<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-18708747</id><updated>2011-12-09T07:40:51.598-08:00</updated><category term='email policy'/><category term='COBIT'/><category term='security policy'/><category term='security policy responsibility'/><category term='social engineering'/><category term='Social Networking Information Security Policies'/><category term='Information Security Policies'/><category term='iso 27002'/><category term='security policy ownership'/><category term='cyber attacks'/><category term='security awareness'/><category term='phishing'/><category term='regulations'/><category term='employee security policy'/><category term='sanctions policy'/><category term='SAS 70'/><category term='iso 17799'/><category term='data breach'/><category term='BITS'/><category term='mobile security'/><category term='acceptable use policy'/><category term='change notification'/><category term='policy violation'/><category term='written security policies'/><category term='encryption policies'/><category term='policy enforcement'/><category term='document management systems'/><category term='third-party security policies'/><category term='security policy version control'/><category term='identity theft'/><category term='Social Networking'/><title type='text'>Information Security Policy</title><subtitle type='html'>Discussions on the creation and management of information security policies, standards and procedures.  Hosted by Information Shield, publisher of Information Security Policies Made Easy and the PolicyShield Information Security Policy Subscription.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://infosecuritypolicy.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>18</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-18708747.post-6491369108137032904</id><published>2009-09-29T08:31:00.000-07:00</published><updated>2009-09-29T11:22:09.469-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cyber attacks'/><category scheme='http://www.blogger.com/atom/ns#' term='security awareness'/><category scheme='http://www.blogger.com/atom/ns#' term='acceptable use policy'/><title type='text'>Critical Security Policies for Preventing Cyber Attacks</title><content type='html'>Is it possible to declare some security policies as more critical than others? When it comes to protecting sensitive data, all security policies are important to reduce the risk of loss. However, when we look at risk mitigation from the perspective of stopping the latest attacks, some security controls rise to the top.&lt;br /&gt;&lt;br /&gt;In September 2009 the SANS Institute released the latest version of the &lt;a href="http://www.sans.org/top-cyber-security-risks/"&gt;Top Cyber Security Risks.&lt;/a&gt; This analysis is based on real-world data collected from thousands of organizations. One of the objectives is to help understand the most dangerous attacks and how they happen. Based on the SANS analysis, we can highlight some of the critical information security policies that every organization should have.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Desktop Configuration Management Policies&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;The first step in the attack against most enterprises is the exploitation of an application running on the user desktop. Common applications are Adobe Acrobat, Flash and Microsoft Office. In short, these are the applications that many internet users use on a regular basis. Research from the SANS report suggests that IT groups are much more adept at patching servers than desktops. This makes sense, given the large and growing numbers of “end user’ devices that access email and the internet.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Desktop/Laptop Configuration Security Policies&lt;/strong&gt; would clearly rise near the top of any prioritized list of security policies. This type of policy addresses controls that help create and manage a secure “footprint” on end-user machines. These involve a combination of both management and technical controls, including remote scanning and management of user desktops, as well as acceptable-use policies limiting what the user can download on their machine. It may also limit the ability for users to make changes to machine configurations, including updates to security settings. While in some cases these features can be automated by technology, it is still important to document these requirements in written policies.  An effective Configuration Security Policy addresses the entire lifecycle of end-user equipment.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Internet and Email Acceptable Use&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The second phase of an exploit involving a vulnerable machine is the user downloading an infected document. In some cases, a user would only have to visit an infected web site (see the next policy) to be exploited. However, a majority of cases still involve the distribution of infected files via email or downloads.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.informationshield.com/information-security-policies.html"&gt;Internet Acceptable Use Security Policies&lt;/a&gt; are critical to make users aware of safe internet practices and educate them on the type of attacks that they face. Acceptable Use policies can involve a variety of controls, including limits on the type of web sites that can be visited, the duration of time spent on web activities, restrictions on software downloads, and limits on the type of software that can be used to access internet-services. For example, uncontrolled use of Peer-to-Peer (P2P) networking software has lead to a number of high-provide breaches of confidential information. &lt;strong&gt;Email Acceptable Use Policies&lt;/strong&gt; are closely related and can be combined with Internet Acceptable Use policies to help reduce this risk of users making critical information security mistakes.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Web Server Security&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Various forms of technical attacks against web servers are creating a growing network of infected web sites that can be used to distribute malicious software to users. By the far the most common are variations of the SQL Injection attack against web-database applications. These attacks are particularly damaging since a legitimate web site becomes an accomplice in infecting real business users of the site.&lt;br /&gt;&lt;br /&gt;To help protect against these attacks, as well as against other potential data loss through the web, every organization should have a &lt;strong&gt;Web Site Security Policy&lt;/strong&gt;. Based on our research, very few organizations have such a formal policy.  A look at information security frameworks such as ISO 27002, &lt;a href="http://www.informationshield.com/hipaa.html"&gt;HIPAA&lt;/a&gt; and NIST SP 800-53 reveal that web site security not a major focus, and certainly not called out as a key control.&lt;br /&gt;&lt;br /&gt;A related and equally critical policy would be a &lt;strong&gt;Secure Application Development Policy&lt;/strong&gt;. This policy would define various controls for designing, developing and deploying security applications. While this is a key requirement of &lt;a href="http://www.informationshield.com/pcistandards.html"&gt;PCI-DSS &lt;/a&gt;version 1.2, the rampant growth of web application exploits indicated that secure application development must be part of any organization that manages a dynamic web site that accesses a database.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Keeping Security Policies Up to Date&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;The evolving nature of these top threats points to the need for information security and data privacy policies to be updated on a periodic basis. Information Shield has developed our &lt;a href="http://www.informationshield.com/information-security-policies.html"&gt;PolicyShield Security Policy Subscription &lt;/a&gt;to address this critical business need. PolicyShield subscribers will find all of the sample documents mentioned in this article as part of their standard subscription.  Each quarter, we update the subscription with new policies that help you stay protected against the latest threats.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18708747-6491369108137032904?l=infosecuritypolicy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecuritypolicy.blogspot.com/feeds/6491369108137032904/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18708747&amp;postID=6491369108137032904' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/6491369108137032904'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/6491369108137032904'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/2009/09/critical-security-policies-for.html' title='Critical Security Policies for Preventing Cyber Attacks'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18708747.post-2129990411934846848</id><published>2009-04-27T16:28:00.000-07:00</published><updated>2009-04-27T20:16:37.383-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mobile security'/><category scheme='http://www.blogger.com/atom/ns#' term='acceptable use policy'/><title type='text'>Acceptable Use Policies to Reduce Risk</title><content type='html'>A few weeks ago, Deloitte Touche Tohmatsu (DTT) released the results of its &lt;a href="http://www.isaca-malta.org/live/attachments/206_dtt_fsi_GlobalSecuritySurvey_0901.pdf"&gt;Annual Global Security Survey for 2008&lt;/a&gt;.  The survey focuses on the information security needs, practices and priorities of the financial industry, which is among the most regulated of all vertical markets.  Not surprisingly, the top priority for the security officers interviewed was “security regulatory compliance.”  What is a bit surprising was that security compliance took the top spot for the first time, followed by “regulating access control”, which was the number one priority in 2007.&lt;br /&gt;&lt;br /&gt;The report provides a number of interesting details,  many of them pointing to continued problem of the “human factor” in security.  According to the survey, the number one root cause of all security incidents experienced at these organizations was “human error.”  (This is not a surprise, as nearly all data breach and incident studies come to a similar conclusion.)  What IS surprising is that despite the concern about human error, the category for “security awareness and education” was 7th on the overall list of 15 priorities.  While this tremendous gap between cause and prevention is indicated in this report, it is echoed throughout the industry.  