Monday, January 4, 2016

Organizational Security (Part II)

More on Organizational Security (Part II)
Jerry Grugin


In this blog, I will discuss the following topics:  Secure Disposal, Acceptable Use Policies (AUP), Mandatory Vacations, Personally Identifiable Information (PII), Due Care, Due Diligence, Due Process, SLA, and Security-Aware HR.

Secure Disposal

One of CompTia's domain objectives is SECURE DISPOSAL.  Secure disposal involves things such as the information storage and retention policy, disposition workflow, information destruction policy, and re-sale of systems.  We have to know what information is going to be stored and how long to store it.  These, sometimes, are dictated by such entities as the Department of Defense, or other smaller entities.  The information destruction policy should include shredding, zeroing out hard drives, and degaussing.  Degaussing means applying a strong magnetic field to initialize the media.  Degaussing is also known is disk wiping.  A low level format can also be done.

Acceptable Use Policy

Acceptable use policies deal with computers and information systems provided by the company or the organization.  The policy needs to lay out in very explicit terms what activities are allowed and what activities are forbidden on the equipment and the systems.  It could be something as simple as the computers provided by the company are for company business only.  AUPs can be broken down into web access policies, email usage policies, and private usage policies.  There are also policies on telephone system usage, how you use information, and how to deal with questions for any gray areas.

Security-Aware Human Resources Team

A security-aware human resources team should have solid security-based hiring policies, a training and awareness process for newly hired people, termination policies, background check procedures, and should be aware of privacy (HIPPA).  A security-aware human resources team should provide training on ethics policies.  Importantly, if a human resources team knows that an involuntary termination is coming, they will actually alert the IT department first before the employee is notified of the termination.  This is so IT can have the ability to back up certain information on file servers and be ready to have badges returned.  Also, physical access badges and tokens have to be given back by the terminated employee.

Personally Identifiable Information (PII)

There are many federal laws that have addressed the issue of making sure personal information does not get into the wrong hands.  There is the Online Privacy Protection Act of 2003 (OPPA), the Privacy Act, the Identity Theft Prevention Act, Consumer Privacy Protection Act, Anti Phishing Act, and HIPPA.  Personal information is any information that could directly identify a person either directly or indirectly.  Examples of PII are full name, national ID number, social security number, telephone number, address information, email information, vehicle registration number, driver's license number, credit card numbers, digital identities, and personal traits.  There are more, but these are just a few.

Mandatory Vacations

Mandatory vacations fall into the category of "rotation of duties."  This concept means you do not want to have any one individual responsible for a certain area or a certain system of your organization indefinitely.  You eventually want to rotate your employees.  This helps prevent fraud.  It also keeps you from having a single point of failure rest with one human being.  Thus, an employer should make their employees take two to three week vacations.  This forces a company to bring in another person.  In the weeks leading up to vacation, the person taking a vacation has to open up their journal and cross train some other person(s) to cover for them while they are gone.  In the process of cross training and exposing the work process, it cuts down on fraud.

Due Care / Due Diligence / Due Process

Due Care and Due Diligence are technically the same thing.  Due diligence is also referred to as standard of care.  Due Diligence came into use as a result of the 1933 Securities Act.  IT persons need to perform security due diligence.  Due process comes directly from the U.S. Constitution, the 5th and 14th Amendment.  A person has the right to be heard in an orderly proceeding in order to protect their own rights against allegations and prosecution.

Service Level Agreement (SLA)

A service level agreement is an agreement between service provider / vendor and you or your company.  It may be security or availability related.  It outlines contractual obligations and deliverables.  SLAs are also known as maintenance contracts.  SLAs also cover MTBF vs. MTTR.  MTBF is known as "Mean Time Between Failure."  MTTR is the "Mean Time to Repair."

Conclusion

In this blog covering additional information on organizational security, we have covered the following topics:  Secure Disposal, Acceptable Use Policies (AUP), Mandatory Vacations, Personally Identifiable Information (PII), Due Care, Due Diligence, Due Process, SLA, and Security-Aware HR.

No comments:

Post a Comment