Monday, May 2, 2016

Requirements of an Incident Management Program


InfoSec incidents are unavoidable even in an organization which takes care of its information security extremely passionately. Incident management is a development of a well understood and predictable response to such damaging events and/or incidents. 

Like any other program, Incident Management Program needs to define and implement a process. The organization adopts this process in order to protect information assets, like IT infrastructure and information systems, if something bad happens. The incident response process depends on the security incident, which may involve malware breach and containment, information disclosure, data leakage, or a DDoS attackThis process in nothing but some detective and corrective safeguards to detect and then respond to such events and intrusions. Minimizing harmful impacts, gathering forensic evidence, and learning are other roles of these safeguards. Incident response team shall follow the above-mentioned process in case of an emergency security event or an incident. 

ISO 27K family of standards has a particular standard focusing on this issue: ISO/IEC 27035:2011, Information technology -- Security techniques -- Information security incident management

Another source might be NIST 800-61 entitled Computer Security, Incident Handling Guide. 

ISO 27001:2013 neither asks for implementation the program based on ISO 27035 nor the specifications in item A.16 of its controls. You can adapt any approach to put such a program in your ISMS.

A typical incident management program requires such steps: 
  • Prepare to handle incidents by having an incident management policy in place and establish a team to handle the incidents
  • Identify and report InfoSec incidents. This step can be performed by an employee, vendor, customer, partner, device, SIEM system or even a sensor. The problem should be reported to Incident Response Team or Security Operations Centers (SOC)
  • Evaluate, analyse and assess incidents including the criticality of the event in order to address them. Bear in mind that lots of issues might be a false positive so evaluation plays a big role here
  • Respond to incidents by either fixing the problem as quick as possible or collecting forensic evidences, even if it delays regular business operations. You definitely need a checklist or reference in case of handling an InfoSec incident.  Zeltser offers a series of free helpful cheat sheets for such purposes for Windows / Linux intrusions, DDoS attacks and more 
  • Investigate the problem in-depth after resolving and then document security weaknesses, report to senior management, and learn the lessons in order to change and improve the processes. Sometimes the problem should be reported to authorities or media as well in accordance with regulatory compliance laws and regulations

If you need a good source to help you in auditing an Incident Management Program, this ISACA document may help a lot. 

Labels: , , , ,

Wednesday, February 17, 2016

List of ISO 27000 Family Standards


The published ISO standards related to Information Technology - Security Techniques are:


Number Title Release Date Description
ISO 27000 Overview and vocabulary 2014 Provides terms & definitions commonly used in the ISMS family of standards
ISO 27001 ISMS Requirements 2013 Specifies an ISMS, a suite of activities concerning the management of information security risks
ISO 27002 Code of practice for IScontrols 2013 Guidelines for organizational ISMS including the selection, implementation and management of controls
ISO 27003 ISMS implementation guidance 2010 Guideline for successful design and implementation of an ISMS
ISO 27004 IS management - Measurement 2009 Security metrics for an ISMS
ISO 27005 IS risk management 2011 Provides guidelines for IS risk management
ISO 27006 Audit and certification of ISMS 2015 Specifies requirements and provides guidance for bodies providing audit to get certification
ISO 27007 Guidelines for ISMS auditing 2011 Provides guidance on managing an ISMS audit program and conducting the audits
ISO 27008 Guidelines for auditors on IS controls 2011 Provides reviewing the implementation and operation of controls
ISO 27010 IS management for inter-sector and inter-organization 2015 Provides additional guidelines for implementing ISMS within information sharing communities
ISO 27011 ISMS for telecommunications organizations 2008 Recommendations for implementation of ISMS in telecommunications organizations.
ISO 27013 Integrated implementation of ISO 27001 & ISO 20000-1 2015 Guidance on the integrated implementation of ISO 27001 and ITIL
ISO 27014 Governance of information security 2013 Provides guidance on concepts and principles for the governance of IS
ISO 27015 IS management guidelines for financial services 2012 Additional controls to ISO 27002 for organizations providing financial services
ISO 27016 IS management - Organizational economics 2014 Provides guidelines on how an organization can make decisions to protect information and understand the economic consequences of these decision
ISO 27017 IS controls for cloud services 2015 Additional implementation guidance for controls specified in ISO 27002
ISO 27018 protection of PII in public clouds 2014 Provides guidance to ensure cloud service providers offer suitable IS controls to protect the privacy of their customers’ clients.
ISO 27019 IS management for energy utility industry 2013 Additional controls to ISO 27002 for organizations in energy utility industry
ISO 27031 ICT readiness for business continuity 2011 Provides guidance on the principles behind the role of ICT in ensuring business continuity
ISO 27032 Guidelines for cybersecurity 2012 Provides guidance for improving the state of Cybersecurity
ISO 27033 Network security Different Set of standards provide detailed guidance on the security aspects of the management, operation and use of computer networks
ISO 27034 Application security Different Set of standards provide guidelines on IS to those specifying, designing and programming or procuring, implementing and using application systems
ISO 27035 IS incident management 2011 Provides guidance on IS incident management for large and medium-sized organizations
ISO 27036 IS for supplier relationships Different Set of standards provide guidelines on IS risks involved in the acquisition of goods and services from suppliers
ISO 27037 Digital evidence 2012 Guidelines for identification, collection, acquisition and preservation of digital forensic evidence
ISO 27038 Specification for digital redaction 2014 Techniques for performing digital redaction on digital documents
ISO 27039 Intrusion Detection Systems (IDPS) 2015 Selection, deployment and operations of intrusion detection systems (IDPS)
ISO 27040 Storage security 2015 Provides detailed technical guidance for organizations to design, document, and implement data storage security
ISO 27041 Assuring suitability and adequacy of incident investigative method 2015 Provides guidance on mechanisms for investigation of IS incidents
ISO 27042 Analysis and interpretation of digital evidence 2015 Provides guidance on the analysis and interpretation of digital evidence for continuity, validity, reproducibility, and repeatability
ISO 27043 Incident investigation principles and processes 2015 Provides guidelines based on idealized models for common incident investigation processes
ISO 27799 IS management in health 2008 Additional controls to ISO 27002 for organizations in helthcare industry

