lagen.nu
Risk Management & IT Security for Micro and Small Businesses

Risk Management & IT Security for Micro and Small Businesses

Utgivare
Europeiska unionens cybersäkerhetsbyrå
Antagen
2007-01-01
Språk
engelska
Källa
www.enisa.europa.eu
Endast på engelskaEuropeiska unionens cybersäkerhetsbyrå har inte publicerat någon svensk version av detta dokument. Texten nedan återges på engelska, så som den publicerats av Europeiska unionens cybersäkerhetsbyrå.

for Micro and Small Businesses

CONTENTS How to proceed with Information Security Phase 1: Risk Profile Selection Phase 2: Critical Assets Identification Phase 3: Control Card Selection Phase 4: Risk Management and Implementation Organisational Controls Organisational Control Cards Asset Based Control Cards System Network People Application Asset Based Controls Appendices Action Checklist IT Security Questionnaire Notes

How to proceed with Information Security

Part of the responsibility of MSB managers is to provide for the security of their business environment. According to most applicable legal requirements, liability for breaches of security lies with them. Just as they must provide a safe and secure physical environment, they must also make sure that information is protected. Given the fact, however, that computers are not “fix and forget” devices, the protection of information is a permanent concern. Decision makers can initiate risk assessment on their environment and trigger the introduction of suitable measures to face unacceptable risks. This is the precondition for the management of information security. In performing this, a variety of approaches may be followed concerning the staffing of such an effort (also known as a “make‐or‐buy” decision). We differentiate between three approaches: • In‐sourcing of risk assessment • Partial outsourcing of risk assessment • Full outsourcing of risk assessment

© 2007 IAAITC. All rightsreserved.

In‐sourcing

Questions for the decision maker Answer ☺ YES NO

Is your business small? Doesit have a flat or simple hierarchical structure?

Do you have internal know‐how in IT Systems and Networks?

Does your business have qualified and available human resources?

Do your business activities have a low dependency on IT systems and are they uninvolved in storing or processing customer data of a sensitive nature and has your organization been involved in similar activities, i.e. quality improvement processes? Can you find a group of three to five people who have a broad and deep understanding of the business and also possess most of the following skills? • problem‐solving ability • analytical ability • ability to work in a team • leadership skills • Ability to understand the firm's business processes and the

underlying infrastructure of the business

• ability to spend a few days working on this method

Do you have a relatively simple information technology infrastructure that is well‐understood by at least one individual in your organization?

A majority of “YESs” will typically mean that the business should be able to develop their own policies internally.

In‐sourcing of risk assessment: the risk assessment and the identification of necessary measures is performed by internal staff. The assessment is based on a risk assessment approach that has been selected by the business (e.g. a good practice, a known standard, etc.). This will help the business to master the assessment approach for recurring executions

© 2007 IAAITC. All rightsreserved.

Partial Outsourcing

Questions for the decision maker Answer ☺ YES NO

Do you deem it necessary to retain an increased focus on core competencies

and strategic business processes but also improve internal information security awareness and competency in information security matters? Is it likely you can make available one to two people in your organisation who have a broad and deep understanding of the organization and also possess most of the following skills? • Ability to understand the business processes and the underlying

infrastructure of the organization

• problem‐solving ability • analytical ability • ability to work in a team • leadership skills • ability to spend a few days working on this method • they are going to be on a longer term employment Do you have a complex and a relatively large IT infrastructure but a relatively simple business model? Do your business and service offerings include financial transactions?

Do you operate a business that is highly subject to strict EU or Domestic Legal and Regulatory constraints and/or mandates?

The more questions that have been answered with a “YES” the better is the MSB suited for this risk assessment implementation approach

Partial outsourcing of risk assessment: this approach assumes that the initial risk assessment is performed by an external company. The assessment will be based on a risk assessment approach that is known to the MSB. Hence, further risk assessments can be performed by internal personnel. The initial assessment performed by the outsourcer serves as know‐how transfer to the MSB’s internal personnel.

© 2007 IAAITC. All rightsreserved.

Full Outsourcing

Questions for the decision maker Answer ☺ YES NO

Do you deem it necessary to retain an increased focus on core competencies and strategic business processes? Would you find it hard to make available two to five people who have a broad and deep understanding of the organization and also possess most of the following skills? • Ability to understand the business processes and the

underlying infrastructure of the organization

• problem‐solving ability • analytical ability • ability to work in a team • leadership skills • ability to spend a few days working on this method Do you have a highly complex and a relatively large IT infrastructure? Does you business and service offerings include financial transactions? Do you operate a business which is highly subject to strict EU or Domestic Legal and Regulatory constraints and/or mandates?

Do you have a relatively simple information technology infrastructure which is well‐understood by at least one individual in your organisation?

The more “YES” answers that appear for the business, the better outsourcing is suited to its needs.

Full outsourcing of risk assessment: according to this approach, the entire risk assessment is performed by an external contractor. The assessment is based on a risk assessment approach that is chosen by the external contractor. The contractor can also undertake recurring future assessments. No know‐how transfer to internalpersonnel is foreseen for the entire life cycle of the risk assessment/risk management of the MSB.

© 2007 IAAITC. All rightsreserved.

Phase 1 ‐Risk Profile Selection

Phase 1

Consider the business risk aspects of information protection that

can: (a) result in legal and regulatory non‐compliance, (b) decrease productivity. (c) create financial loss (d) directly or indirectly affect or damage reputation and

Select an appropriate risk level for each risk area using the risk

profile evaluation table. The specified areas are the following: Legal and Regulatory, Productivity, Financial Stability, Reputation and Risk Profile Loss of Customer Confidence. As shown above, the phase involves

Risk Areas High Medium Low

To identify the current or potential risk level, highlight the risk area and read the description in each column. Risk areas that are closer to the business profile are chosen. The process is followed for every risk area. At the end there should be a MATRIX highlighting the applicable risk level in each risk area.

© 2007 IAAITC. All rightsreserved.

This page left blank

© 2007 IAAITC. All rightsreserved.

Phase 2 Critical Assets Identification

Phase 2 requires decisions that shape the remainder of the evaluation— selecting the business criticalassets. Depending upon the size of the business, the number of information assets identified during this phase could easily exceed a hundred. To make the analysis manageable, MSBs need to narrow the focus of the evaluation by selecting the few assets that are most critical to achieving their mission and meeting the objectives of the business. These are the only assets that will be analysed during later activities. As depicted in figure one the phase involves three steps.

Step 1. Select your organisation's five most critical assets

When critical assets are selected, teams are not limited to choosing only five. Five assets are normally enough to enable organizations to develop a good set of mitigation plans during phase 4. However, analysis team members must use their judgement whether to use more or fewer than five. During the selection process of critical assets, team members should consider which assets will result in a large adverse impact on the organization in one of the following scenarios: • Disclosure of information to unauthorized people • Modification of information without authorization • Loss or destruction of the asset • Interrupted access to the asset or to the information stored

Asset Category Description Asset (types)

© 2007 IAAITC. All rightsreserved.

Security Requirements Selection

Step 2. Identify Critical Asset security requirements

In general, when describing a security requirement for an asset, you need to understand what aspect of the asset is important. For information assets, security requirements will focus on the confidentiality, integrity, and availability of the information. Security requirements can vary for different categories of assets within an MSB, but careful selection of requirements is critical for the controls selection task that follows. In other words, high availability requirements impose high availability controls etc. You should use the requirements selection criteria as provided in order to identify most important security requirements. Asset

security requirements will be used later during the asset control card selection.

The security requirements evaluation criteria have been developed as a simple and practical guide for evaluating the security requirements in terms of confidentiality, integrity and availability of the critical assets selected. The evaluation highlights the importance of the asset security attributes and indicates the appropriate controls for their protection. As an output, you should have a table listing critical assets along with a short description of their importance for the accomplishment of the business mission, its basic elements, and the security requirements.

Asset Category Confidentiality Integrity Availability

Step 3. Record the Rationale for selecting each Critical Asset

© 2007 IAAITC. All rightsreserved.

Phase 3 ‐ Control Cards Selection

The selection of the organisational control cards is performed in a fairly straightforward manner: organisation controls are available for every risk profile (defined in the risk profiling matrix created in Phase 1 Risk Profile Selection). The following table assigns organisational controls to the risk profiles. Controls listed below are recommended in order to mitigate respective organisational risks.

Controls Control No. Name of the control Category

There are 6 Organisational SP1 Security Awareness and Training

Organisational Control SP2 Security Strategy Cards as shown in the

SP3 Security Management

table to the right.

SP4 Security Policies and Regulations SP5 Collaborative Security Management SP6 Contingency Planning/Disaster Recovery

Risk Areas High Medium Low

Legal and Regulatory (SP1) (SP1) SP1.1 (SP4) (SP4) Productivity (SP3) (SP4) SP4.1 (SP4) (SP6) (SP6) (SP5) Financial Loss (SP2) (SP4) SP4.1 (SP1) (SP4) Reputation and Loss of Customer (SP1) (SP4) SP4.1

Confidence

(SP5) (SP1)

© 2007 IAAITC. All rightsreserved.