Everyone “gets it” that security is fundamentally a people problem, and yet when you look at spending and organizational priorities, education and awareness is near the middle or bottom of the list.&lt;br /&gt;&lt;br /&gt;When new technology is introduced into the mix, the potential knowledge gap widens as technology makes into production before the much-needed awareness and policy guidance.  In fact, the report revealed a fairly large gap between the deployment of new technology and the issuing of specific policies and guidance on the safe use of the technology.&lt;br /&gt;&lt;br /&gt;One prime example is mobile security.  According to the survey, very few organizations (less that 10%) actually prohibit the use of mobile storage (USB drives, Media Players, etc.) because of fears that this will limit productivity.  In other words, 90% of organizations are using mobile storage in the enterprise.  Yet only 40% of these same organizations publish policies and procedures on acceptable use of mobile storage.  The statistics are similar for mobile computing technology (handheld computers, PDA, etc.).  Only 27% limit these devices, and yet only 42% claim to have issued acceptable use policies.&lt;br /&gt;&lt;br /&gt;Given the facts that human error is the root cause of most security incidents, the “knowledge gap” created when organizations permit technology without written &lt;a href="http://www.informationshield.com/information-security-policies.html"&gt;acceptable use policies &lt;/a&gt;represents a significant risk.  Written security policies are the official “contract” between management and employees on the appropriate use and misuse of new technology.  And while polices do not replace awareness and training, they significantly enhance these efforts by forcing management to think through the various risks and trade-offs of adopting new technology.  &lt;br /&gt;&lt;br /&gt;If your organization is searching for cost-effective ways to keep policies updated based on the latest technologies, we encourage you to evaluate our &lt;a href="http://www.informationshield.com/information-security-policies.html"&gt;PolicyShield Security Policy Subscription&lt;/a&gt;. We believe written policies are key for enabling safe, yet productive use of new technology.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18708747-2129990411934846848?l=infosecuritypolicy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecuritypolicy.blogspot.com/feeds/2129990411934846848/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18708747&amp;postID=2129990411934846848' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/2129990411934846848'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/2129990411934846848'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/2009/04/acceptable-use-policies-to-reduce-risk.html' title='Acceptable Use Policies to Reduce Risk'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18708747.post-936010992190386110</id><published>2009-02-17T12:44:00.000-08:00</published><updated>2009-02-19T09:42:15.291-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sanctions policy'/><category scheme='http://www.blogger.com/atom/ns#' term='employee security policy'/><title type='text'>Ideas for Security Policy Sanctions</title><content type='html'>In order for written &lt;a href="http://www.informationshield.com/information-security-policies.html"&gt;information security policies&lt;/a&gt; to have "teeth", there must be consequences for employees that do not follow policies, and this fact must be documented as part of the published policy.  The "sanctions" portion of most security policies reads something like this:&lt;br /&gt;&lt;br /&gt;&lt;em&gt;"Failure to comply with this policy will result in disciplinary action, up to and including termination."&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;While this idea certainly makes sense as a formal statement, it leaves a lot of gray area in the real world of policy implementation and enforcement. And it will likely leave questions in the minds of employees. "Does this mean that everyone who violates a policy gets fired?" "What happens if I violate a policy by accident?" "What offenses would warrant termination?"&lt;br /&gt;&lt;br /&gt;When developing written policies, the organization should prepare some internal guidelines for proper sanctions. These should be developed in conjunction with Human Resources and the Legal Department, and considered with regard to consequences for violation of other policies such as Code of Conduct. Certainly, all policy violations are not the same, and some violations present greater legal and market risk that others.&lt;br /&gt;&lt;br /&gt;The following are some ideas for possible employee sanctions with increasing levels of severity:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;1. Warning from Management&lt;/strong&gt; -The employee receives a warning from their manager that they were in violation of policy.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;2. Official Warning in Personnel File&lt;/strong&gt; - The employee is warned, and official notice is put in their personnel file. This may have negative consequences during future performance reviews or promotion considerations.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;3. Revoking Privileges&lt;/strong&gt; - Access to certain company resources, such as internet or email, can be revoked for a limited period. (Providing that they are not critical to job functions.) In one organization, the CEO gave everyone in the organization 30 days to read and acknowledge the written security policy. After 30 days, each employee had their email disabled. Within 24 hours all of the offenders had read and acknowledged the policy.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;4. Requiring Additional Training&lt;/strong&gt; - Another sanction is to require the employee to take additional training on security and privacy practices. This must be done on their own personal time, such as during lunch or after business hours.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;5. Suspension without Pay&lt;/strong&gt; - After multiple warnings, or for serious policy violations that may put the company at substantial risk, employees may be suspended for a limited time without pay.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;6. Termination&lt;/strong&gt; - The organization should consider which types of offenses could trigger a termination. If termination is an option, consult with the legal and human resources department to make sure the organization is on solid ground with respect to written policies. Some employees have sued for wrongful termination and won the case when it was shown that the company was lax in its overall deployment and enforcement of security policies.&lt;br /&gt;&lt;br /&gt;Of course, you can combine any of these into a type of sanctions "mix" that works for the organization. The important task is to prepare the organization by thinking through the problem and deciding what works best for the employees and management. Once guidelines have been established, they can be communicated to employees as part of their regular security or human resources training activities.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If your organization has come up with some unique and effective ways to encourage compliance with policies, we would like to hear from you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18708747-936010992190386110?l=infosecuritypolicy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecuritypolicy.blogspot.com/feeds/936010992190386110/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18708747&amp;postID=936010992190386110' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/936010992190386110'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/936010992190386110'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/2009/02/ideas-for-security-policy-sanctions.html' title='Ideas for Security Policy Sanctions'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18708747.post-8308774178411500388</id><published>2009-01-26T19:30:00.000-08:00</published><updated>2009-01-26T20:38:29.928-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Information Security Policies'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='encryption policies'/><title type='text'>Top Security Policy Priorities for 2009</title><content type='html'>A New Year is always a good time to reflect on the past and make plans for the future. 2008 was a very busy year for security breaches, with 656 reported breaches exposing up to 35 million customer records according to a recent report by the &lt;a href="http://www.idtheftcenter.org/"&gt;Identity Theft Resource Center &lt;/a&gt;(ITRC). This was nearly a 50% jump from 2007.&lt;br /&gt;&lt;br /&gt;Since our focus is the development of &lt;a href="http://www.informationshield.com/information-security-policies.html"&gt;information security policies&lt;/a&gt;, we decided to take a look back at 2008 and see if we could draw some conclusions about trends and priorities for 2009. Think of this as an industry-wide risk assessment exercise. Based on some of the largest incidents of 2008, which information security and data privacy policies, if properly implemented, would have helped reduce the likelihood or impact of these incidents? (Needless to say, many of these policies are contained within Information Security Policies Made Easy.)&lt;br /&gt;&lt;br /&gt;The stakes are getting higher. According to a study conducted by the &lt;a href="http://www.ponemon.org/"&gt;Ponemon Institute&lt;/a&gt;, data breaches are costing businesses an average of $197 per customer record, up from $182 in 2006. So, based on some of the top incidents of 2008, here are our suggested top security policy priorities for 2009:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;1. Data Breach Notification Policies&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Despite the many costly, embarrassing data breaches that have been reported over the last several years, organizations seem to get caught without a plan for dealing with breaches that involve sensitive customer data. Slow or poorly organized responses end up creating confusion and increasing the potential damage of the breaches.&lt;br /&gt;&lt;br /&gt;Six months after a breach happened at the parent company of the &lt;a href="http://www.bankinfosecurity.com/articles.php?art_id=901"&gt;Montgomery Ward website&lt;/a&gt;, the company Direct Marketing Services finally began notifying customers that their credit card information was stolen in part of a hack that stole at least 51,000 records in December 2007. In March, the Maine-based Hannaford Brothers grocery store chain announced that 4.2 million customer card transactions had been compromised by hackers. More than 1800 credit card numbers were immediately used for fraudulent transactions.