Acceptable Use Policies (AUP)
- What is acceptable use of company assets
Incident Response Roles
- IR team
- IT security management
- Compliance officers
- Technical staff
- User community
Software Development Lifecycle (SDLC)
- Details ways to get from idea to app
- Change management
Security Standards
- formal definition for using security technologies and processes
Regulatory Considerations
- Sarbanes-Oxley Act (SOX)
- all financial data is protected and accessible to authorized data
- HIPAA
- same for medical data
Data roles
- data controller
- manages the purpose and means by which personal data is processed
- data processor
- processes data on behalf of the data controller, often 3rd party
- data custodian
- responsible for data accuracy, privacy, and security
Risk Analysis
Qualitative Risk Assessment
- Identify risk factors (usually visually)
Quantitative risk assessment
- value calculated
- ARO (Annualized Rate of Occurence)
- Asset value (AV)
- Exposure Factor (EF)
- percentage of value lost due to an incident
- Single Loss Expectancy (SLE)
- AV * EF
- Annualized Loss Expectancy (ALE)
- ARO * SLE
Risk appetite
- risk-taking deemed acceptable
- risk appetite posture
- description for readiness to take risk
risk tolerance
- an acceptableness variance from the risk appetite
e.g. speed limit of 55 is our risk appetite, risk tolerance the speed at which you will be ticketed
Risk register
- every project has a plan but also a risk
- identify risks that could impact org, gives risk owners, and risk thresholds
Business Impact Analysis
Recovery Time Objective (RTO)
- get back to particular service lelvel
Recovery Point Objective (RPO)
- how much data loss is acceptable
- when bringing back systems, how far back does the data go?
Mean Time to repair (MTTR)
- average time required to fix an issue
Mean time between failures (MTBF)
- time between outages
- uptime divided by number of breakdowns
Third-party assessment
Right-to-audit clauses
- should be in contract
- have the option to perform a security audit at any time
Have a third-party perform an audit
supply chain analysis
- system involved when creating a product
Agreement Types
Service Level Agreement (SLA)
- Minimum terms for services provided
- uptime, response time agreement, etc.
Memorandum of understanding (MOU)
- both sides agree in general to the contents of the memorandum
- states common goals but not more
- informal letter of intent, not a contract
Memorandum of Agreement (MOA)
- next step after a MOU
- both sides conditionally agree to the objectives
- can be a legal document
- but not contain legally enforceable promises
Master Service Agreement (MSA)
- legal contract and agreement of terms
- framework for later transactions
Work order (WO) or Statement of Work (SOW)
- specific list of items to be completed
- used with MSA
- details scope of the job, location, etc.
Non-disclosure agreeement (NDA)
- confidentiality agreement between parties
- information should not be disclosed
- unilateral or bilateral
Business Partners Agreement (BPA)
- going into business together
- financial contract
- who makes the business decisions?
Compliance
Meeting the standard of laws, policies, and regulations