Asset‐Based Control Cards Selection

Based on the risk profile and the asset security requirements MSBs assessment teamscan use asset the control cards table below to identify the controls appropriate for the protection of critical assets.

Asset control cardsare essentially grouped in three categories, corresponding to organisation risk profile, asset category and security requirement. For example assessment teams facing a high risk organisation profile will have different security requirements than medium or low risk profiles. Each control card involves a number of asset controls to address the complete range of risks and security requirements as needed in the particular profile and dictated by the selected security requirements.

Assessment teams, using the previously identified security requirements and the control card can subsequently identify more specific controls (e.g. the controls for availability, confidentiality or integrity). It has to be noted that in cases where more than one requirement is selected, the controls that apply to the asset are the sum of the controls for each requirement.

Asset Control Cards

Asset High Risk Cards Medium Risk Cards Low Risk Cards

Application CC‐1A CC‐2A CC‐3A

System CC‐1S CC‐2S CC‐3S Network CC‐1N CC‐2N CC‐3N

People CC‐1P CC‐2P CC‐3P

There are 12 Asset‐Based Control Cards as shown in the table below.

Controls Control No. Name of the control Category

Asset Based OP1.1 Physical Security Plans and Procedures OP1.2 Physical Access Control OP1.3 Monitoring and Auditing Physical Security OP2.1 System and Network Management OP2.2 System Administration Tools OP2.3 Monitoring and Auditing IT Security OP2.4 Authentication and Authorisation OP2.5 Vulnerability Management OP2.6 Encryption OP2.7 Security Architecture and Design OP3.1 Incident Management OP3.2 General Staff Practices

© 2007 IAAITC. All rightsreserved.

Phase 4 ‐Risk Management and Implementation

During Phase 4 the MSB identifies actions and recommends an action list, setting forth the direction for security improvement. Essential for the successful implementation is the establishment of Senior Management (Decision Makers) sponsorship for the ongoing security improvement. Step 1. Gap Analysis

Gap analysis is essential in order to improve how an organization handles information security, and establish the current state of security, that is, what is currently done well and where improvement is needed.

In this step, analysis teams are occupied with the evaluation of the organization's current security practices against the controls as these are depicted from the control cards. Analysis teams read carefully selected control cards and elicit detailed information about the organization's current security policies, procedures, and practices, thus providing a starting point for improvement.

During the Gap Analysis process teams use the control cards as the “requirements” and assess the gaps between these and current security practices both at an organizational and critical asset level. Analysis teams should carefully document output in two distinct plans – (1) one for the organizational improvement and (2) one for the asset protection.

The output from this process can form the basis for the planning activity that follows next. It is separated into two categories: (a) Organizational Controls, where the analysis teams should identify what they do and don’t do and define actions for improvement at an organizational level and (b) Asset Based controls where analysis teams assess existing protection measures for the identified critical assets.

© 2007 IAAITC. All rightsreserved.

Step 2. Create Risk Mitigation Plans

In this step MSBs have already identified critical assets, their organisation risk profile, the security requirements and have further selected appropriate controls and are about to determine the mitigation approach for each identified risk area and critical asset.

By taking these initial steps toward improvement, businesses can start to build the momentum needed to implement its protection strategy.

The output of this activity is the risk mitigation plan, which leads to a series of steps that a business can take to raise or maintain its existing level of security. Its objective is to provide a direction for future information security efforts rather than to find an immediate solution to every security vulnerability and concern. Since a mitigation plan provides organisational direction with respect to information security activities, we suggest structuring it around the selected (phase 3) control cards (organisational and critical‐asset‐based).

Step 3. Implementation, Monitoring and Control

NOTE:

© 2007 IAAITC. All rightsreserved.

Organisational Controls

The selection of the organisational control cards is performed in a fairly straightforward manner: Organisation Controls are available for every risk profile (defined in the risk profiling matrix created in Phase 1 Risk Profile Selection).

Security Awareness and Training (SP1)

SP1 Security Awareness and Training Control Card includes controls that require staff members to understand their security roles and responsibilities. Security awareness, training, and periodic reminders should be provided for all personnel. Staff understanding and roles should be clearly documented and conformance should be periodically verified.

Security Strategy (SP2)

SP2 Security Strategy Control Card includes controls that require the organization’s business strategies to routinely incorporate security considerations. Equally, security strategies and policies must take into consideration the organization’s business strategies and goals. Security strategies, goals, and objectives should be documented and are routinely reviewed, updated, and communicated to the organization.

Security Management (SP3)

SP3 Security Management Control Card includes controls that require a security management process to be implemented and enforced. The process must continuously assess the required levels of information security and define appropriate and cost/risk balanced controls that should be applied and documented.

Security Policies and Regulations (SP4)

SP4 The Control Card requires an organization to have a comprehensive set of documented, current information security policies that are periodically reviewed and updated.

Collaborative Security Management (SP5)

SP5 Collaborative Security Management Control Cards includes security controls that enforce documented, monitored, and enforced procedures for protecting the organization’s information when working with external organizations (e.g., third parties, collaborators, subcontractors, or partners).

Contingency Planning/Disaster Recovery (SP6)

SP6 Continuity Planning/Disaster Recovery Control Cards incorporates security controls in order to assure continuous business operations in case of a disaster or unavailability of the information. Key elements of the control card are: • business continuity or emergency operation plans, • disaster recovery plan(s) and • contingency plan(s) for responding to emergencies.

© 2007 IAAITC. All rights reserved.

Organisational Control Cards

Security Awareness and Training (SP1) Security Awareness and Training (SP1)

SP1.1 Staff members understand their security roles and responsibilities. This is documented and

SP1.2 There is adequate in‐house expertise for all supported services, mechanisms, and technologies (e.g., logging, monitoring, or encryption), including their secure operation. This

SP1.3 Security awareness, training, and periodic reminders are provided for all personnel. Staff understanding is documented and conformance is periodically verified. Training includes

security strategies, goals, and objectives security regulations, polices, and procedures policies and procedures for working with third parties contingency and disaster recovery plans physical security requirements users’ perspective on system and network management system administration tools monitoring and auditing for physical and information technology security authentication and authorization vulnerability management encryption architectureand design incident management general staff practices enforcement, sanctions, and disciplinary actions for security violations how to properly access sensitive information or work in areas where sensitive

termination policies and procedures relative to security

© 2007 IAAITC. All rights reserved.

Organisational Control Cards

Security Strategy (SP2) Security Strategy (SP2)

SP2.1 The organization’s business strategies routinely incorporate security considerations. SP2.2 Security strategies and policies take into consideration the organization’s business strategies

SP2.3 Security strategies, goals, and objectives are documented and are routinely reviewed,

Security Management (SP3) Security Management (SP3)

SP3.1 Management allocates sufficient funds and resources to information security activities. SP3.2 Security roles and responsibilities are defined for all staff in the organization. SP3.3 The organization’s hiring and termination practices for staff takeinformation security issues

SP3.4 The required levels of information security and how they are applied to individuals and

SP3.5 The organization manages information security risks, including assessing risks to information security both periodically and in response to major changes in technology, internal/external threats, or the organization’s systems and

takingsteps to mitigate risks to an acceptable level maintaining an acceptable level of risk using information security risk assessments to help select cost‐effective security/

SP3.6 Management receives and acts upon routine reports summarizing the results of review of system logs review of audit trails technology vulnerability assessments security incidents and the responses to them risk assessments physical security reviews security improvement plans and recommendations

© 2007 IAAITC. All rights reserved.

Organisational Control Cards

Security Policies and Regulations (SP4) Security Policies and Regulations (SP4)

SP4.1 The organization has a comprehensive set of documented, current policies that are

security strategy and management security risk management physical security system and network management system administration tools monitoring and auditing authentication and authorization vulnerability management encryption security architecture and design incident management staff security practices applicable laws and regulations awareness and training collaborative information security contingency planning and disaster recovery SP4.2 There is a documented process for management of security policies, including creation administration (including periodic reviews and updates) communication SP4.3 The organization has a documented process for periodic evaluation (technical and non‐ technical) of compliance with information security policies, applicable laws and regulations,

SP4.4 The organization has a documented process to ensure compliance with information security

SP4.5 The organization uniformly enforces its security policies. SP4.6 Testing and revision of security policies and procedures is restricted to authorized personnel.

© 2007 IAAITC. All rights reserved.

Organisational Control Cards

Collaborative Security Management (SP5) Collaborative Security Management (SP5)

SP5.1 The organization has documented, monitored, and enforced procedures for protecting its information when working with external organizations (e.g., third parties, collaborators,

SP5.2 The organization has verified that outsourced security services, mechanisms, and technologies

SP5.3 The organization documents, monitors, and enforces protection strategies for information belonging to external organizations that is accessed from its own infrastructure components or

SP5.4 The organization provides and verifies awareness and training on applicable external organizations’ security polices and procedures for personnel who are involved with those

SP5.5 There are documented procedures for terminated external personnel specifying appropriate security measures for ending their access. These procedures are communicated and

Contingency Planning/Disaster Recovery (SP6) Contingency Planning/Disaster Recovery (SP6)

SP6.1 An analysis of operations, applications, and data criticality has been performed. SP6.2 The organization has documented business continuity or emergency operation plans disaster recovery plan(s) contingency plan(s) for responding to emergencies SP6.3 The contingency, disaster recovery, and business continuity plans consider physical and electronic access requirements and controls. SP6.4 The contingency, disaster recovery, and business continuity plans are periodically reviewed, tested, and revised. SP6.5 All staff are aware of the contingency, disaster recovery, and business continuity plans understand and are able to carry out their responsibilities

© 2007 IAAITC. All rights reserved.

