• No results found

Also, within each of these functions, the ISSMP must be aware of the specific business processes and types of information that support and are produced by the system. The things that the ISSMP needs to understand about business processes are as follows:

■ Who is in charge and manages the business?

■ Who is responsible overall for controlling the system’s operations and resources?

■ How does the business work?

■ What is the determination of success – input, output, profit, number of customers, and so forth?

■ How is the information entered?

■ Who receives or reviews it?

■ Who does what with it (change, consolidate, delete, store, transmit, etc.)?

■ To whom is information transmitted and from where and why?

■ Are there any product or service providers?

■ Are there any external or internal customers or buyers?

■ Are there any management reviews and approvals required in the processes?

■ Who does any required reviews and approvals and what is approved?

■ How fast do these actions need to happen?

■ What is the impact if they do not happen?

■ Who provides oversight and how often?

www.allitebooks.com

The above list is not a complete list, but it is an appropriate start. As the review is conducted, more questions will become obvious as the ISSMP tries to gain solid insight into the business the system supports or will be supporting. With a full understanding of the business process, the ISSMP can determine things such as:

■ What is the flow of the information?

■ Who communicates what and with whom?

■ What privileges will each person require?

■ Who drafts requests and who approves them?

■ How critical are the individual system components and their capabilities to supporting the success of the organization?

■ What information types and sensitivities are being processed in the system?

■ Who are the providers and what agreements are in place or are needed?

■ Who are the customers and what are their capabilities and expectations?

■ Who is the owner of the system?

■ Who will be the ultimate person to accept any residual risk and authorize the system to become operational or continue to operate?

The above are all key pieces of information required for the ISSMP to ensure that the most effective security is applied to the system. Some people may say that this is the job of a systems analyst and they would be right, but it is recommended that the ISSMP work closely with the systems analysts and designers to ensure that security is considered during the entire development process.

Identity Management

The information collected has a major impact on the security needs of the system, specifically in the area of identity management, by identifying where the concepts of “least privileges” and

“role based security” can be applied. Both of these concepts are demonstrated in the following example:

There are three individuals who work in the payments section of a major corporation. Mary is the supervisor, who oversees the efforts of Sally and John.

Sally and John draft fund transfers from banks to pay corporate bills. Mary is the only one who can authorize and make the transfers online. Each bank has a unique method of authenticating Mary prior to her making a money transfer, i.e., one-time passwords and challenge-and-response tokens.

To make the transfers, Sally and John review the vendor invoices using a word processing program, and using that data they use a standard Funds Transfer Form to create a Draft Funds Transfer, which they submit to Mary. Mary reviews the Draft Funds Transfer and creates a Final Funds Transfer using the word processing program. Mary then connects to the bank via the Internet using an Internet browser program. With the connection to the bank, she authenticates to the bank using the book or token authentication processes, which are secured in a safe that only Mary has access to, and she uploads the Final Funds Transfer to the bank. Upon acceptance of the funds transfer, the bank forwards a Transfer Confirmation Notice to the system. At any time during this process, any individual can print a copy of any file. To ensure that proper oversight is conducted, the corporate auditors must have access to all of the files that are created during this process.

Securit y L eadership & M anagemen t

10

Knowing all of this, the ISSMP can now recommend the “role based” security solutions that can be used to implement the concept of “least privilege.” Table 1.2 provides a summary of the privileges that each role (“Drafter” [Sally and John],

“Approver” [Mary], and Auditor [senior management, auditing staff, or third-party auditors]) will be granted in the system to support this scenario.

Note that in this example, Mary, although she is in the role of supervisor, does not have full privileges in the system. Specifically, she cannot change the Submitted Draft Funds Transfer or the Transfer Confirmation Notice. This is to ensure that she cannot modify key documents required by the auditors to ensure that the process and the actions of the employees are in full compliance with standard accounting procedures.

Privileges Approver Drafter Auditor

Word processing program Execute Execute Execute

Vendor invoices Read Read Read

Funds transfer forms Read Read/Write Read

Draft funds transfers Read Read/Write Read

Submitted draft funds transfers Read Read Read

Final funds transfers Read/Write Read Read

Submitted draft funds transfers Read Read Read

Internet browser program Execute No Access No Access Authentication books/tokens Access No Access No Access

Transfer confirmation notice Read Read Read

Printer Write Write Write

Table 1.2 – Roles and Privileges

Compliance

In addition to the mission, business, and operating requirements, the ISSMP must understand the legal and regulatory restrictions and demands that are imposed on each group in the organization. These are critical because deploying security that fails to make the system compliant with one of these can result in major fines or negatively impact the reputation of the organization. The following are some of the more common legal and regulatory compliance needs:

■ Privacy Act of 1974 – The purpose of this act is to protect the rights of individuals by placing restrictions on government agencies as to what they can do with personal information (e.g., transferring, matching, etc.), and it mandates security requirements to prevent the unauthorized release of the information.

■ Computer Security Act of 1987 – The U.S. Congress declared that improving the security and privacy of sensitive information in federal computer systems was in the public interest and established the means to create minimum acceptable security practices for such systems.

■ European Union (EU) Directive of 1995 (95/46/EC) – The EU issued this directive to protect individuals with regard to the processing and free movement of their personal data.

■ Health Insurance Portability and Accountability Act of 1996 (HIPAA) – The purpose of HIPAA is to protect an individual’s healthcare information from being used in an unethical and fraudulent manner. The act mandates that the officers and employees of organizations related to healthcare (e.g., hospitals, healthcare providers, insurance companies, etc.) deploy safeguards to ensure the integrity and confidentiality of all individual healthcare information, and violations are punishable by fines and jail time.

■ The Health Information Technology for Economic and Clinical Health (HITECH) Act -- Subtitle D of the HITECH Act addresses information relevant to an ISSMP. It mandates privacy and security related to electronic transmission of health information and strengthens rules (both civil and criminal) beyond HIPAA.

■ Personal Information Protection and Electronic Document Act of 2000 (PIPEDA) – PIPEDA is a Canadian law supporting and promoting electronic commerce by protecting personal information that is collected, used, or disclosed in certain circumstances by providing for the use of electronic means to communicate or record information or transactions.

■ Sarbanes-Oxley Act of 2002 (SOX) – The purpose of SOX is to protect investors by improving the accuracy and reliability of corporate disclosures made pursuant to the securities laws, and for other purposes.

■ Federal Information Security Management Act of 2002 (FISMA) – The purposes of Title III of this act are to provide a comprehensive framework for ensuring the effectiveness of information security controls over information resources that support federal operations and assets, effective government wide management and oversight of the related information security risks, and a mechanism for improved oversight of federal agency information security programs (e.g., FISMA compliance reporting to the Office of Management and Budget [OMB], Congressional Federal Computer Security Grades identifying Agency security status, linking deficiencies with budget process, etc.).

Take note that under FISMA, Congress linked the reporting of IT security deficiencies to the government budget process. This connection is one of the keys to gaining and maintaining IT security in the government and commercial sectors. This will be further discussed later in this chapter.

There are also guidances related to security that are issued by various regulatory bodies. The Federal Financial Institutions Examination Council (FFIEC), for example, has issued several security-related guidances to financial institutions.

Securit y L eadership & M anagemen t

12

Cultural Expectations