&lt;br /&gt;&lt;br /&gt;A data breach notification policy must include a variety of possible elements, including breach reporting procedures, documentation of breach notification requirements (by state or country), notification methods and schedules, and the establishment of breach response teams. (See our free &lt;a href="http://www.informationshield.com/privacybreachcalc.html"&gt;Privacy Breach Calculator &lt;/a&gt;from the &lt;strong&gt;Privacy Management Toolkit.&lt;/strong&gt;)&lt;br /&gt;&lt;br /&gt;Data breach response is going to end up on the radar sooner or later. The recent &lt;a href="http://www.whitehouse.gov/agenda/homeland_security/"&gt;Homeland Security Agenda&lt;/a&gt; announced from President Obama includes a goal for a nationwide breach notification law, but so far no national law has been passed, leaving a patchwork of state-level requirements within the United States.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;2. Tracking of Physical Media in Transit&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Another common theme in many incidents is the loss of physical media, including laptops, PDAs, hard drives and backup tapes. Since the data is often not encrypted (See item #3), the loss triggers breach notification requirements (See item #1).&lt;br /&gt;&lt;br /&gt;There are a variety of controls that can be addressed in policy, from the most basic (tracking the delivery of sensitive equipment) to the more complex (laptop tracking software, RFID tags). As always, employees play a key role since they are often the ones transporting the sensitive information. An effective Mobile Device security policy must cover the controls around the logical and physical protection of mobile devices.&lt;br /&gt;&lt;br /&gt;The number of incidents involved lost media and mobile devices are too numerous to talk about in detail. (Several web sites do maintain such a list, including the &lt;a href="http://datalossdb.org/"&gt;Open Security Foundation (OSF)&lt;/a&gt; Loss Database and the &lt;a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm"&gt;Privacy Rights Clearinghouse&lt;/a&gt;. According to the Open Security Foundation, stolen laptops account for the largest share of data breaches, at 22% of the total.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;3. Encryption of Sensitive Data Backups&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;This policy is really a subset of a wider set of controls involving the monitoring and tracking of sensitive customer data throughout its lifecycle. However, this one deserves special attention due to some large incidents in 2008.&lt;br /&gt;&lt;br /&gt;In February 2008, an unencrypted backup tape with 4.5 million customers of the &lt;a href="http://datalossdb.org/incidents/937"&gt;Bank of New York Mellon &lt;/a&gt;went missing after it was sent to a storage facility. The missing tape contains social security numbers and bank account information on 4.5 million customers - including several hundred thousand depositors and investors of People's United Bank of Connecticut. Early in January, Iron Mountain reported that it could not find a backup tape that belonged to GE Money, containing information on over 650,000 J.C. Penney customers and 100 other retailers.&lt;br /&gt;&lt;br /&gt;Encryption policies involve a variety of control areas, including identifying the data that must be encrypted, choosing and implementing encryption methods, and encryption key management. (&lt;a href="http://www.informationshield.com/ispmemain.htm"&gt;ISPME&lt;/a&gt; has over 50 security policies addressing this topic.) Many organizations that process sensitive customer data are finding it more cost effective to simply encrypt all data, rather than identifying the subsets required. Despite the obvious need for encryption, according to ITRC reports, only 2.4% of all breaches had encryption or other strong protection methods in use.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;4. Malicious Software Prevention&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Companies are increasingly falling prey to malicious software being installed and resident on their systems. Trojans and keystroke loggers were responsible for a number of high-profile breaches, including the Best Western Hotels, where thousands of user accounts were stolen and began appearing on Russian Mafia web sites within hours of the heist. In potentially one of the largest recent breaches, Heartland Data Systems has acknowledged a &lt;a href="http://www.msnbc.msn.com/id/28758856/"&gt;data security breach &lt;/a&gt;that may affect tens of millions of payment card accounts. Initial investigation revealed malicious software on their network.&lt;br /&gt;&lt;br /&gt;In November, &lt;a href="http://www.bankinfosecurity.com/articles.php?art_id=1041"&gt;security vendor RSA &lt;/a&gt;said it found a single Trojan that had taken more than 500,000 online banking accounts credentials, credit cards and other resources. The reported indicated that the hacking gang behind the Trojan may have been operating for as long as three years. The compromised data came from hundreds of financial institutions around the world.&lt;br /&gt;&lt;br /&gt;There are a number of related information security policies that can help address this common threat. These include standard security configurations for desktop and mobile devices, regular updates of virus and malicious software signatures, regular scanning of networked systems, and user education and awareness on software downloading and responding to phishing emails (see Item #5).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;5. Employee Security - Screening, Education and Awareness&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;It is unlikely that there will be a year when employee education and awareness would not be a top information security priority. From rogue insiders going undetected to employees accidentally downloading spyware from a phishing attack, users are always at the front lines of many attacks. It has been said so many times that we can be numb from hearing it – educated users are essential to any security program. And yet, organizational priorities to not always follow this basic premise. A 2008 study by the Computer Security Institute showed that the average organization spends less than 1% of their budget on security awareness.&lt;br /&gt;&lt;br /&gt;There are a number of security policies that can help integrate information security responsibilities into the workforce. Some examples include the requirements for annual security training, quarterly awareness activities, the formal documentation of information security responsibilities for various job roles, and validation of these in formal job reviews.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;5.1 - The Insider Threat&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;This special area of employee-related security deserves special attention.&lt;br /&gt;An alarming number of breaches now involve malicious employees or contractors. The breaches range from cases of espionage, to the simple pilfering of customer data for personal gain. According the ITRC report, insider theft - now at 15.7% of all breaches - has more than doubled between 2007 and 2008.&lt;br /&gt;&lt;br /&gt;In one of the largest insider incidents of 2008, a former Countrywide Financial Corp. senior financial analyst was arrested and charged by the FBI for stealing and selling sensitive personal information of an estimated 2 million mortgage loan applicants. The data was taken over a two year period and sold to competitors. In March 2008, a former bank programmer at &lt;a href="http://datalossdb.org/incidents/937"&gt;Compass Bank&lt;/a&gt; was charged after he had stolen a hard drive with 1 million customer records and used it to commit debit-card fraud.&lt;br /&gt;&lt;br /&gt;A recent case involved a database administrator of a UK company, who was fined and sentenced to three months in jail after hacking into his former employer’s computer system. Later investigation revealed that the man had lied on his resume and also had prior criminal charges.&lt;br /&gt;&lt;br /&gt;Written security policies can also help address the growing insider threat, and must focus on the entire lifecycle of employees and contractors. Examples include screening of employees in positions of trust, regular review of access rights, integration of security roles into job descriptions, monitoring of systems for unusually large transactions, and post-employment removal of logical and physical access rights.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Summary&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;So there are our top five categories. They are certainly not comprehensive, but they can give you a start on your priorities for 2009.&lt;br /&gt;&lt;br /&gt;So what can we learn from this list? First, most data breaches involve a variety of factors, including both people and technology. So a variety of controls are required to help reduce the risk of these incidents. As we see from the analysis, most security policies are dependent on other policies to be completely effective. Privacy policies, encryption policies and backup policies must work together to prevent a breach involving stored sensitive data. User awareness and training policies must worth with malicious software detection and configuration control to help stop identity theft and the spread of botnets.&lt;br /&gt;&lt;br /&gt;That is why Information Shield strives to provide the most comprehensive library &lt;a href="http://www.informationshield.com/"&gt;of information security policies &lt;/a&gt;available. If your organization has gaps in any of these key areas, we encourage you to take a look at our &lt;a href="http://www.informationshield.com/products.html"&gt;security policy products&lt;/a&gt;. We look forward to serving you in 2009.