Skip to content
CBT Nuggets
DemoBook a Demo

Creating An Information Security Program

The skill 'Creating An Information Security Program' explores the essential components and strategies for developing and managing an effective information security program. It emphasizes the importance of aligning security initiatives with organizational culture and goals, and discusses the role of governance, risk management, and compliance in maintaining security. The content also covers the use of various security frameworks and tools, such as SWOT analysis and the Capability Maturity Model, to guide strategic planning and implementation. Overall, the skill provides a comprehensive overview of the processes and considerations necessary for safeguarding organizational assets and ensuring data confidentiality, integrity, and availability.

Full skill from CISM. Preview the IT training 23,000+ organizations trust.

1h 1m

Skill 1 of 14 in CISM

Introduction

As an Information Security Manager (ISM) you may be tasked with creating an Information Security program if one doesn't already exist. On the other hand if one does exist, is it meeting the needs of the organization and is it continually improving and maturing? In this skill we're going to start looking into what makes up an Information Security program and these same points apply to existing programs that may need to be overhauled or updated. Let's get started!

Organizational Culture

How does organizational culture play into information security and vice versa? That's the topic of this nugget.

Knowledge Check

Information security programs that align with organizational culture are more likely to be successful. (True or False)

Security Governance

Information security governance is overseen by the Information Security Manger (ISM) and is the process of overseeing and managing information security within an organization.

Nugget 1:

Nugget 2:

Knowledge Check

The CIA Triad consists of Confidentiality, Integrity and which other topic?

The Importance of Strategy

Within an information security program we must have a strategy. Where does the strategy come from? How do we develop a strategy? That's what this nugget is all about.

Nugget 1:

Nugget 2:

Knowledge Check

The process of identifying how we can get from where we are today, to our objective or goal can be done through which of the following?

Information Security Frameworks

One way to decide upon our objective is to choose a framework to comply with. Let's discuss some common industry standard frameworks.

Knowledge Check

Which framework was created by ISACA?

Strategic Objectives

Once we decide upon our objectives, we should consider using some tools to ensure we are taking the correct steps to reach our objectives. Let's discuss some of those tools.

Knowledge Check

One of the tools we discussed was a SWOT analysis. SWOT stands for Strenght, Weaknesses, Opportunities and what else?

Business Model for Information Security (BMIS)

BMIS was created by ISACA as a guide for a business oriented approach to information security. Let's see how this model is used.

Knowledge Check

The four key elements of BMIS are Organization, People, Technology and what other element?

Validation

Congratulations on finishing the skill. Now it's time to put your newly acquired knowledge to the test with some validation challenge questions.

Question 1

Knowledge Check

Susan's company recently experienced a data breach that affected a database that had credit card data in it. Which framework would Susan's company need to be in compliance with since they handle credit card data?

Question 2

Knowledge Check

John's the IT manager at his company and they're experiencing an attack on one of their servers that's using up all of the resources so that nobody can use the application running on that server. Which part of the CIA triad is being affected in this instance?

Question 3

Knowledge Check

Molly is performing a SWOT analysis on her companies password security and has identified that there are no minimum password requirements. In which area of SWOT would this finding fall under?

Question 4

Knowledge Check

Javier is a database administrator at his company and has found a malicious piece of software on the database server. He has researched this malware and found out that it's objective is to alter data within databases in an effort to corrupt the data. Which part of the CIA triad is being affected in this instance?

Question 5

Knowledge Check

Pradeep is the information security manager at a large urgent care center and he'd found out that one of the employees has been stealing patient records in order to sell personal data. Which of the frameworks we discussed, would this be in violation of?

Knowledge Check

Have you ever worked with any of the frameworks we discussed?

This interactive assessment is available in the full learning experience.

Want to answer questions like this yourself?
with no purchase required. Already have an account?

View Transcript

Organizational Culture

0:00Let's talk about organizational culture. When it comes to information security,

0:05the question is, "Is organizational culture important?" And the answer to that

0:10is an astounding "yes." Not just a little "yes" but a big "yes" because

0:17organizational culture is absolutely crucial to having a successful

0:23information security program. It significantly influences the effectiveness

0:29of any security initiatives and the overall security posture of an

0:34organization. So that's why this is an astounding "yes." So let's go through a

0:41little exercise here. Think of your favorite restaurant. Where do you like to

0:45go and you really enjoy it? You just show up there, the people are so friendly,

0:49and

0:49they know your name, they know what you like to order, the food's

0:52consistently good. So every time you go in you have a great experience. The

0:57atmosphere is nice. Well this is all because of the culture of that business.

1:03The culture of the business might be that they want their guests, their

1:08customers, to feel like they're eating at a friend's house. And again, back to

1:13the

1:13big smile. Culture, it really influences everything in a business. And that's

1:19why

1:19it's so important. So the reason you like to go to these places that you enjoy

1:23and

1:24there have friendly employees working there and the atmosphere is great and the

1:28food is great. You just have a good time. It's because of the culture. So think

1:34about taking that culture and the influence it has and putting it in your

1:38standard business environment where you're dealing with information security.

1:43So

1:43culture is a driving force behind getting everyone in the same mindset.

1:48Getting everyone on the same bus so that they can take this trip together in

1:56the

1:56business to arrive at whatever their goal is right down here as the number one

2:03team. So that culture is the driving force that brings everybody together and

2:08gets them in alignment with the organizational goals. And CBT Nuggets has a

2:13great culture. It's an amazing culture and it's what drives us to deliver the

2:18best content that we can and to relate with our learners and to interact with

2:22them and feel the struggle so that we can share in this together. So let's talk

2:28about how does this tie into information security when we're talking about

2:32culture. Because down here there's a label I don't know if you can read it or

2:36not but it says one size fits all. And guess what? There is no such thing as a

2:41one size fits all when it comes to information security. And that's because

2:46in information security our policies pretty much define everything that we do

2:53within an organization. They outline what the business's stances are on

2:58various topics. And under the policies we'll end up creating procedures later

3:04on.

