency system and the ISO 27001 and 27002 standards.
2227542 Chapter 10
2228Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2229Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
223010
2231Review Questions
22321. What is a project plan? List what a project plan can accomplish.
22332. What is the value of a statement of vision and objectives? Why is it needed before a
2234project plan is developed?
22353. What categories of constraints to project plan implementation are noted in the chap-
2236ter? Explain each of them.
22374. List and describe the three major steps in executing the project plan.
22385. What is a work breakdown structure (WBS)? Is it the only way to organize a project
2239plan?
22406. What is projectitis? How is it cured or its impact minimized?
22417. List and define the common attributes of tasks within a WBS.
22428. How does a planner know when a task has been subdivided to an adequate degree and
2243can be classified as an action step?
22449. What is a deliverable? Name two uses for deliverables.
224510. What is a resource? What are the two types?
224611. Why is it a good practice to delay naming specific people as resources early in the
2247planning process?
224812. What is a milestone, and why is it significant to project planning?
224913. Why is it good practice to assign start and end dates sparingly in the early stages of
2250project planning?
225114. Who is the best judge of effort estimates for project tasks and action steps? Why?
225215. Within project management, what is a dependency? What is a predecessor? What is a
2253successor?
225416. What is a negative feedback loop? How is it used to keep a project in control?
225517. When a task is not being completed according to the plan, what two circumstances are
2256likely to be involved?
225718. List and describe the four basic conversion strategies that are used when converting to
2258a new system. Under which circumstances is each strategy the best approach?
225919. What is technology governance? What is change control? How are they related?
226020. What are certification and accreditation when applied to information systems security
2261management? List and describe at least two certification or accreditation processes.
2262Review Questions 543
2263Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2264Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2265Exercises
22661. Create a first draft of a WBS from the following scenario. Make assumptions as needed
2267based on the section about project planning considerations and constraints in this chap-
2268ter. In your WBS, describe the skill sets required for the tasks you have planned.
2269Sequential Label and Supply has a problem with employees surfing the Web to
2270access material the company deems inappropriate for a professional environment.
2271Therefore, SLS wants to insert a filtering device in the company Internet connec-
2272tion that blocks certain Web locations and content. According to the vendor, the
2273filter is a hardware appliance that costs $18,000 and requires 150 hours to
2274install and configure. Technical support for the filter costs 18 percent of the pur-
2275chase price and includes a training allowance for the year. A software component
2276that runs on the administrator’s desktop computer is needed to administer the fil-
2277ter; this component costs $550. A monthly subscription provides the list of sites
2278to be blocked and costs $250 per month. An estimated four hours per week are
2279required for administrative functions.
22802. If you have access to commercial project management software, such as Microsoft
2281Project, use it to complete a project plan based on the data shown in Table 10-2. Pre-
2282pare a simple WBS report or Gantt chart that shows your work.
22833. Write a job description for Kelvin Urich, the project manager described in the opening
2284vignette of this chapter. Be sure to identify key characteristics of the ideal candidate, as
2285well as work experience and educational background. Also, justify why your job
2286description is suitable for potential candidates of this position.
22874. Search the Web for job descriptions of project managers. You can use any number of
2288Web sites, including www.monster.com or www.dice.com, to find at least 10 IT-
2289related job descriptions. What common elements do you find among the job descrip-
2290tions? What is the most unusual characteristic among them?
2291Case Exercises
2292Charlie looked across his desk at Kelvin, who was absorbed in the sheaf of handwritten notes
2293from the meeting. Charlie had asked Kelvin to come to his office and discuss the change con-
2294trol meeting from earlier that day.
2295“So what do you think?†Charlie asked.
2296“I think I was blindsided by a bus!†Kelvin replied. “I thought I had considered all the possi-
2297ble effects of the change in my project plan. I tried to explain this, but everyone acted as if I
2298had threatened their lives.â€
2299“In a way you did, or rather you threatened their jobs,†Charlie stated. “Some people believe
2300that change is the enemy.â€
2301544 Chapter 10
2302Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2303Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
230410
2305“But these changes are important.â€
2306“I agree,†Charlie said. “But successful change usually occurs in small steps. What’s your top
2307priority?â€
2308“All the items on this list are top priorities,†Kelvin said. “I haven’t even gotten to the second
2309tier.â€
2310“So what should you do to accomplish these top priorities?†Charlie asked.
2311“I guess I should reprioritize within my top tier, but what then?â€
2312“The next step is to build support before the meeting, not during it,†Charlie said, smiling.
2313“Never go into a meeting where you haven’t done your homework, especially when other
2314people in the meeting can reduce your chance of success.â€
2315Discussion Questions
23161. What project management tasks should Kelvin perform before his next meeting?
23172. What change management tasks should Kelvin perform before his next meeting, and
2318how do these tasks fit within the project management process?
23193. Had you been in Kelvin’s place, what would you have done differently to prepare for
2320this meeting?
2321Ethical Decision Making
2322Suppose Kelvin has seven controls listed as the top tier of project initiatives. At his next
2323meeting with Charlie, he provides a rank-ordered list of these controls with projected
2324losses over the next 10 years for each if it is not completed. Also, he has estimated the
232510-year cost for developing, implementing, and operating each control. Kelvin has identi-
2326fied three controls as being the most advantageous for the organization in his opinion. As
2327he prepared the slides for the meeting, he “adjusted†most projected losses upward to the
2328top end of the range estimate given by the consultant who prepared the data. For the pro-
2329jected costs of his preferred controls, he chose to use the lowest end of the range provided
2330by the consultant.
2331Do you think Kelvin has had an ethical lapse by cherry-picking the data for his
2332presentation?
2333Suppose that instead of choosing data from the range provided by the consultant, Kelvin sim-
2334ply made up better numbers for his favorite initiatives. Is this an ethical lapse?
2335Suppose Kelvin has a close friend who works for a firm that makes and sells software for a
2336specific control objective on the list. When Kelvin prioritized the list of his preferences, he
2337made sure that specific control was at the top of the list. Kelvin planned to provide his friend
2338with internal design specifications and the assessment criteria to be used for vendor selection
2339for the initiative. Has Kelvin committed an ethical lapse?
2340Case Exercises 545
2341Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2342Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2343Endnotes
23441. The SANS Institute. “GIAC Certified Project Manager (GCPM).†Accessed 5 March
23452014 from www.giac.org/certification/certified-project-manager-gcpm.
23462. Ibid.
23473. EC Council. “Project Management in IT Security Exam Information.†Accessed
23485 March 2014 from www.eccouncil.org/Certification/exam-information/pmits-exam
2349-212-38.
23504. “Critical Security Controls for Effective Cyber Defense.†Accessed 3 March 2014 from
2351www.sans.org/critical-security-controls/.
23525. Ibid.
23536. Schein, Edgar H. “Kurt Lewin’s Change Theory in the Field and in the Classroom:
2354Notes Toward a Model of Managed Learning.†Working paper, MIT Sloan School of
2355Management. Accessed 7 July 2007 from www.solonline.org/res/wp/10006.html#one.
23567. Federal Information Security Management Act of 2002. Title 44, U.S. Code Section
23573542.
23588. National Institute of Standards and Technology. Joint Task Force Transformation Ini-
2359tiative. Guide for Applying the Risk Management Framework to Federal Information
2360Systems: A Security Life Cycle Approach. SP 800-37, Rev. 1. February 2010. Accessed
23615 March 2014 from http://csrc.nist.gov/publications/PubsSPs.html.
23629. Ibid.
236310. Ibid.
236411. Ibid.
236512. The ISO 27000 Directory ISO 27001 Certification Process. Accessed 5 March 2014
2366from www.iso27001certificates.com/certification_directory.htm.
2367546 Chapter 10
2368Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2369Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2370chapter 11
2371Security and Personnel
2372I think we need to be paranoid optimists.
2373ROBERT J. EATON, CHAIRMAN OF THE BOARD OF
2374MANAGEMENT, DAIMLERCHRYSLER AG (RETIRED)
2375Among Iris Majwubu’s morning e-mails was a message from Charlie Moody, with the
2376subject line “I need to see you.†As she opened the message, Iris wondered why on earth the
2377senior manager of IT needed to see her. The e-mail read:
2378From: Charles Moody [cmoody@slsco.com]
2379To: Iris Majwubu [imajwubu@slsco.com]
2380Subject: I need to see you
2381Iris,
2382Since you were a material witness in the investigation, I wanted to advise you of the status
2383of the Magruder case. We completed all of the personnel actions on this matter yesterday,
2384and it is now behind us.
2385You might like to know that the Corporate Security Department believes that you helped us
2386resolve this security matter in its early stages, so no company assets were compromised.
2387Please set up an appointment with me in the next few days to discuss a few things.
2388—Charlie
2389547
2390Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2391Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2392Two days later, Iris entered Charlie Moody’s office. He rose from his desk as she entered.
2393“Come in, Iris,†Charlie said. “Have a seat.â€
2394Nervously, she chose a chair closest to the door, not anticipating that Charlie would come
2395around his desk and sit down next to her. As he took his seat, Iris noticed that the folder in
2396his hand looked like her personnel file, and she took a deep breath.
2397“I’m sure you’re wondering why I asked you to meet with me,†said Charlie. “The company
2398really appreciates your efforts in the Magruder case. Because you followed policy and acted
2399so quickly, we avoided a significant loss. You were right to bring that issue to your man-
2400ager’s attention rather than confronting Magruder directly. You not only made the right
2401choice, but you acted quickly and showed a positive attitude throughout the whole
2402situation—basically, I think you demonstrated an information security mindset. And
2403that’s why I’d like to offer you a transfer to Kelvin Urich’s information security group.