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18708747-8308774178411500388?l=infosecuritypolicy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecuritypolicy.blogspot.com/feeds/8308774178411500388/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18708747&amp;postID=8308774178411500388' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/8308774178411500388'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/8308774178411500388'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/2009/01/top-security-policy-priorities-for-2009.html' title='Top Security Policy Priorities for 2009'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18708747.post-531036672470265764</id><published>2009-01-26T19:26:00.001-08:00</published><updated>2009-01-26T19:30:31.430-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security policy version control'/><category scheme='http://www.blogger.com/atom/ns#' term='written security policies'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 27002'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 17799'/><title type='text'>Effective Security Policy Management - Part 1</title><content type='html'>How mature is your information security policy program? Do you have a set of outdated documents stored in a binder or intranet site? Or do you have a documented management program that keeps your policies up to date, your users informed and your internal auditors sleeping at night?&lt;br /&gt;&lt;br /&gt;This is the first article in the series: &lt;strong&gt;Seven Elements of an Effective Information Secrurity Policy Management Program.  &lt;/strong&gt;(Find more on this in our &lt;a href="http://www.informationshield.com/whitepapers.html"&gt;Security Policy Whitepapers&lt;/a&gt;)  In this series we review seven key characteristics of an effective policy management program. These characteristics are culled from leading practices, security and privacy frameworks, and incidents involving information security policies. Organizations can use this quick checklist to evaluate the maturity of their existing management program.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Part 1: Written documents with version control&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;Even though it seems obvious, nearly every information security standard and framework specifically requires information security policies to be written. Since security policies define management’s expectations and stated objectives for protecting information, policies cannot be “implied” – but have to be documented. Having a “written policy document” is the first key control established within the international standard &lt;a href="http://www.informationshield.com/iso17799.html"&gt;ISO/IEC 1-7799:2005&lt;/a&gt;, and is critical to performing both internal and external audits. But what are some characteristics that make for an effectively-written policy document?&lt;br /&gt;&lt;br /&gt;Policy documents should be written in plain and simple language. Many information security and privacy policies are written in legalese that is difficult for end users to read and understand. Since user education and training is a key component of all information security frameworks, clear, user-oriented language is critical. If your &lt;a href="http://www.informationshield.com/ispmemain.htm"&gt;information security policies &lt;/a&gt;are written by either the information technology (IT) or legal department, make sure you employ a technical writer or other editor who can help simplify the language of your documents.&lt;br /&gt;&lt;br /&gt;Policy documents should also have a &lt;strong&gt;standard format&lt;/strong&gt; so that they can be effectively managed and updated. The standard format not only enforces consistency among documents, it ensures that each document contains key elements that facilitate the overall management of the information security policies, such as the owner/author, title, scope and effective dates of the policy. Written documents should also have a policy version number. A &lt;strong&gt;policy version number&lt;/strong&gt; clearly articulates which version of the policy is in force at the time of publication, and helps maintain a version history of each document. Maintaining a version history is not only good practice for preserving digital evidence in case of a lawsuit, it also demonstrates that the organization was performing due-diligence by updating its security policies on a regular basis.&lt;br /&gt;&lt;br /&gt;In order to facilitate a clear document history that can be reviewed by auditors, some form of access-controlled document management system should be used. It can be as simple as folders on a network drive or a full-blown document management system. Complete systems usually provide a detailed audit trail of all changes and updates to documents.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18708747-531036672470265764?l=infosecuritypolicy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecuritypolicy.blogspot.com/feeds/531036672470265764/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18708747&amp;postID=531036672470265764' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/531036672470265764'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/531036672470265764'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/2009/01/effective-security-policy-management.html' title='Effective Security Policy Management - Part 1'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18708747.post-7928686529212013264</id><published>2008-08-21T07:19:00.000-07:00</published><updated>2009-02-17T13:13:26.839-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAS 70'/><category scheme='http://www.blogger.com/atom/ns#' term='BITS'/><title type='text'>Information Security Policies and BITS Assessment</title><content type='html'>The events of 2007 and 2008 have led to an increased focus on governance, security and privacy within the financial services market. One increasingly common scenario is when a third-party service provider must have their security program validated by the financial institution that it serves.&lt;br /&gt;&lt;br /&gt;Historically, these audits were based on the &lt;a href="http://www.bitsinfo.org/fisap"&gt;BITS framework&lt;/a&gt; and have been somewhat painful for both the service providers and the financial organizations due to a lack of standardization. While BITS provided an overall framework, the specific assessment methods and questionnaires varied widely between organizations and projects.&lt;br /&gt;&lt;br /&gt;An initiative called the "&lt;a href="http://www.sharedassessments.org/"&gt;The Financial Institution Shared Assessments Program &lt;/a&gt;" aims to bring some order and consistency to these audits. The program was created by &lt;a href="http://www.bitsinfo.org/fisap"&gt;BITS&lt;/a&gt; and member financial institutions to fix the cumbersome and expensive service provider assessment process. The shared assessments are managed and promoted by the BITS consortium and the &lt;a href="http://www.santa-fe-group.com/"&gt;Sante Fe Group&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Many organizations that are subject to these assessments discover weaknesses in written security policies. For example, one of the major BITS/Shared Assessment control areas is "Asset Classification and Control." Within the guidance for this section, one of the documents that may be requested for verification is a written Asset Control Policy.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;For these organizations, &lt;a href="http://www.informationshield.com/ispmemain.htm"&gt;Information Security Policies Made Easy&lt;/a&gt; and the &lt;a href="http://www.informationshield.com/information-security-policies.html"&gt;PolicyShield Security Policy Subcription&lt;/a&gt; can help fill in the gaps with high-quality, pre-written security policies. Using Data Classification as an example, ISPME provides over 100 pre-written policy statements relating to the classification, labeling, and management of assets. It also includes a sample, pre-written "Data Classification Policy" that can easily be customized with a minimum of effort.&lt;br /&gt;&lt;br /&gt;ISPME and PolicyShield provide pre-written policy-level controls for each section of the BITS/Shared Asssessment framework. Organizations can save hundreds of man-hours by customizing ISPME policies versus creating them from scratch. Since ISPME is organized around ISO 17799, there is an easy mapping between the BITS requirements and the security policies with ISPME.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18708747-7928686529212013264?l=infosecuritypolicy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecuritypolicy.blogspot.com/feeds/7928686529212013264/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18708747&amp;postID=7928686529212013264' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/7928686529212013264'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/7928686529212013264'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/2008/08/information-security-policies-and-bits.html' title='Information Security Policies and BITS Assessment'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18708747.post-6082778349853382954</id><published>2007-10-29T12:52:00.000-07:00</published><updated>2007-10-29T14:02:27.764-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='social engineering'/><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='email policy'/><title type='text'>Policy Sound-Off - Responding to Email Requests</title><content type='html'>Phishers are coming up with increasingly sophisticated ways to encourage corporate users to open emails. Two recent incidents using two different attack methods help illustrate the increased threat.&lt;br /&gt;&lt;br /&gt;In the first, a large retail grocery chain narrowly &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9043618&amp;amp;source=rss_topic82"&gt;escaped a $10 million loss &lt;/a&gt;when employees were instructed via email to begin depositing funds to a new bank account for two existing vendors. In this case of very narrow “spear phishing” the attackers clearly had specialized knowledge about the company operations that made the emails seem legitimate. They targeted specific individuals within one organization, making detection more difficult.&lt;br /&gt;&lt;br /&gt;Another recent phishing attack involves fake email messages claiming to come from the Equal Employment Opportunity Comm (&lt;a href="http://www.eeoc.gov/"&gt;EEOC&lt;/a&gt;). In this attack, the fake emails claim to be notifying the company of an employee complaint made against the organization. This is one of the many examples of phishers playing on the desire of employees to comply with state and federal legislation. In these attacks, many organizations are targeted but with a more credible-sounding business message. In both the narrow and broad approaches, attacks are getting more sophisticated and often contain logos and content that is stolen directly from the organization being spoofed in the emails.