3:04And these procedures outline the how to of following our policies. These

3:10policies

3:11are how we feel about X. Okay and Y and Z and ABC as an organization. So it

3:18could

3:18be about data privacy. You know we're very strong about data privacy and we

3:22want to follow these standards or frameworks about data privacy. And then

3:28we get down to the procedures and these are the technical how to's to be in

3:32alignment with our policy. So when it comes to our policies a one size fits

3:36all just doesn't really work. So oftentimes we need to tailor policies to

3:40work with our organizational culture. That's very important here. When we're

3:45talking about these policies they need to fit in to our culture. Because if we

3:53do it this way and we fit in these policies are much more likely to be

4:00adopted and followed by the organization. We don't want to fight an uphill

4:05battle

4:05on telling you folks. So let's talk about how this ties into communications. So

4:11let's talk about communications just kind of in general here. So as security

4:16managers we communicate both up and down the org chart or our chain of command

4:21right. And we need to understand the culture again we're going back to

4:25culture. The culture within the organization and how the communications

4:30works within the organization within the culture. What's normal? Is this a

4:36communications culture that uses Microsoft Teams channels and SharePoint

4:40sites for making documentation and training available? Well if so then when

4:45we come up with our information security program and within it we have our

4:50documentation or docs and we're gonna have training. Well in that we need to

4:55make sure that this aligns with the culture. And as I had mentioned when we're

5:02talking about communications they were using like Microsoft Teams and Share

5:06Point

5:07as part of their communications. Well we would want to incorporate our

5:11documentation and training into these platforms because our users are

5:17really familiar with them. We do not want to go in and deploy a whole new set

5:21of

5:22applications and cloud services and such for security because our users they

5:28just like to do their job. They don't want to have to go outside the norm. And

5:31again that goes back to culture something outside the normal culture. So if we

5:36follow the culture and we're here we're talking about communications then it's

5:41much more likely to be adopted and accepted by everyone in the organization.

5:46So again we need to be in alignment with culture. We really need to understand

5:51the organizational culture. And we're gonna talk about this as we go

5:54throughout the skill and really it's gonna come up throughout the entire

5:57course because it is so important. So in review a security program that clashes

6:02with the organization culture is likely to face resistance. It's not gonna be

6:07understood very well and ultimately it's gonna be less effective at protecting

6:12the organization. So again culture is so very important. All right well that

6:18wraps

6:18up our Nugget on Culture!

Security Governance

0:00Alright, let's talk about security governance.

0:03And let's start off with the word governance.

0:05Okay, that's what we're going to start with because security we're pretty much

0:08in tune

0:08with as far as everybody has already experienced security throughout their life

0:12.

0:13I mean, we talk about things like locking your doors at home.

0:15That's part of security, buckling your seat belt.

0:18That's kind of part of security.

0:20And we deal with this all the time.

0:22So what I really want to focus on here is governance and what that means.

0:26So governance is overseeing the control and direction of something.

0:31So I'm going to put that up here.

0:32So really it's overseeing the control and direction.

0:38And in this instance, it's of security and really our security program.

0:43So that being said, this happens in two key ways.

0:48Number one is strategy because we're overseeing the control and direction.

0:53And when it comes to strategy that's generally associated with direction, we're

0:57going to talk

0:57about strategy more in depth here shortly.

1:00But you need strategy and that strategy needs to align with whatever the

1:04organizational

1:05goals are.

1:06Okay.

1:07And then number two is oversight because if you think about it, we don't just

1:12create

1:13something and send it out on its own and let it just be without any oversight.

1:18That would be well, negligent.

1:20We don't send rockets off into space without oversight with folks at Mission

1:25Control watching

1:26the rockets and controlling computers and such.

1:29We just don't do that.

1:31So it really does take the two of these.

1:33We need a strategy so we can stay in the fight and we need oversight to make

1:38sure that our

1:39strategy is in the correct direction, meaning it's in alignment with

1:45organizational goals.

1:46And you'll see this over and over and over again throughout this course and

1:50pretty much

1:51anything in information security.

1:53So let's take a look at some key activities that take place as part of

1:57information security

1:58governance.

1:59The first one is going to be defining objectives and objectives.

2:05Another word for that would just be goals.

2:07So we need to define our goals.

2:09What are these going to be?

2:10Because if we don't define a goal or an objective that we don't have something

2:14to aim for and

2:15to measure up against, we got to have a roadmap.

2:18But we can't have a roadmap if we don't have a destination.

2:22So that's what we're setting here with our objectives and our goals.

2:26Then we need to create policies because these policies are how the organization

2:32feels about

2:33certain things.

2:34What are their stance on this?

2:35And again, I'm going to go back to data privacy because that's so big these

2:39days.

2:40When it comes to data privacy, how do they feel about it?

2:42Is it of not of concern, which of course it is of concern, but we need to

2:46define what

2:47is that we're concerned about and why do we feel this way as an organization?

2:53So these policies are going to define the stance on key topics.

2:58Because these are going to give us some guidance because again, our strategies

3:04and oversight

3:05need to be in alignment with the organizational goals.

3:08Well, these policies are going to be guidance about our goals.

3:14Then we need delegating authority.

3:18Delegating authority.

3:19How does that play into this, Bob?

3:20Well, let me tell you, as a manager, we must delegate responsibility.

3:24We can't do everything ourselves.

3:27So think about this.

3:28We have here our org chart and we've got folks all the way at the top and here

3:33and here as

3:34we go down the pyramid here and the folks down here in the trenches working in

3:40the fields.

3:41Well, think about this.

3:43If we didn't delegate authority, every single decision that needs to take place

3:49down here

3:50by the folks who are working with triaging security incidents and such, they

3:54would have

3:55to send all requests for approval all the way up to the sea level executives

4:00and that's

4:01going to take time.

4:02We don't have enough time for that to happen.

4:05There's not enough bandwidth in the sea level executives day to day routine to

4:09handle that.

4:10That's why we need to delegate authority so that when there is an infected

4:14machine as

4:15malicious software on it, the folks who are trained to handle that can make

4:18decisions

4:19and do that and then report the findings back up the chain.

4:23Okay, so that is very important.

4:25And lastly, here we're going to talk about monitoring through metrics.

4:30So you may be familiar with KPIs or key performance indicators or object and

4:36key results, OKRs.

4:39Either way, these are data points.

