What is a security plan?
A plan that identifies and organizes the security activities for a system/organization
What does a security plan do?
Describes the current situation and highlights the improvement
It is an official record of current security practices and a blueprint for orderly change to improve those practices
What three essential questions should a security policy answer?
Who should be allowed access?
To what system and organizational resources should access be allowed?
What types of access should each user be allowed for each resource?
What should a security policy specify?
How should a security policy be written?
Not too long, complex, detailed, and fast and easy to read
What does “current security status” mean?
What is risk analysis?
A systematic investigation of the system, its environment, and what might go wrong
And then forms the basis for describing the current security state
What’s the meaning of security requirements?
Security requirements are functional or performance demands placed on a system to ensure a desired level of security
What is the characteristics of good security requirements?
What’s the meaning behind accountability/responsibility for implementation
A section of the security plan that will identify which people (roles) are responsible for implementing security requirements
What is the common roles in a security plan?
What is a timetable?
A timetable means of how and when the elements in it will be performed must be included
What is a plan maintenance?
A plan that specify the order which controls are to be implemented.
What must be included in a plan maintenance?
Why does security planning need team members and commitment?
Security planning touches every aspect of an organization and therefore requires participation well beyond the security group
What three groups must contribute to making a security plan if you want it to succeed?
What is a business continuity plan?
A (business) continuity plan documents how a business will continue to function during or after a computer security incident
What does a business continuity plan address?
What does a business continuity plan assess?
What us the goal of a incident response?
Be able to handle the current security incident without direct regard for the business issues
What is a security incident response plan?
It tells the staff how to deal with a security incident
A incident response plan should include?
What is ISO/IEC 27005 about?
Information security risk management (ISRM)
What is ISO 31000 about?
(general) Risk Management (RM) (principles and guidelines)