&lt;br /&gt;&lt;br /&gt;Does your organization have a formal policy on how your employees and contractors should respond to external requests for sensitive information? Are employees educated on the various types of phishing attacks, including where and how to report a suspected attack? &lt;br /&gt;&lt;br /&gt;(Note: For organizations that wish to include phishing attacks in their formal training and awareness programs, the January 2008 issue of &lt;a href="http://www.informationshield.com/protectinginformation.html"&gt;Protecting Information &lt;/a&gt;will cover social engineering in more detail.)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18708747-6082778349853382954?l=infosecuritypolicy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecuritypolicy.blogspot.com/feeds/6082778349853382954/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18708747&amp;postID=6082778349853382954' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/6082778349853382954'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/6082778349853382954'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/2007/10/policy-sound-off-responding-to-email.html' title='Policy Sound-Off - Responding to Email Requests'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18708747.post-2787584394255450675</id><published>2007-09-26T12:53:00.000-07:00</published><updated>2007-09-26T13:04:56.801-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Social Networking'/><category scheme='http://www.blogger.com/atom/ns#' term='Information Security Policies'/><category scheme='http://www.blogger.com/atom/ns#' term='security awareness'/><title type='text'>Security Policy on Social Networking Sites</title><content type='html'>Social Networking sites present some unique challenges for organizations that must attract and keep young workers.  Is the use of social networking sites at work a necessary perk or an unacceptable risk to corporate information?   Some argue that organizations must allow access to social networking and other Web 2.0 sites to help attract a more "fickly" twenty-something workforce that are used to life online.   Others say that the risks are simply too great, both in terms of wasted time and potential for infected computers.&lt;br /&gt;&lt;br /&gt;The Fall 2007 issue of the &lt;a href="http://www.informationshield.com/protectinginformation.html"&gt;security awareness newsletter &lt;/a&gt;&lt;em&gt;Protecting Information&lt;/em&gt; covers the most common risks of social networking sites.  In the issue Rebecca Herold describes several incidents where employees were terminated based on content posted on their personal pages on various social networking sites.   Clearly this issue is going to grow as fast as the number of people that use social networking sites - now estimated at over 200 million.&lt;br /&gt;&lt;br /&gt;Does your organization block social networking sites?  Is social networking addressed within your &lt;a href="http://www.informationshield.com/ispmemain.htm"&gt;information security policies&lt;/a&gt;?  What are some of the concerns that you feel should be addressed in policy?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18708747-2787584394255450675?l=infosecuritypolicy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecuritypolicy.blogspot.com/feeds/2787584394255450675/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18708747&amp;postID=2787584394255450675' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/2787584394255450675'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/2787584394255450675'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/2007/09/security-policy-on-social-networking.html' title='Security Policy on Social Networking Sites'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18708747.post-8084975092332678337</id><published>2007-09-17T13:09:00.000-07:00</published><updated>2009-02-17T12:42:50.847-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security policy responsibility'/><category scheme='http://www.blogger.com/atom/ns#' term='written security policies'/><category scheme='http://www.blogger.com/atom/ns#' term='security policy ownership'/><title type='text'>Effective Security Policy Management - Part 2</title><content type='html'>&lt;p&gt;Part 2 of 7: Seven Elements of an Effective &lt;a href="http://www.informationshield.com/information-security-policies.html"&gt;Information Security Policy&lt;/a&gt; Management Program&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;Effective Security Policies Part 2. Defined Policy Document Ownership&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.informationshield.com/ispmemain.htm"&gt;Security Policies&lt;/a&gt; can be viewed as contract between senior management, employees and third-parties about the ways in which the organization will protect information. By definition, a contract is between parties, and in the case of written security and privacy policies one of the parties is always senior management.&lt;/p&gt;&lt;p&gt;Each written security policy document should have a defined owner and/or author. This statement of ownership is the tie between the written policies and the acknowledgement of management’s responsibility for updating and maintaining information security policies. The policy author also provides a point of contact if anyone in the organization has a question about specific policies. Many organizations have written information security policies that are so out-of-date that the author is no longer employed by the organization.&lt;br /&gt;&lt;br /&gt;Another area of responsibility that should be documented within written &lt;a href="http://www.informationshield.com/ispmemain.htm"&gt;security policies&lt;/a&gt; is the executive sponsor. The executive sponsor is a C-level manager or executive that puts the final “stamp of approval” on each document. A high-level executive sponsor demonstrates to all employees that your organization is serious about information security in general, and security policies in particular. Ideally, this is the CEO or equivalent top executive within the organization. In some larger organizations, this might be the head of large region or perhaps the Chief Operating Officer. Within the requirements of &lt;a href="http://www.informationshield.com/sarbanes.html"&gt;Sarbanes-Oxley&lt;/a&gt;, senior management must actually sign a written document attesting to the adequacy of the organization's internal controls. Written policies are a key part of these internal controls.&lt;/p&gt;&lt;p&gt;In some cases, the executive sponor is listed as part of each published policy document. In other cases, the sponsoring executive may issue a seperate memorandum stating the importance of information security and that following published policies is required for continued employement within the company. &lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18708747-8084975092332678337?l=infosecuritypolicy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecuritypolicy.blogspot.com/feeds/8084975092332678337/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18708747&amp;postID=8084975092332678337' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/8084975092332678337'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/8084975092332678337'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/2007/09/effective-security-policy-management.html' title='Effective Security Policy Management - Part 2'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18708747.post-3567365923031792711</id><published>2007-09-17T12:52:00.000-07:00</published><updated>2009-01-26T19:17:10.507-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='document management systems'/><category scheme='http://www.blogger.com/atom/ns#' term='Social Networking Information Security Policies'/><category scheme='http://www.blogger.com/atom/ns#' term='written security policies'/><title type='text'>Effective Information Security Policy Management - Part 1</title><content type='html'>&lt;p&gt;How mature is your information security policy program? Do you have a set of outdated documents stored in a binder or intranet site? Or do you have a documented management program that keeps your policies up to date, your users informed and your internal auditors sleeping at night? &lt;/p&gt;&lt;p&gt;This is the first article in the series: Seven Elements of an &lt;a href="http://www.informationshield.com/whitepapers.html"&gt;Effective Information Security Policy Management Program&lt;/a&gt;. In this series we review seven key characteristics of an effective policy management program. These characteristics are culled from leading practices, security and privacy frameworks, and incidents involving information security policies. Organizations can use this quick checklist to evaluate the maturity of their existing management program.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Part 1: Written documents with version control&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Even though it seems obvious, nearly every information security standard and framework specifically requires information security policies &lt;strong&gt;to be written&lt;/strong&gt;. Since security policies define management’s expectations and stated objectives for protecting information, policies cannot be “implied” – but have to be documented. Having a “written policy document” is the first key control established within the international standard &lt;a href="http://www.informationshield.com/iso17799.html"&gt;ISO/IEC 1-7799:2005&lt;/a&gt;, and is critical to performing both internal and external audits. But what are some characteristics that make for an effectively-written policy document?&lt;br /&gt;&lt;br /&gt;Policy documents should be written in plain and simple language. Many information security and privacy policies are written in legalese that is difficult for end users to read and understand. Since user education and training is a key component of all information security frameworks, clear, user-oriented language is critical. If your &lt;a href="http://www.informationshield.com/ispmemain.htm"&gt;information security policies &lt;/a&gt;are written by either the information technology (IT) or legal department, make sure you employ a technical writer or other editor who can help simplify the language of your documents.&lt;br /&gt;&lt;br /&gt;Policy documents should also have a standard format so that they can be effectively managed and updated. The standard format not only enforces consistency among documents, it ensures that each document contains key elements that facilitate the overall management of the information security policies, such as the owner/author, title, scope and effective dates of the policy.