Study sheet: Information Security and Continuity Planning

Course Outline

  1. Information Security Foundations
  2. Information Classification
  3. Security Policies and Standards
  4. Security Roles and Awareness
  5. Risk Analysis and Assessment
  6. Quantitative Risk Management
  7. Business Continuity Planning
  8. Business Impact Analysis
  9. Disaster Recovery Planning
  10. DRP Testing and Procedures

1. Information Security Foundations

Key Concepts & Definitions

  • Information security : protects an organization's valuable resources and ensures that resources are protected and available when needed.
  • Availability : assures that a computer system is accessible by authorized users whenever needed.
  • Integrity : protects system information from intentional or accidental unauthorized changes.
  • Confidentiality : assures that unauthorized people cannot access protected information.

โ˜… Must-know

  • The three basic information security requirements are:
    • availability
    • integrity
    • confidentiality

Further detail

๐Ÿ“Œ Identification is how users claim their identities, authentication tests evidence of identity, authorization grants rights and permissions, accountability uses audit trails and logs, and privacy concerns the level of confidentiality and privacy protection.

Memory Hook

CIA: confidentiality, integrity, availability

2. Information Classification

Essential Points

๐Ÿ“Œ Information classification focuses protection and control on data that needs it most because not all data has the same value to an organization, and it can support privacy-law and regulatory compliance.

  • The private-sector classification terms are:

    • public
    • sensitive
    • private
    • confidential
  • The classification procedure identifies the administrator or custodian, specifies classification and labeling criteria, classifies data by its owner subject to supervisor review, documents exceptions, specifies controls for each level, defines declassification or custody-transfer procedures, and creates an enterprise awareness program.

๐Ÿ“Œ The information owner determines the required classification and delegates protection duties to the custodian, while the custodian protects the information and the user routinely uses it for work.

Memory Hook

Identify, classify, control, declassify, educate

3. Security Policies and Standards

Key Concepts & Definitions

  • Security policy : is the first and highest level of documentation, consists usually of general statements, and provides the basis for a sound security implementation.

Essential Points

  • The senior management statement of policy acknowledges the importance of computing resources, supports information security throughout the enterprise, and commits to authorizing and managing lower-level standards, procedures, and guidelines.

๐Ÿ“Œ Standards specify technologies uniformly and are compulsory, guidelines provide flexible non-compulsory recommendations, and procedures contain the detailed steps for performing a specific task.

Memory Hook

Policy โ†’ standard/guideline โ†’ procedure

4. Security Roles and Awareness

Essential Points

  • Security responsibilities are assigned as follows:
    • Senior manager: ultimate responsibility for security
    • Information security officer: functional responsibility for security
    • Owner: determines data classification
    • Custodian: preserves confidentiality, integrity, and availability
    • User or operator: performs stated policies
    • Auditor: examines security

๐Ÿ“Œ Security awareness training is necessary because people are often the weakest link in a security chain, employees must protect enterprise information assets, and operators need secure job-function skills.

5. Risk Analysis and Assessment

Key Concepts & Definitions

  • Risk management : identifies, analyzes, and assesses risk before mitigating or transferring it.
  • Risk assessment : assigns value to assets, threat frequency, consequences, and other elements of chance to characterize the process and result of analyzing and assessing risk.

โ˜… Must-know

  • ๐Ÿ”„ Risk analysis proceeds by:
    1. Examining the target environment and risk-related attributes
    2. Identifying vulnerabilities
    3. Associating vulnerabilities with affected assets
    4. Determining potential undesirable results
    5. Evaluating risk-reducing countermeasures

Further detail

๐Ÿ“Œ Risk decisions must consider what can happen, how severe the impact could be, how often it could happen annually, how certain the answers are, what mitigation is possible, its annualized cost, and whether it is cost-effective.

Memory Hook

Threat โ†’ impact โ†’ frequency โ†’ uncertainty โ†’ mitigation

6. Quantitative Risk Management

Key Concepts & Definitions

  • Exposure Factor : measures the magnitude of loss on an asset and is expressed as a percentage from 0 to 100% of asset value lost from a threat event.
  • Annualized Rate of Occurrence : Annualized Rate of Occurrence is the frequency with which a threat is expected to occur, such as 50 occurrences in one year producing an ARO of 50 or one occurrence in ten years producing an ARO of 0.1.

โ˜… Must-know

๐Ÿ“ Formula โ€” Single Loss Expectancy is the monetary loss for each occurrence of a threatened event and satisfies SLE=Assetย Valueร—Exposureย FactorSLE = Asset\ Value \times Exposure\ Factor.

๐Ÿ“ Formula โ€” Annualized Loss Expectancy is the expected annual loss and satisfies ALE=SLEร—AROALE = SLE \times ARO.

Further detail

๐Ÿ“ Formula โ€” The value of a safeguard satisfies Valueย ofย safeguard=ALEbeforeโˆ’ALEafterโˆ’annualย safeguardย costValue\ of\ safeguard = ALE_{before} - ALE_{after} - annual\ safeguard\ cost.