4:42And what we're doing is collecting these data points so that we can see how we

4:45're doing.

4:46We don't know if we're doing things right, if we can't measure it.

4:50So that's why we need to measure these things through our KPIs and OKRs or

4:55whatever you want

4:56to call them, these data points.

4:58So we need to collect that data so we can analyze it and see, hey, are we doing

5:02well?

5:03Are we meeting our goals?

5:05Because if we're not measuring it, we can't analyze it and identify how we're

5:09doing.

5:09That's why we need to measure these and monitor these metrics.

5:14So those are four key activities that take place as part of information

5:17security governance.

5:19So now, let's talk about the purpose of information security governance.

5:23So we have activities like information security efforts, part of our programs.

5:28We have our business objectives.

5:30And you'll notice that these two arrows are pointing in the same direction.

5:35That's right.

5:36That's on purpose.

5:37Because we need to ensure that all of our security efforts align keyword here,

5:42align

5:43with business objectives.

5:46And I'm going to put slash organizational goals because these are used

5:50interchangeably.

5:51And you'll hear me reference both of them throughout the course.

5:54But the idea is when we have our information security in place and we're

5:59creating policies

6:00and procedures and we're implementing solutions, we need to make sure that they

6:04're in alignment

6:05with our business objectives.

6:07If they are not, then we have a problem.

6:10Maybe we decide that we're going to do something new.

6:12We're going to start performing some new test or something.

6:16Well, if it starts to veer off from our organizational goals, well, then we

6:21need to stop because it's

6:23not in alignment at that point.

6:25We are wasting resources because we need to be in alignment with the

6:29organizational goals

6:30or business objectives.

6:32Very important there.

6:33So the primary objective of information and security governance.

6:38What is it?

6:39What is the primary objective?

6:40Just boil it down for me.

6:42Bob.

6:43All right.

6:44Here you go.

6:45That right there.

6:46CIA.

6:47And it stands for confidentiality, integrity, and availability.

6:53That is the primary objective of information security governance is to protect.

6:59I'll put that up here.

7:00Protect the CIA.

7:04And this is not the government agency.

7:06We're talking about our confidentiality of our data, the integrity of our data

7:10and the

7:11availability of our data.

7:13Here's why.

7:14Confidentiality, it means that our data is kept secret.

7:19Simply means that other folks who shouldn't have access don't have access.

7:22We're keeping and maintaining confidentiality of our data.

7:26The integrity of our data is the trustworthiness of our data.

7:31Can we trust that data?

7:32If the answer is no, then we don't need it.

7:35And what do I mean by trust?

7:36Well, has this data here been manipulated by outside forces?

7:42Being bad guys out there, malicious actors, has it been manipulated?

7:47Has the data been changed at some point?

7:50Because we must be able to trust our data.

7:53Otherwise, it's useless because if our data is not trustworthy and we use it in

7:57a process,

7:58then the result is going to be untrustworthy results.

8:02Garbage in, garbage out.

8:04That's how it works.

8:05So integrity is very important.

8:07And then lastly, availability, our data must be available to use.

8:11If our data is not available due to something like maybe a ransomware attack or

8:16outages

8:16or something, well, then we're kind of at a standstill.

8:20We can't access that data.

8:21We can't use it.

8:22So it must be available as often as it can be.

8:27So this is the CIA triad.

8:29Confidentiality, integrity, availability.

8:32The primary objective of IS governance is to protect the CIA triad of our

8:37organizational

8:38assets.

Security Governance

0:00Moving on, information security governance requires several activities.

0:05Okay, we're going to talk about some of them briefly.

0:08So, for example, we've already mentioned this, defining objectives or goals.

0:14We've already talked about it and discussed it, but I'm bringing it up again

0:18because it is very important.

0:20Then we need to create a strategy, which is going to be a plan to achieve our

0:25objectives.

0:26Then we need to define security policies.

0:30Because again, our security policy are going to define the organization's

0:35stance on various things, such as security.

0:37And again, it could be data privacy policy or device use policy or lots of

0:43different things.

0:44And we're going to go through various different standards.

0:46When we talk about that, this is just the beginning.

0:49Then we need to adopt standards.

0:52And this helps the organization towards consistency.

0:56For example, we follow a set of standards so that we have something to measure

1:00against and keep us in alignment with those standards.

1:03So the standards are generally a set of best practices that we want to follow.

1:09Then we're going to create processes.

1:13And these define how activity should be performed.

1:17And we're looking for repeatable processes.

1:19They're going to be the most advantageous.

1:23And then we're going to define controls.

1:26And these controls are safeguards.

1:29And they're safeguards that are used to detect, avoid, or counteract security

1:33risks to an organization.

1:35Think of things like firewalls and antivirus and fences and a barbed wire,

1:40maybe at data centers and guards and cameras and all these different things.

1:44These are all controls that we can put in place to address certain types of

1:49risks.

1:50And then lastly, define and analyze metrics.

1:55So again, we're back to our KPIs and OKRs.

1:58And we need to define what do we want to collect.

2:01And then of course we need to analyze the output.

2:04We need to do this to make sure that we are succeeding at our efforts.

2:09Because again, if we can't measure it, then we can't analyze it.

2:12And we don't know how we're doing.

2:14And that's why those are so important.

2:16Now, some additional information security governance activities that are

2:20specifically aimed at protecting the organization.

2:24And these are things we're going to see over and over again as well.

2:28And the first one is risk management.

2:30And when it comes to risk management, this is a huge part of information

2:35security and business in general.

2:37And to be honest, we're going to have a whole section on risk management later

2:42on.

2:42And in my opinion, information security boils down to one thing.

2:47And that's risk management.

2:49We do all these other things.

2:51We put controls in place.

2:52We follow compliances and standards and frameworks.

2:55We perform business continuity and disaster recovery.

2:58We manage all the things.

3:00We collect KPIs, no cars, and we do the analysis.

3:03And why?

3:04Because we need to control risk.

3:06So there's risk management.

3:08That was my little spill on risk management.

3:10I'm a huge believer in risk management when it comes to information security.

3:14Okay, so next up compliance.

3:16So this could be regulatory compliance.

3:19It could be legal compliance or contractual compliance.