2404I think his team would really benefit from having someone like you on board.â€
2405“I’m glad I was able to help,†Iris said, “but I’m not sure what to say. I’ve been a DBA
2406for three years here. I really don’t know much about information security other than what
2407I learned from the company training and awareness sessions.â€
2408“That’s not a problem,†Charlie said. “What you don’t know you can learn.†He smiled.
2409“So how about it, are you interested in the job?â€
2410Iris said, “It does sound interesting, but to be honest I hadn’t been considering a career
2411change.†She paused for a moment, then added, “I am willing to think about it, though.
2412But I have a few questions.…â€
2413LEARNING OBJECTIVES:
2414Upon completion of this material, you should be able to:
2415• Describe where and how the information security function should be positioned within
2416organizations
2417• Explain the issues and concerns related to staffing the information security function
2418• Enumerate the credentials that information security professionals can earn to gain recognition in
2419the field
2420• Discuss how an organization’s employment policies and practices can support the information
2421security effort
2422• Identify the special security precautions that must be taken when using contract workers
2423• Explain the need for the separation of duties
2424• Describe the special requirements needed to ensure the privacy of personnel data
2425Introduction
2426When implementing information security, an organization must first address how to position and
2427name the security function. Second, the information security community of interest must plan for
2428the function’s proper staffing or for adjustments to the staffing plan. Third, the IT community of
2429interest must assess the impact of information security on every IT function and adjust job
2430descriptions and documented practices accordingly. Finally, the general management community
2431548 Chapter 11
2432Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2433Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
243411
2435of interest must work with information security professionals to integrate solid information
2436security concepts into the organization’s personnel management practices.
2437To assess the effect that the changes will have on the organization’s personnel management prac-
2438tices, the organization should conduct a behavioral feasibility study before the implementation
2439phase—that is, in the analysis phase. The study should include an investigation into the levels of
2440employee acceptance of change and resistance to it. Employees often feel threatened when an
2441organization is creating or enhancing an information security program. They may perceive the
2442program to be a manifestation of a Big Brother attitude, and might have questions such as:
2443â—
2444Why is management monitoring my work or my e-mail?
2445â—
2446Will information security staff go through my hard drive looking for evidence to fire me?
2447â—
2448How can I do my job well now that I have to deal with the added delays of informa-
2449tion security technology?
2450As you learned in Chapter 10, resolving these sorts of doubts and reassuring employees about
2451the role of information security programs are fundamental objectives of implementation. Thus,
2452it is important to gather employee feedback early and respond to it quickly. This chapter
2453explores the issues involved in positioning the information security unit within the organization
2454and in staffing the information security function. The chapter also discusses how to manage the
2455many personnel challenges that arise across the organization and demonstrates why these chal-
2456lenges should be considered part of the organization’s overall information security program.
2457Positioning and Staffing the Security Function
2458There are several valid choices for positioning the Information Security department within an
2459organization. The model commonly used by large organizations places the information security
2460department within the Information Technology department and usually designates the CISO
2461(chief information security officer) or CSO (chief security officer) to lead the function. The
2462CISO reports directly to the company’s top computing executive, or CIO. Such a structure
2463implies that the goals and objectives of the CISO and CIO are aligned, but this is not always
2464the case. By its very nature, an information security program can sometimes work at odds with
2465the goals and objectives of the Information Technology department as a whole. The CIO, as the
2466executive in charge of the organization’s technology, strives to create efficiency in the availabil-
2467ity, processing, and accessing of company information. Thus, anything that limits access or
2468slows information processing can impede the CIO’s mission for the entire organization.
2469The CISO’s function is more like that of an internal auditor in that he must direct the Information
2470Security department to examine data in transmission and storage to detect suspicious traffic, and
2471examine systems to discover information security faults and flaws in technology, software, and
2472employees’ activities and processes. These examinations can disrupt the speed at which the orga-
2473nization’s information is processed and accessed. Because the addition of multiple layers of secu-
2474rity inevitably slows users’ access to information, information security may be viewed by some
2475employees as a hindrance to the organization’s operations. A good information security program
2476maintains a careful balance between access and security, and works to educate all employees
2477about the need for necessary delays to ensure the protection of critical information.
2478Because the goals and objectives of CIOs and CISOs tend to contradict each other, the trend
2479among many organizations has been to separate their information security function from the
2480Positioning and Staffing the Security Function 549
2481Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2482Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2483IT division. An article in the IT industry magazine InformationWeek summarized the reason-
2484ing behind this trend quite succinctly: “The people who do and the people who watch
2485shouldn’t report to a common manager.†1 This sentiment was echoed in an ISO 27001 post-
2486ing: “One of the most important things in information security is to avoid conflict of interest;
2487that is, to separate the operations from control and audit.†2
2488A survey conducted by the consulting firm Meta Group found that while only 3 percent of its
2489clients position the Information Security department outside IT, these clients regarded such
2490positioning as the mark of a forward-thinking organization. Another group, Forrester
2491Research, concludes that the traditional structure of the CISO or CSO reporting to the CIO
2492will be prevalent for years to come, but that it will begin to involve numerous variations in
2493which different IT sections report information to the CSO, and thereby provide IS depart-
2494ments the critical input and control they need to protect the organization’s IT assets. 3 In gen-
2495eral, the data seems to suggest that while many organizations believe the CISO or CSO should
2496function as an independent, executive-level decision maker, information security and IT are
2497currently too closely aligned to separate into two departments.
2498In his book Information Security Roles and Responsibilities Made Easy, Charles Cresson
2499Wood compiles the best practices from many industry groups regarding the positioning of
2500information security programs. According to Wood, information security can be placed within
2501any of the following organizational functions:
2502â—
2503IT, as a peer of other subfunctions such as networks, applications development, and
2504the help desk
2505â—
2506Physical security, as a peer of physical security or protective services
2507â—
2508Administrative services, as a peer of human resources or purchasing
2509â—
2510Insurance and risk management
2511â—
2512The legal department
2513Once the proper position of information security has been determined, the challenge is to design
2514a reporting structure that balances the competing needs of each community of interest. The
2515placement of information security in the reporting structure often reflects the fact that no one
2516actually wants to manage it; thus, the unit is moved from place to place within the organization
2517without regard for the impact on its effectiveness. Organizations should find a rational compro-
2518mise by placing information security where it can best balance its duty to monitor compliance
2519with its ability to provide the education, training, awareness, and customer service needed to
2520make information security an integral part of the organization’s culture. Also, the need to have
2521the top security officer report directly to the executive management group instead of just the
2522CIO becomes critical, especially if the security department is positioned in the IT function.
2523‡ Staffing the Information Security Function
2524The selection of information security personnel is based on several criteria, some of which are
2525not within the control of the organization. Consider the fundamental concept of supply and
2526demand. When the demand for any commodity—for example, a critical technical skill—
2527increases too quickly, supply initially fails to meet demand. Many future IS professionals seek
2528to enter the security market by gaining the skills, experience, and credentials they need to
2529meet this demand. In other words, they enter high-demand markets by changing jobs, going
2530to school, or becoming trained. Until the new supply reaches the demand level, organizations
2531550 Chapter 11
2532Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2533Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
253411
2535must pay the higher costs associated with limited supply. Once the supply meets or exceeds the
2536demand, organizations can become more selective, and the amount they are willing to pay
2537drops. Hiring trends swing back and forth like a pendulum, from high demand and low supply
2538to the other extreme of low demand and high supply, because the economy is seldom in a state
2539of equilibrium. In 2002, the information security industry enjoyed a period of high demand,
2540with relatively few qualified and experienced applicants available for organizations seeking
2541their services. The economic realities of 2003 through 2006—a climate of lower demand for
2542all IT professionals—led to more limited job growth for information security practitioners.
2543From 2008 to 2012, the downturn in the U.S. economy stifled jobs across IT, not just in infor-
2544mation security. In the last couple of years, the demand has begun to increase again.
2545The latest forecasts for IT hiring in general and information security in particular project more
2546openings than in many previous years. According to the Bureau of Labor Statistics (BLS):
2547Employment of information security analysts is projected to grow 37 percent
2548from 2012 to 2022, much faster than the average for all occupations. Demand
2549for information security analysts is expected to be very high, as these analysts
2550will be needed to come up with innovative solutions to prevent hackers from
2551stealing critical information or creating havoc on computer networks. 4
2552This information is illustrated with additional job outlook data in Figure 11-1.
2553Positioning and Staffing the Security Function 551
2554Figure 11-1 BLS job summary for information security analysts
2555Source: U.S. Bureau of Labor Statistics.
2556Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2557Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2558For more information on job forecasts in information security, visit the Bureau of Labor Statistics
2559at www.bls.gov and search on “information security.â€
2560The BLS data in Figure 11-1 only examines specific positions for an information security ana-
2561lyst. It does not consider the positions of a network and computer systems administrator or a
2562computer and information systems manager with information security responsibilities. The
2563BLS summaries for these two positions are provided in Figure 11-2. There are almost
2564800,000 positions in the IT arena that could potentially have information security responsi-
2565bilities, with an estimated 120,000 more to be filled in the next decade.