Asset‐Based CControl Card ‐ High Risk ‐ System

System

A high rrisk profile implies threats tthat occur in ssystem unavaailability leadinng to unavailaability of businness service. Systems are unable tto host busineess applicationns or may cauuse loss of critical information. Threat source can be the insttability of the system due to mechanical malfunction oor improper innstallation and use.

Systemm based confiddentiality conttrols for high risk organizattional profiles involve methhods that ensuure proper configuuration and functionality of the system. SSystem based integrity conttrols for a high risk organizaational profilee typically address security requiremments on an aapplication, syystem, networrk and people level to ensure stability of the systtem and criticcal information integrity. Coonstant Availaability of the ssystem is a reqquirement forr business continuuity. Controls aare selected tto address maainly information assets from disclosure tto unauthorizzed entities either eexternal or intternal to the eenvironment.

Essential Controls for the safeguarrd of integrityy in critical asssets are the foollowing:

OP2.1..3 Control rrequires that ssensitive inforrmation is prootected by seccure storage, ssuch as defineed chains of custoddy,backups stooredoff site, removable stoorage media aand discard prrocess for sennsitive informaation or its storagee media.

OP2.1..4 Control rrequires that tthe integrity oof installed sofftware is reguularly verified..

OP2.1..5 Control rrequires that aall systems aree up to date wwith respect to revisions, paatches, and recommendations inn security advvisories.

OP2.1..6 Control rrequires that tthere is a documented dataa backup plan that is routinnely updated, is periodicallyy tested,, calls for reguularly scheduled backups off both software and data and requires periodic testingg and verificaation of the abbility to restore from backuups.

OP 2.11.7 Control rrequires that aall staff underrstand and aree able to carryy out their ressponsibilities uunder the backupp plans.

©© 2007 IAAITCC. All rights resserved.

Asset‐Based Control Card ‐ High Risk ‐ System

OP2.1.8 Control requires that changes to IT hardware and software are planned, controlled, and documented. OP2.1.9 Control requires that IT staff members follow procedures when issuing, changing, and terminating users’ passwords, accounts, and privileges. Unique user identification is required for all information system users, including third‐party users. Default accounts and default passwords have been removed from systems.

OP2.1.10 Control requires that only necessary services are running on systems – all unnecessary services have been removed.

OP2.2.1 Control requires that new security tools, procedures, and mechanisms are routinely reviewed for applicability in meeting the organization’s security strategies.

OP2.2.2 Control requires that tools and mechanisms for secure system and network administration are used, and are routinely reviewed and updated or replaced. Examples are: data integrity checkers, cryptographic tools, vulnerability scanners, password quality‐checking tools, virus scanners, process management tools, intrusion detection systems, secure remote administrations, network service tools, traffic analyzers, incident response tools, forensic tools for data analysis.

OP2.3.1 Control requires that system and network monitoring and auditing tools are routinely used by the organization. Activity is monitored by the IT staff, System and network activity is logged/ recorded, Logs are reviewed on a regular basis, Unusual activity is dealt with according to the appropriate policy or procedure, Tools are periodically reviewed and updated.

OP2.4.1 Control requires that appropriate access controls and user authentication (e.g., file permissions, network configuration) consistent with policy are used to restrict user access to information, system utilities, program source code, sensitive systems, specific applications and services, network connections within the organization, network connections from outside the organization.

OP2.4.3 Control requires that access control methods/mechanisms restrict access to resources according to the access rights determined by policies and procedures.

OP2.4.6 Control requires that authentication mechanisms are used to protect availability, integrity, and confidentiality of sensitive information. Examples are the digital signatures and biometrics.

OP2.6.1 Control requires appropriate security controls to be used to protect sensitive information while in storage and during transmission, including: Data encryption during transmission, data encryption when writing to disk, use of public key infrastructure, virtual private network technology, encryption for all Internet‐based transmission.

OP2.7.1 Control requires that System architecture and design for new and revised systems include considerations for security strategies, policies, and procedures, history of security compromises and results of security risk assessments.

OP2.7.2 Control requires that the organization has up‐to‐date diagrams that show the enterprise‐wide security architecture and network topology.

© 2007 IAAITC. All rights reserved.

Asset‐Baased Control CCard ‐ Mediuum Risk ‐ Systeem

System

A mmedium risk pprofile implies moderate levvel threats thaat occur in sysstem instabilitties leading too unaavailability of business servvice for a shorrt period of timme. Systems aare unable to support applications or functions properly.

Sysstem based coontrols for meedium risk orgganizational profiles involvee methods thaat ensure propper connfiguration annd functionalitty of the systeem for approppriate access.

Esssential Controol for the proteection of conffidentiality, integrity and avvailability in syystems is the following:

OPP2.4.1 Conttrol requires tthat appropriaate access conntrols and useer authentication (e.g., file perrmissions, nettwork configuuration) consisstent with policyare used tto restrict user access to information, sysstem utilities, program sourrce code, senssitive systems, specific appllications and sservices, nettwork connecctions within tthe organizatioon, network cconnections frrom outside thhe organizatioon.

OPP2.1.6 Conttrol requires tthat there is a documented data backup plan which is routinely upddated, is perriodically tested, calls for reegularly schedduled backupss of both softwware and dataa and requiress periodic tessting and veriffication of thee ability to restore from bacckups.

OPP2.1.7 Conttrol requires tthat all staff understand and is able to caarry out their responsibilitiees under thee backup plans.

OPP2.1.9 Conttrol requires tthat IT staff mmembers followw procedures when issuingg, changing, annd terrminating users’ passwordss, accounts, annd privileges. Unique user identification is required foor all information systtem users, inccluding third‐pparty users. Default accounnts and defaultt passwords hhave been remmoved from systems.

© 2007 IAAITC. All rightts reserved.

Asset‐Baased Control CCard ‐ Low Riisk ‐ System

System

A loow risk profilee implies miniimum level threats that enttail potential ssystem instabbilities leadingg to unaavailability of business servvice for a shorrt period of timme.

Sysstem based coontrols for minnimum risk orrganizational profiles involvve methods thhat ensure prooper connfiguration annd functionalitty of the systeem for approppriate access.

Impact of systemm unavailabilitty does not afffect organization reputatioon as informattion is neitherr private nor critical to the organizationn.

Unavailability off system does not affect quality of servicce or product.

Esssential Controol for the proteection of conffidentiality and availability in systems aree the followinng:

OPP2.4.1 Conttrol requires tthat appropriaate access conntrols and useer authentication (e.g., file perrmissions, nettwork configuuration) consisstent with policyare used tto restrict user access to information, sysstem utilities, program sourrce code, senssitive systems, specific appllications and sservices, nettwork connecctions within tthe organizatioon, network cconnections frrom outside thhe organizatioon.

OPP2.1.6 Conttrol requires tthat there is a documented data backup plan that is rooutinely updated, is perriodically tested, calls for reegularly schedduled backupss of both softwware and dataa and requiress periodic tessting and veriffication of thee ability to restore from bacckups.

OPP2.1.9 Conttrol requires tthat IT staff mmembers followw procedures when issuingg, changing, annd terrminating users’ passwordss, accounts, annd privileges. Unique user identification is required foor all information systtem users, inccluding third‐pparty users. Default accounnts and defaultt passwords hhave been remmoved from systems.

© 2007 IAAITC. All rightts reserved.

Asset‐Based CControl Card ‐ High Risk ‐ Network

Netwwork

A high rrisk profile implies threats tthat occur in nnetwork vulneerabilities thaat can lead to external attaccks or internal unauthorised access to certain network areas oof high interesst or risk. Lack of Network secuurity has an immmediate andd direct effect in applicationns running and informationn flow. Networrk‐based confidentiality conntrols for a higgh risk organizational profile should prottect critical annd internal informaation from potential loss orr misuse. Furtthermore, infoormation storred in network must be avaailable and easily aaccessed and sseparated acccording to criticality level.

Essential Controls for the safeguarrd of confidenntiality, integrrity and availability in a netwwork are the ffollowing:

OP2.6.11 Control rrequires approopriate security controls too be used to protect sensitivve information while in storagee and during transmission inncluding data encryption during transmission, data enncryption wheen writing to disk, usse of public keey infrastructuure, virtual priivate networkk technology, eencryption for all Internet‐based transmission.

OP2.4.66 Control rrequires that aauthenticationn mechanismss are used to protect availaability, integritty, and confideentiality of sennsitive information. Examplles are digital signatures annd biometrics..

OP2.7.22 Control rrequires that tthe organizatiion has up‐to‐‐date diagramms that show the enterprisee‐wide securityy architecturee and networkk topology.

OP2.1.11 Control rrequires that tthere are documented secuurity plan(s) foor safeguardinng the systemms and networrks.