3:22But the idea is we have something we need to be in compliance with.

3:26And that being said, we need to be aware that we need to be compliant with

3:31something, right?

3:32Absolutely.

3:33And then we need to monitor this so that we can ensure that we are maintaining

3:39our compliance.

3:40Then next up, number three here, business continuity and disaster recovery

3:44planning.

3:45BCDR.

3:46And business continuity and disaster recovery go hand in hand.

3:51And here's what it comes down to.

3:52Things break.

3:53And bad things happen.

3:54No matter how much we invest in information security, something at some point

4:01will happen.

4:02Just the law of numbers.

4:04It's just how it works.

4:05So this is why business continuity and disaster recovery planning are so

4:10important so that

4:11when something does happen, we can immediately respond and we can minimize the

4:16impact of

4:17whatever event happened has on our organization.

4:21We can survive that with minimal impact.

4:24That's the goal.

4:25All right.

4:26And then lastly is resource management.

4:29And when we're talking about resources, we're talking primarily about two

4:32different things.

4:34Number one is budgetary or financial resources.

4:37Number two is personnel.

4:40Because we only have so many folks working with this, right?

4:43There is a limited or a finite resource both monetarily and when it comes to

4:48personnel.

4:49So we need to manage these things properly.

4:53We need to be good stewards of the resources that we have at our disposal.

4:56And we need to ensure that whatever we're doing is in alignment with, that's

5:01right, our business

5:02objectives or our organizational goals, whichever way you want to look at it.

5:07But it needs to be in alignment with that.

5:09All right.

5:10Let's wrap this up here.

5:12Effective information security governance outcomes.

5:15There's two of them right here that we're going to talk about.

5:18Number one is increased trust.

5:21Okay.

5:23And this actually has two subcategories internal and external.

5:28So here we're talking about the employees, the folks that we work with, as well

5:33as the

5:33seed level suite, right?

5:36And our board, the board of directors or other boards that we might have

5:40working with this.

5:41But the idea is if we are practicing information security properly, we're

5:47monitoring, we're

5:48maintaining, we're planning, we're strategizing, we're doing all the things

5:52that we need to

5:53do.

5:54Then we're going to gain an increased level of trust from our internal folks

5:58here.

5:58But also external.

6:00Think about business partners and customers.

6:04So if a customer comes to you and asks for your most recent audit, well, you're

6:07going

6:07to be able to provide it to them because you're doing auditing and you're

6:11ensuring that you

6:12can provide that audit to your customers upon request so they can see for

6:16themselves that

6:17you are doing security the right way.

6:19And again, it's going to increase trust.

6:22So that is the first one, increased trust.

6:24The second one down here is improved reputation.

6:30And this is as a business or as an organization.

6:33So the idea is all these folks out here are going to see that information

6:37security is

6:38being done right at your organization.

6:42And that word will spread and that will provide you with improved reputation.

6:47It lets the world know that you've taken a stance on information security.

6:51body into it and you're there for the long haul.

The Importance of Strategy

0:00Let's talk about information security strategy and let's focus on starting with

0:05what is a strategy?

0:07Well, it's simply a plan to get where you want to be

0:10That's what a strategy is so when it comes down to this and we've already

0:17talked about some of the things that come in to

0:19Play when defining a strategy. Well, you need to first

0:24Define your objective so when put over here and one

0:29Define objective or goal and if you think back in the last night

0:35We talked about this exact thing a couple of times and then number two you need

0:39to identify

0:41Where you are today and this is in relation to your goal where you want to end

0:48up and then number three

0:50You're going to define

0:52how to get there and

0:55It's the how to get there or how to get to your goal that is going to be your

1:00strategy

1:01So let's talk about an example here. Let's say you want to become a

1:08professional pickleball player

1:10And truth be told I've never played it. So I don't know

1:13But your goal is to become a professional pickleball player

1:18So you down here you play pickleball let's say a couple times a week you'll go

1:23out and you'll play pickleball

1:25With some friends and you've actually played in a couple of tournaments and you

1:28've done okay

1:29But you've decided you want to be a professional pickleball player. All right.

1:33So now we have a goal

1:35The goal is to become a professional pickleball player number two. We need to

1:41identify where we're at today

1:42Well, we know we play periodically. Okay, so we know where we are and

1:48We know that we play in some tournaments. Okay, so then number three down here.

1:53We're going to define how to get to the goal

1:55So how are we going to do that? Let's talk about it. Well, maybe I'm going to

1:59Increase my practice to five times a week and I'm going to start focusing on

2:05Doing some exercises for key muscles that are used to get them stronger for my

2:10pickleball ventures

2:11And then maybe I'm going to play in more tournaments to get exposure to better

2:14players. So those three things

2:16That's my strategy for becoming a professional pickleball player think about

2:21that

2:21It's pretty simplified but from this you can kind of see into what you would do

2:26When defining a strategy for an information security goal

2:31So let's talk about some different tools that you could use to help achieve

2:36that goal

2:37So some of these tools that are going to be part of your strategy are going to

2:41be policies and procedures

2:42Better known as P and P

2:47So these policies and procedures are going to create the foundation from which

2:51our information security program will be built

2:53And if you're not familiar with policies and procedures, I did talk about

2:57policies before but policies

2:58Are basically the organization's stance

3:02Well, what they believe in as far as a particular topic and it could it could

3:07it could be data privacy

3:08It could be password protection or it could be

3:11Asset management it could be the lots of different things, but it's going to be

3:15a

3:16Non-technical approach to this stance. So I do want to put that. They're

3:20generally non-technical

3:22So for example, if we had a policy that was a password policy

3:27And this policy just basically meant that

3:30We as an organization believe you should use secure passwords and we'll follow

3:35industry best practices

3:37As far as what a secure password means. So right there

3:41We kept it pretty generic and non-technical. It just means that we want to use

3:44secure passwords in our organization

3:46Perfect. Hey, that's a great policy. Now

3:50Procedures

3:52This is the technical

3:54How to when it comes to carrying out our policies. So here

3:59It would say on systems

4:01We need to configure them to require a password of so many characters in length