Labels: , ,

Wednesday, October 21, 2015

How to Get ISO 27000 Certification in 6 Steps?


Getting certified for ISO 27001 certification is not necessarily complicated or expensive. It needs time, effort and support of senior manager(s). 
You also need attention to details and proper documentation and forms.


Step 0. Decision

Senior manager(s) need to be behind the decision for ISO 27000 implementation and support it in each and every step. 


Step 1. Defining Scope of Implementation

Scope of implementation should be defined as well as the operational and functional boundaries.


Step 2. Documentation

Like ISO 9000, ISO 27000 needs comprehensive documentation in order to address all applicable millstones and administrative, technical, and physical controls. 
These documents will be used to check weather or not the organization meets ISO 27000 requirements. These documents would be a policy (or set of policies), and its related procedures and guidelines to ensure the business is adhering to ISO requirements in an efficient and achievable way. ISO 27002 standard would be a huge help to prepare such documentation but in is not necessary to select the controls from ISO 27002 text. 

At least 15 different documents are required for ISO/IEC 27001:2013
  1. Scope of ISMS (item 4.3, Page 1)
  2. Policy (item 5.2, Page 2)
  3. IS Risk Assessment process (item 6.1.2, Page 3)
  4. IS Risk Treatment process (item 6.1.3, Page 4)
  5. IS Objectives (item 6.2, Page 5)
  6. Evidence of the competence of the people doing work on IS (item 7.2, Page 5)
  7. Other documents deemed necessary by the organization for ISMS (item 7.5.1b, Page 6)
  8. Operational Planning and Control Documents (item 8.1, Page 7)
  9. Results of IS Risk Assessments (item 8.2, Page 7)
  10. Results of IS Risk Treatment (item 8.3, Page 7)
  11. Documented information as evidence of the monitoring and measurement results (item 9.1, Page 7)
  12. Internal audit program plus audit results. (item 9.2, Page 8)
  13. Documented information as evidence of top management review (item 9.3, Page 8)
  14. Evidence of nonconformities identified, actions taken and the results (item 10.1, Page 9) 
  15. Other documentations might be needed: rules for acceptable use of assets, access control policy, operating procedures, confidentiality and nondisclosure agreements, secure system principles, information security policy for supplier relationships, information security incident response procedures, regulations and contractual obligations, associated compliance procedures, and information security continuity procedures.
Auditors will check that above-mentioned documentation are present, up-to-date and fit to ISMS scope. 

Step 3. Realization

By applying Gap Analysis, comparison of actual performance with desired performance and documentation, it is time to make sure that the company is following all procedures and guidelines. 
We'd better conduct a pre-assessment in order to make sure that the organization is on the right track. Pre-assessment can be conducted by using pre-assessments forms, gathering of evidences and filling checklists. Another key to have a successful realization step is to communicate with all employees about the processes in place and the need to adopt them fully and report back on all discrepancies.


Step 4. Internal Audit

An experienced internal or external auditor is needed for this step. Some audit tools like forms and checklists are needed for such a job. 


Step 5. Certification Audit

ISO does not perform certification for ISO 27001. Certification companies like SGS, TÜV Rheinland or BSI can do the audit and issue the certificate for you. 

Step 6. Maintaining the certification

In order to maintain the ISMS working, the organization should integrate it into daily operations. Continual improvement and change management are other essential parts of this ongoing step. 

Labels: , ,