OP2.4.11 Control rrequires that aappropriate access controlss and user autthentication (e.g., file permmissions, networrk configuratioon) consistentt with policy aare used to resstrict user acccess to informmation, systemm utilities, programm source codee, sensitive syystems, specific applications and servicess, network connnections within the organizzation, networrk connections from outside the organizaation.

OP2.4..3 Control rrequires that aaccess control methods/meechanisms resstrict access too resources acccording to the acccess rights dettermined by ppolicies and procedures.

©© 2007 IAAITCC. All rights resserved.

Asset‐Based Control Card ‐ High Risk ‐ Network

OP2.1.10 Control requires that only necessary services are running on systems – all unnecessary services have been removed. OP 2.5.3 Control requires that technology vulnerability assessments are performed on a periodic basis, and vulnerabilities are addressed when they are identified. OP1.1.4 Control requires that there are documented policies and procedures for managing visitors, including sign in, escort, access logs, reception and hosting. OP2.4.6 Control requires that authentication mechanisms are used to protect availability, integrity, and confidentiality of sensitive information. Examples are digital signatures and biometrics.

© 2007 IAAITC. All rights reserved.

Asset‐Baased Control CCard ‐ Mediuum Risk ‐ Netwwork

Netwwork

A mmedium risk profile impliees threats that occur in nnetwork vulneerabilities duee to wrong oor poorly‐ impplemented neetwork architecture that caan lead to external attackss or internal uunauthorised access to cerrtain network areas of modderate interest and of medium organization value.

Lacck of Networkk security has immediate and direct effeect on applications runningg and information flow. Thee risk is conssidered mediuum when thee system doess not permit access to criitical componnents that couuld directly afffect organizattion reputatioon or financial health.

Esssential Controols for the saafeguard of cconfidentialityy, integrity and availability in a netwoork is the following:

OPP2.6.1 Conttrol requires appropriate ssecurity contrrols to be useed to protectt sensitive infformation whhile in storagee and during transmission including dataa encryption dduring transmission, data eencryption whhen writing to disk, use of ppublic key infrrastructure, virtual private network techhnology, encryyption for all Internet‐baseed transmissioon.

OPP2.4.3 Conttrol requires that access control metthods/mechannisms restrictt access to resources acccording to thee access rightss determined by policies annd proceduress.

OPP2.1.5 Conttrol requires that all systeems are up tto date with respect to revisions, patcches, and reccommendations in security advisories.

© 2007 IAAITC. All rightts reserved.

Asset‐Baased Control CCard ‐ Low Riisk ‐ Networkk

Netwwork

A loow risk profilee implies threats that occurr in minor nettwork vulnerabilities or unaavailability of information duee to wrong or poorly‐implemmented netwoork architectuure. The impacct however coould be connsidered insiggnificant sincee information is not of greatt interest nor highly confideential for the orgganization. Thherefore potenntial financial loss for the organization iss small.

Nevertheless, seecurity controols that addresss encrypted ttransferred information aree recommended.

Esssential Controols for the safeeguard of conffidentiality in a network is tthe following:

OPP2.6.1 Conttrol requires aappropriate seecurity controols to be used to protect sensitive informmation whhile in storage and during trransmission inncluding data encryption duuring transmisssion, data enncryption whhen writing to disk, use of ppublic key infraastructure, virrtual private nnetwork technnology, encrypption for all Internet‐baseed transmissioon.

© 2007 IAAITC. All rightts reserved.

Asset‐Baased Control CCard ‐ High RRisk ‐ People

Peoplle

A hhigh risk profille implies threeats that occuur in managemment of people and in humaan resources iin genneral. The level of staff commmitment on using the apppropriate secuurity controls oon network reesources dettermines leveel of protection that can be achieved.

Thee manipulatioon of informattion and the reeuse of older records with high value forr the organizaation is a crittical aspect. Innternal or connfidential information from staff should bbe treated resspectfully. Moonitoring of sstaff policies oon such proceedures ensurees the confidentiality, integrity and availaability of inforrmation.

Esssential Controols for securingg the confidenntiality, integrrity and availaability of information in commbination witth a critical assset like people are the folloowing:

OPP3.2.1 Conttrol requires tthat staff memmbers follow goodg security practice: secuuring informattion for whhich they are rresponsible; nnot divulging ssensitive information to othhers (resistancce to social enggineering); haaving adequatte ability to usse informationn technology hhardware andd software; using good passsword practices; understanding and following securitty policies andd regulations;; recognizing aand repporting incidents.

OPP3.2.2 Conttrol requires tthat all staff att all levels of rresponsibility implement thheir assignedroles and ressponsibility for information security.

OPP3.2.3 Conttrol requires tthat there are documented procedures ffor authorizingg and overseeeing those whho work with ssensitive inforrmation or whho work in loccations where such informaation is stored. This inccludes employyees, contractors, partners,, collaboratorss, and personnel from thirdd‐party organiizations, sysstems maintennance personnel, or facilitiees maintenance personnel..

OPP1.1.4 Conttrol requires tthere are docuumented policcies and proceedures for maanaging visitorrs, inccluding signingg in, escort, acccess logs, recception and hoosting.

OPP1.3.2 Conttrol requires tthat an individdual’s or groupp’s actions ‐‐ wwith respect tto all physically conntrolled media ‐‐ can be acccounted for.

© 2007 IAAITC. All rightts reserved.

Asset‐Baased Control CCard ‐ Mediuum Risk ‐ Peopple

Peoplle

A mmedium risk pprofile implies threats that ooccur in manaagement of huuman resourcces of mediumm size entterprises wheen current security practices could lead to business prooblems of mooderate impacct.

Inccidents from immproper use oof passwords or access righhts can lead too information leakage. A medium levvel of confidenntiality of infoormation determines the rissk level or thee money loss ffor the organizzation.

Moonitoring of sttaff policies onn such proceddures ensuresthe confidenttiality, integritty and availabbility of information.

Esssential Controols for securingg the confidenntiality, integrrity and availaability of information in commbination witth a critical assset like people are the folloowing:

OPP3.2.1 Conttrol requires tthat staff memmbers follow goodg security practice: secuuring informattion for whhich they are rresponsible; nnot divulging ssensitive information to othhers (resistancce to social enggineering); haaving adequatte ability to usse informationn technology hhardware andd software; using good passsword practices; understanding and following securitty policies andd regulations;; recognizing aand repporting incidents.

OPP3.2.2 Conttrol requires tthat all staff att all levels of rresponsibility implement thheir assignedroles and ressponsibility for information security.

OPP1.1.4 Conttrol requires tthere are docuumented policcies and proceedures for maanaging visitorrs, inccluding signingg in, escort, acccess logs, recception and hoosting.

© 2007 IAAITC. All rightts reserved.

Asset‐Baased Control CCard ‐ Low Riisk ‐ People

Peoplle

A loow risk profilee implies poteential threats with low impaact on management of humman resourcess when currrent security practices couuld lead to bussiness problemms but with a minimum riskk for the organization.

Criticality of infoormation is noot of a high levvel. Thus, imppact in financiaal terms is loww and money loss can be considered as insignificantt.

Hoowever, monittoring of staff policies even on such proccedures furtheer ensures thee confidentialiity, integrity and avaailability of infformation.

Esssential Controol for securing the confidentiality, integrity and availabbility of informmation in commbination witth people is thhe following:

OPP1.1.4 Conttrol requires tthat there are documented policies and procedures foor managing vvisitors, inccluding signingg in, escort, acccess logs, recception and hoosting.

© 2007 IAAITC. All rightts reserved.

Asset‐ Based Control Card ‐ High Risk ‐‐ Application

Appliccation

Application‐based connfidentiality coontrols for a hhigh risk organnizational proffile typically address security requiremments on an appplication, sysstem, networkk and people level to safeguard critical innformation liffecycle. Controls are selected mmainly to adddress informattion assets froom disclosure to unauthorizzed entities wwhether external or internal to the environmment.

Essential Controls for tthe protectionn of confidenttiality in critical assets are tthe following:

OP2.4.2 Control reqquires documeented informaation‐use policies and procedures for inddividual and group access to (A) esttablish the rulles for grantinng the appropriate level of aaccess, (B) esttablish an initial right of acccess, (C) modify thhe right of acccess, (D) terminate the righht of access, and (F) periodically review aand verify the rights of access.

OP2.5.1 Control reqquires that theere is a docummented set of procedures foor managing vvulnerabilitiess, including selectingg vulnerability evaluation toools, checklistss, and scripts,, keeping up to date with knnown vulneraability types and attacck methods, reviewing sourrces of informmation on vulnnerability annoouncements, security alertss, and notices, iidentifying inffrastructure coomponents too be evaluatedd, scheduling of vulnerability evaluationss, interpretingg and responding to thee results, mainntaining secure storage andd disposition oof vulnerabilityy data.

OP2.1.3 Control reqquires that sennsitive informmation is proteected by securre storage succh as defined cchains of custody, backups storeed off site, remmovable storaage media, disscard process for sensitive information oor its storage media.

OP2.1.4 Control reqquires that thee integrity of iinstalled softwware is regularly verified.

OP2.1.6 Control reqquires that theere is a docummented data bbackup plan thhat is routinelyy updated, is periodically tested, caalls for regulaarly scheduledd backups of bboth software and data andd requires periiodic testing aand verification of the ability to restore from backupss.