Memory Hook

SLE ร— ARO = ALE

7. Business Continuity Planning

Key Concepts & Definitions

  • Business Continuity Planning : creates plans and a framework to ensure that business can continue during an emergency through scope and plan initiation, business impact analysis, and continuity plan development.
  • Disaster Recovery Planning : recovers from an emergency with minimum organizational impact through recovery processes, testing, and recovery procedures.

โ˜… Must-know

  • BCP objectives include:
    • preventing interruptions
    • protecting critical processes
    • minimizing disturbances
    • resuming business processes
    • reducing financial loss
    • improving prompt recovery
    • minimizing disruptive-event costs

Further detail

๐Ÿ“Œ Natural disruptive events include fires, explosions, hazardous material spills, earthquakes, storms, floods, and utility failures, while man-made events include bombings, sabotage, strikes, employee unavailability, and communications infrastructure failures.

Memory Hook

Scope โ†’ BIA โ†’ continuity strategy โ†’ approval

8. Business Impact Analysis

Key Concepts & Definitions

  • Business Impact Analysis : creates a document that helps determine the impact a disruptive event would have on the business.
  • Maximum Tolerable Downtime : is the longest period a critical process can remain interrupted before the company can never recover.

โ˜… Must-know

  • ๐Ÿ”„ Scope and plan initiation involves:
    1. Examining operations and support services
    2. Creating a detailed account of required work
    3. Listing resources
    4. Defining management practices

Further detail

  • BIA documents required processes, identifies interdependencies, determines acceptable interruption periods, identifies support for critical areas, records quantitative and qualitative impacts, and recommends recovery priorities to senior management.

9. Disaster Recovery Planning

โ˜… Must-know

  • The continuity strategy addresses:
    • computing
    • facilities
    • people
    • supplies and equipment

๐Ÿ“Œ Plan approval and implementation requires senior management approval, enterprise-wide awareness, training for personnel with specific duties, maintenance responsibilities, regular audits, and prevention of multiple plan versions.

Further detail

๐Ÿ“Œ DRP objectives include organized crisis decisions, reduced confusion, protection from major computer-service failure, reduced service-delivery delays, tested standby-system reliability, and reduced disaster-time decision-making by personnel.

Memory Hook

Hot sites are ready immediately; cold sites require equipment

10. DRP Testing and Procedures

Key Concepts & Definitions

  • Mutual aid agreement : is an arrangement in which companies with similar computing needs agree to support each other during a disruptive event.
  • Service bureau : is contracted to provide alternate backup processing services, offering quick response and possible testing but exposing the organization to expense and resource contention during a large emergency.

โ˜… Must-know

  • The DRP process develops recovery plans by planning data-processing continuity for a disaster and maintaining the data recovery plan so it remains current and relevant.

๐Ÿ“Œ A hot site is a fully configured facility available immediately, a cold site provides space and utilities but no resident hardware, and a warm site provides facilities and utilities while applications or workstations may require configuration and setup.

๐Ÿ“Œ Electronic vaulting transfers backup data off-site, remote journaling processes transactions in parallel at an alternate site, and database shadowing duplicates database sets across multiple servers.

  • DRP testing verifies recovery-procedure accuracy, identifies deficiencies, trains personnel for emergency duties, and verifies the alternate site's processing capability.

  • The five DRP test types are:

    • checklist
    • structured walk-through
    • simulation
    • parallel
    • full-interruption

๐Ÿ“Œ The recovery team activates recovery procedures and restores critical functions at the alternate site, the salvage team restores the primary site, and normal operations resume when processing returns from the alternate site to the primary site.

Further detail

  • Other alternate processing services include:

    • mutual aid agreements
    • multiple centers
    • service bureaus
    • other data-center backup alternatives
  • DRP maintenance builds maintenance and audit procedures into the organization so the plan remains current and its state is reported regularly.

  • Other recovery issues include:

    • interfacing with external groups
    • employee relations
    • fraud and crime
    • financial disbursement
    • media relations

Memory Hook

Checklist โ†’ walk-through โ†’ simulation โ†’ parallel โ†’ full interruption

Synthesis Tables

BCP and DRP Comparison

DimensionBCPDRP
Primary purposeContinue business during an emergencyRecover from an emergency
Main componentsScope initiation, BIA, plan developmentRecovery process, testing, procedures
Main concernProtect and resume critical business processesRestore services with minimum impact

Policy Implementation Levels

ElementFunctionCompulsion
PolicyGeneral, high-level directionRequired foundation
StandardUniform technology requirementsCompulsory
GuidelineFlexible recommendationsNot compulsory
ProcedureDetailed task stepsOperational instruction

Test your knowledge

Test your knowledge on Information Security and Continuity Planning with 32 multiple-choice questions with detailed corrections.

1. What is the primary purpose of information security within an organization?

2. Which set correctly identifies the three basic requirements of information security?

Take the quiz โ†’

Review with flashcards

Memorize the key concepts of Information Security and Continuity Planning with 63 interactive flashcards.

What does information security protect in an organization?

An organization's valuable resources.

What are the three basic information security requirements?

Availability, integrity, and confidentiality.

What does availability assure in information security?

That authorized users can access a system whenever needed.

See flashcards โ†’

Similar courses

Create your own study sheets

Import your course and AI generates sheets, quizzes and flashcards in 30 seconds.

Sheet generator