2566In 2014, U.S. News and World Report ranked the “100 best jobs†of the year, based on
2567growth in the field, salary, job prospects, employment rate, stress level, and work-life bal-
2568ance. The position of information security analyst came in 11th overall and fourth in “best
2569technology jobs,†with software developer and computer systems analyst ranking first and
2570second, respectively. 5 The Department of Homeland Security reports that:
2571DHS will be doing extensive hiring in the next three years. Key occupational areas
2572that will be the focus of hiring in the Washington, D.C., metropolitan area are
2573552 Chapter 11
2574Figure 11-2 BLS summaries for computer administrators and managers
2575Source: www.bls.gov.
2576Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2577Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
257811
2579contracting and information technology specialists at all grade levels. Hiring for the
2580following positions will be for locations nationwide at various grade levels: border
2581patrol agents, customs and border protection officers, agriculture specialists, pilots,
2582adjudication officers, attorneys, intelligence analysts, criminal investigators, depor-
2583tation officers, immigration enforcement agents, cybersecurity specialists, chemical
2584safety inspectors and transportation security officers (airport screeners). 6
2585(Emphasis added.)
2586Perhaps more meaningful to this discussion is the (ISC) 2 Global Information Security Workforce
2587Study, which found that 56 percent of all respondents felt their information security workforce
2588was understaffed. More importantly, this percentage included two-thirds of all responding C-
2589level executives, those with the greatest influence over hiring and budget decisions. Respondents
2590attributed the shortage to “three factors: business conditions; executives not fully understanding
2591the need; and an inability to locate appropriate information security professionals.†7 The good
2592news is that the study predicts an increase in information security personnel; more than 30 per-
2593cent of respondents indicated that information security spending on personnel will increase.
2594For more information on the (ISC) 2 Global Information Security Workforce Study, visit www
2595.isc2cares.org/uploadedFiles/wwwisc2caresorg/Content/2013-ISC2-Global-Information-Security-
2596Workforce-Study.pdf.
2597Qualifications and Requirements A number of factors influence an organization’s
2598hiring decisions. Because information security has only recently emerged as a separate disci-
2599pline, hiring in this field is complicated by a lack of understanding among organizations
2600about what qualifications an information security professional should possess. In many
2601organizations, information security teams currently lack established roles and responsibili-
2602ties. Establishing better hiring practices in an organization requires the following:
2603â—
2604The general management community of interest should learn more about the skills and
2605qualifications for information security positions and IT positions that affect informa-
2606tion security.
2607â—
2608Upper management should learn more about the budgetary needs of information secu-
2609rity and its positions. This knowledge will enable management to make sound fiscal
2610decisions for information security and the IT functions that carry out many informa-
2611tion security initiatives.
2612â—
2613The IT and general management communities should grant appropriate levels of influ-
2614ence and prestige to information security, especially to the role of CISO.
2615In most cases, organizations look for a technically qualified information security generalist
2616who has a solid understanding of how an organization operates. In many fields, the more
2617specialized professionals are more marketable. In information security, however, overspecial-
2618ization can be risky. It is important, therefore, to balance technical skills with general
2619knowledge about information security.
2620When hiring information security professionals, organizations frequently look for candidates
2621who understand the following:
2622â—
2623How an organization operates at all levels
2624â—
2625That information security is usually a management problem and is seldom an exclu-
2626sively technical problem
2627Positioning and Staffing the Security Function 553
2628Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2629Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2630â—
2631How to work with people and collaborate with end users, and the importance of
2632strong communications and writing skills
2633â—
2634The role of policy in guiding security efforts, and the role of education and training in
2635making employees and other authorized users part of the solution rather than part of
2636the problem
2637â—
2638Most mainstream IT technologies at a general level, not necessarily as an expert
2639â—
2640The terminology of IT and information security
2641â—
2642The threats facing an organization and how they can become attacks
2643â—
2644How to protect an organization’s assets from information security attacks
2645â—
2646How business solutions, including technology-based solutions, can be applied to solve
2647specific information security problems
2648Entry into the Information Security Profession Many information security pro-
2649fessionals enter the field through one of two career paths. Some come from law enforcement or
2650the military, where they were involved in national security or cybersecurity. Others are technical
2651professionals—networking experts, programmers, database administrators, and systems admin-
2652istrators—who find themselves working on information security applications and processes
2653more often than traditional IT assignments. In recent years, a third, perhaps more traditional
2654career path has developed: college students who select and tailor their degree programs to pre-
2655pare for work in the field of information security. Figure 11-3 illustrates these career paths.
2656554 Chapter 11
2657Information security
2658college graduates Law enforcement
2659Information technology
2660Information security
2661Military
2662Figure 11-3 Career paths to information security positions
2663© 2015 Cengage Learning ® . Bottom left: © pio3/www.Shutterstock.com. Bottom right: © michaeljung/www.Shutterstock.com.
2664Top right: © dotshock/www.Shutterstock.com. Center: © IM_photo/www.Shutterstock.com
2665Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2666Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
266711
2668Many hiring managers in information security prefer to recruit security professionals who
2669have proven IT skills and professional experience in another IT field. IT professionals who
2670move into information security, however, tend to focus on technology, sometimes in place
2671of general information security issues. Organizations can foster greater professionalism in
2672the discipline by expanding beyond the hiring of proven IT professionals and instead filling
2673positions by matching qualified candidates to clearly defined roles in information security.
2674Information Security Positions The use of standard job descriptions can increase
2675the degree of professionalism in the information security field and improve the consistency
2676of roles and responsibilities among organizations. Organizations that expect to revise these
2677roles and responsibilities can consult Charles Cresson Wood’s book, Information Security
2678Roles and Responsibilities Made Easy, which offers a set of model job descriptions for infor-
2679mation security positions. The book also identifies the responsibilities and duties of IT staff
2680members whose work involves information security. 8 Figure 11-4 illustrates a standard
2681reporting structure for information security positions.
2682A study of information security positions by Schwartz, Erwin, Weafer, and Briney found
2683that the positions can be classified into one of three areas: those that define information
2684security programs, those that build the systems and create the programs to implement infor-
2685mation security controls, and those that administer information security control systems and
2686programs that have been created. The definers are managers who provide policy and
2687planning and manage risk assessments. They are typically senior information security man-
2688agers—they have extensive and broad knowledge, but not a lot of technical depth. The
2689builders are techies who create security technical solutions to protect software, systems, and
2690networks. The administrators apply the techies’ tools in accordance with the decisions and
2691guidance of the definers; they provide day-to-day systems monitoring and use to support an
2692organization’s goals and objectives. By clearly identifying which type of role it is seeking and
2693then classifying all applicants into these three types and matching them, the organization can
2694recruit more effectively. 9 Some examples of job titles shown in Figure 11-4 are discussed in
2695the following sections.
2696Positioning and Staffing the Security Function 555
2697Chief Security
2698Officer
2699Information Security
2700Consultant
2701Information Security
2702Manager
2703Information Security
2704Technician / Engineer
2705Information Security
2706Administrator
2707Physical Security
2708Manager
2709Physical Security
2710Officer
2711Figure 11-4 Positions in information security
2712© Cengage Learning 2015
2713Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2714Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2715Chief Information Security Officer (CISO) The CISO is typically the top information
2716security officer in the organization. As indicated earlier in the chapter, the CISO is usually
2717not an executive-level position, and frequently the person in this role reports to the chief
2718information officer. Though CISOs are business managers first and technologists second,
2719they must be conversant in all areas of information security, including the technical, plan-
2720ning, and policy areas. In many cases, the CISO is the major definer or architect of the infor-
2721mation security program. The CISO performs the following functions:
2722â—
2723Manages the overall information security program for the organization
2724â—
2725Drafts or approves information security policies
2726â—
2727Works with the CIO on strategic plans, develops tactical plans, and works with secu-
2728rity managers on operational plans
2729â—
2730Develops information security budgets based on available funding
2731â—
2732Sets priorities for the purchase and implementation of information security projects
2733and technology
2734â—
2735Makes decisions or recommendations for the recruiting, hiring, and firing of security
2736staff
2737â—
2738Acts as the spokesperson for the information security team
2739The most common qualification for this type of position is the Certified Information Systems
2740Security Professional (CISSP) accreditation, which is described later in this chapter. A gradu-
2741ate degree is also often required, although it may be from a number of possible disciplines,
2742including information systems, computer science, another information technology field, crim-
2743inal justice, military science, business, or other fields related to the broader topic of security.
2744A typical example of a CISO’s job description is shown below. The example has been edited
2745for length and is from a state government job posting, but it is very similar to postings in
2746general industry.
2747Position: Chief Information Security Officer
2748Job duties: The Chief Information Security Officer reports to the State’s Deputy
2749Division Administrator, DET and is responsible for the statewide security pro-
2750gram. The CISO’s role is to provide vision and leadership for developing and
2751supporting security initiatives. The CISO directs the planning and implementa-
2752tion of enterprise IT system, business operation, and facility defenses against
2753security breaches and vulnerability issues. This individual is also responsible for
2754auditing existing systems, while directing the administration of security policies,
2755activities, and standards.
2756The CISO is responsible for providing regulatory oversight for information secu-
2757rity. This oversight includes the development of enterprise-wide policy, procedures,
2758and guidance for compliance with federal laws, regulations, and guidelines, and
2759sound security and privacy practices. Additionally, the CISO is responsible for
2760reviewing security program documentation developed to ensure compliance and
2761further enhance security practices across all component agencies.
