Showing posts with label Information Security. Show all posts
Showing posts with label Information Security. Show all posts

Wednesday, December 14, 2011

ISMS Implementation: Examing Roles & Responsibilities by Rafidah Abdul Hamid



“Security is everyone’s responsibility”.

Everyone have roles and responsibilities for maintaining security in organization.The management, technical people, employees, vendors and contractors havedifferent roles in developing and implementing an effective security process. For this article, we will look at the roles and responsibilities of management, Information Security Department and users in implementing and maintaining information security management system (ISMS) in organization.

Management's responsibilities
Management's responsibility goes beyond the basics of support. They must set the tone for the entire program. It is not enough just to bless the program. Management must own up to the program by becoming a part of the process. Management is responsible for overseeing the development, implementation, and maintenance of ISMS. This includes defining the information security objectives of the organization, allocating an amount of money to be invested in information security, and ensuring the compliancy and enforcement of implementation.

Management has specific goals for the organization, and sometimes technical people are not in the position to understand these nuances. Both groups should understand that security is not something that can be wrapped in a package and bought off the shelf. It should be a goal that both parties strive to maintain. One of the ways to bridge the divide is by setting up an Information Security Management Committee.

It is the responsibility of management to form this committee that will be responsible for reviewing changes in the business and determining how ISMS implementation should support those changes. To make this committee success, it is good to distribute the responsibilities throughout the organization depending on the institution’s size, complexity, culture, nature of operations, and other factors. The distribution of duties should ensure an appropriate segregation of duties between individuals or organizational groups. Management should also ensure integration of security controls throughout the organization by performing the following:

-Ensure the security process is governed by organizational policies and practices
that are consistently applied,
-Require that information with similar criticality and sensitivity characteristics
be protected consistently regardless of where in the organization it resides,
-Enforce compliance with the security program in a balanced and consistent manner
across the organization, and
-Coordinate information security with physical security.

Information
Security Department Responsibilities
The Information Security Department is responsible and accountable for security administration. At a minimum, they should directly manage or oversee risk assessment, development of policies, standards, and procedures, testing, and security reporting processes. Security officers should have the authority to respond to a security event by ordering emergency actions to protect the organization from an imminent loss of information or value. They should have sufficient knowledge, background, and training, as well as an organizational position, to enable them to perform their assigned tasks.

User
Responsibilities
Users should know, understand, and be held accountable for fulfilling their security responsibilities. The means of ensuring users understanding and/or recognition of their responsibilities varies. User security awareness training is one of the most common means available to achieve recognition of responsibility and computing asset worth. Some organizations require personnel to sign an agreement that includes the protection of computing assets as a condition of employment, while others sign agreements as a condition of allowing their
connection to the organizations network. One way to ensure that every current and future user knows that security is part of his job function is to make it part of each job description. Spelling out the security function or expectations within the job description demonstrates the commitment to information security, as well as emphasizes that it is part of the job. After it is made part of the job description, it becomes something that can be considered in performance evaluations.

Conclusion
Information security is the responsibility of everyone in the organization. Management support is crucial for a successful ISMS implementation. Along with its support is a responsibility to the ongoing maintenance of this program. To have a successful ISMS implementation; management, Information Security Department and users must have a good understanding of their roles and responsibilities and be willing to take actions.

Infosecurity World Exhibition & Conference 2012 in Kuala Lumpur, Malaysia (21-22 March 2012)


Infosecurity World Exhibition and Conference aims to answer the growing concerns of the international IT market regarding the threats to information security and protection of crucial and confidential data.

On one hand this trade show will serve the requirements of the channel players and retailers in terms of providing them with a platform to display their products and services as well as indulge in networking and business development initiatives, while on the other hand, it enlightens the visitors about the emerging trends in data security and cyber security.

Infosecurity World Exhibition and Conference is expected to be visited by more than 5,000 commercial and non commercial customers, who will get an unrivaled opportunity to interact with top industry players from all over the world

More info:

Friday, December 9, 2011

ISO27001 compliance database keeps UK companies up to date with laws and regulations

Ely, England, 6 December 2011 – There are over 70 information-related laws and statutes currently in force in the UK. Organisations need to know what laws they have to comply with and how to ensure compliance. For those implementing ISO27001, there is a requirement that their ISMS takes ‘into account business and legal or regulatory requirements, and contractual security obligations’.

Since the new UK Government’s Cyber Security Strategy was published in November, there is an even greater incentive for all industries to familiarise themselves with the existing legislation and adhere to those laws relevant them. Important laws, such as the Data Protection Act (DPA), Freedom of Information Act, Privacy and Electronic Communications Regulations and many more, exist in order to protect organisations’ information assets, as well as the well-being of their customers and stakeholders. The Information Commissioner’s Office looks after their application and has the right to fine any organisation that violates these laws. The internationally recognised ISO27001, on the other hand, ensures that companies comply with this legislation.

More importantly, some experts believe, that the new Cyber Security Strategy can only be successful if organisations are required to pursue ISO27001 with a number of mandated controls, and if businesses are encouraged to invest in improving their information security.

Speaking to risk.net in November, Alan Calder, CEO of IT Governance, stated “The big thing is that, while the Government talks about needing to take the lead and have a public–­private partnership, what it really needs to be doing is making sure companies in the UK financial sector, and outside the financial sector, take information security a massive amount more seriously".

The experts at IT Governance, the single-source provider for everything related to ISO27001 and information security, have recently launched their revised ISO27001 Compliance Database and Update Service. This is the only product on the market that holds a repository of all the 71 statutes and regulations relevant to ISO27001. Updated for 2011, the ISO27001 Compliance Database includes 10 new laws and offers regular updates (depending on the subscription period) as and when new laws are published.