4:07And maybe it expires every six months or maybe it doesn't expire. It just

4:10depends on what industry best practice is

4:13So here we have in our policy our kind of generic non-technical stance on

4:19something

4:19And then in our procedures, that's our how to carry this out

4:24How to take this and put it into production so that we are following policies

4:29And that is again is going to lay a foundation

4:32From which our information security program is going to be built

4:36All right, so that's one. Next is risk assessment program

4:40And now i'm going to get back on my soapbox about risk

4:44And risk management. So risk management

4:47We're going to see this over and over again. It is a key part of any

4:51information security program

4:53So we really need a dedicated program to risk assessment

4:58That's assessing the risk in our organization and that's going to feed into

5:02other things that we'll talk about later

5:04like risk mitigation and

5:06Implementing security controls and things like something called a risk appetite

5:11even so again

5:13There it's going to be risk assessment baked into our strategy then number

5:19three down here

5:20We're going to look at implementing security and risk frameworks

5:24So when you think of frameworks, I want you to think of a pattern and by a

5:30pattern

5:31I'm referencing maybe you're creating something you're going to

5:35Maybe you're a seamstress or something and you're creating a dress or a shirt

5:40and you follow a pattern

5:41Or you're cooking something you follow recipe, which is a pattern

5:45You're building something you might follow directions, which is really a

5:49pattern

5:50But the idea is

5:52If we can find a security framework and or risk framework that falls into our

5:57organization and how we do business

6:00We can use it as a pattern and what do we do with pattern? We end up with

6:04repeatability

6:05Which is key

6:08To business in general we want processes that are repeatable and using

6:13frameworks helps us to do that

6:16All right, then number four we've got asset management program

6:19And this is very important because we have lots of assets in our organizations

6:25Maybe thousands and tens of thousands of them or it might be like a hundred or

6:29two

6:29But the idea is we need to be able to from an information security standpoint

6:34Properly manage our assets and think of the assets this way servers

6:38Computers workstations laptops

6:41Wireless devices iPads, you know tablets all these things phones all of these

6:47pieces of technology

6:48fall under asset management

6:51And it's important that we manage our assets because we need to know

6:56What we have if we don't know what we have we can't protect it

7:00Because we need to ensure these devices are securely configured

7:03We don't want devices coming in our environment on our networks that are not

7:07properly protected

7:09So again asset management program

7:11And then finally we're going to see this several times our disaster recovery

7:16and our business continuity plans and practices

7:20Because we know that someday something's going to happen

7:23So having a disaster recovery and a business continuity plan that are up to

7:27date

7:27Is going to help minimize the impact that those events have on our organization

The Importance of Strategy

0:00So, as we focus on strategy, we first need to define where we want to be.

0:05So, let's answer that question.

0:08Where do we want to be?

0:10And one of the good ways to do this is to consider choosing a framework of some

0:17sort

0:17to help us along the way because these frameworks are generally industry

0:22standards and they're

0:24proven.

0:25Okay?

0:26And again, think of the framework as a pattern that we can follow.

0:29So if I want to go out and take a look at various frameworks, where can I go?

0:32Well, you can just go out and Google frameworks for and then put in your

0:36specific industry.

0:38Okay?

0:39Maybe it's banking or healthcare or financial or whatever it might be.

0:43So, let's talk about some common frameworks pretty briefly.

0:46So, the first one I want to talk about is from Isaka.

0:51And it is the COVID framework.

0:53Okay?

0:54So, that's one from Isaka.

0:56You have ITIL.

0:58ITIL has various frameworks such as the IT service management best practices,

1:03all right,

1:04which is great.

1:06We also have the ISO 27001 right down here that we see the image for and this

1:11is focusing

1:12on information security management.

1:15What about HIPAA?

1:16If you're not familiar with HIPAA, it is a framework for protecting healthcare

1:21information.

1:23And here we're talking about patient data.

1:26There's also, put down here NIST 800-53.

1:32And NIST is the National Institute for Standards and Technology.

1:35And they create hundreds of different standards.

1:38And this is just one of them.

1:39And this is focusing on security and privacy controls for information security.

1:44And the DOD here in the US, the government and government contractors have to

1:47follow

1:47this.

1:48This is a very popular one.

1:50There's the CIS top 20, also known as the SANS top 20.

1:55And it outlines the top 20 security controls that you should have in your

1:58environment.

1:59Another one is PCI DSS.

2:02And this focuses on credit card data.

2:05So if you handle credit card data, you may have to follow some PCI DSS

2:10standards.

2:11And it just depends on the amount of transactions you're dealing with.

2:16If you're actually working with credit card data or if it's on your network or

2:20maybe it's

2:20not even on your network, so you don't have to deal with it.

2:23So that's just another one, but that focuses on credit cards.

2:26And we're going to discuss these more in depth later on.

2:30So don't get too enamored with this right now.

2:33It's just the idea that when you're deciding where do you want to be, choosing

2:37a framework

2:38is a great place to start.

2:41Okay?

2:42So moving on.

2:43So how do we figure out where we're at?

2:47So we know where we want to be.

2:48We've chosen something.

2:49Let's say we went with the ISO 27001.

2:52And that's where we want to be.

2:53So how do we figure out where we're at?

2:56Because I can't come up with a strategy until I know where I'm at.

2:59So how to figure out where we're at?

3:01Well we can perform some assessments.

3:04You might call them self audits.

3:06So assessments are how we're going to figure out where we are at.

3:11Okay?

3:12And there's different types of assessments.

3:13So there could be risk assessments.

3:16Have threat assessments.

3:18Compliance assessments.

3:21And within a security assessment, in particular, we're talking about things

3:25like policies and

3:26procedures, standards, guidelines, controls, metrics, insurance, business

3:31impact analysis,

3:32audit results, all kinds of things.

3:34And we're going to get into that.

3:36If I don't write it down here, then you don't need to really remember it at

3:38this point.

3:39We're going to get into that.

3:40All right.

3:41So we need to know where we're at because then comes the next part, creating a

3:45strategy.

3:46But how do we do that?

3:47Well, here we go.

3:48How do we get to where we want to be?

3:50That is going to define our strategy.

3:53I love it.

3:54So we know where we're at because we just performed some assessments.

3:57We know our desired state, which in this instance is ISO 27001.

4:03And we performed our assessments over here.