2762The CISO is responsible for deployed security across the enterprise, including plat-
2763forms, network, and security tools. The CISO is also responsible for identifying
2764556 Chapter 11
2765Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2766Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
276711
2768and assessing internal and external threats, vulnerabilities and risks as well as
2769ensuring that robust monitoring, timely detection, containment, and incident
2770response necessary to mitigate the exposure caused by the breach is in place.
2771The CISO provides leadership, guidance, direction, and authority for technology
2772security across all corporate technology departments, including measurements
2773applicable to services provided.
2774The CISO is responsible for ensuring that workflow within the division runs
2775smoothly so that new technology projects are appropriately monitored for secu-
2776rity risks and appropriate risk mitigation requirements are efficiently set forth
2777and appropriately designed and delivered with the newly developed production
2778system. Policies, procedures and technical standards and architecture will need
2779to be regularly reviewed and updated to prevent unauthorized access of State of
2780Wisconsin technology systems.
2781Special notes:
2782Due to the nature of the position, DOA will conduct a thorough background
2783check on applicant prior to selection.
2784Job knowledge, skills, and abilities:
2785General:
2786â—
2787Strong oral and written communication skills, including the ability to com-
2788municate business and technical concepts and information effectively to a
2789wide range of audiences, including the public
2790â—
2791Strong interpersonal skills, including the ability to work independently with
2792high-level government officials, business and IS managers and staff in fed-
2793eral, state and local agencies, and with division and department managers
2794in a decentralized environment
2795â—
2796Strong project management skills
2797â—
2798Demonstrated ability to effectively interface with technical staff, senior
2799management, and external parties
2800â—
2801Proven ability to plan and organize work, requiring an in-depth under-
2802standing of security issues and ability to integrate into the work of others
2803â—
2804Ability to defend and explain difficult issues with respect to key decisions
2805and positions to staff and senior officials
2806â—
2807Experience in analyzing enterprise business and technology issues in a large
2808corporation or government organization
2809â—
2810Ability to establish credibility so decisions and recommendations are
2811adopted
2812â—
2813Ability to identify appropriate members and develop effective teams with
2814specific knowledge and skills needed to develop solutions and make
2815recommendations
2816â—
2817Resourceful in identifying and obtaining information sources needed to
2818perform responsibilities effectively
2819Positioning and Staffing the Security Function 557
2820Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2821Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2822Technological/specific:
2823â—
2824Must be an intelligent, articulate, and persuasive leader who can serve as
2825an effective member of the senior management team and who is able to
2826communicate security-related concepts to a broad range of technical and
2827nontechnical staff
2828â—
2829Security background, experience in business management, and professional
2830expertise in security and law
2831â—
2832Possess a strong technical background in information technology security
2833â—
2834Knowledge of secure software development
2835â—
2836Computer/network investigation skills and forensics knowledge
2837â—
2838Extensive knowledge of networks, system, database and applications
2839security
2840â—
2841Demonstrated ability to work with management and staff at various levels
2842of the organization to implement sound security practices
2843â—
2844Ability to provide technical direction to security architects and project con-
2845sultants to ensure appropriate security requirements are set forth on new
2846development efforts
2847â—
2848Knowledge of standards-based architectures, with an understanding of how
2849to get there, including compliance monitoring and enforceability
2850â—
2851Experience with business continuity planning, auditing, and risk manage-
2852ment, as well as contract and vendor negotiation
2853â—
2854Strong working knowledge of security principles (such as authentication,
2855vulnerability testing, penetration testing, auditing, crime scene preservation
2856and risk management) and security elements (such as locking systems,
2857evacuation methods, perimeter controls, VPNs, and firewalls)
2858â—
2859Certifications such as Certified Protection Professional (CPP), Certified
2860Information Systems Manager (CISM), or Certification for the Information
2861Systems Security Professional (CISSP) preferred 10
2862Chief Security Officer (CSO) In some organizations, the CISO’s position may be com-
2863bined with physical security responsibilities or may even report to a security manager who is
2864responsible for both logical (information) security and physical security. Such a position is
2865generally referred to as a CSO. The CSO must be capable and knowledgeable in both infor-
2866mation security requirements and the “guards, gates, and guns†approach to protecting the
2867physical infrastructure, buildings, and grounds of a place of business.
2868To qualify for this position, the candidate must demonstrate experience as a security manager
2869and with planning, policy, and budgets. As mentioned earlier, some organizations prefer to
2870hire people with law enforcement experience. The following is a typical example of a CSO’s
2871job description:
2872Position: Director of Security
2873Responsibilities: Reporting to the Senior Vice President of Administration, the
2874Director of Corporate Security will be responsible for all issues related to the
2875558 Chapter 11
2876Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2877Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
287811
2879security and protection of the company’s employees, executives, facilities, proprie-
2880tary data and information. Accountable for the planning and design of the com-
2881pany’s security programs and procedures, this individual will facilitate protection
2882from and resolution of theft, threats, and other situations that may endanger the
2883well-being of the organization. Working through a small staff, the Director will be
2884responsible for executive protection, travel advisories, employee background checks,
2885and a myriad of other activities throughout the corporation on a case-by-case basis.
2886The Director will serve as the company’s chief liaison with law enforcement agen-
2887cies and, most importantly, will serve as a security consultant to all of the com-
2888pany’s autonomously run divisions. Travel requirements will be extensive.
2889Qualifications: The ideal candidate will have a successful background with a fed-
2890eral law enforcement agency, or other applicable experience, that will afford this
2891individual an established network of contacts throughout the country. Additional
2892private industry experience with a sizeable corporation—or as a consultant to
2893same—is preferable. A proactive attitude with regard to security and protection
2894is a must. The successful candidate must be capable of strategically assessing …
2895client security needs and have a track record in areas such as crisis management,
2896investigation, facility security, and executive protection. Finally, the candidate
2897should have a basic understanding of the access and use of electronic information
2898services as they apply to security issues. We seek candidates who are flexible
2899enough to deal with varied business cultures and who possess the superior inter-
2900personal skills to perform well in a consulting role where recommendations and
2901advice are sought and valued, but perhaps not always acted upon. A college
2902degree is required. 11
2903Security Manager Security managers are accountable for the day-to-day operation of the
2904information security program. They accomplish objectives identified by the CISO and resolve
2905issues identified by technicians. Management of technology requires a general understanding
2906of that technology, but it does not necessarily require proficiency in the technology’s configu-
2907ration, operation, and fault resolution. Note that several positions have titles that contain the
2908word manager or suggest management responsibilities, but only people who are responsible
2909for management functions, such as scheduling, setting relative priorities, or administering
2910budgetary control, should be considered true managers.
2911A candidate for this position often has CISSP certification. Traditionally, managers earn the
2912CISSP or CISM, and technical professionals earn the Global Information Assurance Certifica-
2913tion (GIAC). You will learn more about these certifications later in the chapter.
2914Security managers must have the ability to draft middle- and lower-level policies as well as
2915standards and guidelines. They must have experience in traditional business matters, such as
2916budgeting, project management, hiring, and firing. They must also be able to manage techni-
2917cians, both in the assignment of tasks and in the monitoring of activities. Experience with
2918business continuity planning is usually a plus.
2919The following is a typical example of a security manager’s job description. Note that there
2920are several types of security managers, as the position is much more specialized than that of
2921CISO. Thus, when applying for a job as a security manager, you should read the job descrip-
2922tion carefully to determine exactly what the employer wants.
2923Positioning and Staffing the Security Function 559
2924Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2925Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
2926Position: Information Security Manager
2927Job description: This management position reports to the Chief Information
2928Security Officer. The successful candidate will manage the development of the
2929information security programs and control systems in conformance with organi-
2930zational policy and standards across the organization. This is a high-visibility
2931role that involves the day-to-day management of IT Security staff and their
2932career development. The principal accountabilities for this role are as follows:
2933â—
2934Develop and manage information security programs and control systems
2935under the supervision of the CISO in conjunction with the evolving infor-
2936mation security architecture of the organization.
2937â—
2938Monitor performance of information security programs and control sys-
2939tems to maintain alignment with organizational policy and common indus-
2940try practices for emerging threats and technologies.
2941â—
2942Prepare and communicate risk assessments for business risk in software
2943developments as well as ongoing systems events (to include merger, acqui-
2944sition, and divestiture) and ensure effective risk management across the
2945organization’s IT systems.
2946â—
2947Represent the information security organization in the organization’s
2948change management process.
2949â—
2950Perform assigned duties in the area of incident response management and
2951disaster recovery response.
2952â—
2953Supervise assigned staff and perform other general management tasks as
2954assigned, including budgeting, staffing, and employee performance reviews.
2955Compare the preceding general job description with the following more specific job descrip-
2956tion found in a recent advertisement:
2957Position: IT Security Compliance Manager
2958Job description: A job has arisen for an IT Security Compliance Manager reporting
2959to the IT Security Manager. In this role you will manage the development of the
2960client’s IT Security standards and operate a compliance program to ensure confor-
2961mance at all stages of the systems life cycle. This is a key, hands-on role with the
2962job holder taking an active part in the delivery of the compliance program. The
2963role will also involve the day-to-day management of IT Security staff and their
2964career development. The principal accountabilities for this role are as follows:
2965â—
2966Develop and manage an IT security compliance program.
2967â—
2968Develop the client’s security standards in line with industry standards and
2969emerging threats and technologies.
2970â—
2971Identify IT-related business risk in new software and game developments
2972and ensure that effective risk management solutions are identified and
2973complied with.
2974â—
2975Manage and conduct IT security compliance reviews in conjunction with
2976operational and IT Audit staff.