OP2.6.1 Control reqquires appropriate security controls to bee used to prottect sensitive information wwhile in storage aand during traansmission inccluding data eencryption durring transmisssion, data enccryption whenn writing to disk, use of public key infrastructuree, virtual privaate network technology, annd encryption for all Internet‐based transmisssion.

©© 2007 IAAITCC. All rights resserved.

Asset‐Baased Control CCard ‐ Mediuum Risk ‐ Appllication

Appliccation

A mmedium risk pprofile implies storage and pprocessing of internal or moderate‐valuee proprietary information thatt would typicaally incur a generic threat pprofile involvinng external malicious entities intending to viollate or comprromise specificc and moderaate‐value inforrmation confidentiality. Application‐ bassed confidenttiality controlss for a mediumm risk organizational profilee typically adddress security reqquirements onn an applicatioon, system, neetwork and peeople level to safeguard criitical informattion life‐ cyccle. Applicatioon‐based integgritycontrols for a mediumm risk organizaational profile define the levvel of acccuracy of information of ann application wwhile availability refers to the level of acccessibility.

Esssential Controols for the prottection of connfidentiality, integrity and aavailability in aapplications aare the following:

OPP2.4.2 Conttrol requires tthat there are documented information‐‐use policies and procedurees for inddividual and group access too establish thee rules for graanting the apppropriate leveel of access, esstablish an initial rightoff access, modify the right oof access, termminate the righht of access annd periodically review andd verify the rigghts of accesss.

OPP2.6.1 Conttrol requires aappropriate seecurity controols to be used to protect sensitive informmation whhile in storage and during trransmission inncluding data encryption duuring transmisssion, data enncryption whhen writing to disk, use of ppublic key infraastructure, virrtual private nnetwork technnology, encrypption for all Internet‐baseed transmissioon.

OPP2.1.6 Conttrol requires tthat there is a documented data backup plan that is rooutinely updated, is peeriodicallytestted, calls for rregularly scheduled backupps of both softtware and datta and requirees peeriodic testingg and verification of the ability to restoree from backupps.

OPP2.1.7 Conttrol requires aall staff understand and is aable to carry oout their respoonsibilities under the baackup plans.

© 2007 IAAITC. All rightts reserved.

Asset‐Baased Control CCard ‐ Low Riisk ‐ Applicatiion

Appliccation

A loow risk profilee implies storaage and proceessing of public or internal information bbut with no critical levvel of importance that woulld entail moree than a minimmal loss of mooney. Organizaation reputation is not at sstake. However, controls thhat would preevent even thaat kind of infoormation leakaage and that ccan seccure the information life‐cyycle should bee applied.

Furrthermore, evven if there is no confidentiiality impact, information inntegrity and aavailability to eevery autthorized user must be secuured.

An essential conntrol for confiddentiality in thhe applicationn asset is the ffollowing:

OPP2.4.2 Conttrol requires tthat there are documented information‐‐use policies and procedurees for inddividual and group access too establish thee rules for graanting the apppropriate leveel of access, esstablish an initial rightoff access, modify the right oof access, termminate the righht of access annd periodically review andd verify the rigghts of accesss.

© 2007 IAAITC. All rightts reserved.

IAAITC Asset‐Based Controls

© 2007 IAAITC. All rights reserved.

IAAITC Asset‐Based Controls

© 2007 IAAITC. All rights reserved.

IAAITC Asset‐Based Controls

© 2007 IAAITC. All rights reserved.

IAAITC Asset‐Based Controls

© 2007 IAAITC. All rights reserved.

IAAITC Asset‐Based Controls

© 2007 IAAITC. All rights reserved.

Risk Management & IT Security Action Checklist

Risk Profile Selection Consider the business risk aspects of information

;

protection that can: (a) result in legal and regulatory non‐compliance, (b) decrease productivity. (c) create financial loss (d) directly or indirectly affect or damage reputation and customer confidence,

Identify your Critical Assets Systems ;

Network People Applications

Select Controls Assets ;

Organisational

Create a Security Policy Document ;

Publish Review

Know where your Critical Data is Documents ;

actually held: Accounting Data

• On IT Systems Email

Specialist Applications

• Paper Systems

PC Operating Systems Older versions of PC Operating Systems do not

;

necessarily have the latest security features available. Versions designed for business usually have more security features than versions designed for home users. Make sure you are using the appropriate operating system version. Passwords Use Strong Passwords, and consider implementing

;

passwords at the BIOS level on laptops. Virus, Worms & Trojans Use anti‐virus software and ensure that the appropriate

;

features are enabled. Spam Understand how your e‐mail software handles Spam,

;

consider upgradingyour anti‐virus software to include this feature. Spyware Your anti‐virus software will probably also support this,

;

but again ensure that it is enabled. Firewalls Firewalls can be built into your operating system, or

;

included as part of your router, make sure that yours is actually switched on and working. Patches Keep all of your software up to dateby enabling the

;

automatic update features. But do ensure that you run them as soon as they are available. Backups Locally to tape or CD

;

Remotely via the Internet Wireless Networks Ensure that the security is “turned on” so that

;

unauthorised users can not access your network.

© 2007 IAAITC. All rights reserved.

Risk Management & IT Security

Protect your IP When sending information electronically ensure that it is

;

in a format that prevents the information being extracted and re‐used. House Keeping Deleting Files – When deleting files often the file is just

;

moved to a “deleted items” folder or the “waste bin”, ensure you “empty” them regularly. CDs – If you have application software that was provided on CD then ensure that those CDs, with authorisation codes are stored somewhere safely and preferably off site. Encrypt Data Business versions of PC operating Systems will allow you

;

to encrypt the data, that way if the PC is stolen the data can not be read. Consider implementing this for laptops. Browser Software The latest versions of your browser software will support

;

things like anti – phishing. Ensure your browser software is up to date and that the feature is switched on. Removable Devices There are an increasing number of devices that can be

;

connected to your PC and allow for the exchange of data. USB memory sticks, but also PDAs, mobile phones, i‐pods and cameras. Your PC sees all of these as external storage and you can easily move files between them. If you want to! Remote Workers Increasingly remote workers are provided with PCs, and

;

access to the corporate system via the internet. Ensure the data on their PCs is backed up and remote access is via a secure channel. E‐commerce If you have a web site that allows customers to order and

;

pay for products ensure that this is secure. Data Protection Act Understand your responsibilities under the DPA

;

Physical Security Don’t forget that you probably still have lots of business

;

critical information on paper. Ensure that it is kept securely as well. Disaster Recovery & Business Even the smallest business should have a basic plan. For

;

Continuity it to be successful it is inevitable that some form of off site storage will be required.

Whilst the above list is comprehensive it is not exhaustive. All businesses are different and if you have any doubts at all then you are advised to take independent advice before implementing a Strategy.

© 2007 IAAITC. All rights reserved.

IT Security Check ‐ Questionnaire IT Security Check About your business

Type of business. Retail Service Distribution Manufacturing Location High Street Industrial / Commercial business park Countryside Number of employees Number of sites/premises

Onsite security: Are the access points to your building secured? YES NO Action Required

Doors/ Gates Locks Windows Skylight Emergency exits

Is your company guarded? YES NO Action Required

Porter Security service Alarm system Visual surveillance (e.g. webcam)

Are there any secure areas in your building? YES NO Action Required

Document archive Accountancy Cash box Safe Server room (server)

Access to special and secured areas for certain groups of persons YES NO Action Required

© 2007 IAAITC. All rights reserved.

IT Security Check ‐ Questionnaire Is access to the building or parts of it logged? YES NO Action Required

Document archive Accountancy Cash box Safe

Server room (server) Do you securely dispose of critical material? YES NO Action Required

Accountancy Logs, printouts Hard copy documents in general Computer and spare parts

Do you dispose of storage media? YES NO Action Required

Discs Hard drives CD, DVD Tapes Other

© 2007 IAAITC. All rights reserved.

IT Security Check ‐ Questionnaire Internal networks / WLAN Do you operate an internal network? YES NO Which technology do you use: YES NO

Windows Linux UNIX

Do you have documentation for?

YES NO Action Required Network connectors Connected computers Printers Modems Other devices

Wireless networks / WLAN

Which type: YES NO Action Required Access control / encryption available

How do you control access/ connection to the network?

YES NO Action Required Switch / patch Mac addresses Encryption

Do you control connection of devices / computers to the network?

Open Controlled Action Required Activate computers Create users and approved devices

Are modems attached?

Open Controlled Action Required Function of modems Configuration of modems Administration of access data for modems

Do you have documentation about network architecture and components?

YES NO Action Required Documentation up to date Roles and responsibilities defined

© 2007 IAAITC. All rights reserved.

IT Security Check ‐ Questionnaire Data Backup/Data Protection/Hard Copy Documents How may PC do you use?

Type/manufacturer: Operating system:

Do you have a central file server?

Type/manufacturer: Operating system Employee Third Party Unknown Server installation Server maintenance Scheduled? Configuration documented

Are redundant mass storage devices in place?

YES NO Action Required / Planned RAID Mirror server Backup / test server

Where do you store paper documents?

