IAS

Lesson 1: Comparing Security Roles and Security Controls

1. Information Security Basics

  • CIA Triad:

    • Confidentiality: Ensures that information is accessible only to those authorized to view it.

    • Integrity: Ensures that data is stored and transferred as intended, with authorized modifications only.

    • Availability: Ensures that information is accessible to authorized users when needed.

  • Non-repudiation: Ensures that subjects cannot deny creating or modifying data.

2. Information Security Competencies

  • Skills needed include:

    • Risk assessments and testing

    • Access control and user privileges

    • Incident reporting and response

    • Security training and education programs

3. Security Roles and Responsibilities

  • Chief Security Officer (CSO): Overall responsibility for security measures.

  • Chief Information Security Officer (CISO): Focused on information security strategy and execution.

  • Information Systems Security Officer (ISSO): Technical roles that include due care/liability responsibilities.

4. Security Operations Units

  • Security Operations Center (SOC): Monitors and responds to security incidents.

  • Computer Security Incident Response Team (CSIRT): Handles incident response and management.

5. Security Control Categories

  • Technical Controls: Implemented through software and hardware.

  • Operational Controls: Require human intervention.

  • Managerial Controls: Provide oversight on security systems.

6. Security Control Functional Types

  • Preventive: Restricts unauthorized access before an attack occurs.

  • Detective: Identifies and records intrusion attempts during an attack.

  • Corrective: Responds to incidents and repairs damages after an attack.

  • Physical Controls: Alarm systems and locks to deter access.

  • Deterrent Controls: Psychologically discourage attacks.

  • Compensating Controls: Serve as substitutes for primary controls.

7. Importance of Security Frameworks

  • Frameworks help in:

    • Assessing current security capabilities

    • Reporting compliance

  • Important frameworks include:

    • NIST Cybersecurity Framework (CSF)

    • Risk Management Framework (RMF)

    • ISO standards for information security management.

8. Regulations and Legislation

  • Key regulations:

    • Sarbanes-Oxley Act (SOX)

    • General Data Protection Regulation (GDPR)

    • Health Insurance Portability and Accountability Act (HIPAA)

9. Summary

  • Effective security roles and controls are essential for protecting information integrity, confidentiality, and availability.