2977â—
2978Conduct investigations into security breaches or vulnerabilities.
2979560 Chapter 11
2980Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
2981Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
298211
2983Candidate profile: The ideal candidate should have five years’ experience of man-
2984aging the implementation of technical security controls and related operational
2985procedures and must have sound business risk management skills. You must
2986have a flexible approach to working and must be able and willing to work unso-
2987ciable hours to meet the demands of the role. 12
2988The second example illustrates the confusion in the information security field regarding job
2989titles and reporting relationships. The first job description identifies responsibilities for the
2990position and describes points where information security interacts with other business func-
2991tions, but the second spreads responsibilities among several business functions and does not
2992seem to reflect a clearly defined role for the position or the information security unit within
2993the organization. Until some similarity in job titles and expected roles and responsibilities
2994emerges, information security job candidates should carefully research open positions instead
2995of relying solely on the job title.
2996Security Technician Security technicians are technically qualified employees who are
2997tasked to configure firewalls, deploy IDPSs, implement security software, diagnose and trou-
2998bleshoot problems, and coordinate with systems and network administrators to ensure that
2999an organization’s security technology is properly implemented. A security technician is often
3000an entry-level position, but to be hired for this role, candidates must possess some technical
3001skills. This often poses a dilemma for applicants, as many find it difficult to get a job in a
3002new field without experience—they can only attain such experience by getting a job. As in
3003the networking arena, security technicians tend to specialize in one major security technology
3004group (firewalls, IDPSs, servers, routers, or software) and in one particular software or hard-
3005ware package, such as Check Point firewalls, Nokia firewalls, or Tripwire IDPSs. These areas
3006are sufficiently complex to warrant a high level of specialization, but to move up in the cor-
3007porate hierarchy, security technicians must expand their knowledge horizontally—that is,
3008gain an understanding of general organizational issues related to information security and its
3009technical areas.
3010The technical qualifications and position requirements vary for a security technician. Organi-
3011zations prefer an expert, certified, proficient technician. Regardless of the area of needed
3012expertise, the job description covers some level of experience with a particular hardware and
3013software package. Sometimes, familiarity with a technology secures an applicant an inter-
3014view; however, actual experience in using the technology is usually required. The following
3015is a typical job announcement for a security technician:
3016Position: Firewall Engineering Consultant
3017Job Description: Working for an exciting customer-focused security group within
3018one of the largest managed network providers in the country. You will have the
3019opportunity to expand your experience and gain all the technical and profes-
3020sional support to achieve within the group. Must have experience to third-line
3021technical support of firewall technologies. Check Point certified. Experienced in
3022Nokia systems.
3023Package: Possible company car, discretionary bonus, private health care, on-call
3024pay, and overtime pay. 13
3025Because overtime and on-call pay are listed, this job is probably an hourly position rather
3026than a salaried one, which is common for security technicians.
3027Positioning and Staffing the Security Function 561
3028Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
3029Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
3030Credentials for Information Security Professionals
3031As mentioned earlier, many organizations seek industry-recognized certifications to screen can-
3032didates for the required level of technical proficiency. Unfortunately, however, most existing
3033certifications are relatively new and not fully understood by hiring organizations. The certify-
3034ing bodies are working hard to educate employers and professionals on the value and qualifi-
3035cations of their certificate programs. In the meantime, employers are trying to understand the
3036match between certifications and position requirements, and hopeful professionals are trying
3037to gain meaningful employment based on their new certifications.
3038‡ (ISC) 2 Certifications
3039The International Information Systems Security Certification Consortium, known as (ISC) 2 ,
3040offers security certifications such as the Certified Information Systems Security Professional
3041(CISSP), the Systems Security Certified Practitioner (SSCP), and the Certified Secure Software
3042Lifecycle Professional (CSSLP). You can visit the Web site at www.isc2.org.
3043CISSP The CISSP certification is considered the most prestigious for security managers
3044and CISOs. It recognizes mastery of an internationally identified Common Body of
3045Knowledge (CBK) in information security. To sit for the CISSP exam, the candidate must
3046have at least five years of direct, full-time experience as a security professional working in
3047at least two of the 10 domains of information security knowledge, or four years of direct
3048security work experience in two or more domains. The candidate must also have a four-
3049year college degree.
3050The CISSP exam consists of 250 multiple-choice questions and must be completed within six
3051hours. It tests candidates on their knowledge of the following 10 domains:
3052â—
3053Access control
3054â—
3055Business continuity and disaster recovery planning
3056â—
3057Cryptography
3058â—
3059Information security governance and risk management
3060â—
3061Legal issues, regulations, investigations, and compliance
3062â—
3063Operations security
3064â—
3065Physical (environmental) security
3066â—
3067Security architecture and design
3068â—
3069Software development security
3070â—
3071Telecommunications and network security
3072CISSP certification requires successful completion of the exam. Also, to ensure that appli-
3073cants meet the experience requirement, they must truthfully submit responses to the follow-
3074ing questions, which are included in the CISSP Candidate Information Bulletin:
30751. Have you ever been convicted of a felony; a misdemeanor involving a computer
3076crime, dishonesty, or repeat offenses; or a Court Martial in military service, or is
3077there a felony charge, indictment, or information now pending against you?
3078562 Chapter 11
3079Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
3080Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
308111
30822. Have you ever had a professional license, certification, membership or registration
3083revoked, or have you ever been censured or disciplined by any professional organi-
3084zation or government agency?
30853. Have you ever been involved, or publically identified, with criminal hackers or hacking?
30864. Have you ever been known by any other name, alias, or pseudonym? 14
3087The breadth and depth of each of the 10 domains makes CISSP certification one of the most
3088challenging to obtain in information security. Holders of the CISSP must earn a specific
3089number of continuing education credits every three years to retain the certification.
3090Once candidates successfully complete the exam, they may be required to submit an
3091endorsement by an actively credentialed CISSP or by their employer as validation of their
3092professional experience.
3093CISSP Concentrations In addition to the major certifications that (ISC) 2 offers, a
3094number of concentrations are available for CISSPs to demonstrate advanced knowledge
3095beyond the CISSP CBK. Each concentration requires that the applicant be a CISSP in good
3096standing, pass a separate examination, and maintain the certification through continuing
3097professional education. These concentrations and their respective areas of knowledge are
3098shown in the following list and presented on the (ISC) 2 Web site:
3099ISSAP ® : Information Systems Security Architecture Professional
3100â—
3101Access control systems and methodology
3102â—
3103Communications and network security
3104â—
3105Cryptography
3106â—
3107Security architecture analysis
3108â—
3109Technology-related business continuity planning and disaster recovery
3110planning
3111â—
3112Physical security considerations
3113ISSEP ® : Information Systems Security Engineering Professional
3114â—
3115Systems security engineering
3116â—
3117Certification and accreditation/risk management framework
3118â—
3119Technical management
3120â—
3121U.S. government information assurance-related policies and issuances
3122ISSMP ® : Information Systems Security Management Professional
3123â—
3124Enterprise security management practices
3125â—
3126Business continuity planning and disaster recovery planning
3127â—
3128Security management practices
3129â—
3130System development security
3131â—
3132Law, investigations, forensics, and ethics
3133â—
3134Security compliance management 15
3135Credentials for Information Security Professionals 563
3136Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
3137Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
3138SSCP Because it is difficult to master the broad array of knowledge encompassed in the
313910 domains covered by the flagship CISSP exam, many security professionals seek less rigor-
3140ous certifications, such as (ISC) 2 ’s SSCP certification. The SSCP focuses on practices, roles,
3141and responsibilities as defined by experts from major information security industries. 16 Like
3142the CISSP, the SSCP certification is more applicable to the security manager than to the tech-
3143nician, as the bulk of its questions focus on the operational nature of information security.
3144Nevertheless, an information security technician who seeks advancement can benefit from
3145this certification.
3146The SSCP exam consists of 125 multiple-choice questions and must be completed within
3147three hours. It covers seven domains:
3148â—
3149Access controls
3150â—
3151Cryptography
3152â—
3153Malicious code and activity
3154â—
3155Monitoring and analysis
3156â—
3157Networks and telecommunications
3158â—
3159Risk, response, and recovery
3160â—
3161Security operations and administration
3162Many consider the SSCP to be a scaled-down version of the CISSP. The seven domains are
3163not a subset of the CISSP domains; they contain slightly more technical content. As with
3164the CISSP, SSCP holders must either earn continuing education credits to retain the certifica-
3165tion or retake the exam.
3166CSSLP The Certified Secure Software Lifecycle Professional (CSSLP) 17 is a new (ISC) 2
3167certification focused on the development of secure applications. To qualify for the CSSLP,
3168you must have at least four years of recent experience with the software development life
3169cycle and be defined as an expert in four of the following seven experience assessment topic
3170areas:
3171â—
3172Secure software concepts: Security implications in software development
3173â—
3174Secure software requirements: Capturing security requirements in the requirements-
3175gathering phase
3176â—
3177Secure software design: Translating security requirements into application design
3178elements
3179â—
3180Secure software implementation/coding: Unit testing for security functionality and
3181resiliency to attack, and developing secure code and exploit mitigation
3182â—
3183Secure software testing: Integrated QA testing for security functionality and resiliency
3184to attack
3185â—
3186Software acceptance: Security implications in the software acceptance phase
3187â—
3188Software deployment, operations, maintenance, and disposal: Security issues for
3189steady-state operations and management of software
3190You must compose an essay in each of your four areas of expertise and submit it as your
3191exam. This test is radically different from the multiple-choice exams (ISC) 2 normally
3192564 Chapter 11
3193Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
3194Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
319511
3196administers. Once your experience has been verified and you successfully complete the essay
3197exam, you can be certified. If necessary, you can qualify as an (ISC) 2 Associate until you
3198obtain the requisite experience to qualify for the CSSLP.
