IAS
Lesson 1: Comparing Security Roles and Security Controls
1. Information Security Basics
CIA Triad:
Confidentiality: Ensures that information is accessible only to those authorized to view it.
Integrity: Ensures that data is stored and transferred as intended, with authorized modifications only.
Availability: Ensures that information is accessible to authorized users when needed.
Non-repudiation: Ensures that subjects cannot deny creating or modifying data.
2. Information Security Competencies
Skills needed include:
Risk assessments and testing
Access control and user privileges
Incident reporting and response
Security training and education programs
3. Security Roles and Responsibilities
Chief Security Officer (CSO): Overall responsibility for security measures.
Chief Information Security Officer (CISO): Focused on information security strategy and execution.
Information Systems Security Officer (ISSO): Technical roles that include due care/liability responsibilities.
4. Security Operations Units
Security Operations Center (SOC): Monitors and responds to security incidents.
Computer Security Incident Response Team (CSIRT): Handles incident response and management.
5. Security Control Categories
Technical Controls: Implemented through software and hardware.
Operational Controls: Require human intervention.
Managerial Controls: Provide oversight on security systems.
6. Security Control Functional Types
Preventive: Restricts unauthorized access before an attack occurs.
Detective: Identifies and records intrusion attempts during an attack.
Corrective: Responds to incidents and repairs damages after an attack.
Physical Controls: Alarm systems and locks to deter access.
Deterrent Controls: Psychologically discourage attacks.
Compensating Controls: Serve as substitutes for primary controls.
7. Importance of Security Frameworks
Frameworks help in:
Assessing current security capabilities
Reporting compliance
Important frameworks include:
NIST Cybersecurity Framework (CSF)
Risk Management Framework (RMF)
ISO standards for information security management.
8. Regulations and Legislation
Key regulations:
Sarbanes-Oxley Act (SOX)
General Data Protection Regulation (GDPR)
Health Insurance Portability and Accountability Act (HIPAA)
9. Summary
Effective security roles and controls are essential for protecting information integrity, confidentiality, and availability.