&lt;br /&gt;&lt;br /&gt;Written documents should also have a policy version number. A policy version number clearly articulates which version of the policy is in force at the time of publication, and helps maintain a version history of each document. Maintaining a version history is not only good practice for preserving digital evidence in case of a lawsuit, it also demonstrates that the organization was performing due-diligence by updating its security policies on a regular basis. &lt;/p&gt;&lt;p&gt;In order to facilitate a clear document history that can be reviewed by auditors, some form of access-controlled document management system should be used. It can be as simple as folders on a network drive or a full-blown document management system. Complete systems usually provide a detailed audit trail of all changes and updates to documents.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18708747-3567365923031792711?l=infosecuritypolicy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecuritypolicy.blogspot.com/feeds/3567365923031792711/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18708747&amp;postID=3567365923031792711' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/3567365923031792711'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/3567365923031792711'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/2007/09/effective-information-security-policy.html' title='Effective Information Security Policy Management - Part 1'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18708747.post-4206274729796895955</id><published>2007-08-27T18:04:00.000-07:00</published><updated>2007-08-27T18:20:28.413-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='policy violation'/><category scheme='http://www.blogger.com/atom/ns#' term='security policy'/><category scheme='http://www.blogger.com/atom/ns#' term='change notification'/><title type='text'>Required Acknowledgement of Security Policy Changes</title><content type='html'>Legal precedents are beginning to dictate a new standard for the notification of policy changes to your customers and employees.  In the "old days" organizations would post changes to &lt;a href="http://www.informationshield.com/ispmemain.htm"&gt;information security policies &lt;/a&gt;on the corporate intranet, and perhaps even notify employees that these changes occurred via email or some other means.  However, in legal actions where employees were terminated for violating policy and then sued for improper termination, the conclusion was that mere notification is not enough.  Organizations are expected to notify employees of important policy changes, but must go a step further and verify acknowledgement by employees affected by the change.  &lt;br /&gt;&lt;br /&gt;A recent case with a telecommunications provider seems to indicate that this standard applies to customers as well.  The typical line in many online privacy policies goes something like "we reserve to change this policy at any time."  While this practice is common, it is certainly not in the spirit of “open” communication with customers as outlined in OECD Privacy Principles.  This ruling came as part of a class-action lawsuit where customers sued for terms of service changes that were applied automatically to their account.  However, it seems likely that an equal case could be made for changes to privacy policies that would effect the collection of personal information.&lt;br /&gt;&lt;br /&gt;I believe it is now "best practice" to require acknowledgement of important security and privacy policy changes.  I am interested to hear if this is becoming standard practice in real organizations, or just the unrealistic musings of a policy "purist."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18708747-4206274729796895955?l=infosecuritypolicy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecuritypolicy.blogspot.com/feeds/4206274729796895955/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18708747&amp;postID=4206274729796895955' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/4206274729796895955'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/4206274729796895955'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/2007/08/required-acknowledgement-of-security.html' title='Required Acknowledgement of Security Policy Changes'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18708747.post-4994315586162767517</id><published>2007-08-27T17:56:00.000-07:00</published><updated>2007-08-27T18:02:23.158-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='policy enforcement'/><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='identity theft'/><title type='text'>New legislation may help prosecution of ID theft</title><content type='html'>Companies that have their identities used in phishing scams have little recorse in stopping the attacks.  However, new legislation proposed by the Justice Department would expand the ability of enforcement agencies to prosecute identity theft, and adds provisions that may help corporations who are used in phishing scams. &lt;br /&gt;&lt;br /&gt;The "Identity Theft Enforcement and Restitution Act of 2007" would expand the reach of federal law to criminal activity that currently “slips through the cracks” of existing federal law.  Among the many provisions, the law would increase the ability of the federal government to prosecute criminals by expanding the definitions of the criminal activity that defined “identify theft” and by addressing specific technologies such as spyware and keystroke logging.  The bill would also expand the rights of victims to seek restitution for the hours spent recovering from ID theft.&lt;br /&gt;&lt;br /&gt;Several provisions introduced in the bill may help corporations fight identify theft.  For example, the law would close gaps in two federal statutes by making it illegal to use not just a person's identification but also the identification of a corporation or organization “such as the name, logo, trademark”, as is common in phishing attacks.  Other language closes more gaps related to cyber-extortion as covered in the Computer Fraud and Abuse Act, by including threats “to steal or corrupt data on a victim's computer, or not repair damage the offender already caused to the computer."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18708747-4994315586162767517?l=infosecuritypolicy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecuritypolicy.blogspot.com/feeds/4994315586162767517/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18708747&amp;postID=4994315586162767517' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/4994315586162767517'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/4994315586162767517'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/2007/08/new-legislation-may-help-prosecution-of.html' title='New legislation may help prosecution of ID theft'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18708747.post-7721700198812646601</id><published>2007-08-09T07:33:00.000-07:00</published><updated>2007-08-09T07:45:23.204-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='policy enforcement'/><category scheme='http://www.blogger.com/atom/ns#' term='third-party security policies'/><title type='text'>Contractors fined for not following security policy</title><content type='html'>In July 2007, several contractors of Los Alamos National Laboratory were fined a total of $3.3 million for failing to adequately protect data as required in their contracts. The Department of Energy (DOE) initiated &lt;a href="http://www.hss.energy.gov/enforce/"&gt;formal enforcement actions &lt;/a&gt;against specific current and former contractors, the reports said that investigations revealed that the contractors failed to prevent "a subcontractor employee's unauthorized reproduction of and removal of classified matter from the site." The DOE also issued a Compliance Order to Los Alamos, requiring corrective action to increase physical protection and cyber-security to safeguard classified information.&lt;br /&gt;&lt;br /&gt;This is another example that illustrates the importance of two areas of security policy related to third-party contractors. First, information security requirements should be included in all written contracts (apparently so in this case). Second, the organization must establish procedures for periodic monitoring of all third-party contractors for compliance with information security policies. &lt;a href="http://www.informationshield.com/ispmemain.htm"&gt;Information security policies made easy &lt;/a&gt;includes over 100 separate security policy controls for managing third-party relationships.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18708747-7721700198812646601?l=infosecuritypolicy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecuritypolicy.blogspot.com/feeds/7721700198812646601/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18708747&amp;postID=7721700198812646601' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/7721700198812646601'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/7721700198812646601'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/2007/08/contractors-fined-for-not-following.html' title='Contractors fined for not following security policy'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18708747.post-8073857161245612507</id><published>2007-08-09T07:17:00.000-07:00</published><updated>2007-08-09T07:32:12.015-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='regulations'/><category scheme='http://www.blogger.com/atom/ns#' term='security policy'/><category scheme='http://www.blogger.com/atom/ns#' term='iso 17799'/><category scheme='http://www.blogger.com/atom/ns#' term='COBIT'/><title type='text'>Regulatory Requirements for Information Security Policies</title><content type='html'>Some organizations still receive little management support or funding for a sound information security policy program. Within the last several years, however, numerous federal, state and international regulations have been passed that require the protection of information. Many organizations are now enhancing their information security policies in response to legal and regulatory requirements.&lt;br /&gt;&lt;br /&gt;&lt;a name="1384188"&gt;&lt;/a&gt;In some cases, these regulations are very specific about the requirements for written security and privacy policies. In other cases, a regulation simply requires safeguards that are "appropriate" for the size and type of organization. In these cases, enforcement agencies and auditors must defer to accepted best practices or frameworks for guidance, all of which require written policies. Examples of these are the Generally Accepted Information Security Principles (GAISP), Control Objectives for Information Technology (COBIT®) and &lt;a href="http://www.informationshield.com/iso17799.html"&gt;ISO/IEC 17799&lt;/a&gt;.