YES NO Action Required / Planned Office Archive External

Are employees instructed to save electronic data on the fileserver?

YES NO Action Required / Planned

Do you use external drives?

YES NO Action Required / Planned USB CD DVD Document server

How do you archive electronic data?

YES NO Action Required / Planned Office Archive External

© 2007 IAAITC. All rights reserved.

IT Security Check ‐ Questionnaire Is access control for files and data in place?

YES NO Action Required / Planned User name/ password public/ private folders database access control other Responsibility for access control defined Administration access / user / passwords defined Compliance with directives checked Backup of application data Daily of more often Monthly Seldom Backup of applications Purchased standard applications Purchased custom applications Self produced applications How are data backed up? Standard applications Backup applications Self-produced system Is there an automatic backup? Responsibility for backup defined Backup data is checked Documentation available Which backup media are used? Disc Tape / type CD/DVD External drives/ removable hard drives Do you do backups to external servers via secure Internet connection? Do you do backups to external servers via secure Internet connection? Do you store backup media externally? External storage of backup media Access to external backup media Do you label backup media? Do you overwrite backup media according to a schedule (cyclical)? Storage of original media of licensed software External backup available Access to original media Access to original media is

© 2007 IAAITC. All rights reserved.

IT Security Check ‐ Questionnaire

logged Installation of original media Licensed software Compatible to new hardware Check of license agreements Is there a regular re-check? Is the re-check documented? Backups older than 12 months Can they still be read Are they tested regularly Are they copied to new media Is the use of portable storage media like USB sticks or removable hard drives authorised? Do you have an emergency plan? emergency plan tested regularly

© 2007 IAAITC. All rights reserved.

IT Security Check ‐ Questionnaire Laptop / Mobile Devices Do you use mobile devices?

YES NO Action Required / Planned Laptop PDA/ handheld Telephone with data interface Camera devices (mobile, PDA)

Where do you use these mobile devices?

YES NO Action Required / Planned Office Home office On the go

Is access control implemented?

YES NO Action Required / Planned User / password Encryption Mechanical access control

What data is stored on mobile devices?

YES NO Action Required / Planned Copies of server data Private data Client information, etc..

Documentation and registration of mobile devices and their usage

YES NO Action Required / Planned Hardware Software

© 2007 IAAITC. All rights reserved.

IT Security Check ‐ Questionnaire Internet connection

YES NO Action Required / Planned Do you have Internet connection? Responsibility for router defined Type of Internet connection Dial in DSL based broadband solution Cable-TV based broadband solution Wireless connection to provider Dedicated line

Do you operate a firewall?

YES NO Action Required / Planned Type / manufacturer: Employee Third Party Unknown Who has installed the firewall Who maintains the firewall YES NO Action Required / Planned Configuration documentation available

Do you run your own mail server?

YES NO Action Required / Planned Type / manufacturer: Employee Third Party Unknown Who has installed the mail server Who maintains the mail server YES NO Action Required / Planned Configuration documentation available Do you secure the mail server

Do you use a proxy?

YES NO Action Required / Planned Proxy filter installed?

Do you run a web server?

© 2007 IAAITC. All rights reserved.

IT Security Check ‐ Questionnaire Malware Operating System

Open Controlled Action Required / Planned administrator rights on computer and server Employee Third Party Unknown Who is responsible for operating system updates? Regular updates YES NO Action Required / Planned Responsibility for license management Responsibility for installation and updates

Applications

Open Controlled Action Required / Planned

Employee Third Party Unknown Who is responsible for application updates? Regular updates YES NO Action Required / Planned Responsibility for license management Responsibility for installation and updates Do you use security settings for applications

Which anti-virus software do you use?

Open Controlled Action Required / Planned

Employee Third Party Unknown Regular updates YES NO Action Required / Planned Responsibility for license management Responsibility for installation and updates Are protocols analysed and discussed regularly

Against what kind of malware is the system protected?

YES NO Action Required / Planned Spyware/adware Server side protection against spyware possible? Spam

© 2007 IAAITC. All rights reserved.

IT Security Check ‐ Questionnaire Written Documentation of Directives / Protocol

YES NO Action Required / Planned Usage of computers in the company Treatment of data (personal)

Hard copy documents Electronic documents

Email correspondence Open Controlled Action Required / Planned What contents may be sent via email For which purpose may email be used

Access to the Internet Open Controlled Action Required / Planned Who may use the Internet for what purpose How is private usage defined and authorised YES NO Action Required / Planned installation and configuration of computer systems documented How is compliance with directives checked Procedures for leaving employees Rules of conduct for employees e.g. if viruses occur

© 2007 IAAITC. All rights reserved.

IT Security Check ‐ Questionnaire Other

YES NO Action Required / Planned Is employee personal data treated according to the Data Protection Act Is client / supplier data treated according to Data Protection Act

Software Application Checklist YES NO Action Required / Planned Internet Security Suite Operating system Anti-virus scanner Firewall/spyware/spam filter

Office products Other software

© 2007 IAAITC. All rights reserved.

Notes

This guide has been developed by the International Association of Accountants Innovation & Technology Consultants (IAAITC) in co‐operation with the European Network and Information Security Agency (ENISA), the Micro Entrepreneurs Acceleration Institute (MEA‐I), and WKO‐ Information and Consulting Division. The respective trademarks and copyright of all contributing parties are acknowledged and all rights reserved. Other product and company names mentioned herein may be the trademarks of their respective owners. The material in this guide reflected acknowledged best practice as at December 2007. This document is for educational and informational purposes only. Neither the IAAITC nor other contributing parties makes any warranties, express or implied, in this document. Readers should consider taking appropriate professional advice before acting on any issue raised. It may be freely distributed but all rights are acknowledged and retained.