3199Associate of (ISC) 2 (ISC) 2 has an innovative approach to the experience requirement
3200in its certification program. Its Associate of (ISC) 2 program is geared toward people who
3201want to take the CISSP or SSCP exam before obtaining the requisite experience for
3202certification.
3203Candidates who pass the CAP ® , CCFP SM , CISSP ® , CSSLP ® , HCISPP SM , or SSCP ® exams and
3204agree to subscribe to the (ISC) 2 Code of Ethics as well as maintain Continuing Professional
3205Education (CPE) credits and pay the appropriate fees can maintain their status as an Associate
3206until they have logged the required years of experience.
3207‡ ISACA Certifications
3208ISACA (www.isaca.org) also offers several reputable security certifications, including the Certified
3209Information Security Manager (CISM), Certified Information Systems Auditor (CISA), and the
3210Certified in the Governance of Enterprise IT (CGEIT).
3211CISM The CISM credential is geared toward experienced information security managers
3212and others who may have similar management responsibilities. The CISM can assure
3213executive management that a candidate has the required background knowledge needed for
3214effective security management and consulting. This exam is offered annually. The CISM
3215examination covers the following practice domains described in the ISACA 2014 Exam
3216Candidate Information Guide:
32171. Information Security Governance (24 percent): Establish and maintain an informa-
3218tion security governance framework and supporting processes to ensure that the
3219information security strategy is aligned with organizational goals and objectives,
3220information risk is managed appropriately and program resources are managed
3221responsibly.
32222. Information Risk Management and Compliance (33 percent): Manage information
3223risk to an acceptable level to meet the business and compliance requirements of the
3224organization.
32253. Information Security Program Development and Management (25 percent):
3226Establish and manage the information security program in alignment with the
3227information security strategy.
32284. Information Security Incident Management (18 percent): Plan, establish, and manage
3229the capability to detect, investigate, respond to, and recover from information
3230security incidents to minimize business impact. 18
3231To be certified, the applicant must:
3232â—
3233Pass the examination.
3234â—
3235Adhere to a code of ethics promulgated by ISACA.
3236â—
3237Pursue continuing education as specified.
3238â—
3239Document five years of information security work experience with at least three years
3240in information security management in three of the four defined areas of practice.
3241Credentials for Information Security Professionals 565
3242Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
3243Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
3244CISA The CISA credential is not specifically a security certification, but it does include
3245many information security components. ISACA touts the certification as being appropriate
3246for auditing, networking, and security professionals. CISA requirements are as follows:
3247â—
3248Successful completion of the CISA examination
3249â—
3250Experience as an information security auditor, with a minimum of five years’ profes-
3251sional experience in information systems auditing, control, or security
3252â—
3253Agreement to the Code of Professional Ethics
3254â—
3255Payment of maintenance fees, a minimum of 20 contact hours of continuing education
3256annually, and a minimum of 120 contact hours during a fixed three-year period
3257â—
3258Adherence to the Information Systems Auditing Standards
3259The exam covers the following areas of information systems auditing, as described in the
3260ISACA 2014 Exam Candidate Information Guide:
32611. The Process of Auditing Information Systems (14 percent): Provide audit services in
3262accordance with IT audit standards to assist the organization with protecting and
3263controlling information systems.
32642. Governance and Management of IT (14 percent): Provide assurance that the neces-
3265sary leadership and organizational structures and processes are in place to achieve
3266objectives and to support the organization’s strategy.
32673. Information Systems Acquisition, Development and Implementation (19 percent):
3268Provide assurance that the practices for the acquisition, development, testing, and
3269implementation of information systems meet the organization’s strategies and
3270objectives.
32714. Information Systems Operations, Maintenance and Support (23 percent): Provide
3272assurance that the processes for information systems operations, maintenance and
3273support meet the organization’s strategies and objectives.
32745. Protection of Information Assets (30 percent): Provide assurance that the organiza-
3275tion’s security policies, standards, procedures and controls ensure the confidential-
3276ity, integrity, and availability of information assets. 19
3277The CISA exam is offered only a few times each year, so planning is a must.
3278CGEIT Also available from ISACA is the Certified in the Governance of Enterprise IT
3279(CGEIT) certification. The exam is targeted at upper-level executives, including CISOs and
3280CIOs, directors, and consultants with knowledge and experience in IT governance. The
3281CGEIT areas of knowledge include risk management components, which make it an inter-
3282esting certification for upper-level information security managers. The exam covers the fol-
3283lowing areas, as described in the ISACA 2014 Exam Candidate Information Guide:
32841. Framework for the Governance of Enterprise IT (25 percent): Ensure the definition,
3285establishment, and management of a framework for the governance of enterprise IT
3286in alignment with the mission, vision, and values of the enterprise.
32872. Strategic Management (20 percent): Ensure that IT enables and supports the
3288achievement of enterprise objectives through the integration and alignment of IT
3289strategic plans with enterprise strategic plans.
3290566 Chapter 11
3291Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
3292Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
329311
32943. Benefits Realization (16 percent): Ensure that IT-enabled investments are managed to
3295deliver optimized business benefits and that benefit realization outcome and perfor-
3296mance measures are established, evaluated and progress is reported to key stakeholders.
32974. Risk Optimization (24 percent): Ensure that an IT risk management framework
3298exists to identify, analyze, mitigate, manage, monitor, and communicate IT-related
3299business risk, and that the framework for IT risk management is in alignment with
3300the enterprise risk management (ERM) framework.
33015. Resource Optimization (15 percent): Ensure the optimization of IT resources,
3302including information, services, infrastructure and applications, and people, to sup-
3303port the achievement of enterprise objectives. 20
3304The certification requirements are similar to those for other ISACA certifications. Candi-
3305dates must have at least one year of experience in IT governance and additional experience
3306in at least two of the domains listed.
3307CRISC The newest ISACA certification is the Certified in Risk and Information Systems
3308Control (CRISC). The certification is targeted at managers and employees with knowledge
3309and experience in risk management. The CRISC areas of knowledge include risk manage-
3310ment components, which make it an interesting certification for upper-level information
3311security managers. The exam covers the following areas, as described in the ISACA 2014
3312Exam Candidate Information Guide:
33131. Risk Identification, Assessment and Evaluation (31 percent): Identify, assess, and evalu-
3314ate risk factors to enable the execution of the enterprise risk management strategy.
33152. Risk Response (17 percent): Develop and implement risk responses to ensure that
3316risk factors and events are addressed in a cost-effective manner and in line with
3317business objectives.
33183. Risk Monitoring (17 percent): Monitor risk and communicate information to the
3319relevant stakeholders to ensure the continued effectiveness of the enterprise’s risk
3320management strategy.
33214. Information Systems Control Design and Implementation (17 percent): Design and
3322implement information systems controls in alignment with the organization’s risk
3323appetite and tolerance levels to support business objectives.
33245. Information Systems Control Monitoring and Maintenance (18 percent): Monitor
3325and maintain information systems controls to ensure that they function effectively
3326and efficiently. 21
3327The certification requires the candidate to have a minimum of three years’ experience in risk
3328management and information systems control in at least three of the stated domains,
3329although the candidate may elect to take the exam before fulfilling the experience require-
3330ment. This practice is accepted and encouraged by ISACA, but the candidate will not receive
3331the certification until the experience requirement is met.
3332‡ SANS Certifications
3333In 1999, the SANS Institute, formerly known as the System Administration, Networking, and
3334Security Institute (www.sans.org), developed a series of technical security certifications
3335known as the Global Information Assurance Certification (GIAC; www.giac.org). GIAC
3336Credentials for Information Security Professionals 567
3337Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
3338Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
3339certifications not only test for knowledge, they require candidates to demonstrate application
3340of that knowledge. With the introduction of the GIAC Information Security Professional
3341(GISP) and the GIAC Security Leadership Certification (GSLC), SANS now offers more than
3342just technical certifications. The GIAC family of certifications can be pursued independently
3343or combined to earn a comprehensive certification called GIAC Security Engineer (GSE).
3344The GISP is an overview certification that combines basic technical knowledge with an
3345understanding of threats, risks, and best practices, similar to the CISSP. Unlike other certifi-
3346cations, some GIAC certifications require applicants to complete a written practical assign-
3347ment that tests their ability to apply skills and knowledge. These assignments are submitted
3348to the SANS Information Security Reading Room for review by security practitioners, poten-
3349tial certificate applicants, and others with an interest in information security. Only when the
3350practical assignment is complete is the candidate allowed to take the online exam. According
3351to SANS:
3352GIAC now offers three types of certification: Silver, Gold, and Platinum. The
3353requirements for Silver certification are the completion of exam(s). Full certifications
3354require two exams; certificates require a single exam. After earning Silver certifica-
3355tion, a candidate can apply for Gold certification, which requires a technical paper.
3356The technical paper demonstrates real-world, hands-on mastery of security skills.
3357Passing technical papers will be posted to the GIAC List of Certified Professionals
3358pages and to the SANS Information Security Reading Room to share candidates’
3359knowledge and research, and to further educate the security community.