ISO27001 requires organisations to develop their information security management system (ISMS), taking into account ‘business and legal or regulatory requirements, and contractual security obligations’ (Clause 4.2.1 b. 2). There are five controls in ISO/IEC 27001 Annex A which impose specific requirements in terms of identifying and staying up to date with statutory and regulatory requirements.

The ISO 27001 Compliance Database and Update Service identifies the specific clauses within each legal instrument that organisations must comply with, providing best-practice guidance on how to comply with that clause. It also enables an ISMS project manager to select appropriate controls at the individual clause level

Source:
http://www.itgovernance.co.uk/media/article.aspx?news_id=1204

Monday, August 30, 2010

CYBER SECURITY MALAYSIA AWARDS, CONFERENCE & EXHIBITION (CSM-ACE) 2010 @ KLCC, Malaysia (Oct 25-29, 2010)


The CSM-ACE 2010 is an annual industry conference that shapes the regional information security landscape. The conference is expected to draw over 1,000 participants from around the world. CSM-ACE 2010 will bring together some of the most influential and innovative minds in business, government and academia, as well as key information security players to exchange policies and ideas on technology.

The theme of CSM-ACE 2010 is “Securing Our Digital City”.

“Securing Our Digital City” is a proactive initiative to address national security concerns and to build community confidence by mitigating the multi-dimensional cyber security challenges in critical infrastructure, economic and cyber crimes.

The vision is to create a cyber-secured community that is engaged at local, state, national and international levels. This will be a holistic approach towards cyber security.

The “Securing Our Digital City” initiative will provide the “community” or digital cities with the knowledge and awareness in cyber security and best practices needed to secure our digital cities.

For more information about Cyber Security Malaysia Awards, Conference & Exhibition (CSM-ACE) 2010, please contact secretariat@csm-ace.my

Saturday, August 28, 2010

Hackers delay payout for 18,000 senior citizens

Published by The Star on Wednesday May 26, 2010
GEORGE TOWN: The RM100 payment due to 18,000 senior citizens by mid-May has been delayed by a month as the computer system of the state government’s appreciation programme for senior citizens was hacked early this month.

State Welfare, Health, Caring Society and Environment Committee chairman Phee Boon Poh said the affected senior citizens are those who had gone overseas and those whose vouchers were returned by the banks due to technical errors when the money was handed out last month.

“The system has been fixed and the officers in charge are now revising and checking the names of the recipients,” he told a press conference here yesterday.

“Many names were missing from the system but we have a back-up,” he said, adding that it would take time to check the names of the people from all five districts.

“The district officers are all working hard to rectify the matter,” added Phee.

It was reported on April 24 that some 93% of the 82,983 senior citizens who registered for the Penang government’s annual RM100 appreciation reward programme had collected their money.

Phee added that the payment for those who registered between May 1 and July 31 would be made by the end of August.

Asked if he had lodged a police report over the hacking, he said he needed to get the full report before considering the move

Info security plan for critical agencies


Published by The Star on Friday August 6, 2010
KUALA LUMPUR: All critical government agencies must obtain information security certificates by 2012 to ward off cyber threats and attacks, said Minister in the Prime Minister’s Department Datuk Seri Nazri Aziz.

He said the Cabinet decided on Feb 24 that these agencies must obtain the Information Security Management System (ISMS) certification within three years to ensure that they were ready to face cyber threats and attacks.

“They will have to meet international security procedures and standards before they can get the certificate from Sirim,” he told reporters after closing the Third National Cyber Crisis Exercise here yesterday.

The agencies in the 10 critical sectors were those in transportation, banking and finance, technology and communication, defence and security, water, energy, health, government, food and agriculture.

Nazri said security did not only involve physical threats but also those in cyber space.

“Any threat against our ICT or critical national information infrastructure can affect national security and our country’s social, economic and political stability.

“The National Security Council has set up the National Cyber Crisis Management Plan to identify possible cyber threats and attacks and find ways to counter them,” he said.

CyberSecurity Malaysia chief operating officer Zahri Yunos said the most worrying threat was distributed denial of service (DDOS) attacks


http://thestar.com.my/news/story.asp?file=/2010/8/6/nation/6810121&sec=nation

Fact or Myth On Information Security



Perception 1:
Information Security is the concern and responsibility of the MIS/IT Manager or Department.
Verdict: MYTH

Perception 2:
Security Threats from outsiders are the greatest source of risks.
Verdict: MYTH

Perception 3:
Information Security is assured by safeguarding networks and the IT infrastructure.
Verdict: MYTH

Perception 4:
Adopting latest technological solutions will increase security
Verdict: MYTH

Information Security Management System (ISO/IEC 27001)- 2W Questions


What is ISO/IEC 27001 (ISMS)?

 is auditable international standard which defines the requirements for an
Information Security Management System (ISMS) was established in 2005
 replaces the BS7799 requirements with the intention to provide the
foundation for third party audit, and is 'harmonized' with other management
standards, such as ISO 9001 and ISO 14001
 helps establish and maintain an effective information management system
 applies to all types of organizations
 is designed to be used for certification purposes
 lists a set of control objectives and controls
 emphasize on a continual improvement approach


Why ISO 27001 (ISMS)?


 a comprehensive approach to the management of information security in the
organization
 ensuring business continuity especially in the event of emergency
 ensuring compliance with the law and regulations
 reducing financial damage due to information theft and fraud
 assist in uphold of reputation of the organization as well as it’s brand
 provision of timely detection, reporting and management of security
incidents. Thus, minimize the impacts of security events
 better planning and investing in areas where proper management and
elimination of security threats are necessary
 competitive advantage and provide confidence to certified organizations as
the certification proves proper protection and management of information