4:06That's how we know where we're at.

4:07So what we need to do is perform a gap analysis.

4:11And a gap analysis simply means, what do I have to do to get from my current

4:14state to

4:15my desired state?

4:16Do I need to practice pickleball more than two times a week?

4:20Do I need to work out more and gain a better strength for pickleballs?

4:24Do I need to play more tournaments and against better players?

4:27You see where I'm going with this.

4:29But as far as information security, what do I have to do to get from my current

4:32state

4:32to my desired state?

4:34And that's performing a gap analysis.

4:37And that gap analysis output is going to be our strategy because it's going to

4:43give

4:43us what we need to do to get from our current state to our desired state.

4:49So let's wrap this up with some key points that we need to adhere to.

4:53All right.

4:54And there are four of them.

4:55Number one is strategic alignment.

4:59And when I say strategic alignment, this is all the efforts that you're putting

5:02into

5:03this.

5:04They have to be in alignment with the organizational goals.

5:07So in alignment, next up is manage risk.

5:11So we've talked about risk several times and risk management is a must for any

5:15decision

5:16making that happens.

5:17You need to identify risk and decide how you're going to deal with it.

5:21So when it comes to identifying our strategy, we need to make sure it's in

5:24alignment with

5:25our organizational goals.

5:26We need to manage risk that could be associated with the steps that we're

5:30taking.

5:30We also need to manage resources.

5:33For example, if ISO 27001 said I need to do XYZ, well, I can't take all the

5:39folks working

5:40in information security in our company here and put them into creating policies

5:46and procedures

5:47for XYZ because then they would ignore the regular job.

5:51So again, we have to balance.

5:52And when it comes to resources, balance is a key point because you still have

5:57to maintain

5:58your current status quo, but you're also looking to improve and strategize and

6:04grow.

6:05So you need to balance your resources.

6:07And then lastly, we've got to measure performance because if you're not

6:10measuring it, then we

6:11cannot see how we're actually doing it.

6:13We've got to collect that performance data.

6:16Then we have to analyze that performance data so that we can make sure that we

6:21are actually

6:21making progress.

6:23So there you go.

6:24These are some key points to adhere to when it comes to your information

6:27security strategy.

Information Security Frameworks

0:00In the last nugget, we talked about strategy.

0:02And the first thing you need to do is go ahead and set your objectives.

0:05What's your goal?

0:06Where do you want to be?

0:07And one of the ways to do that was choosing a security framework.

0:10And I had mentioned some in the last nugget and I said, we were going to go

0:14into detail on them.

0:15And that's what we're doing today.

0:16All right.

0:17Let's get started.

0:18The first one we're talking about is COVID.

0:20And COVID is from Isaka, which you should definitely know.

0:24And it's an IT management framework.

0:29And it focuses on IT processes, not only security processes.

0:34So it's not just security.

0:36It's also IT.

0:38So that's the first one.

0:40The second one is our ISO, IEC 27001 for information security management.

0:46And this focuses on the continual improvement of your information security

0:51program.

0:52And it focuses a lot on risk management, which is a huge part of information

0:58security

0:58as you already know.

0:59And its requirements are pretty generic actually.

1:03So it can be used in a lot of different environments.

1:06And that's why it's so popular.

1:09It's because it's not super focused on one industry.

1:13All right.

1:14Moving on, here we have ITIL, not ISO, IEC 20,000.

1:19And ITIL was who created it.

1:21And now ISO, IEC manages it.

1:24And this is a framework that focuses on the IT management processes.

1:29And this is actually a process framework, not security specific.

1:36So it's really focusing on IT and not necessarily IT security.

1:41But it does help us to create a solid foundation within IT and its processes

1:47from which your security program can grow.

1:51So it's really focused on IT and not so much on security.

1:54Next up is HIPAA.

1:56And this is our Health Insurance Portability and Accountability Act.

2:00And this is within the US and it covers the protection of EPHI.

2:05So put that down, EPHI.

2:07And that is electronic protected health information.

2:10And so what does that mean?

2:13Well, we're talking about patient data.

2:15So when you're dealing with medical systems like electronic medical records

2:21and electronic health information systems, EMRs and EHIs, what those are doing

2:27is

2:27they're basically using patient data within them.

2:30And the doctors use these systems to track into input data and to create

2:35reports and

2:36such, but they're in electronic format.

2:38So we're moving away from the paper.

2:40Now HIPAA still protects the idea of all protected health information.

2:47It's just that EHI is just a newer form of that.

2:51So HIPAA still does protect your paper records no matter what format your

2:56health

2:57information is in HIPAA protects that.

3:00That's what it's there for.

3:01So that means all the health care providers out there, hospitals, clinics,

3:04physical therapy offices, dentists, eye doctors, health insurance providers,

3:10anybody that deals with patient information, they must abide by HIPAA within

3:15the US.

3:16And that includes other companies too, like there's document management

3:19companies

3:19where let's say a hospital will take their paper records and they will send

3:26them

3:26to an imaging facility where a company will digitize those images and then send

3:33them back.

3:33Well, guess what?

3:34This company down here, this imaging facility, they must follow HIPAA because

3:39they're managing patient information.

3:41So that is HIPAA moving on.

3:45We've got the NIST 853 and this is the security and privacy controls for

3:52federal information systems and organizations.

3:54So I'm going to put it over here, federal and US.

4:00Okay.

4:01So here in the US, our federal, meaning all government agencies have to follow

4:05in NIST

4:06853 and it's security and privacy controls.

4:09So all the US government agencies have to follow this.

4:14All the US Department of Defense or DOD contractors, they have to follow this.

4:18And it contains 18 different categories of controls.

4:22So it could be things like standard configuration, asset management, disaster

4:28recovery, all these different things fall under these categories.

4:32So if you're dealing with the federal space, then you're going to want to look

4:36at it.

4:36NIST 853.

4:38Next up is our NIST Cybersecurity Framework and this being the National

4:43Institute

4:43for Standards and Technology created a cyber security framework.

4:47And this is a risk based framework.

4:49And it's used to identify, assess and manage cyber risks.

4:55So again, it's really looking at risks.