&lt;br /&gt;&lt;a name="1398559"&gt;&lt;/a&gt;&lt;br /&gt;This &lt;a href="http://www.informationshield.com/securitypolicyregulatoryrequirements.html"&gt;information security policy requirements table &lt;/a&gt;contains a partial list of security or privacy-related regulations and their specific &lt;a href="http://www.informationshield.com/ispmemain.htm"&gt;information security policy &lt;/a&gt;requirements. Where appropriate, the list includes the security policy requirements of several key frameworks used to manage compliance with various regulations. Organizations may use this table to help build a case to senior management that written security policies are "not just a good idea, they're the law."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18708747-8073857161245612507?l=infosecuritypolicy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecuritypolicy.blogspot.com/feeds/8073857161245612507/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18708747&amp;postID=8073857161245612507' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/8073857161245612507'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/8073857161245612507'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/2007/08/regulatory-requirements-for-information.html' title='Regulatory Requirements for Information Security Policies'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18708747.post-116224709264349607</id><published>2006-10-30T14:20:00.000-08:00</published><updated>2006-10-30T14:25:40.520-08:00</updated><title type='text'>Security Policy and Responsibility</title><content type='html'>&lt;span style="font-size:85%;"&gt;Last month we discussed the security policy problems revealed within the department of Veteran's Affairs (VA) in the wake of the highly public data breach, including the firing of two employees responsible for information security. Over the last month, employees at both &lt;/span&gt;&lt;a href="http://news.com.com/2102-1030_3-6107830.html?tag=st.util.print" target="new"&gt;&lt;span style="font-size:85%;"&gt;AOL&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt; and &lt;/span&gt;&lt;a id="new" href="http://www.computerworld.com/action/article.do?command=printArticleBasic&amp;articleId=9002206" name="new"&gt;&lt;span style="font-size:85%;"&gt;Ohio University&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt; were terminated or resigned in the aftermath of data privacy breaches. All of these cases point to some interesting security policy questions for all organizations to consider. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Security Scapegoats?&lt;/strong&gt;&lt;br /&gt;While termination seems to be an obvious step to attempt to restore customer confidence, in both cases serious questions were raised about the overall security and privacy practices of the entire organization. In the wake of very damaging or embarrassing data breaches, some organizations seem to focus the blame on individuals, rather than on weaknesses of internal policies and procedures.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;In the past, similar incidents have resulted in lawsuits for improper termination, since many organizations failed to clearly communicate their data security and privacy policies to all employees. In the case of Ohio University, lawyers have already made statements for the fired employees indicating that they were improperly targeted. Similar statements were made by ex-employees of the VA.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Security Policy Lessons&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;These incidents and their public fall-out raise some important questions for organizations concerned with policy creation, education and enforcement:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Question:&lt;/strong&gt; Do your information security policies cover sanctions against employees? Is the language in the policies specific to violation of existing corporate policies?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;In neither of these cases did the public statements mention that employees were violating any specific policy, but instead seemed to indicate that the employees should have "known better." AOL CEO Jon Miller in an internal memo stated that "This incident took place because some employees did not exercise good judgment or review their proposal with our privacy team. We are taking appropriate action with the employees who were responsible." &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;The fundamental question here is whether or not an employee should be fired for making mistakes, especially in areas where there is very little official guidance on how employees can operate safely with sensitive data. While we are not attempting to judge the legality of such actions, evidence suggests that terminating employees without proper cause or documentation will create problems. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;During a risk-assessment or policy update phase, organizations would do well to consider what would happen in their own organization if an individual makes a mistake that causes an information security and privacy breach. What should be done if the organizational policies only address violation of stated policy?&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Question:&lt;/strong&gt; Does your organization clearly communicate information security and privacy policies to users based on their role in the organization?&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Organizations that wish to terminate employees for violation for company policy should take great care to have their information security and privacy policies clearly documented and communicated.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;In the case of AOL, it is not clear if there was a corporate privacy policy that prohibited researchers from using data without consulting the privacy group. But other data casts some doubt. Public statements by AOL suggest that they are now taking a serious look at their internal policies. Public response to the AOL incident included allegations that sensitive search data should be destroyed as part of a regular data destruction policy.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;In a separate statement, Ohio University announced a 20-point plan to improve information security at the school, which has about 16,640 undergraduate students and 862 full-time faculty members on its Athens campus.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Question:&lt;/strong&gt; Are information security and privacy responsibilities clearly documented in job responsibilities?&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;In the case of the VA and Ohio University, the terminated employees had direct responsibility for information security. Even so, statements from the attorneys of fired employees seem to raise some questions as to which systems the individuals were responsible for.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;In the case of AOL, the employees were doing research on web searches. Company statements indicate that there were no official procedures in place for protecting customer privacy, but that the employees "were to consult the privacy team" before posting their research.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;While we can only extrapolate from these public statements, the common thread is all of these cases is a poor documentation of information security responsibilities. While have information security policies is critical, they are much more effective when they are tied to specific responsibilities of various job roles. Organizations that take this more structured approach will not only have better security, but will be better prepared for any sanctions.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Resources&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.informationshield.com/ispmemain.htm"&gt;&lt;span style="font-size:85%;"&gt;Information Security Policies Made Easy, Version 10&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt; - A complete library of information security policies, including policies for personnel security.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.informationshield.com/israr_main.htm"&gt;&lt;span style="font-size:85%;"&gt;Information Security Roles &amp;amp; Responsibilities Made Easy, Version 2&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt; - An extensive library of documented information security requirements for various organizational roles.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.informationshield.com/privacy_main.html"&gt;&lt;span style="font-size:85%;"&gt;Privacy Management Toolkit, Version 1&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt; - A complete resource for managing customer and employee privacy based on OECD Fair Information Principles.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18708747-116224709264349607?l=infosecuritypolicy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecuritypolicy.blogspot.com/feeds/116224709264349607/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18708747&amp;postID=116224709264349607' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/116224709264349607'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/116224709264349607'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/2006/10/security-policy-and-responsibility.html' title='Security Policy and Responsibility'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18708747.post-116224656920205782</id><published>2006-10-30T14:11:00.000-08:00</published><updated>2006-10-30T14:16:09.216-08:00</updated><title type='text'>Policy Controls for Building Secure Applications</title><content type='html'>&lt;span style="font-size:85%;"&gt;A number of recent surveys indicate that an increasing number of attacks are targeting applications, rather than operating systems. Hackers have discovered that applications are patched far less frequently than operating systems and web servers. For example, the recent release of the SANS Top 20 vulnerabilities of 2005 points to a number of problems related to application security. The results prompted SANS Institute Research Director Allan Paller to state that "Security has been set back nearly six years in the past 18 months" because of problems with application patching. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Application security weaknesses are now under tremendous scrutiny within commercial software. For years, commercial software vendors have been under fire for not developing secure code and then not fixing flaws fast enough once they are discovered. Applications that effect large number of users, such as email clients and web browsers, have been the focus of much coverage in the news. While commercial software is certainly a large problem, often overlooked are the applications that are developed in-house. