Information Security Policy
A critical starting point for establishing an appropriate Information Management System (ISMS) is the organisation’s policy with regards to security matters. This must be:
- firmly articulated and agreed from the top down;
- clearly documented;
- proactively communicated to all relevant parties; and
- regularly reviewed and kept up to date.
It can be difficult for an enterprise to make objective, well informed decisions about how to address the need to adopt, document and communicate policies that strike an optimum balance between effectiveness, accessibility and cost. Most organisations’ internal IT functions are focused at delivering the operational services required for their business, leaving little if any time to be focused on more specialist security matters, or maintain currency with the latest developments in Information Security best practice. Those with dedicated security teams also acknowledge that with internal business pressures they cannot be expected to always be completely objective in assessment of risk and making decisions on appropriate measures to address this – objectivity and independence being critical to adequately addressing security requirements.
It is therefore a sensible, best practice first step for any organisation to solicit support from an independent, expert reviewer and advisor, to assess how current practices and security measures match up to currently accepted industry good practice. The critical requirement to establish and document appropriate corporate security policy is an ideal starting point where commissum is able to add significant value.
approach
commissum typically adopts a two phased approach. Initially, we work with the client to establish a sound understanding of the organisation and its business drivers and risk profile. Any existing documentation will be reviewed and recommendations made on addressing deficiencies. The output is:
1. Advice on any gaps in the existing policies – that is ensure they:
- appropriately adopt current industry good security practice; and
- reflect the security posture of the organisation, including any industry/organisation specific issues.
2. Recommendations on a structure for the policy set that ensures:
- the policy set is simple to access, navigate and understand; and
- is readily supportable by the client from the perspective of maintaining currency.
3. A more detailed schedule for the implementation of recommendations.
Phase 1 is conducted as an intensive period of discussion with key staff and inspection of facilities, systems and documentation; a picture is built up of the security posture of the organisation, its business drivers and the business context for the policies. This includes analysis of any existing policies and other relevant documentation and preparation of recommendations.
The schedule that is produced from Phase 1 is discussed with the client and the areas for Phase 2 are agreed. We would usually propose that the final documentation set will adopt our preferred hierarchical structure as follows, but this will be discussed and agreed as part of this assignment:
- Top level security policy document – provides the statement of corporate commitment and high level statement of objectives and scope. It establishes the framework for the supporting policy and procedures
- Subsidiary policy documents – these would cover discrete identified subject areas at policy level, e.g. incident response, third party access, etc
- Supporting procedures, technical standards and AUPs – these identify a more detailed specification of what should be done and how.
Get in touch with one of our security consultants today
- No obligation
- Expert advice
- Tailored solutions
"I was very pleased with the work delivered by commissum from start to finish. The quality of reporting was excellent and the consultants very helpful with clear communication throughout the engagement. I would happily recommend commissum to others.”
Ms Louisa L, IT Manager, National Building Society
Latest News
Alleged Chinese Government Hacking Department back in action
Allegedly the Chinese state sponsored cyber division named as Unit 61398 are back in action after a lull in their activities. This group that allegedly specialises in governmental and industrial espionage was very active and successful up until February this year. The targets of Unit 61398, also known as APT1, have ...Tue 21 May, 2013 //
Leading USA military contractor QinetiQ hacked and ransacked by Chinese hackers for three years
A new report from Bloomberg, the business information provider (www.bloomberg.com/news/2013-05-01/china-cyberspies-outwit-u-s-stealing-military-secrets.html) outlines how hackers from China stealthily infiltrated the computer systems of QinetiQ North America, a leading espionage and military contractor to the US government, and the US branch of the British defence technology company QinetiQ. A vast range of highly ...Wed 08 May, 2013 //
Suspected hacker arrested after “biggest-ever DDoS attack”
Police in Spain have arrested a Dutch national on suspicion of launching the largest-ever “Distributed Denial of Service” (DDoS) attack. Sven Olaf Kamphuis, 35, was arrested on April 25th near Barcelona, Spain. At the time, he was in possession of a specially-equipped van set up as a mobile computing and ...Tue 30 Apr, 2013 //