4:59It focuses on using business drivers to guide cybersecurity activities,

5:04including

5:04risk management and it focuses on identifying, protecting, detecting,

5:11responding and recovering, all that falls within that NIST Cybersecurity

5:17Framework.

5:17Next up, we have right here, CIS Top 20, AKA, I'll put up here, AKA, SANS Top

5:2520.

5:26That's just kind of a nickname and you'll see it.

5:28So if you see Top 20, that's probably going to be this information.

5:31And this is the Top 20 Security Controls and Organizations Should Use.

5:36So this includes things like your inventory control.

5:41So you got inventory of your hardware and your software, vulnerability,

5:44management,

5:45controlling administrator privileges, secure configurations, data recovery and

5:50data

5:50protection, malware defenses.

5:52I mean, the list goes on and on.

5:54You can just Google the SANS Top 20 or the CIS Top 20.

5:58All right.

5:59And we're going to wrap this up with the PCIDSS.

6:02That's our payment card, industry data security standard.

6:04And this is dealing with credit cards and their data.

6:09This standard is aimed at the protection of that credit card data and

6:14compliance

6:14with PCIDSS is mandatory for all organizations that store, process or transmit

6:21credit

6:21card data.

6:21So that is store, process or transmit.

6:25That's our credit card data there.

6:27And compliance requirements change based on the number of transactions or the

6:32amount

6:33of credit card data that is stored.

6:34So it's going to be different from company to company.

6:37So those are some of the more common security frameworks that you should be

6:41familiar with.

Strategic Objectives

0:00So we talked about an information security strategy and how to come up with

0:04that strategy because you identify what our goal is or objective

0:07We're right now. We perform the gap analysis and we have our strategy. All

0:11right, so let's talk about managing our

0:14strategic objectives

0:17Because we can't just say we have these objectives and we come out and we say

0:20we're doing number one and two and three and four

0:24And you know the list goes on on

0:26We can't just go out and blindly do that because we need to make sure that each

0:30step along the way is the right step

0:33And we're doing it the right way

0:35Because we know that we have risks involved with all kinds of things

0:39So we need to be mindful one of the tools that we can use is called SWAT

0:44Analysis and SWAT stands for strengths weaknesses

0:48opportunities and

0:51threats

0:52So let's talk about how we go about doing this. So a SWAT analysis is a tool

0:58that we use for strategy planning and

1:00It's used to study a specific area of an organization or a step that you're

1:05going to take and determine it's well

1:08It's SWAT

1:09So we do SWAT to analyze individual processes or steps that we're taking so let

1:14's kind of go through this process here

1:15So let's say we want to perform a SWAT analysis for I'm gonna put over your

1:21cloud security

1:22Okay, because in the last year we have moved a few of our services from on

1:29premise up into the cloud

1:31So let's go ahead and take a look at performing a SWAT analysis of cloud

1:36security for our organization

1:38Excuse me a simple little walkthrough. So we're starting with strengths

1:41So there we go

1:44Strengths our strengths is that we have cloud engineers on staff. So we have

1:50Engineers that is a strength. So we have the technical ability and know-how to

1:56properly manage our cloud

1:58environment

2:00Okay, and we have off cloud backups and this simply means that our backups are

2:07not stored in the same cloud vendor as our data

2:10So they're being secured somewhere else, which is good. It's definitely a

2:14strength now

2:15Let's talk about weaknesses. Well, our weaknesses is that we don't have a

2:19security program specific to the cloud

2:21So we say no cloud

2:23Security program, okay, that is definitely a weakness

2:28Because we simply don't have any security policies about the cloud either. So

2:33that's something we need to consider

2:35Let's talk about opportunities

2:37So when it comes to opportunities, these are here to help us strengthen

2:41whatever we're analyzing with SWAT

2:43And so in this instance, what can I use to help me strengthen?

2:47My cloud security stands. Well, I could adopt the framework. So what I'm gonna

2:52put down here is

2:53ISO

2:5627

2:5817, okay, and this is a framework about security controls in the cloud. So I'll

3:04put down here cloud

3:06Sick framework. This is definitely an opportunity that I can use to help me get

3:11to where I need to be as far as cloud

3:13Security and lastly threats. Let's put some threats in here that we need to be

3:18concerned with now

3:19The first one I'm gonna put is misconfigurations and that's due to human error.

3:25Okay, that's definitely one and

3:27Because we don't have a security program aimed at the cloud

3:31We're not gonna be able to identify and fix these errors that are here and they

3:36could lead to a security incident or even a security breach

3:38So this is how we go about performing a SWAT

3:42So here we see that if we take advantage of our opportunity here and we were to

3:47implement that ISO

3:4827,017 and become

3:51compliant with that it would really change the way that our cloud security

3:55looks compared to what it looks like today

3:58So this would become part of our strategy then because as part of our strategy

4:02for obtaining cloud security

4:05We're going to implement ISO

4:0827,017 and become compliant with it and it's at that point that we can then go

4:14and perform another SWAT analysis on the same

4:17situation where our strength would have appear ISO 27,017

4:25compliant so then we could see that our weaknesses would change because we

4:30would have a secure cloud program

4:32We would be able to identify misconfigurations and you'll see how this goes. We

4:37're continually looking to improve upon our

4:40cloud security in this instance

4:42All right, so that is one tool that we can use that is called the SWAT analysis

4:49another tool is

4:51our CMM capability maturity model and what this is it is right here a

4:57scale of maturity

4:59So let's take a look at this and we'll stick with the idea of our cloud

5:04security that we don't have at this point in time in our

5:07Organization so this right here our CMM helps us understand the maturity of a

5:12process on a scale of one to five

5:15So you see here we have the one is initial two is repeatable three is defined

5:21Four is managed and five is optimized so each one of these mean something

5:25different obviously

5:27So level one is initial and that means that the process is in consistent

5:32It's not being measured and it's not repeatable. So it's basically our cloud

5:36security at this point

5:38So we could put cloud security and if we had set processes up around it it

5:42would be at initial

5:44It would simply mean that we are in the infancy of this process and as we grow

5:49We want to get up to number two which is repeatable so that we can repeat the