3360GIAC Platinum certifications require a multiple-choice test, along with a day-long
3361lab to test candidates’ hands-on skill. 22
3362The GIAC management certificates and certifications include:
3363â—
3364GISP
3365â—
3366GSLC
3367â—
3368GIAC Certified ISO-27000 Specialist (G2700)
3369â—
3370GIAC Certified Project Manager (GCPM)
3371GIAC has also added several shorter programs known as Skills Test and Reports (STARs),
3372which are “less involved but more focused†than standard GIAC certifications.
3373Most GIAC certifications are offered in conjunction with SANS training. For more informa-
3374tion on the GIAC security-related certification requirements, visit www.giac.org/certifications.
3375‡ EC Council Certifications
3376A new competitor in certifications for security management, EC Council, now offers a
3377Certified CISO (C|CISO) certification, which is designed to be a unique recognition for those
3378at the peak of their professional careers. The C|CISO tests not only security domain knowl-
3379edge, but knowledge of executive business management. The C|CISO includes the following
3380domains:
3381â—
3382Domain 1: Governance (Policy, Legal, and Compliance): This domain focuses on the
3383external regulatory and legal issues a CISO faces, as well as the strategic information
3384security governance programs promoted in forward-thinking organizations. It also
3385contains areas related to security compliance to ensure that the organization conforms
3386568 Chapter 11
3387Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
3388Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
338911
3390to applicable laws and regulations. Finally, it includes areas of information security
3391standards, such as Federal Information Processing Standards and ISO 27000, and it
3392incorporates areas in risk management. 23
3393â—
3394Domain 2: IS Management Controls and Auditing Management (Projects, Technology,
3395and Operations): This domain includes knowledge areas associated with information
3396systems controls and auditing, similar to those found in ISACA certifications. These
3397areas include developing, implementing, and monitoring IS controls as well as report-
3398ing the findings to executive management. Auditing areas include planning, conduct-
3399ing, and evaluating audits in the organization. 24
3400â—
3401Domain 3: Management (Projects and Operations): This domain contains basic mana-
3402gerial roles and responsibilities any security manager would be expected to have mas-
3403tered. It includes the fundamentals of management covered in earlier chapters, includ-
3404ing planning, organizing, staffing, directing, and controlling security resources. 25
3405â—
3406Domain 4: Information Security Core Competencies: This domain covers the common
3407body of information security knowledge that any CISO would be expected to possess.
3408The domain includes subdomains in the following areas:
3409â—
3410Access control
3411â—
3412Social engineering, phishing attacks, identity theft
3413â—
3414Physical security
3415â—
3416Risk management
3417â—
3418Disaster recovery and business continuity planning
3419â—
3420Firewalls, IDPSs, and network defense systems
3421â—
3422Wireless security
3423â—
3424Viruses, Trojans, and malware threats
3425â—
3426Secure coding best practices and securing Web applications
3427â—
3428Hardening operating systems
3429â—
3430Encryption technologies
3431â—
3432Vulnerability assessment and penetration testing
3433â—
3434Computer forensics and incident response 26
3435â—
3436Domain 5: Strategic Planning and Finance: This domain addresses CISO tasks associ-
3437ated with conducting strategic planning and financial management of the security
3438department. The domain includes performance measures, IT investments, internal and
3439external analyses, and developing and implementing enterprise security architectures. 27
3440‡ CompTIA Certifications
3441CompTIA (www.comptia.com)—the organization that offered the first vendor-neutral profes-
3442sional IT certifications, the Aþ series—now offers a program called the Security+ certification.
3443The CompTIA Securityþ certification tests for security knowledge. Candidates must have
3444two years of on-the-job networking experience. The exam covers industry-wide topics,
3445including communication security, infrastructure security, cryptography, access control,
3446authentication, external attack, and operational and organization security. CompTIA
3447Securityþ curricula are taught at colleges, universities, and commercial training centers
3448Credentials for Information Security Professionals 569
3449Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
3450Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
3451around the globe. CompTIA Securityþ is used as an elective or prerequisite to advanced
3452vendor-specific and vendor-neutral security certifications. 29
3453The exam covers the domains shown in Table 11-1.
3454‡ ISFCE Certifications
3455The International Society of Forensic Computer Examiners (ISFCE) offers two levels of
3456certification.
3457Certified Computer Examiner (CCE) Certified Computer Examiner (CCE) ® is a
3458computer forensics certification provided by the ISFCE (www.isfce.com). To complete the
3459CCE certification process, the applicant must:
3460â—
3461Have no criminal record
3462â—
3463Meet minimum experience, training, or self-training requirements
3464â—
3465Abide by the certification’s code of ethical standards
3466â—
3467Pass an online examination
3468â—
3469Successfully perform actual forensic examinations on three test media
3470The CCE certification process covers the following areas:
3471â—
3472Ethics in practice
3473â—
3474Key legislation in, and its impact on, digital forensics
3475â—
3476Software licensing and validation
3477â—
3478General computer hardware used in data collection
3479â—
3480Networking and its involvement in forensics and data collection
3481â—
3482Common computer operating system and file systems organization and architecture
3483â—
3484Forensics data seizure procedures
3485â—
3486Casework and other forensics examination procedures
3487570 Chapter 11
3488Domain Percentage of examination
34891.0 Network Security 20%
34902.0 Compliance and Operational Security 18%
34913.0 Threats and Vulnerabilities 20%
34924.0 Application, Data, and Host Security 15%
34935.0 Access Control and Identity Management 15%
34946.0 Cryptography 12%
3495Table 11-1 Domains Covered in the CompTIA Security+ Exam
3496Source: CompTIA. 28
3497Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
3498Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
349911
3500â—
3501Common computer media, as used as evidence, in physical and logical storage media
3502operations, and procedures for sterilization and use
3503â—
3504Use of forensic boot disks
3505â—
3506Forensic examination skills and procedures
3507This certification also includes concentrations and endorsements corresponding to the vari-
3508ous operating systems in current business environments. A CCE who earns three or more
3509of these endorsements qualifies as a Master Certified Computer Examiner (MCCE). 30
3510‡ Certification Costs
3511Certifications cost money, and the more preferred certifications can be expensive. Individ-
3512ual certification exams can cost as much as $750, and certifications that require multiple
3513exams can cost thousands of dollars. In addition, the cost of formal training to prepare
3514for the exams can be significant. While you should not rely completely on certification
3515preparation courses as groundwork for a real-world position, they can help you round
3516out your knowledge and fill in gaps. Some certification exams, such as the CISSP, are
3517very broad; others, such as components of the GIAC, are very technical. Given the nature
3518of the knowledge needed to pass the examinations, most experienced professionals find the
3519tests difficult without at least some review. Many prospective certificate holders engage in
3520individual or group study sessions and purchase one of the many excellent exam review
3521books on the subject.
3522Certifications are designed to recognize experts in their respective fields, but the cost of certi-
3523fication deters those who might take the exam just to see if they can pass. Most examinations
3524require between two and three years of work experience, and they are often structured to
3525reward candidates who have significant hands-on experience. Some certification programs
3526require that candidates document certain minimum experience requirements before they are
3527permitted to sit for the exams. Before attempting a certification exam, do your homework.
3528Look into the exam’s stated body of knowledge as well as its purpose and requirements to
3529ensure that the time and energy spent pursuing the certification are worthwhile. Figure 11-5
3530shows several approaches to preparing for security certification.
3531On the topic of professional certification for information security practitioners, Charles Cresson
3532Wood reports the following:
3533With résumé fraud on the rise, one of the sure-fire methods for employers to be
3534sure that the people they hire are indeed familiar with the essentials of the field
3535is to insist that they have certain certifications. The certifications can then be
3536checked with the issuing organizations to make sure that they have indeed been
3537conferred on the applicant for employment. […] The key is to insist that they
3538have certain certifications. The […] professional certifications are relevant pri-
3539marily to centralized information security positions. They are not generally rele-
3540vant to staff working in decentralized information security positions, unless
3541these individuals intend to become information security specialists. You may
3542also look for these certifications on the résumés of consultants and contractors
3543working in the information security field. You may wish to list these designations
3544in help-wanted advertisements, look for them on résumés, and ask about them
3545during interviews. Automatic résumé scanning software can also be set up to
3546search for these strings of characters. 31
3547Credentials for Information Security Professionals 571
3548Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
3549Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
3550‡ Advice for Information Security Professionals
3551As a future information security professional, you may benefit from the following suggestions:
3552â—
3553Always remember: business before technology. Technology solutions are tools for
3554solving business problems. Information security professionals are sometimes guilty of
3555looking for ways to apply the newest technology to problems that do not require
3556technology-based solutions.
3557â—
3558When evaluating a problem, look at the source of the problem first, determine what
3559factors affect the problem, and see where organizational policy can lead you in design-
3560ing a solution that is independent of technology. Then use technology to deploy the
3561controls necessary for implementing the solution. Technology can provide elegant
3562solutions to some problems, but it only exacerbates others.
3563â—
3564Your job is to protect the organization’s information and information systems
3565resources. Never lose sight of the goal: protection.
3566â—
3567Be heard and not seen. Information security should be transparent to users. With
3568minor exceptions, the actions taken to protect information should not interfere with
3569users’ actions. Information security supports the work of end users, not the other way
3570572 Chapter 11
3571Self-study guides
3572Certification Mentors and study partners
3573Work experience Training media Formal training programs
3574Figure 11-5 Preparing for security certification
3575© 2015 Cengage Learning ® . Top left: © Hong Vo/www.Shutterstock.com. Bottom left: © auremar/www.Shutterstock.com.