Fotnoter

  1. Risk Profiling
  2. Identify Risk
  3. Use Risk Evaluation Matrix to mark customer confidence,
  4. applicable risk areas (Legal and Regulatory, Productivity, Financial Stability, Marketing) and risk levels
  5. (high, medium,low)
  6. Identify Business Risk Profile. Typically highest risk levels in risk two steps. classes define the overall business risk profile.
  7. Legaland Business handlescustomer Business handles customer Business does nothandle personal Regulatory information ofa sensitiveand information ofa personal butnot data otherthan those of the people personal nature including medical sensitivenature as defined bythe employed bythe business. recordsand critical personal data EUData Protection Law. as defined by the EUData Protection Law.
  8. Productivity Business employs morethan 100 Business employs morethan 50 Business employs lessthan 10 employees who haveadaily need employees who haveadaily need employees who havea dailyneed to to access business applications to access business applicationsand access business applicationsand and services. services. services.
  9. Financial Stability Yearly revenuesof the business Yearly revenuesof the businessdo Yearly revenuesof the business do exceed £15 million or/and notexceed £6million. not exceed £1 million. financial transactionswith third partiesor customersare taking place as part ofthe business as usual process.
  10. Reputationand Unavailability or Service Quality Unavailability or Service Quality Unavailability or Service Quality Loss of Customer directlyimpact the businesses of can indirectlyimpactthe cannot directlyorindirectlyimpact Confidence the organisation or/and more businesses of the organization and/ the businesses of the organization or than 70% ofcustomer base have or less than 5% ofcustomer base result in loss of revenues. online access to business products have online access to business and services. products and services.
  11. Systems Information systems that process and store information.Systems are a Server combination of information, software, and hardwareassets. Anyhost, client, Laptop server, or network can be considered asystem. Critical systemsare those identified as essential forthe continuous provision of the businessservice and Workstation product offerings, those that store criticalbusiness information(customer or Archiving and Backup business proprietary)or these that are exposedto the outside world for business functions or services. Storage
  12. Network Devices important to the organization’s networks. Routers,switches, and Routers modems are all examples of thisclass ofcomponent. Wireless components/ Cabling devices, such as cell phonesand wireless accesspoints thatstaff members use to access information (forexample, email).Typically, critical networks are Gateways those that are used to support essentialcritical applications or systems or WirelessAccess Points those that are shared withthirdparty and usuallyun‐trusted networks. Network Segment (e.g. cablingand equipment between twocomputers) Other (SAT, Laser)
  13. People Peoplein the organization, including their skills,training, knowledge, and Business and HumanResourcesManagement experience. Criticalpeopleare those that play akey role in productionor operational processes. Importanceshould be givento critical resources Operations and Technology (people) that areconsidered irreplaceableor constitute asingle pointof Research and Development failure. Salesand Marketing Contractors and Third Parties
  14. Applications Critical Applications.Applications that arekey to orpart of the product and Financial Control service offerings. Disruption ofcritical applicationstypically resultsin severe Customer Care hindering or evencongestion of the dependent processes. Logistics E‐commerce ERP
  15. Systems A system withconfidentiality requirements Systems withintegrity requirements Availability requirements are often handles informationwith corporate typically handle transactions of financial encounteredin systems that are proprietary information (R&D), customer nature, procurement of goods ore‐ critical to daily businessoperations baseinformation, sensitivecustomer commerce. and where downtimeusually incurs information ofmedical or personal nature. costsand overheadsin terms of resourceallocation.
  16. Network A networkwith confidentiality Network integrity requirements are Availability requirements are requirements typically covers typically necessary when transactionsthat especially necessary when the communications and informationexchange take place overpublic and shared networkis used as part ofcustomer over insecure and un‐trusted environments. metropolitan network or care, or service and product offerings. telecommunication providers.
  17. People Confidentialityrequirements are typically Integrity requirements when people are Availability requirements for people encounteredwhen people handle concerned addressshared secretslike assetsare especiallyimportant when organizational proprietary and confidential cryptographic keys or passwords. these peopleare critical resources for information that whendisclosed can Possession ofsuch knowledgeintroduces the continuous operationsof the damage the organization’sbrand nameand human factor threats that shouldbe service or product offerings. customer base. addressed with respective controls.
  18. Applications Applications withconfidentiality Applications withintegrity requirements Availability requirements are metin requirements often handle information with typically handle transactions of financial applications thatare critical to the corporate proprietary information (R&D), nature, procurement of goodor e‐ businessdaily operationsand where customer baseinformation, sensitive commerce. downtimeusually incurs costs and customer information ofmedical or overheads interms ofresource personal nature. allocation.
  19. While selecting critical assetsin step 1,a numberof issues related to theseassets arediscussed. In this stepthe rationale for selecting eachcritical asset is documentedfor futurereference during the decision making process. In addition,understanding why anasset is critical can better enable the definition of the security requirements during the nextstep. For eachcritical asset,the following questions should be consideredand answers recorded: • Why is the asset critical to meeting the mission of the organization? • Who controlsit? • Who is responsible for it? • Who usesit? • How is it used? Thesequestions focus onhow assets areused and why they areimportant. Ifanswers to all of thesequestions are notprovided, peoplein the organizationwho canprovide the answers must be located and includedin the analysis team. The informationthat is generated by answeringthese questions will be usefullater in thisprocess. In thisregard, information gatheredhere mustbe carefully recorded.
  20. One of the principles of the risk assessment method is settingthe foundation for a continuous process. This principle addressesthe needto implement the results of an information security risk evaluation, providing the basis for security improvement. If a business fails to implement the results ofan evaluation, it will also fail to improveits security position.
  21. One of the mostdifficult tasks in any improvement activity is maintaining the momentum generated during an evaluation. However, practical considerations will prevent most organizations from immediately implementing allof the initiatives after the evaluation. MSBs will likely have limited funds and staff members availableto implement the protection strategy.
  22. In thisstep analysis teamsprioritise the activities and then focuson implementing the highest‐priority activities. Two distinct options are provided: • Risks accepting. When a risk is accepted, no action toreduce the risks is taken and the consequences should the risk materialise are accepted. • Risks mitigating. When a risk is mitigated, actions designed to counter the threat and thereby reduce the risk are identifiedand enforced. Now thatspecific action items have been identified, analysis team members need to assignresponsibility for completingthem aswell as seta completion date. Answers ‐‐ for each action item ‐‐ to the following questions must be reordered: • Who will be responsible for eachaction item? • What can management do to facilitate the completion of this action item? • How muchwill it cost? • How long will ittake? • Can we do it ourselves? • Do we need external assistance?
  23. The last twoquestions are critical towhether a businesscan handleimplementation ofthe necessary controlsinternally. The answers to theseare equally important and very hard to establish sinceboth (outsource or in‐source) have benefitsand disadvantages. Outsourcing is the “make orbuy” decision appliedto theresource in question. Ifit is doneright, outsourcing canoffer definiteadvantages. The main objectives for outsourcingare, besidessupport functions, cost‐cutting, downsizing, and a desireto focus onthe business (core competence). The lackof IT competence in the businesscan alsobe a reason for IToutsourcing. AsIT is getting more important, companiesfrequently confront awide disparity betweenthe capabilities and skills necessary to realizethe potential ofinformation technology and the realityof their own in‐housetechnology expertise.
  24. Asset Baased Control Caard ID CC-1S
  25. Risk Proffile High
  26. Asset Caategory System
  27. Security Requirements ty d ri n d u on and n nt tio an o yy nt nt g ilit me IT me on ture an me rin g ticati c t l Staff o n n orkork nistra ss tin ww
  28. Physical Sec System and NetNet Manage System Admi ToolTool Monit Audi Security Authen Authorizati Vulnerab Manage Encrypti Security Archite Desig Incide Manage Genera Practices
  29. Asset Bassed Control Caard ID CC-2S
  30. Risk Profiile Medium
  31. Asset Cattegory System
  32. Security RRequirements ty dd ri n d u n an an on and t nt tio an o nt g ility en me IT on tureture me rin g ticati em cc t l Staff nistra o gg n n orkork s tin ww ls oooo Physical Sec System and NetNet Manage System Admi T Monit Audi Security Authen Authorizati Vulnerab Mana Encrypti Security ArchiteArchite Desig Incide Manage Genera Practices
  33. Confidenttiality 2.1.66
  34. Integrity 2.1.99 2.4.1
  35. Availabilitty 2.1.66
  36. Asset Baased Control CCard ID CC-3S
  37. Risk Proofile Low
  38. Asset Caategory System
  39. Securityy Requirementss ty d ri n d u on and n nt tio an o nt nt g ility me IT me on ture an me kk rin g ticati ) yy c t l Staff o 5 n n nistra tin .5) ss twor e Physical Sec System and NtN Manage System Admi ToolTool Monit Audi Security Authen Authorizati Vulnerab Manage (OP2(OP2 Encrypti Securit Archite Desig Incide Manage Genera Practices
  40. Confidenntiality 2.1.9 2.4.1
  41. Integrityy 2.4.1
  42. Availability 2.1.6
  43. Asset Bassed Control Caard ID CC-1N
  44. Risk Profiile High
  45. Asset Cattegory Network
  46. Security RRequirements ty d ri n d u on and n nt tio an o ntnt ntnt g ility me IT meme on ture an meme kk rin g ticati c t l Staff o n n nistra s tin twor e Physical Sec System and NtN Manage System Admi Tool Monit Audi Security Authen Authorizati Vulnerab ManageManage Encrypti SecuritySecurity Archite Desig Incide ManageManage Genera Practices
  47. Confidenttiality 2.4.6 2.5.33 2.6.1
  48. Integrity 2.4.1
  49. Availabilitty 1.1.4 2.4.6
  50. Asset Baased Control CCard ID CC-2N
  51. Risk Proofile Medium
  52. Asset Caategory Network
  53. Securityy Requirementss ty d ri n d u on and n nt tio an o nt nt g ility me IT me on ture an me k rin g ticati ) yy c t l Staff nistra o 5 n n ss tin .5)
  54. etwor Physical Sec System and NkN Manage System Admi ToolTool Monit Audi Security Authen Authorizati Vulnerab Manage (OP2(OP2 Encrypti Securit Archite Desig Incide Manage Genera Practices
  55. Confidenntiality 2.6.1
  56. Integrityy 2.4.3
  57. Availability 2.1.5
  58. Asset Based Control CCard ID CC-3N
  59. Risk Proofile Low
  60. Asset Category Network
  61. Securityy Requirementss ty d ri n d u on and n nt tio an o nt nt g ility me IT me on ture an me rin g ticati ) yy c t l Staff nistra o 5 n n ork ss tin .5) w Physical Sec System and Net Manage System Admi ToolTool Monit Audi Security Authen Authorizati Vulnerab Manage (OP2(OP2 Encrypti Securit Archite Desig Incide Manage Genera Practices
  62. Confidentiality 2.6.1
