null - iso 27001 : a business view

17
A Business View

Upload: sripati-ms

Post on 01-Dec-2014

382 views

Category:

Technology


0 download

DESCRIPTION

 

TRANSCRIPT

Page 1: Null - ISO 27001 : A Business View

A Business View

Page 2: Null - ISO 27001 : A Business View

Who Am IM.S.SripatiInformation Security Enthusiast and StudentISMS ImplementerCISA (cleared exam in June 2008)

Page 3: Null - ISO 27001 : A Business View

What Am I NOT going to talk aboutNothing technicalNothing on what is information security (this is NULL

chapter, for god sake!)Not much on some basic terms (Google devo bhav||)

Page 4: Null - ISO 27001 : A Business View

What Am I going to talk aboutSome cases where regular firewalls and web application

security measures failWhat is ISO 27001 and how does it helps us

Page 5: Null - ISO 27001 : A Business View

Can you save your organization from these cases?

Page 6: Null - ISO 27001 : A Business View

Someone using you ID card to enter into a secure premise and steal/alter/delete some information

Copy/paste by developerPassword sharingKevin Mitnick (!)Unlocked desktops/laptopsPassword re-useWriting passwords down on paperNatural CalamitiesLegal fines (in case of data breach – HIPAA, PCI-DSS)Work backlog in antivirus companiesSomeone trying to get your personal data so that he/she

can sell it in underground

Page 7: Null - ISO 27001 : A Business View

Some unknown third party vendor working on your computer;Someone asking for a password posing as client;Some random mail asking you to click so that you can receive

some money immediately;Social networking sites;Farmville and other third party apps;Employee having high access to data/information and who has

a shady past;No frisking of housekeeping personnel, putting information

systems at risk (think about hardware key-loggers)Taking pictures of code using a camera phone and third party

app on it (think about an android app AD)Data getting lost because of a natural calamity (fire, flood,

earthquake, etc) and having a business requirement to start work as soon as possible;

Page 8: Null - ISO 27001 : A Business View

So, what does it all mean?

Page 9: Null - ISO 27001 : A Business View

Noteworthy pointsChanging nature of security incidents;System ownage through an un-suspecting user click;Info-sec as a business, both legit, and non-legit;Human as a weak link in info-sec chain;Changing legal landscape (HIPAA, PCI-DSS);Changing business landscape (threats to India from

BRIC);

Page 10: Null - ISO 27001 : A Business View

Implementer’s Dilemma

Page 11: Null - ISO 27001 : A Business View

http://gallery.trupela.com/

Legal Compliance (HIPAA, PCI-DSS,

Data Protection Act)

Web Application Security

Human Awareness Quotient (Technical and Non-technical)

Network Security (Firewall, IDS, IPS,

Antivirus, etc.)

Page 12: Null - ISO 27001 : A Business View

Copied From:- http://pumapac.org/

Page 13: Null - ISO 27001 : A Business View

Saving Private Ryan

Page 14: Null - ISO 27001 : A Business View

What is ISO 27001Specifies the requirements for establishing a comprehensive

Information Security Management System (ISMS) helping to achieve information security and to give assurance to interested parties.

Interested Parties are-Share Holders / OwnersManagementEmployeesBusiness PartnersService providersContractorsCustomers / ClientsRegulators etc…

Page 15: Null - ISO 27001 : A Business View

InterestedParties

InterestedParties

InformationSecurity

Requirements&

Expectations

InformationSecurity

Requirements&

Expectations

PLANEstablish

ISMS

PLANEstablish

ISMS

CHECKMonitor &

Review ISMS

CHECKMonitor &

Review ISMS

ACTMaintain &Improve

ACTMaintain &Improve

Management ResponsibilityManagement Responsibility

ISMS PROCESSISMS PROCESS

PDCA Process

InterestedParties

InterestedParties

ManagedInformation

Security

ManagedInformation

Security

DOImplement &Operate the

ISMS

DOImplement &Operate the

ISMS

Page 16: Null - ISO 27001 : A Business View

Information Security Policy

Organisation of Information

Security

Asset Management

Human Resource Security

Physical Security

Communication & Operations

ManagementAccess Control

System Development &

Maintenance

Incident Management

Business Continuity Planning

Compliance

Confiden

tialit

y Integrity

Availability

Page 17: Null - ISO 27001 : A Business View

Thank You

M.S.Sripati