5:53process we can consistently perform

5:55Our process with the same outcome and then if we get to two then we look to

6:01jump up to number three

6:02And this is where it is defined. It's well defined and well documented

6:06So that means we are not only able to reproduce it so it is repeatable

6:10But we also have documentation we have processes and procedures defined and

6:16then as we grow at this point with managed

6:19We add in metrics

6:21Okay, and that helps us to then we can monitor and we can analyze those metrics

6:27and make sure that we are doing things right

6:29And then lastly five is optimized and this is the idea of continuous

6:34improvements being made

6:35All right, and so down here I'm gonna put documentation

6:38for number three all right super so one thing you should understand is that not

6:45all

6:46Processes will make it appear to optimize and that's okay

6:49The idea is we want to continuously improve and if we can get to where we're

6:54having metrics and we're managing it

6:56Then that's pretty good

6:58But sure we shoot for five but we won't always make it there and it's just how

7:02it is

7:03So this model helps us to see where we're at and what we need to work on so let

7:07's talk about next up our road map development

7:10This is another tool and if you've seen this if you've done anything with

7:14project management

7:15You know, this is a Gantt chart GAN double T and the idea is as part of our

7:20roadmap development with our strategy

7:22We can outline our steps with our strategy

7:26So we've got our steps here and this is where we're listing them out on our

7:30road map so that we can visualize and track our

7:33Progress and usually it is based on a timeline like we see here

7:38We have days of the month here and we see each step is associated with a

7:42specific time

7:44Okay, and this here that you see again is a Gantt chart

7:47And that's one way to use this again

7:49It just helps us to visualize and track progress towards whatever our objective

7:53is so road map development is another tool that we can use as

7:57far as

7:59Making sure that we're making progress with our strategy and we're able to

8:03track it and visualize it as well

8:05So these are some different tools that can help us along with our strategic

8:09objectives

Business Model for Information Security (BMIS)

0:00Welcome to the business model for information security, aka BMIS, and it is

0:06created by Iseca.

0:07And this is a guide for, I'm going to put up here in quotes, business-oriented

0:12approach.

0:13As far as an information security program goes, and it really focuses on the

0:21culture of the

0:22organization. So again, culture comes back into play in the first nugget in

0:27this skill we talked

0:28about the importance of culture. Now we're coming full circle back to the BMIS,

0:33which is really focused

0:35on culture. So let's talk about what we have here. So this is a diagram of the

0:43BMIS, and it uses a

0:44three-sided model like a pyramid defining four key elements. So up here at the

0:50top, we have organization,

0:52then over here in the bottom left, we have people, bottom right, we have

0:56technology, and then in the

0:58middle, we have process. So let's talk about these four things here. Now

1:02organization,

1:03this focuses on the organization as a whole, and how all the roles work toward

1:08a common goal.

1:09So all the roles here work toward again a common goal. Then when it comes to

1:16the people, well,

1:17these are the employees, the contractors, the consultants, all the people

1:21involved in reaching,

1:23that's right, the goal. And again, the culture here, we're focused on achieving

1:29the organization's goals. We have our technology in the bottom right here, and

1:34technology is simply

1:35a tool. It's the people and the processes using these tools that make them

1:40valuable in reaching

1:41our goals. And then finally, in the middle, we've got our process, and this is

1:47all the activities

1:48within the organization that help us to achieve. That's right, our goal. And

1:53our processes in here

1:56should be reliable and repeatable. And if you think back, we talked previously

2:03about the capability

2:06maturity model. And one of the things was in there, as you go through the

2:10levels from level one to

2:12level five is the repeatability of processes. And that's where we see this in

2:18the BMIS as well.

2:19So now we see each of the four key elements we notice here, that we have them

2:26all interconnected,

2:27and this is through DIs or dynamic interconnections. And each of these

2:32connections are how interaction

2:35between the four key elements works. So for example, between organization and

2:42the people,

2:43we have culture. Here's that word again. And then between organization and down

2:50here to technology,

2:51we have architecture, because we have to ensure that that technology there fits

2:57in with our

2:58architecture of our organization. Then between organization and our process, we

3:03have governing

3:04or governance, because we need somebody to watch over the processes to make

3:08sure that they're

3:09meeting our needs. Between people and technology, we have human factors that we

3:16need to take into

3:17account between people and process, we have emergence, and then between process

3:22and our technology,

3:24we need to make sure that they're enabled and we have support. So moving on, BM

3:30IS, it focuses on

3:33organizational culture. I'm really trying to drive this home. I want you to

3:38think, whenever you see

3:39BMIS, I want you to think culture, because that's really what it's focused on.

3:44The culture is the

3:45spirit of the organization. It's what drives the organization. And when it

3:51comes to BMIS,

3:52the primary objective of it, that's the number one objective over here, is to

3:57find out how to

3:59influence culture. Because if we can find out how to influence the culture, we

4:05can then steer it

4:07towards a security-based culture. And that would be beneficial for everyone.

4:14All right, now there

4:16are three key aspects of the BMIS. And the first one is alignment of

4:20information security with

4:22business objectives. And we've been saying this since the very beginning of

4:29this course that

4:30everything we need to do needs to be in alignment with the business objectives.

4:35Number two, it uses a risk-based approach. So risk is being taken into account

4:44as you go through

4:45and use the BMIS. And then lastly, it's a balance across the organization. And

4:53that means across

4:54the four key elements of the BMIS. So remember, we had appeared organization,

5:02we had people, we had

5:03technology and process in the middle. And we need to balance so that we can all

5:08work together

5:10to reach our goals. So finally, the $10 million question, why use BMIS? Well,

5:17it used to help better

5:18understand people, processes and technology. And what factors influence them so

5:26that you can

5:27influence culture. And again, it goes back to influencing culture. And knowing

5:34this, the business

5:35can drive the response they're needing to achieve their goals. And so well,

5:40that's BMIS in a nutshell.

Team training path

Turn this skill into assignable team training

This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.

What's next?

Ready to keep going?

For your team

Bring this training to your team

See how CBT Nuggets helps IT teams close skills gaps, hit compliance targets, and prove training ROI.

Book a Demo
Just need CISM?

Learning on your own? Browse individual plans ($49/month, billed annually)

Not ready to buy?
with no purchase required. Already have an account?
Book a Demo