Implications of the Internet being very new
New uses continually developing
No time for Information Security to mature as a discipline.
Current Issue with Information Security
Security is seen as a Non-Functional Requirement
What is needed to make security a priority?
Pressure is needed to make security a priority
4 questions to start designing information security
What are we protecting?
Who are we protecting against?
What capability are we worried about?
Can we afford it?
Possible Approaches to Increase Security
Defense in Depth
Limitations of Defense in Depth
3 requirements (strong rec.) for information security
1. Security Policy
2. Technical Documentation
3. An organisationto support all this
12 things we need in a Security Organisation
1 Security Engineering
1. Security Engineering
2 Identity and Access Management
2. Identity and Access Management
3 Logging and Monitoring
3. Logging and Monitoring
4 Security Operations
4. Security Operations
5 Security Architects
5. Security Architects
Problems:
6 Application Security
6. Application Security
7 Security Compliance
7. Security Compliance
8 Risk Management
8. Risk Management
Problems:
9 Physical Security
9. Physical Security
10 Data Protection
10. Data Protection
11 Internal Audit
11. Internal Audit
Problems:
12 Regulatory & Audit Response
12. Regulatory & Audit Response
Pros and Cons of Security Outsourcing
Pros:
Cons:
Conclusion and Predictions