3576Bottom center: © Petinov Sergey Mihilovich/www.Shutterstock.com. Bottom right: © wavebreakmedia/www.Shutterstock.com.
3577Top right: © Goodluz/www.Shutterstock.com.
3578Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
3579Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
358011
3581around. The only routine communications from the security team to users should be
3582periodic awareness messages, training announcements, newsletters, and e-mails.
3583â—
3584Know more than you say, and be more skillful than you let on. Don’t try to impress
3585users, managers, and other nontechnical people with your level of knowledge and
3586experience. One day you just might run into a Jedi master of information security who
3587puts you in your place.
3588â—
3589Speak to users, not at them. Use their language, not yours. Users aren’t impressed with
3590technobabble and jargon. They may not comprehend all the TLAs (three-letter acro-
3591nyms), technical components, software, and hardware necessary to protect their sys-
3592tems, but they do know how to short-circuit your next budget request or pick out the
3593flaws in your business report.
3594â—
3595Your education is never complete. As sensitive as you are to the fact that information
3596technology is ever evolving, you must be equally sensitive to the fact that information
3597security education is never complete. Just when you think you have mastered the latest
3598skills, you will encounter changes in threats, protection technology, your business
3599environment, or the regulatory environment. As a security professional, you must
3600expect to continue with the learning process throughout your entire career. This is best
3601accomplished by seeking out periodic seminars, training programs, and formal educa-
3602tion. Even if the organization or your pocketbook cannot afford the more extensive
3603and expensive training programs and conferences, you can keep abreast of the market
3604by reading trade magazines, textbooks, and news articles about security. You can also
3605subscribe to the many mailing lists for information security professionals. Several are
3606listed in the nearby Offline feature entitled “What’s in a Name?†Join at least one
3607professional information security association, such as the Information Systems Security
3608Association (www.issa.org). Whatever approach you take, keep on top of the reading,
3609never stop learning, and make yourself the best-informed security professional possi-
3610ble. It can only enhance your worth to the organization and your career.
3611Employment Policies and Practices
3612To create an environment in which information security is taken seriously, an organization
3613should make it a documented part of every employee’s job description. In other words, the
3614general management community of interest should integrate solid concepts for information
3615security into the organization’s employment policies and practices. This section examines
3616important information security issues associated with recruiting, hiring, firing, and managing
3617human resources in an organization.
3618From an information security perspective, the hiring of employees is a responsibility laden
3619with potential security pitfalls. Therefore, the CISO and information security manager should
3620work with the Human Resources department to incorporate information security into the
3621guidelines used for hiring all personnel. Figure 11-6 highlights some of the hiring issues.
3622‡ Job Descriptions
3623The process of integrating information security into the hiring process begins with reviewing
3624and updating all job descriptions. To prevent people from applying for positions based solely
3625Employment Policies and Practices 573
3626Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
3627Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
3628574 Chapter 11
3629OFFLINE
3630What’s in a Name?
3631Here are some job titles listed in job search databases that the authors reviewed to
3632prepare this section. See if you can guess the position level based on the title.
3633â— Senior security analyst
3634â— SAP security analyst
3635â— Security supervisor
3636â— Direct loss prevention manager
3637â— Security officer (not a guard job)
3638â— Loss prevention consultant
3639◠Site supervisor—security
3640â— Safeguards and security specialist
3641To perform your own job title search or search for an actual job in the field of
3642information security, you can begin by reviewing the job search databases at the
3643following Web sites:
3644â— Commercial job listing sites such as www.justsecurityjobs.com, www.itsecurityjobs
3645.com, and securityjobs.net
3646â— U.S. federal agency position listings such as www.usajobs.gov
3647â— Job listing sites associated with periodicals, such as www.csoonline.com/secu-
3648rity/jobs/1 and http://online.wsj.com/public/page/news-career-jobs.html
3649â—
3650Job listings by professional organization, such as www.isc2.org/careers/ and
3651www.isaca.org (click on Career Center)
3652Background checks
3653Covenants and agreements
3654Certifications
3655Policies
3656Contracts
3657Figure 11-6 Hiring issues
3658© 2015 Cengage Learning ® . Top left: The Federal Bureau of Investigation. Bottom center: © Andrey_Popov/www.Shutterstock.com.
3659Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
3660Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
366111
3662on access to sensitive information, the organization should avoid revealing access privileges
3663to prospective employees when it advertises open positions.
3664‡ Interviews
3665Some interviews with job candidates are conducted with members of the Human
3666Resources (HR) staff, and others include members of the department for which the posi-
3667tion is being offered. An opening within the Information Security department creates a
3668unique opportunity for the security manager to educate HR on the various certifications
3669and specific experience each certification requires, as well as the qualifications of a good
3670candidate. In all other areas of the organization, Information Security should advise HR
3671to limit information provided to the candidate about responsibilities and access rights of
3672the new hire. For organizations that include onsite visits as part of their initial or follow-
3673up interviews, it is important to exercise caution when showing a candidate around the
3674facility. Avoid tours through secure and restricted sites. Candidates who receive tours
3675may be able to retain enough information about operations or information security func-
3676tions to become a threat.
3677‡ Background Checks
3678A background check should be conducted before an organization extends an offer to a job
3679candidate. A background check is an investigation into the candidate’s past that looks for
3680criminal behavior or other types of behavior that could indicate potential for future miscon-
3681duct. Several government regulations specify what the organization can investigate and how
3682much of the information uncovered can be allowed to influence the hiring decision. The secu-
3683rity manager and HR manager should discuss these matters with legal counsel to determine
3684what state, federal, and perhaps international regulations affect the hiring process.
3685Background checks differ in the level of detail and depth with which they examine a candi-
3686date. In the military, background checks determine the candidate’s level of security classifi-
3687cation, a requirement for many positions. In the business world, a background check can
3688determine the level of trust the business places in the candidate. People being considered
3689for security positions should expect to be subjected to a moderately high-level background
3690check. Those considering careers in law enforcement or high-security positions may even
3691be required to submit to polygraph tests. The following list summarizes various types of
3692background checks and the information checked for each:
3693â—
3694Identity checks: Validation of identity and Social Security number
3695â—
3696Education and credential checks: Validation of institutions attended, degrees and certi-
3697fications earned, and certification status
3698â—
3699Previous employment verification: Validation of where candidates worked, why they
3700left, what they did, and for how long
3701â—
3702Reference checks: Validation of references and integrity of reference sources
3703â—
3704Worker’s compensation history: Investigation of claims from worker’s compensation
3705â—
3706Motor vehicle records: Investigation of driving records, suspensions, and DUIs
3707â—
3708Drug history: Screening for drugs and drug usage, past and present
3709â—
3710Credit history: Investigation of credit problems, financial problems, and bankruptcy
3711Employment Policies and Practices 575
3712Copyright 2016 Cengage Learning. All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Due to electronic rights, some third party content may be suppressed from the eBook and/or eChapter(s).
3713Editorial review has deemed that any suppressed content does not materially affect the overall learning experience. Cengage Learning reserves the right to remove additional content at any time if subsequent rights restrictions require it.
3714â—
3715Civil court history: Investigation of the candidate’s involvement as a plaintiff or defen-
3716dant in civil suits
3717â—
3718Criminal court history: Investigation of criminal background, arrests, convictions, and
3719time served
3720As mentioned, there are federal regulations for the use of personal information in employ-
3721ment practices, including the Fair Credit Reporting Act (FCRA), which governs the activities
3722of consumer credit reporting agencies and the uses of information procured from them. 32
3723These credit reports generally contain information about a job candidate’s credit history,
3724employment history, and other personal data.
3725Among other things, the FCRA prohibits employers from obtaining these reports unless the
3726candidate is informed in writing that such a report will be requested as part of the employment
3727process. The FCRA also allows the candidate to request information about the nature and type
3728of reporting used in making the employment decision and subsequently enables the candidate
3729to learn the content of these reports. The FCRA also restricts the periods of time these reports
3730can address. If the candidate earns less than $75,000 per year, the report can contain only
3731seven years of negative credit information. If the candidate earns $75,000 or more per year,
3732there is no time limitation. Note that “any person who knowingly and willfully obtains infor-
3733mation on a consumer from a consumer reporting agency under false pretenses shall be fined
3734under title 18, United States Code, imprisoned for not more than two years, or both.†33
3735‡ Employment Contracts
3736Once a candidate has accepted a job offer, the employment contract becomes an important secu-
3737rity instrument. Many of the policies discussed in Chapter 4—specifically, the fair and responsible
3738use policies—require an employee to agree in writing to monitoring and nondisclosure agree-
3739ments. If existing employees refuse to sign these agreements, security personnel are placed in a dif-
3740ficult situation. They may not be able to force employees to sign or to deny employees access to
3741the systems necessary to perform their duties. With new employees, however, security personnel
3742are in a different situation because the procedural step of policy acknowledgment can be made a
3743requirement of employment. Policies that govern employee behavior and are applied to all
3744employees may be classified as “employment contingent upon agreement.†This classification
3745means the potential employee must agree in a written affidavit to conform with binding organiza-
3746tional policies before being hired. Some organizations choose to execute the remainder of the
3747employment contract after the candidate has signed the security agreements. Although this may
3748seem harsh, it is a necessary component of the security process. Employment contracts may also
3749contain restrictive clauses regarding the creation and ownership of intellectual property while the
3750candidate is employed by the organization. These provisions may require the employee to actively
3751protect the organization’s information assets—especially assets that are critical to security.