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Many organizations that are assessing their internal controls for Sarbanes-Oxley or other compliance efforts are discovering that many in-house applications (as well as those developed by commercial vendors) are lacking in basic security controls. To help reduce the overall corporate risk, compensating controls in the form of manual procedures will need to be implemented. As organizations are beginning to see, the cost of not building security into applications from the beginning can be very many times the cost of manual compensating controls.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Policy-based controls&lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;There are a number of internal control points that make sense to address with policies and procedures. First, is to have an overall policy that concisely establishes security as part of the overall application development process. For example:&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Policy:&lt;/strong&gt; For all business application systems, systems designers and developers must consider security from the beginning of the systems design process through conversion to a production system.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Of course, this policy is equally valid for any development undertaken by the company, either using in-house or contracted staff. A similar policy should be implemented for the acquisition of new systems from third party or commercial vendors. So what some of the organizational standards and procedures that will support this policy?&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Security Requirements Reviews&lt;/strong&gt; - Applications usually begin with a set of requirements. The first step is to review system requirements document for security, and putting specific security controls in the application from the design phase. If you organization has a formal project development process, a formal security review checkpoint should be established.&lt;br /&gt;With all of the procedures mentioned here, it is important to understand the implied personnel responsibilities. A person or team in the organization should be designated to review applications for security requirements. These can either be members of the development staff training in information security practices, or members of the information security team with specific knowledge of application development issues. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Secure Coding Practices&lt;/strong&gt; - Once requirements have been defined, design and coding begins. At this point, developers begin the process of turning ideas into code. Ideally, developers should be trained in secure coding practices. However, more realistic would be to have one or two senior developers or system architects that can participate in code reviews and coach other team members. For example, these lead developers can establish a set of secure coding "best practices" that get distributed to all development staff.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Testing for Security Features&lt;/strong&gt; - Assuming that security features where included in the system requirements documents, these features would then generate test cases for system and integration testing. The more complicated the application, the more opportunity there is for vulnerabilities to be created by unanticipated combinations of system state, or assumptions of secure messaging that may get compromised. Again, the testing team should have key members who are trained in developing cases that test availability, confidentiality and data integrity, including error and recovery states. Testing may also include disaster recovery scenarios, such as how to recover the application state from a complete system failure.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Application Vulnerability Analysis&lt;/strong&gt; - Finally, some organizations may consider performing "white-hat" vulnerability analysis on their own systems. In this scenario, team members or outside consultants who are familiar with system vulnerability can try to "hack" the applications systems in a test environment. This process may expose vulnerability associated with operating system or network configuration flaws that were impossible to anticipate during the design phase.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Conclusion - Have procedures to support your policies&lt;/strong&gt;&lt;br /&gt;It is important to have policies in place that require security in the application development and acquisition process. However, if your internal procedures are not modified to support the policy, there is no way for the policy to have any impact on the organization. A little bit of homework, and some targeted training for key staff members will help insure that your applications are developed with security in mind. Secure applications will not only make your customers happy, they may keep you out of the headlines.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:85%;"&gt;Related Resources and Information&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.informationshield.com/ispmemain.htm"&gt;&lt;span style="font-size:85%;"&gt;Information Security Policies Made Easy, Version 10.0&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt; contains over 1300 pre-written policies, including policies for application development and system acquisition. If you have any gaps in your incident policies, this is the most cost-effective way to fill them. &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18708747-116224656920205782?l=infosecuritypolicy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecuritypolicy.blogspot.com/feeds/116224656920205782/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18708747&amp;postID=116224656920205782' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/116224656920205782'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/116224656920205782'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/2006/10/policy-controls-for-building-secure.html' title='Policy Controls for Building Secure Applications'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18708747.post-114193665885891364</id><published>2006-03-09T12:23:00.000-08:00</published><updated>2006-03-09T12:37:38.876-08:00</updated><title type='text'>COBIT or ISO17799?</title><content type='html'>Many organizations just getting started with information security policies ask us the question:  Should we use &lt;strong&gt;ISO 17799&lt;/strong&gt; or &lt;strong&gt;COBIT&lt;/strong&gt;?  The answer, of course, is that it depends on what you are trying to accomplish.  In fact, they are not mutually exclusive, but can be used together.&lt;br /&gt;&lt;br /&gt;The basic difference between COBIT and ISO17799:2005 is that ISO 17799 is only focused on information security, whereas COBIT is focused on more general information technology controls.  Thus, COBIT has a broader coverage of general information technology topics, but does not have as many detailed information security requirements as ISO 17799:2005.   If an organization addresses all of the security controls within ISO 17799:2005, then they will be covering a large part of COBIT in the process - especially the section DS5 Ensure Systems Security. However, COBIT covers a much larger set of issues related to information technology "governance," and is typically used as part of an overall corporate governance framework.&lt;br /&gt;&lt;br /&gt;Organizations that must comply with overall corporate governance requirements such as Sarbanes-Oxley (in the US) or Basel II (international banking) tend to use COBIT, whereas organizations focused primarily on information security may use ISO 17799.   As of late 2005, organizations can now get certified against the ISO 17799:2005 standard.  This certification is based on the existing BS 7799 standard, and has now been adoped by ISO. So if your organization desires a security certification, ISO 17799:2005 would be an appropriate choice.&lt;br /&gt;&lt;br /&gt;COBIT (Control Objectives for Information Technology) is published by ISACA and the IT Governance Institute.  ISO 17799:2005 is available from BSI or ANSI.  For more information, see our compliance information at &lt;a href="http://www.informationshield.com/compliance.html"&gt;http://www.informationshield.com/compliance.html&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18708747-114193665885891364?l=infosecuritypolicy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://infosecuritypolicy.blogspot.com/feeds/114193665885891364/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18708747&amp;postID=114193665885891364' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/114193665885891364'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/114193665885891364'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/2006/03/cobit-or-iso17799.html' title='COBIT or ISO17799?'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18708747.post-113131542045840654</id><published>2005-11-06T14:07:00.000-08:00</published><updated>2005-11-06T14:17:00.460-08:00</updated><title type='text'>Welcome to the Information Security Policy Weblog</title><content type='html'>The &lt;strong&gt;Information Security Policy&lt;/strong&gt; Weblog is published by &lt;a href="http://www.informationshield.com/"&gt;Information Shield&lt;/a&gt;.  We provide this weblog (aka blog) to share and discuss various ideas that relate to the protection of both corporate and personal information through information security policies.  We hope this will provide a forum to discuss real-world issues involving the practice of protecting information.  We encourage your advice, comments, stories and feedback.&lt;br /&gt;&lt;br /&gt;David Lineman&lt;br /&gt;President&lt;br /&gt;Information Shield, Inc.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18708747-113131542045840654?l=infosecuritypolicy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/113131542045840654'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18708747/posts/default/113131542045840654'/><link rel='alternate' type='text/html' href='http://infosecuritypolicy.blogspot.com/2005/11/welcome-to-information-security-policy.html' title='Welcome to the Information Security Policy Weblog'/><author><name>Dave L.</name><uri>http://www.blogger.com/profile/07459157660202043487</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://www.informationshield.com/images/djlphoto1.jpg'/></author></entry></feed>