  63. Asset Based Control CCard ID CC-1P
  64. Risk Proofile High
  65. Asset Category People
  66. Securityy Requirementss ty d ri n d u on and n t nt tio an o nt g ility en and me IT on ture an me and rin g ticati yy c t l Staff em n ork nistra o gg n s tin w Physical Sec SystemSystem Net Manage System Admi Tool Monit Audi Security Authen Authorizati Vulnerab Mana Encrypti Securit Archite Desig Incide Manage Genera Practices
  67. Confidentiality 3.2.1
  68. Integrityy 3.2.1
  69. Asset Bassed Control Caard ID CC-2P
  70. Risk Profiile Medium
  71. Asset Cattegory People
  72. Security RRequirements n ty o dd ri n d nn u ati an an oo nt tio an nt nt g ility me IT me on tureture me rin g ticatiticati thoriz ) cc t l Staff nistra o u n n orkork s tin ww Physical Sec System and NetNet Manage System Admi Tool Monit Audi Security AuthenAuthen and A Vulnerab Manage (OP2.5() Encrypti Security ArchiteArchite Desig Incide Manage Genera Practices
  73. Confidenttiality 3.2.1
  74. Integrity 3.2.1
  75. Availabilitty 1.1.4
  76. Asset Bassed Control Caard ID CC-3P
  77. Risk Profiile Low
  78. Asset Cattegory People
  79. Security RRequirements rity nd ty u a and dd ri n d nn u n an an oo nt tio an o nt nt g ility me IT Sec me on tureture me rin g ticatiticati ) cc t l Staff nistra o n n orkork s tin ww Physical Sec System and NetNet Manage System Admi Tool Monit Audi AuthenAuthen Authorizati Vulnerab Manage (OP2.5() Encrypti Security ArchiteArchite Desig Incide Manage Genera Practices
  80. Availabilitty 1.1.4
  81. AssetBasedd Control CardIDD CC‐1A
  82. Risk Profile High
  83. AssetCateggory Application
  84. SecurityReqquirements k y re Tools rit and d u itectu t Networ an Sec d ch en ation IT ility n Security mentment ng ment Ar m Staff an ri tication b gege istr ng n ge nt to ti orization era Desig age ysical nana min ni th ln na ide d an udi Ph System MaMa System Ad Mo A Authe Au Vu Ma Encryption Security an Inc MtM General Practices
  85. Confidentiaality 2.1.33 2.4.2 2.5.11 2.6.1
  86. Integrity 2.1.44 2.4.2 2.5.11 2.6.1
  87. Availability 2.1.66
  88. Asset Bassed Control Caard ID CC-2A
  89. Risk Profiile Medium
  90. Asset Cattegory Application
  91. Security RRequirements ty d ri n d u on and n t nt tio an o nt n g ility e me IT me on ture an m rin g ticati y c t l Staff o tit n n orkork nistra tin s ww ecur anage Physical Sec System and NetNet Manage System Admi Tool Monit Audi Security Authen Authorizati Vulnerab Manage Encrypti SiS Archite Desig Incide MtM Genera Practices
  92. Confidenttiality 2.4.2 2.6.1
  93. Integrity 2.4.2
  94. Availabilitty 2.1.66
  95. Asset Based Control CCard ID CC-3A
  96. Risk Proofile Low
  97. Asset Category Applicationn
  98. Securityy Requirementss rity ty u d ri n d u on and n nt tio an o nt nt g ility me IT Sec me on ture an me rin g ticati ) yy c t l Staff o 5 n n ork nistra tin .5) ss w Physical Sec System and Net Manage System Admi ToolTool Monit Audi Authen Authorizati Vulnerab Manage (OP2(OP2 Encrypti Securit Archite Desig Incide Manage Genera Practices
  99. Confidentiality 2.4.2
  100. Physical Security (OP1)
  101. Physical Security Plans and Procedures (OP1.1)
  102. There are documented facility security plan(s) for safeguarding the premises, buildings, and any restricted OP1.1.1 areas. OP1.1.2 These plans are periodically reviewed, tested, and updated. OP1.1.3 Physical security procedures and mechanisms are routinely tested and revised. There are documented policies and procedures for managing visitors, including · sign in OP1.1.4 · escort · access logs · reception and hosting There are documented policies and procedures for physical control of hardware and software, including · workstations, laptops, modems, wireless components, and all other components used to access information · access, storage, and retrieval of data backups OP1.1.5 · storage of sensitive information on physical and electronic media · disposal of sensitive information or the media on which it is stored · reuse and recycling of paper and electronic media
  103. Physical Access Control (OP1.2)
  104. There are documented policies and procedures for individual and group access covering · the rules for granting the appropriate level of physical access · the rules for setting an initial right of access OP1.2.1 · modifying the right of access · terminating the right of access · periodically reviewing and verifying the rights of access There are documented policies, procedures, and mechanisms for controlling physical access to defined entities. This includes OP1.2.2 · work areas · hardware (computers, communication devices, etc.) and software media OP1.2.3 There are documented procedures for verifying access authorization prior to granting physical access. Workstations and other components that allow access to sensitive information are physically safeguarded to OP1.2.4 prevent unauthorized access.
  105. Monitoring and Auditing Physical Security (OP1.3)
  106. OP1.3.1 Maintenance records are kept to document the repairs and modifications of a facility’s physical components. OP1.3.2 An individual’s or group’s actions, with respect to all physically controlled media, can be accounted for. OP1.3.3 Audit and monitoring records are routinely examined for anomalies, and corrective action is taken as needed.
  107. Information Technology Security (OP2)
  108. System and Network Management (OP2.1)
  109. OP2.1.1 There are documented security plan(s) for safeguarding the systems and networks. OP2.1.2 Security plan(s) are periodically reviewed, tested, and updated. Sensitive information is protected by secure storage, such as · defined chains of custody OP2.1.3 · backups stored off site · removable storage media · discard process for sensitive information or its storage media OP2.1.4 The integrity of installed software is regularly verified. OP2.1.5 All systems are up to date with respect to revisions, patches, and recommendations in security advisories. There is a documented data backup plan that · is routinely updated OP2.1.6 · is periodically tested · calls for regularly scheduled backups of both software and data · requires periodic testing and verification of the ability to restore from backups OP2.1.7 All staff understands and is able to carry out their responsibilities under the backup plans. OP2.1.8 Changes to IT hardware and software are planned, controlled, and documented. IT staff members follow procedures when issuing, changing, and terminating users’ passwords, accounts, and privileges. OP2.1.9 · Unique user identification is required for all information system users, including third-party users. · Default accounts and default passwords have been removed from systems. OP2.1.10 Only necessary services are running on systems – all unnecessary services have been removed.
  110. System Administration Tools (OP2.2)
  111. New security tools, procedures, and mechanisms are routinely reviewed for applicability in meeting the OP2.2.1 organization’s security strategies. Tools and mechanisms for secure system and network administration are used, and are routinely reviewed and updated or replaced. Examples are · data integrity checkers · cryptographic tools · vulnerability scanners · password quality-checking tools OP2.2.2 · virus scanners · process management tools · intrusion detection systems · secure remote administrations · network service tools · traffic analyzers
  112. · incident response tools · forensic tools for data analysis
  113. Monitoring and Auditing IT Security (OP2.3)
  114. System and network monitoring and auditing tools are routinely used by the organization. · Activity is monitored by the IT staff. · System and network activity is logged/recorded. OP2.3.1 · Logs are reviewed on a regular basis. · Unusual activity is dealt with according to the appropriate policy or procedure. · Tools are periodically reviewed and updated. OP2.3.2 Firewall and other security components are periodically audited for compliance with policy.
  115. Authentication and Authorization (OP2.4)
  116. Appropriate access controls and user authentication (e.g., file permissions, network configuration) consistent with policy are used to restrict user access to · information · systems utilities · program source code OP2.4.1 · sensitive systems · specific applications and services · network connections within the organization · network connections from outside the organization There are documented information-use policies and procedures for individual and group access to · establish the rules for granting the appropriate level of access · establish an initial right of access OP2.4.2 · modify the right of access · terminate the right of access · periodically review and verify the rights of access Access control methods/mechanisms restrict access to resources according to the access rights determined OP2.4.3 by policies and procedures. OP2.4.4 Access control methods/mechanisms are periodically reviewed and verified. Methods or mechanisms are provided to ensure that sensitive information has not been accessed, altered, or OP2.4.5 destroyed in an unauthorized manner. Authentication mechanisms are used to protect availability, integrity, and confidentiality of sensitive information. Examples are OP2.4.6 · digital signatures · biometrics
  117. Vulnerability Management (OP2.5)
  118. There is a documented set of procedures for managing vulnerabilities, including · selecting vulnerability evaluation tools, checklists, and scripts · keeping up to date with known vulnerability types and attack methods · reviewing sources of information on vulnerability announcements, security alerts, and notices OP2.5.1 · identifying infrastructure components to be evaluated · scheduling of vulnerability evaluations · interpreting and responding to the results · maintaining secure storage and disposition of vulnerability data OP2.5.2 Vulnerability management procedures are followed and are periodically reviewed and updated. Technology vulnerability assessments are performed on a periodic basis, and vulnerabilities are addressed OP2.5.3 when they are identified.
  119. Encryption (OP2.6)
  120. Appropriate security controls are used to protect sensitive information while in storage and during transmission, including · data encryption during transmission · data encryption when writing to disk OP2.6.1 · use of public key infrastructure · virtual private network technology · encryption for all Internet-based transmission OP2.6.2 Encrypted protocols are used when remotely managing systems, routers, and firewalls. OP2.6.3 Encryption controls and protocols are routinely reviewed, verified, and revised.
  121. Security Architecture and Design (OP2.7)
  122. System architecture and design for new and revised systems include considerations for · security strategies, policies, and procedures OP2.7.1 · history of security compromises · results of security risk assessments The organization has up-to-date diagrams that show the enterprise-wide security architecture and network OP2.7.2 topology.
  123. Staff Security (OP3)
  124. Incident Management (OP3.1)
  125. Documented procedures exist for identifying, reporting, and responding to suspected security incidents and violations, including · network-based incidents OP3.1.1 · physical access incidents · social engineering incidents OP3.1.2 Incident management procedures are periodically tested, verified, and updated. OP3.1.3 There are documented policies and procedures for working with law enforcement agencies.
  126. General Staff Practices (OP3.2)
  127. Staff members follow good security practice, such as · securing information for which they are responsible · not divulging sensitive information to others (resistance to social engineering) OP3.2.1 · having adequate ability to use information technology hardware and software · using good password practices · understanding and following security policies and regulations · recognizing and reporting incidents OP3.2.2 All staff at all levels of responsibility implements their assigned roles and responsibility for information security. There are documented procedures for authorizing and overseeing those who work with sensitive information or who work in locations where the information resides. This includes · employees OP3.2.3 · contractors, partners, collaborators, and personnel from third-party organizations · systems maintenance personnel · facilities maintenance personnel